Cyber industry coalition urges federal action after suspected Iran-linked water hacks

AndreyPopov/Getty Images

The group called on CISA to impose baseline security standards across federal operational technology systems and pressed Congress to revive several stalled cyber initiatives.

An industry coalition representing operational technology cybersecurity firms and critical infrastructure operators on Friday called for a stronger federal response to a wave of cyberattacks against U.S. water systems, including suspected Iran-linked intrusions affecting more than 30 utilities in Minnesota.

The Operational Technology Cybersecurity Coalition urged the Cybersecurity and Infrastructure Security Agency to issue a governmentwide directive establishing baseline cybersecurity requirements for operational technology used across federal civilian agencies.

“No clearer call to action has existed in the operational technology space,” former CISA cyber policy official and OTCC Executive Director Tatyana Bolton told Nextgov/FCW.

The statement comes a day after CISA warned that hackers are increasingly targeting internet-exposed programmable logic controllers used by water and wastewater systems. The FBI said it is aware of cyber incidents affecting water and wastewater entities in at least seven states. 

OTCC’s main recommendation is for CISA to issue a Binding Operational Directive requiring federal civilian agencies to strengthen security across operational technology systems used in buildings and other facilities.

The directive would not apply to the local water utilities targeted in Minnesota, but the coalition contends it would establish stronger federal standards and encourage broader adoption across the private sector.

CISA did not immediately respond to a request for comment.

The group also called on Congress to renew the State and Local Cybersecurity Grant Program, extend the Cybersecurity Information Sharing Act of 2015 and support Andrew McClure in leading the Energy Department office responsible for protecting the power sector from cyber threats.

“By not extending this [state and local] grant program, Congress is leaving small towns to protect themselves from nation-state actors like Iran,” the coalition said.

The information-sharing law is set to expire at the end of September. OTCC said allowing it to lapse could make it harder for the government to identify large-scale cyber campaigns and warn potential victims.

The recent attacks follow years of warnings that Iranian and Chinese hackers have targeted vulnerable systems that support water, energy and other critical services.

“To date, we have been lucky that a more catastrophic incident hasn’t occurred,” Bolton said. “We can no longer rely on luck. We must act.”

Editor's note: This article has been updated to correct the coalition's call for Congress to support Andrew McClure.