> failed to anticipate not only these infrastructure breach
They've been warning them for close to two decades.
Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.
Passing the buck to the Federal Government is not understanding the problem.
What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment?
I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comment.
> make the feds do it
National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a war with another country they’re absolutely responsible for minimizing by collateral damage at a fucking minimum.
NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.
I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.
And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.
I'll say, you should see the hours I have to work sometimes. Honestly I've rarely seen IT jobs pay OT.
It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly.
> But what does that fundamentally mean for boots on the ground?
How does any regulation look on the ground? How does the federal government regulate banks and airports?
> these are for the most part, not federal government funded entities nor government controlled even at a state level
Neither are banks or airports
> What about Energy? Data Centers? Pharma?
Energy and pharma are already regulated. Maybe data centers will be eventually if they are deemed sufficiently critical.
> Regulation is way too far behind to just instantly drop a silver bullet.
I don’t know what this even means in the context of securing our water system. Do you mean to say that regulation can’t ensure that these software systems don’t use default passwords and so on?
> And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI
What is new is that we started a war with a country with a respectable technology competency without doing anything to shore up our defenses.
It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.
It needs some real backing and effort to make it happen.
Top down regulation drives the systematic change, just like it did with the banking sector.
> It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.
I'm not sure how this analogy works. What's the ATC equivalent to leaving default passwords on critical infrastructure?
Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default passwords are a symptom, not the failure mode.
ATC is already federal, with the FAA running that. 20 years of regulation has not fixed the problems that still plague that industry: outdated equipment, short-staffed, a small niche talent and training pipeline, and people dying as a consequence of those systemic problems. That's even closer to my point. Making something regulated doesn't change the inherent problems inside the industry.