OTSecurity

NIST outlines secure remote access strategies to strengthen water and wastewater OT cybersecurity


The National Institute of Standards and Technology (NIST) published practical guidance to help U.S. water and wastewater utilities secure operational technology (OT) environments against cyberattacks targeting internet-facing systems and industrial control devices. The guidance outlines reference architectures using conventional firewalls and remote access servers, cloud-based access services for resource-constrained utilities, and encrypted system-to-system communications for automated OT environments. 

In an Oct. 1 blog post, NIST researchers CheeYee Tang, Robert Stea, and John Wiltberger highlighted recent attacks in which threat actors remotely accessed programmable logic controllers (PLCs) without authorization, seeking to change settings, reduce staff monitoring and control capabilities, and disrupt operations. The researchers said utilities need to manage cybersecurity risks across people, processes and technologies while ensuring that connectivity supporting modern operations is designed and maintained with security as a core priority.

NIST also emphasized importance of maintaining accurate OT asset inventories and announced a new project focused on OT asset management and visibility to help operators identify, inventory and manage systems requiring protection. Recommended safeguards include multifactor authentication, network segmentation, encryption, access controls, activity logging and monitoring.

The researchers also mentioned that NIST is launching a new project on OT Asset Management and Visibility. “Soon, we will issue a call for collaborators — asset owners, operators, and technology providers — to work with the NCCoE to demonstrate effective techniques for asset management in OT environments, including automated and manual asset discovery, inventory management, configuration management, and change management processes.” 

In June, NIST’s National Cybersecurity Center of Excellence (NCCoE) published NIST SP 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture (Operational Technology Remote Access), demonstrating approaches to securing remote access across utilities with different operational requirements and resources.  

The NIST post outlined that many consider utilities in terms of the physical plant made up of treatment systems, pumps, pipes, and tanks. But behind this physical infrastructure, there are staff monitoring and controlling system operations from computers or handheld devices. WWS personnel now have real-time visibility into what is happening across the entire system, including equipment and stations that may be miles away from the central treatment plant. These capabilities are accomplished by an underlying digital infrastructure, connecting physical systems via networked components such as supervisory control and data acquisition (SCADA), PLCs, and human-machine interfaces (HMIs).

“This digital transformation over the last few decades has led to an increase in efficiencies, improvements in operations, and reductions in costs. Work that used to be manually intensive and required on-site personnel is now highly automated and can be managed remotely,” the post recognizes. “Personnel can now access real-time information on system operations and perform troubleshooting activities, like monitoring remote pump stations, measuring water quality, or analyzing data to identify and resolve issues.” 

It added that larger and more complex utilities also have automated feedback and process loops across OT systems, enabling one system to access controls of other systems without humans in the loop to manage or control the interaction. “However, as we will see next, these improvements have also introduced unforeseen cybersecurity challenges.”

NIST identifies that digital transformation has made connectivity a defining feature, and for some water and wastewater utilities, this means OT systems and devices are exposed to external networks and the internet so authorized users can reach them from anywhere. That same exposure lets threat actors use scanning tools to find devices with known vulnerabilities and exploit them to gain unauthorized access to OT systems or to network segments further out in the utility’s ecosystem. 

Technically, OT environments are at risk when network connectivity lacks protections such as firewalls, segmentation, jump hosts, or well-protected DMZs, and when devices run outdated firmware, use shared or default credentials, have misconfigurations, or run unpatched software. These factors enlarge the attack surface, as seen in recent attacks where actors accessed internet-facing PLCs with poor configurations and changed their passwords and IP addressing to lock out authorized users.

The key question is how best to protect OT environments and devices from unauthorized access. Utilities are encouraged to maintain an accurate asset inventory, reduce internet exposure by minimizing public-facing systems, and strengthen the security of systems that must be accessible remotely. Some utilities may remove external connectivity entirely through an ‘air gap,’ while others that need limited internet-based connectivity for operations and support are working to protect access to their OT environments and networks. The next step is a closer look at ‘secure remote access’ and how it can be achieved.

The agency mentioned that not all remote access is secure, and securing it typically means layering technical and administrative controls. Technical controls include encrypting data and network traffic, using multifactor authentication to verify users, segmenting OT networks from the enterprise, routing traffic to OT assets through jump or bastion servers, and using visibility tools to log and monitor access. Administrative controls include access control lists that limit who can reach an asset, least privilege to minimize permissions, log reviews for accountability, and supporting governance policies.

These controls can work together in any WWS utility’s OT environment, but differences in operational complexity, capacity, and resources make it hard to know which to implement and how they combine, particularly for secure remote access. Demonstration architectures can help by offering practical, step-by-step reference material showing how controls are adapted to work together in OT environments, which is what the NCCoE is developing.

The NCCoE has spent the past few years working with small, medium, and large water and wastewater utilities and technology companies to identify sector-wide cybersecurity challenges and their mitigations. Its recent publication, NIST SP 1800-45, offers practical guidelines showing how utilities of varying sizes and capacities can use commercially available technologies to secure remote access to OT systems. Utilities can use the example approaches to evaluate their own security practices and design more secure setups suited to their operational needs, environments, and resources.

Reference architectures were built in the NCCoE lab with collaboration partners to show how technologies and standards apply in typical WWS OT environments. A conventional architecture using firewalls and a remote access server suits utilities with on-premises OT networks; a cloud-based approach using an external service provider suits smaller, resource-constrained utilities; and a system-to-system approach suits larger utilities with direct machine-to-machine communication. In the first example, remote users connect to a server through a web browser over HTTPS, with firewalls restricting ports and protocols and role-based access control governing how each user interacts with OT assets.

The second example uses a cloud security provider to manage user access and activity logging, with authentication and authorization handled in a cloud-hosted control plane. After identity management, remote users connect to the OT environment through a secure, token-based channel, while logs are collected and stored in the cloud for analysis. The third example covers automated system-to-system data exchange between geographically dispersed OT assets across externally managed infrastructure, where hardware encryption devices at two remote sites establish an authenticated session and pass encrypted process data securely between the two environments.

Many WWS organizations and federal agencies already offer tools, best practices, and support to help utilities improve their cybersecurity. The NCCoE builds on this with reference architectures and example demonstrations that show the ‘how-to’ steps of implementation, giving utilities a clearer path to applying protections in their own OT environments.

Work with sector collaborators reinforced that secure remote access is only one part of a broader security approach. Utilities are encouraged to use NIST CSF 2.0 to manage risks across people, process, and technology, and NIST SP 800-82r3 for OT-specific guidance that accounts for performance, reliability, and safety needs. Together, these resources support an enterprise-wide, risk-based approach that establishes governance alongside technical fixes, covers detection, prevention, response, and recovery, and supports resilient operations across the sector.

In conclusion, the post noted that beyond this effort, the NCCoE is turning to a related and persistent challenge for organizations operating OT assets, including WWS providers, which is accurately identifying and managing those assets. The secure remote access guidelines work best when providers have a complete inventory of their OT systems.

“OT operators cannot protect what they do not know about,” the researchers wrote. “Secure remote access is about who can reach assets; asset visibility establishes what those assets are, where they are, how they’re configured, and what needs to be secured. The ability of any critical infrastructure operator to identify and manage all the assets across its enterprise is vitally important in establishing secure environments.”



Source link