The UK's security agency, NCSC, has urged the companies to implement stricter security, following a breach at a US organisation where hackers exploited industrial control systems.

The Cybersecurity and Infrastructure Security Agency US (CISA) revealed earlier this week that a facility had been taken offline after Unitronics programmable logic controllers (PLC) were compromised.
The UK's National Cyber Security Centre (NCSC) considered that these breaches could also pose a threat to the country's water providers.
See also: Hackers Attacked Aliquippa Water System
Thus, the NCSC encourages organizations using Unitronics PLC to follow the steps outlined in the CISA cybersecurity guide.
The measures proposed are the following:
- Changing default passwords on PLCs and human machine interfaces (HMI)
- Use a strong password
- Multi-factor authentication (MFA) application for remote access to the operational technology (OT) network
- Disconnecting the PLC from the public internet and implementing a firewall/VPN
- Using a list of allowed IP addresses to access the PLC
- Back up configurations on any Unitronics PLC for immediate recovery in the event of a ransomware attack
- Using a TCP port other than the default port (TCP 20256)
- Updating Unitronics PLCs/HMIs to the latest version
The NCSC has repeatedly highlighted the risk of cybercriminals.
“Our American counterparts, CISA, have issued an advisory outlining a threat to the water sector,” said expert Jonathon Ellison. “We are alerting UK providers to this threat and recommend that they protect consumers by following the advice set out by CISA.”
See also: Cyberattacks on “critical infrastructure” are increasing

Importance of safety
Strengthening the security of water utility control systems is crucial. Water utilities are critical infrastructure for society, as they are responsible for providing clean drinking water to citizens. Any failure or outage of control systems can have serious consequences for the health and safety of the population.
In addition, water companies use modern control systems to manage their water supply networks. These systems are connected to the internet and information technology , making them vulnerable to cyberattacks . If their security is not strengthened, these attacks can lead to irreparable damage and even dangerous situations, such as contamination of drinking water.
See also: Microsoft: Warns of Chinese attacks on United States infrastructure
Additionally, cyberattacks on water utility control systems can have serious financial consequences . If an attacker gains access and control of the systems, they can cause damage to infrastructure, compromise customer data, or cause financial loss. Recovering from such an attack can be costly and time-consuming, impacting the company’s financial performance.
Finally, strengthening the security of control systems is important for maintaining public trust. Citizens must have confidence in water companies to provide safe and reliable drinking water. If attacks on control systems are frequent or successful, this trust can collapse, with negative consequences for the company and the public at large.
Source: www.infosecurity-magazine.com
