GET A QUOTE: sales@columbiaweather.com 503-629-0887 M-F 8:30-5:00 PT
Click here to download as a PDF
Over the past few months, hackers have attacked municipal water systems across the country, targeting the programmable logic controllers (PLCs), that run pumps and valves controlling water flow.1 In August, the NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory about a related threat targeting equipment common across water, wastewater, energy, and manufacturing facilities.2 The advisory found attackers scanning the internet for systems that are exposed online, running outdated software, or still using default passwords. As the agencies put it plainly: this isn’t a theoretical risk, it’s an active one.
Weather monitoring equipment often sits on these same industrial networks, connected to the PLCs and SCADA systems these advisories are warning about.
While we are not aware of any attacks involving our equipment, CWS president Nader Khoury provides some tips on how to keep your weather station secure, so that it does not become a system vulnerability.
Hackers generally aren’t breaking through sophisticated defenses. They’re finding equipment that was left exposed, whether through a weak password, outdated firmware, or a remote connection nobody locked down properly.
Vulnerable equipment gets identified through internet scans that look for anything connected directly online. Attackers try default or previously leaked passwords, or take advantage of outdated firmware. Sometimes the opening comes through a remote access connection that was set up for convenience and never properly secured, including one set up by a third-party vendor.
Water and wastewater managers aren’t standing still on this. The EPA has announced $11.75 million in grants to help drinking water systems strengthen cybersecurity and resilience, including funding for San Diego to replace vulnerable PLCs.3 It’s a sign the industry is taking this seriously, and a good moment for anyone managing connected equipment to do the same. Weather station sensors may be connected to the monitoring systems via 4-20 mA analog interface which is a secure connection. Alternatively, many water systems utilize CWS’s Weather MicroServer for industrial interfaces.
A proper configuration already avoids nearly every one of the pitfalls mentioned above. The Weather MicroServer connects to a network over a single Ethernet cable, and its ports and interfaces are hardened to minimize the risk of a security breach.4 CWS president Nader Khoury offers the following reminders:
The diagram below shows a typical Weather MicroServer setup. The MicroServer, circled, is the component this guidance focuses on: sensors connect to the system through the interface module, and it communicates outward using protocols such as Modbus, DNP3, BACnet, SNMP, FTP, and our own Cloud Server.
This is the same category of equipment named in the recent advisories: industrial hardware that reports real-time data, sometimes over a network.2 The difference is in how it’s set up. When a system is placed behind a firewall, kept off direct remote access, and connected to the internet only through our encrypted Cloud WeatherServer, it no longer matches the profile these recent cyberattacks exploited.
The reassuring part is that the fix rarely requires anything complicated. Changing a default password, keeping firmware current, and being thoughtful about remote access, these actions close off almost every entry point of attack.
Our job is to make weather monitoring easy -- and secure -- so you can do your job better.
Contact us to learn how we can help you set up your weather monitoring system securely.
Call or email for a quote | 503-629-0887 | info@columbiaweather.com
We can help you specify the best weather station for your requirements.
Or call 503-629-0887