Water system controllers don't belong on the internet, says ex-NSA chief

Former NSA chief Paul Nakasone has warned that critical US water infrastructure is highly vulnerable to cyberattacks because many programmable logic controllers (PLCs) are improperly connected to the internet. Security experts suspect Iranian-linked actors are behind recent disruptions, highlighting the need for better cybersecurity standards in underfunded municipal systems.
Why it matters
The vulnerability of essential public utilities to state-sponsored cyber warfare poses a significant threat to national security and public health.
With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON.
“We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.”
In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices , which monitor sensor data like tank levels, and can turn pumps on and off, for years .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in