Why are U.S. utilities so vulnerable to cyberattacks?

When the streets of Muleshoe, Texas, flooded with water in January, most people probably didn’t blame Russian hackers.

But that’s exactly who was at blame, according to a report published this week by Google-owned cybersecurity firm Mandiant, which said Russia was responsible for hacks of water utilities in Texas as well as in France and Poland.

The January attack was far from the first to hit U.S. utilities. In December, Fast Company reported on U.S. National Security Council concerns that critical infrastructure providers could pose easy targets for hackers. 

But why are they so vulnerable to cyberattacks in the first place?

“They have proven to be a little vulnerable because they are private companies and hence the profit motive prevails,” says Alan Woodward, professor of cybersecurity at the University of Surrey. “Security is seen as a cost center.” That’s borne out by data compiled by the International Energy Agency (IEA) on the power sector, which found that there were more than 1,100 targeted attacks launched across the world in 2022.

The utilities sector seems uniquely understaffed, according to the IEA’s analysis: While the finance and insurance sector accounted for nearly 1% of all cybersecurity job postings in September 2022, and public administration 0.57%, power utilities languished behind at 0.49%. The average wage offered by the utility sector also pales into comparison to competing industries, which could mean it’s losing out on quality candidates.

The U.S. government has also failed to pass a number of legislative attempts to force utilities to adopt minimal cybersecurity standards. As a result, U.S. utilities are comparatively underprotected in comparison to their peers. “Compare that to the U.K. where we have a specialist government agency that focuses on such service providers and assesses them regularly,” Woodward says.

But the utilities sector also bears much of the blame here. “Utilities also have a lot of older equipment as they have lots of embedded systems and these tend to be updated less frequently simply because of scale,” Woodward says. That results in a Frankenstein’s monster of infrastructure that is built on top of shaky systems and is difficult to chart and understand—even for those tasked with doing just that. “People still haven’t got the message that they may be a way into a network,” says Woodward—meaning that some of the vulnerabilities may remain unspotted until they’re exploited by bad actors.

It all adds up to a worry for critical parts of our national infrastructure—and the latest attacks suggest little has changed. Though there is one silver lining: The IEA data shows that utilities boost spending on cybersecurity and hiring in the immediate aftermath of an attack… but then return back to a baseline shortly after.

https://www.fastcompany.com/91109661/why-are-u-s-utilities-so-vulnerable-to-cyberattacks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 10mo | Apr 19, 2024, 6:30:05 PM


Login to add comment

Other posts in this group

Why your IoT devices are the weakest link in security

The Fast Company Impact Council is a private membership community of influential leaders, experts, executives, and entrepreneurs who share their insights with our audience. Members pay annual

Feb 13, 2025, 1:30:05 AM | Fast company - tech
Meet the Bop House, the internet’s divisive new OnlyFans hype house

What if the Playboy Mansion was filled with OnlyFans content creators? That’s the pitch for the Bop House, a TikTok page that has gained nearly three

Feb 12, 2025, 11:10:10 PM | Fast company - tech
This Valentine’s Day, don’t fall for romance scams, Meta warns

If your social media suitor seems too good to be true, it might be a scam.

Facebook and Instagram parent company Meta Platforms is urging users to stay vigilant about “

Feb 12, 2025, 11:10:08 PM | Fast company - tech
‘I will never recover from this’: The internet is spiraling over the Duolingo owl’s untimely death

Duo, the infamous Duolingo owl, is dead. 

The language-learning app shared the news in a tongue-in-cheek post yesterday. The cause of death remains under investigation, but Duolingo

Feb 12, 2025, 8:50:05 PM | Fast company - tech
Hate speech dramatically increased on X under Elon Musk’s watch, researchers say

Hate speech on X dramatically increased during the several months that Elon Musk served as CEO when compared to the prior months, according to a new study.

The

Feb 12, 2025, 8:50:04 PM | Fast company - tech
SoftBank reveals $2.4 billion loss in Q3

Japanese technology company SoftBank Group Corp. reported a 369.2 billion yen ($2.4 billion)

Feb 12, 2025, 6:30:10 PM | Fast company - tech
SEC and Binance request 60-day pause in lawsuit as the agency shifts to be more crypto-friendly

The U.S. Securities and Exchange Commission is seeking to pause its high-profile lawsuit

Feb 12, 2025, 6:30:09 PM | Fast company - tech