A Review of Cybersecurity Incidents in the Water Sector

Review (2020)
Author(s)

Amin Hassanzadeh (Cyber Fusion Center)

Amin Rasekh (Texas A&M University)

Stefano Galelli (Singapore University of Technology and Design)

Mohsen Aghashahi (Texas A&M University)

Riccardo Taormina (TU Delft - Sanitary Engineering)

Avi Ostfeld (Technion Israel Institute of Technology)

M. Katherine Banks (Texas A&M University)

Research Group
Sanitary Engineering
Copyright
© 2020 Amin Hassanzadeh, Amin Rasekh, Stefano Galelli, Mohsen Aghashahi, R. Taormina, Avi Ostfeld, M. Katherine Banks
DOI related publication
https://doi.org/10.1061/(ASCE)EE.1943-7870.0001686
More Info
expand_more
Publication Year
2020
Language
English
Copyright
© 2020 Amin Hassanzadeh, Amin Rasekh, Stefano Galelli, Mohsen Aghashahi, R. Taormina, Avi Ostfeld, M. Katherine Banks
Research Group
Sanitary Engineering
Bibliographical Note
Accepted Author Manuscript@en
Issue number
5
Volume number
146
Pages (from-to)
1-13
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

This study presents a critical review of disclosed, documented, and malicious cybersecurity incidents in the water sector to inform safeguarding efforts against cybersecurity threats. The review is presented within a technical context of industrial control system architectures, attack-defense models, and security solutions. Fifteen incidents were selected and analyzed through a search strategy that included a variety of public information sources ranging from federal investigation reports to scientific papers. For each individual incident, the situation, response, remediation, and lessons learned were compiled and described. The findings of this review indicate an increase in the frequency, diversity, and complexity of cyberthreats to the water sector. Although the emergence of new threats, such as ransomware or cryptojacking, was found, a recurrence of similar vulnerabilities and threats, such as insider threats, was also evident, emphasizing the need for an adaptive, cooperative, and comprehensive approach to water cyberdefense.

Files

Hassanzadeh_et_al_2019.pdf
(pdf | 0.577 Mb)
License info not available