OnDefend’s Aaron Rosenmund joined CNN to break down the recent wave of coordinated cyberattacks on U.S. water systems.
Full transcript below.
OMAR JIMENEZ, CNN Anchor/Reporter: A series of coordinated cyberattacks on water systems in at least a dozen states is raising real concern. Experts say years of underinvestment in critical infrastructure across America have left water utilities open to these attacks.
Now, officials say the intrusions have only led to water pressure drops and flooding at facilities, but have not compromised the safety of drinking water. Still, though, the successful hacks are raising questions about what sort of disruptions these hackers could cause in the future.
So, I want to bring in cyber security expert, Aaron Rosenmund. He’s Managing Director of Tradecraft and Programs for Cybersecurity Testing and consulting firm OnDefend. He also serves as a First Lieutenant and Cyber Warfare Officer in the Delaware Air National Guard. Appreciate you taking the time.
I just want to start with how vulnerable are American water systems to foreign cyberattacks. In your assessment?
AARON ROSENMUND, MANAGING DIRECTOR OF TRADECRAFT AND PROGRAMS FOR CYBERSECURITY TESTING, ONDEFEND: Yes, frankly, the answer is very vulnerable. They fall under Presidential Policy Directive 21, which covers a lot of sectors or 16 sectors of critical infrastructure that really matter towards humanity and National Security for the U.S., but the problem is, is that this type of technology, which we define as operational technology, wasn’t really made with cybersecurity in mind, right?
So, these bits of infrastructure, and particularly in these attacks, what we’re finding is there’s devices like this, these are called PLCs. Increasingly they have the ability to communicate with the internet. Now, they’re not really supposed to be connected to the internet because again, they weren’t made with cybersecurity in mind. But this instance and the reports we are getting today are seeing that these, these being directly connected to internet, a pretty unsophisticated attack was able to compromise them.
JIMENEZ: You know, a mayor from New Jersey City impacted by recent water hacks, told CNN he views this as modern warfare. And I know you recently took place or took part in the Defense Department’s largest annual unclassified cyber defense training event.
How is the U.S. military working to prevent and counter future threats? Or at the very least, what did you see as part of that exercise?
ROSENMUND: Absolutely, so part of the exercise called cyber shield largest unclassed exercise for cybersecurity in the world. I run the opposing force or the team that’s job is to come up with scenarios and emulate advanced attacks on our critical infrastructure and systems in the U.S. and so we do this every year. I’ve ran that team eight years in a row. Every year we do a different bit of critical infrastructure.
As part of this, years ago now, this is two years ago now, we focused on the water infrastructure, particularly. And one of the scenarios that we played out, like in this case, like you said, there wasn’t any public safety concerns or any concerns over the final impact of the compromise.
But the water systems affect much more than just the drinking water. They’re also used for cooling for data centers. And in one special case in the U.S. at Palo Verde, they’re used for the cooling system used for the nuclear reactors there, so, wastewater system from Arizona.
So, were digging in depth with industry partners, working with their engineers at Fortum nuclear plants to understand how these systems work and then where those vulnerabilities are, where they integrate with systems like municipalities’ water every year.
JIMENEZ: And, you know, you were showing me that device earlier. I’m not going to try and say it back to you. I’ll have you say it in a second here. But one of the things I think you were talking about and that other cyber experts have said or have raised, is that too much critical infrastructure remains directly accessible from the internet, which can create major security risks.
And I just wonder, tell us a little bit about the evolution, like, how did we get to that point? And can you take these systems offline without sacrificing efficiency?
ROSENMUND: Yes, that’s a fantastic question. It’s called a PLC or a Programmable Logic Controller. It’s really just what it takes beeps and boops from computers and makes us able to connect to the physical world, right? So, in this case, I can control a pump with a computer. This is the interface for that.
The way we got here is really, and if you think of COVID as a great example, everybody kind of had to go home, try to work remote. And that includes workers at municipalities, electric facilities, nuclear facilities everywhere.
So how do they manage those physical systems remotely? Connecting these things to the internet is one of the answers.
Now, that’s not where it started. It started way before that. As soon as we had the ability to make things convenient like that. But COVID definitely was like a bit of a Cambrian explosion of that kind of capability and access.
The real issue has been there’s an academic view of how we secure these industrial systems that I think the academic view has been overly estimated to be how it works in reality. And when we think about water systems, particularly, or that critical infrastructure, you know, some of these are really small counties that run the water systems or mom and pop shops that are like, you know, 20 employees or coop or and there’s thousands of them all across the U.S.
And so, though we have a capability or a directive like PPD21 that the federal government has resources and strategic initiative to invest in cybersecurity for these systems, there is a disconnect between how we get from that strategic initiative to actually testing these systems and make sure that they don’t have the vulnerabilities or they’re not connected to the internet like we’ve seen over the last month before our adversaries can.
JIMENEZ: Aaron Rosenmund, really appreciate you taking the time and saying that device’s name so I don’t have to. The insight incredibly interesting, thanks again, man.
ROSENMUND: Thanks for having me, thanks so much.