<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Water System Hacked in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43159#M5298</link>
    <description>&lt;DIV class="el__leafmedia el__leafmedia--sourced-paragraph"&gt;&lt;P class="zn-body__paragraph speakable"&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;A hacker gained access into the water treatment system of Oldsmar, Florida, on Friday and tried to increase the levels of sodium hydroxide -- commonly referred to as lye -- in the city's water, officials said, putting thousands at risk of being poisoned.&lt;P class="1612889272388"&gt;&lt;A href="https://www.cnn.com/2021/02/08/us/oldsmar-florida-hack-water-poison/index.html" target="_blank" rel="noopener"&gt;https://www.cnn.com/2021/02/08/us/oldsmar-florida-hack-water-poison/index.html&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;This is a successful incident response story.&amp;nbsp; The duty-operator immediately noticed the attack, watched the&amp;nbsp;level be changed and immediately restored it the proper level.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;They then disabled their remote access system and noted that had there were additional "downstream" monitors that would have triggered had their first level control (the operator) failed.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;So kudos for Detect and Respond, but Protect does seem to have room for improvement (e.g. MFA and isolation) that will become evident in the lessons-learned phase.&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 09 Feb 2021 17:18:22 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2021-02-09T17:18:22Z</dc:date>
    <item>
      <title>Water System Hacked</title>
      <link>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43159#M5298</link>
      <description>&lt;DIV class="el__leafmedia el__leafmedia--sourced-paragraph"&gt;&lt;P class="zn-body__paragraph speakable"&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;A hacker gained access into the water treatment system of Oldsmar, Florida, on Friday and tried to increase the levels of sodium hydroxide -- commonly referred to as lye -- in the city's water, officials said, putting thousands at risk of being poisoned.&lt;P class="1612889272388"&gt;&lt;A href="https://www.cnn.com/2021/02/08/us/oldsmar-florida-hack-water-poison/index.html" target="_blank" rel="noopener"&gt;https://www.cnn.com/2021/02/08/us/oldsmar-florida-hack-water-poison/index.html&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;This is a successful incident response story.&amp;nbsp; The duty-operator immediately noticed the attack, watched the&amp;nbsp;level be changed and immediately restored it the proper level.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;They then disabled their remote access system and noted that had there were additional "downstream" monitors that would have triggered had their first level control (the operator) failed.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;So kudos for Detect and Respond, but Protect does seem to have room for improvement (e.g. MFA and isolation) that will become evident in the lessons-learned phase.&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="zn-body__paragraph"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Feb 2021 17:18:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43159#M5298</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-02-09T17:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Water System Hacked</title>
      <link>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43168#M5299</link>
      <description>&lt;P&gt;Turns out their "remote access solution" was teamviewer, which notoriously does not play nice with corporate security (e.g. no SAML nor MFA in thier standard package).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 21:06:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43168#M5299</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-02-09T21:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Water System Hacked</title>
      <link>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43204#M5302</link>
      <description>&lt;P&gt;&lt;A href="https://stpetecatalyst.com/proper-training-system-configuration-could-have-prevented-oldsmar-hack/" target="_blank"&gt;https://stpetecatalyst.com/proper-training-system-configuration-could-have-prevented-oldsmar-hack/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:40:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Water-System-Hacked/m-p/43204#M5302</guid>
      <dc:creator>AndreaMoore</dc:creator>
      <dc:date>2021-02-11T14:40:08Z</dc:date>
    </item>
  </channel>
</rss>

