Zero Excuses for Critical Infrastructure
There is NO and I mean ZERO excuses to not have a Programmable Logic Controller (PLCs) secure for government #criticalinfrastructure. This includes 🌊 water, 💩 waste, ⚡utilities/grid, and other important citizen-centric infrastructure.
It doesn't even matter whether this is over a 🛜 cellular network or wireline network (heck the network itself is also critical infrastructure). VPNs and private IP are a thing! I totally get the bad actors and the people factor is a bit different...hackers, foreign spies, and workers that mean to do harm. There are so many moving parts...
Security Remains an Afterthought or a Cost Constraint
📢Modems/Routers
📢PLCs
📢Smart Cameras
📢Servers and Gateways
For industrial and government, don't forget about valves, sensors, pumps, regulators, relays, controllers, processors....as there are an abundance that are "connected" to the Internet.
THE RESPONSIBILITY CHALLENGE
There is a national security vs. responsible party issue. A national security asset or interest may be owned and operated by a local or regional entity, as so many of the critical infrastructure remains at the state and local level. The control and management over essential government infrastructure can sometime sit with the most unsophisticated and budget challenged communities and local entities. While there may be #cybersecurity concerns, often you may find smaller and rural communities may not have the skilled personnel or financial resources to execute effectively.
There are resources out there...
CISA (Cybersecurity and Infrastructure Security Agency): As the primary defender of U.S. critical infrastructure, CISA offers extensive toolkits, including the CISA Cross-Sector Cybersecurity Performance Goals (CPGs). The CPGs provide a concrete, easy-to-read checklist specifically designed to help water, energy, and transportation utilities establish a baseline defense against nation-state hackers. CISA’s Joint Cyber Defense Collaborative (JCDC): A public-private partnership hub that releases joint security advisories (often co-authored with the FBI, NSA, and international allies) detailing the exact tactics, techniques, and procedures (TTPs) used by threat actors like Volt Typhoon.
cisa.gov
NIST (National Institute of Standards and Technology): NIST publishes foundational cybersecurity guidelines. For utility and government infrastructure, the gold standards are the NIST Cybersecurity Framework (CSF) and the NIST SP 800-82 (Guide to Industrial Control Systems Security), which outlines how to securely isolate OT edge devices from corporate IT networks.
nist.gov
AI Graphic created based on what I wrote...me as a marketer testing out the graphics of AI sometimes makes me giggle.