Water utility attacks revive cyber insurance’s war exclusion debate

Small US utilities face mounting threats from hacking groups

Water utility attacks revive cyber insurance’s war exclusion debate

Cyber

By Gia Snape

A wave of cyberattacks targeting US water systems is raising questions over whether escalating geopolitical tensions could turn state-linked activity against critical infrastructure into a more significant cyber insurance exposure.

Malicious activity affected water system technology in at least seven states, with more than 30 community systems in Minnesota and nine in Michigan among those impacted, according to media reports last week. Federal authorities are investigating whether Iranian hackers were responsible, although the attacks had not been definitively attributed.

The incidents largely targeted programmable logic controllers and other operational technology used to remotely monitor and manage water infrastructure. Several utilities shifted to manual operations, while officials said drinking water quality and public health were not compromised.

“State-backed attacks have always been one of the primary threats to the critical infrastructure sector, but with the current geopolitical atmosphere, there are possibly more groups inspired to attack,” said Steph Barnes, senior intelligence analyst at Resilience.

“They are not doing the quieter pre-positioning like we saw with Salt Typhoon and Volt Typhoon, and instead are attempting more fast-paced attacks to make a point. This isn’t espionage for a future possible attack, it’s more likely a tit for tat retaliation based on the kinetic conflict.”

Public utilities vulnerable to mounting cyber exposures

The attacks have again exposed the cybersecurity challenges facing smaller public utilities, many of which rely on aging systems, limited budgets and dated operational technology.

“Utilities still run on a lot of legacy systems that were never meant to touch the internet,” Barnes said. “As everything digitizes, it’s difficult to foresee what improvements might also be opening security gaps, especially if those are smaller, resource-strapped utilities.”

Federal officials have urged water and wastewater operators to remove publicly exposed controllers and other operational technology from the internet. Authorities also warned utilities to examine external connections established through cellular modems, vendors and system integrators, which may not appear in normal attack-surface scans.

Barnes said risk modeling remains another obstacle, particularly where small utilities underestimate their attractiveness to attackers. “There’s still a mindset change necessary to believe that, yes, the smallest utility provider in the smallest town is a target because it’s part of the national infrastructure and may have a product with a flaw that attackers know how to exploit,” he told Insurance Business.

The affected utilities’ ability to fall back on manual processes prevented more serious disruption. South St. Paul transitioned to manual operations without interrupting service, while workers in Braham isolated an affected system and restarted the plant in around 90 minutes. Plymouth also temporarily operated manually after compromised controllers were identified.

“In this campaign, the water providers were able to pivot to manual operations; this speaks to their preparedness,” Barnes said. “If smaller utilities have actionable incident response plans, they’ll be better off.”

Cyberwar exclusions face renewed scrutiny

Although the incidents produced limited disruption, a broader or more successful campaign could generate substantial business interruption, restoration and liability losses. It could also force renewed examination of how cyber policies respond when attackers are linked to a nation state, according to Barnes.

Attribution is likely to remain central to any coverage dispute. Investigators are considering whether Iranian actors were responsible and whether another group may have attempted to appear Iran-based; such uncertainty could complicate efforts to determine whether a policy’s war or cyberwar exclusion applies.

“I think it depends on the clauses,” Barnes said. “If these types of attacks are traced back to a state-backed group, is the attack excluded from coverage? If there are many more such attacks, will there be pushback from the public utilities sector to rethink these types of clauses?”

The current incidents stopped short of contaminating drinking water or causing prolonged service failures. Barnes said that threshold could determine how quickly the insurance market is forced to confront the issue.

“If a campaign is more successful, i.e. the smaller utilities aren’t able to pivot or the drinkable water or electrical grid is compromised, I think that we’ll be revisiting the cyberwar clause conversation.”

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!