Beyond digital: Protecting public health from water sector cybersecurity risks

Daniel Visser,Vida Ghoddousi,Peter Clissold,Blair Shackleton,Hayden Cole
DOI: https://doi.org/10.21139/wej.2023.004
2023-01-01
Water e-Journal
Abstract:Historically, the design of water treatment plants relied on infrastructure such as pipelines, tanks and sand filters. Today the industry uses more advanced equipment, control systems, instrumentation and communication technologies. Improved technology brings benefits, but it also introduces cybersecurity risks. Due to the potential impact on public health, the potential for cyber attack on a water treatment facility is not an insignificant issue. Are digital controls sufficient, or should additional methods be used to secure drinking water supplies? In light of the safety hierarchy of controls and the multiple barrier (Defence-in-Depth) approach, the authors contend that water authorities should be doing more to address the risk of cybersecurity events to water infrastructure. Discussion about some opportunities to further reduce cyber risks is included in this paper. However, by no means should these considerations be taken as exhaustive. Cybersecurity incidents are a continuously evolving concern for most industries. Safety and security management must evolve faster to close the current gaps and keep pace with emerging risks.
What problem does this paper attempt to address?