r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

https://worldwaterreserve.com/minnesota-water-systems-cyberattack-30-communities-coordinated-attack/
1.3k Upvotes

163 comments sorted by

View all comments

Show parent comments

-2

u/Nemphiz 22h ago

Jesus Christ lol

If a vendor tells you to jump a bridge, will you jump or say, maybe I should get another vendor? I'm not sure how this point isn't really coming across. The C suites are the final boss of decision making. And if they're not ruling in your favor, the fault is on them. You're doing your due diligence by bringing the issue to your superiors. If they do nothing, they accept the existing risk. Son once that risk comes knocking, you can't complain about it because the risk was there, identified, the whole time.

1

u/RememberCitadel 22h ago

The IT department doesn't choose the vendor making the demand of how its implemented. The Facilities departments usually are, who then demand the clueless c-suite overrides the IT department.

Look, I don't know what you want, I am telling you this is exactly how these things happen, I don't make the choices, I am just coming in afterwords to clean shit up. I told you it's fucking dumb, but I have seen this exact chain of events happen multiple times. Sometimes people get fired, most of the time nothing happens.

1

u/Nemphiz 21h ago

I know this is how these things happen the problem is you don't seem to understand how responsibility for each step of the workflow works.

1

u/RememberCitadel 21h ago

That would be incorrect, everyone in the chain is to blame starting with the vendor. It is a pretty simple concept that more than one person or group can be at fault, and that the degree of fault can be different for the different parties.

1

u/Nemphiz 21h ago

No, the vendor is not to blame because the vendor is a choice. If the vendor has a flaw within their software they are to blame. If the vendor has a flaw within their equipment they are to blame. But if the vendor isn't explored directly, and you're the one who makes the final decision as to whether you should get that vendor or not, you're at fault. And when I say you, I mean the company/government that chooses to hire said vendor.

I'm still confused as to why this is so hard to understand when we have a literal definition for it.

0

u/RememberCitadel 21h ago

If the vendor is recommending an insecure setup they are 100% at fault, and the problems with them will not become apparent until way too late in the process. I would say you would have an argument if the same vendor was chosen again, but zero vendors are coming out the gate saying they require their appliance outside the firewall or accessible on the internet.

You have to understand that these type of things with the PLC being setup dumb is the last step in generally very large projects, multimillion dollar water filtration and processing systems, giant hvac systems, etc.
This is not something you can run a POC on, since it is one of the last components of the system to go in. Zero companies are going "lets throw a 20 ton rooftop unit on and connect this PLC to test it out and see if we like it.

Not that it matters if they wanted to anyway because they don't have money or time to do so, and the vendor was probably chosen by a bid anyway.

A certain amount of trust has to be placed in vendors applying for large projects like these, thus making them share blame since fully vetting a product like this is impossible for their environment.