The Protecting Critical Water Systems with the Five ICS Cybersecurity Critical Controls white paper, published by SANS Institute in March 2024 and written by Dean Parsons, examines how water and wastewater utilities can apply the Five ICS Cybersecurity Critical Controls to defend against escalating attacks on industrial control systems. The paper explains why traditional IT security controls fail when applied directly to operational technology, and walks through each control's specific application to water sector engineering environments.
Key findings:
- Close to 40% of compromises within ICS environments originate from vulnerabilities in IT business networks that provide adversaries a pathway into the ICS environment
- Water and wastewater facilities commonly lack ICS network visibility, multifactor authentication, network segmentation, and trained ICS cybersecurity analysts
- Human machine interfaces (HMIs) can be manipulated by an adversary without any malware or exploit code, simply through unauthorized local or remote access
- Programmable logic controllers (PLCs) governing water pumping, chemical dosing, filtration, and disinfection can have all operating parameters directly altered if their logic code is manipulated
- A January 2024 ransomware incident disrupted water utility operations in both the UK and US
- A documented incident showed an attacker altering the chemical mixture in a water treatment process via insecure remote access to an HMI
- PIPEDREAM, a scalable ICS-targeting threat not specific to any one sector, could enable attacks causing safety impacts and physical equipment damage
- IT and ICS environments differ across six core areas: safety, security incident response, skill sets, cybersecurity controls, system designs, and support
- The Five ICS Cybersecurity Critical Controls are: an ICS-specific incident response plan, defensible control system network architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management
The paper's core argument is that water and wastewater cybersecurity requires controls purpose-built for engineering environments rather than adapted IT practices, since ICS assets carry different risk profiles, protocols, and safety consequences than business IT systems. Effective defense depends on pairing dedicated ICS incident response planning and network architecture with staff who understand both cybersecurity and water treatment operations, since technology alone cannot close the gap between IT and OT security postures.
This paper is a strategic and technical framework analysis rather than a survey-based research report, so no respondent methodology applies; its findings draw on incident data, CISA advisories, and prior SANS ICS/OT research such as the 2023 ICS/OT Cybersecurity Survey.