Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Critical Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
State audit warns drinking-water systems are vulnerable to cyberattacks; committee refers cybersecurity audit to interim committees
Summary
Auditors told the Legislative Audit Committee that many community water systems lack incident-response plans and governance attention to cybersecurity; the audit cited a 2023 Utah ransomware event and recommended requiring systems to adopt cyber best practices; the legislature referred the matter to interim committees for review.
Get email alerts on the Critical Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
Auditors presented a performance audit examining cybersecurity for drinking-water systems and said operational-technology (OT) devices that monitor pumps, valves and chemical dosing create exploitable vulnerabilities.
The audit team cited a 2023 Utah municipal ransomware incident that locked operators out of control systems and required weeks of manual operation and equipment replacement, and a Florida breach where attackers changed sodium hydroxide dosing. A survey of community water systems found more than 55% lacked cyber incident-response plans and that of the systems that reported having plans, more than one-third could not describe how they would operate in manual mode.
The audit recommended the Utah Drinking Water Board require community water systems to adopt plans that implement cybersecurity best practices, that governing bodies be regularly briefed on cyber risk, and that systems improve network configuration, multi-factor authentication and vulnerability management. Auditors also recommended more education and strategic engagement by governing boards.
Nathan Lundstad, director of the Division of Drinking Water, and his assistant acknowledged the findings, said the report was timely and noted House Bill 19 (pending) contains provisions that could address requirements for emergency-response plans and data-breach reporting timelines. The committee voted to refer the audit to the Public Utilities, Energy and Technology Interim Committee (lead) and to the Political Subdivisions Interim Committee (review) for follow-up.
What happens next: referred committees will review the audit, consider whether rulemaking or legislation (including HB19) should be pursued, and request follow-up reporting from the Division of Drinking Water and the Utah Drinking Water Board.
