153
CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet
(www.privacyguides.org)
This is a most excellent place for technology news and articles.
A lot of this is often down to shitty IT practices by the vendor who has little IT knowledge let alone decent security insight.
I helped support a new PCL installation (technician control PCs and software upgrade) in this exact scenario many years ago. The vendor came in expecting to treat our system as their own. Direct remote access to several over-specced, physical servers from the outside world, available on our core network, shared account names (and passwords!) across all devices, every account a local admin and their own domain admin account so they can make changes as required... Needless to say our security guy almost broke a rib from laughing so hard!
What they got was very different. I ended up doing fairly basic troubleshooting to get the shitty software working without it needing admin rights to run - XP era software running on Win7 clients so it was meeting basic folder and reg key write permissions - everything else was locked down as tight as we could. They didn't even get admin on the servers.
A few years later I heard they'd reported that our site was their most reliable. Probably due to the fact that they (or the techs) couldn't fuck with anything without our permission. Apparently their original configuration is normal in the industry... Shudder