232
CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet
(www.privacyguides.org)
This is a most excellent place for technology news and articles.
So are we just kind of admitting that there exists no way to expose any networked device to the internet securely? Because if it's not possible for PLCs I don't see why it would be possible for any device. If water utilities have to take these offline, then how does that advice not apply for every internet-capable device in every commercial and industrial facility worldwide?
I don't work directly with PLCs but we do have them at my work. The main thing that makes these different from any other devices is that they typically control physical machines. Which means there is a real danger that them becoming compromised could lead to damaged equipment or even death.
Additionally, many PLCs use older OS versions like xp because their software is notoriously out of date (if it's working why rewrite it when that could introduce safety concerns)
This "urgent" message from CISA does not prove that any of these devices are internet accessible just that if they are then they should be removed. If CISA wanted to require this then they would have released a binding operational directive (BOD) or an emergency directive (ED). Both of which are publicly viewable on their site.