Control systems running Queensland’s water supply are open to attack, according to a new audit report. The report, compiled by the Queensland Audit Office, found the water control systems operated by water service providers were “not as secure as they should have been” at the time of audit testing. Acting Auditor-General Anthony Close said the age of these systems, combined with more recent integration with corporate networks had resulted in higher risks that had not always been recognised and tested by the utilities. “Security controls did not sufficiently protect them from internal or external information technology-related attacks. Information security is like a chain – it is only as strong as the weakest link. All entities were susceptible to security breaches or hacking attacks because of weaknesses in processes and controls,” Close said in his report. “At the time of our testing, attacks could disrupt water and wastewater treatment services. They could also disrupt other services that relied on the entities’ information technology environments.” He said this was a risk to public health and appreciable economic loss in terms of lost productivity not only to water service providers but also to citizens and businesses. Although all organisations were capable of responding to information security incidents if they detected them, they were not well prepared to respond to cyber attacks. “They had not planned or tested their response and recovery from a malicious or cyber incident. These can occur without notice and can affect availability and integrity of multiple systems,” said Close in his report. Audited organisations said that they could operate smaller plants or parts of their larger water treatments plants manually following a disruption to computer systems but they had not demonstrated this capability. “Only one entity had documents its manual operating procedures, and none had ever tested running their whole plants manually. This places a high reliance on individual knowledge, experience and physical presence to continue water services in the event of an attack,” Close said. “The results of this audit serve as a timely reminder for any public sector entity managing critical infrastructure. Entities should assess and strengthen defences to protect their systems from information technology and cyber threats, and ensure that manual operation of critical infrastructure is documented and well tested.” The audit office recommended that Queensland’s Department of Energy and Water Supply integrate IT risks and cyber threats into the existing management framework for drinking water services and in Queensland water and sewerage service provider frameworks. It also recommended that the department facilitate information sharing about adopting standards for securing IT amongst entities that manage water control systems. Meanwhile, it recommended that the entities audited improve oversight, identification and monitoring of IT risks and cyber threats to water control systems. Related content feature 8 tips for unleashing the power of unstructured data For most organizations, data in the form of text, video, audio, and other formats is plentiful but remains untapped. Here’s how to unlock business value from this overlooked data trove. By Bob Violino Nov 28, 2023 10 mins Data Mining Data Mining Data Mining opinion What you don’t know about data management could kill your business Organizations without a solid data management strategy are on a collision course with catastrophe. Unfortunately, that’s most businesses, judging by the fundamental disconnect on the importance of strong data foundations. By Thornton May Nov 28, 2023 6 mins Data Architecture Data Governance Master Data Management brandpost Sponsored by Dell Technologies and Intel® Gen AI without the risks Demystifying generative AI: Practical tips for cost-effective deployment in your organization. By Andy Morris, Enterprise AI Strategy Lead at Intel Nov 27, 2023 6 mins Artificial Intelligence brandpost Sponsored by SAP Old age isn’t what is used to be: a versatile solution for a more independent breed of seniors An award-winning company from Down Under gives today’s seniors the power to access the services they need while keeping control of their own destinies and preserving their independence. By Michael Kure, SAP Contributor Nov 27, 2023 4 mins Digital Transformation Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe