PUC Issues Cybersecurity Advisory on Threats to Utility Systems
Published on 3/10/2021
Filed under: Electric Gas Telecommunications Water and Wastewater
Encourages Steps to Address Vulnerabilities Highlighted by Recent Utility Cyber Attack in Florida and Importance of Strong Cyber Hygiene
HARRISBURG –The Pennsylvania Public Utility Commission (PUC) has issued a Cybersecurity Advisory to water utilities across Pennsylvania with specific cybersecurity information following a recent cyberattack on a water system in Florida – and continues to encourage all other utilities to maintain good cyber hygiene and remain vigilant.
“A PUC-regulated utility is required to have a cybersecurity plan for their operations, and we have regular conversations with our utility community about cybersecurity and developing cyberthreats,” noted PUC Chair Gladys Brown Dutrieuille, who leads the Committee on Critical Infrastructure for NARUC – the national organization for state utility commissioners – and is also a member of NARUC’s national Task Force on Emergency Preparedness, Recovery and Resiliency.
A great deal of the PUC’s time and attention is focused on information-sharing about developing cyber threats, connecting utilities with cybersecurity resources, and improving communication between different groups of utilities – because a cyberthreat that appears in one sector may be part of a broader effort to penetrate another type of utility or business.
The Commission noted that cyber issues impact every size and type of utility, along with other businesses – further underscoring the importance of strong cybersecurity practices.
Cyber Tips Following Florida Incident
Based on preliminary information about the Florida incident, the PUC’s Office of Cybersecurity Compliance and Oversight has issued a Cybersecurity Advisory - reaching out to regulated water utilities in Pennsylvania about the importance of strong cyber hygiene.
Key recommendations in the PUC Cybersecurity Advisory include:
- Operating Systems - Update all computers operating software.
- Passwords - Use strong passwords and multiple-factor authentication.
- Other Safeguards - Ensure that anti-virus, spam filters and firewalls are updated, properly configured and secure.
- Training - Users should be trained to identify and report attempts at social engineering.
- Respond Quickly - Identify and suspend access of users exhibiting unusual activity.
- Study Risks – Conduct regular physical and cybersecurity risk assessments on critical infrastructure.
Most of these tips are also excellent cyber hygiene practices for every business and every personal computer user, especially with the dramatic increase in remote work since the beginning of the COVID-19 pandemic. The larger number of people now working remotely has expanded the number of possible avenues for cyberattacks and further emphasized the need for constant vigilance by everyone.
Cyber Careers at Utilities
As utilities work to address these new potential threats, the Commission encouraged cyber professionals and young people learning about cybersecurity to consider career opportunities in the utility sector.
“There is a massive state, national and global demand for job candidates with strong cybersecurity skills, and we hope that many will explore possible #UtilityCareers,” PUC Chairman Dutrieuille said. “While our utilities can often ‘hide in plain sight,’ – unnoticed by many unless there is a problem with service – the work of ensuring the safety and reliability of these essential community services can be very rewarding.”
For a new generation searching for opportunities to start their careers, as well as other skilled candidates, like our veterans, looking for new possibilities, utilities represent tens-of-thousands of community-oriented jobs, combining good wages with the satisfaction of knowing that you are serving your neighbors.
About the PUC
The Pennsylvania Public Utility Commission balances the needs of consumers and utilities; ensures safe and reliable utility service at reasonable rates; protects the public interest; educates consumers to make independent and informed utility choices; furthers economic development; and fosters new technologies and competitive markets in an environmentally sound manner.
Visit the PUC’s website at www.puc.pa.gov for recent news releases and video of select proceedings. You can also follow us on Twitter, Facebook, LinkedIn, Instagram and YouTube. Search for the “Pennsylvania Public Utility Commission” or “PA PUC” on your favorite social media channel for updates on utility issues and other helpful consumer information.
# # #
Learn how to submit a complaint with a public utility. You can also search existing formal complaints.Get Details
Subscribe to Press Releases
Keep track of PUC news and activities with press releases delivered straight to your email inbox.Subscribe
Need More Help?
If you can't find what you're looking for here, please contact the PA Public Utility Commission. Call us at 1-800-692-7380 or contact us online.
Public utility documents available electronically include case dockets, public meeting orders and more.
Filing & Resources
Find utility-related reports, laws and regulations, federal filings, tariffs, procedures and more.
Consumers, utilities and attorneys can save time by submitting documents to the PUC electronically.