1 of 24

KANSAS | MISSOURI

2 of 24

3 of 24

Best Practices to Mitigate Cyber Security and Employee Security Threats

An Overview of Legal and Regulatory Guidelines

4 of 24

Introduction

  • Water and sewer utilities are critical infrastructure and are frequent targets for cyber threats and employee security risks.
  • This presentation covers best practices to safeguard systems, data, and personnel from potential threats.

5 of 24

Legal Framework in Missouri

Key Statutes Regarding Privacy and Security:

  • Missouri Revised Statutes (RSMo):
    • Chapter 610 -Governmental Bodies and Records
    • Chapter 407.1500 - Missouri Data Breach Notification Law
    • Chapter 407.1308 - Missouri Identity Theft Protection Act – Doesn’t exist but AI says it does Prohibits unauthorized disclosure of personal information. Requires secure disposal of documents containing private data. Cities and districts must safeguard customer and employee information. HB 850 2004 & 2003 Chap. 570.222 (2008)

6 of 24

Legal Framework in Missouri

Key Statutes Regarding Privacy and Security:

  • Potentially Applicable Federal Laws:
    • Gramm-Leach-Bliley Act (GLBA) May applies if a district offers payment plans, loans, or financial services. Requires: Privacy Notices explaining how personal data is used. Safeguards Rule to protect customer information from cyber threats. Restrictions on sharing financial data with third parties.
    • Red Flags Rule (Fair Credit Reporting Act) Applies if a utility district offers deferred payment arrangements. Requires a written Identity Theft Prevention Program to detect and prevent fraud. Cities and districts must train employees to identify warning signs of identity theft.

7 of 24

Legal Framework in Missouri

Key Potential Federal Statutes Regarding Privacy and Security:

    • Health Insurance Portability and Accountability Act (HIPAA) Applies if a district provides employee health benefits or maintains medical records. Requires secure handling and restricted access to health-related data.
    • The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (Regulations pending)
    • Payment Card Industry Data Security Standard (PCI DSS)If accepting credit card payments, districts must encrypt, secure, and restrict access to payment data.

8 of 24

 610.011.  Liberal construction of law to be public policy.

  •  1. It is the public policy of this state that meetings, records, votes, actions, and deliberations of public governmental bodies be open to the public unless otherwise provided by law. Sections 610.010 to 610.200 shall be liberally construed and their exceptions strictly construed to promote this public policy.

  •   2. Except as otherwise provided by law, all public meetings of public governmental bodies shall be open to the public as set forth in section 610.020, all public records of public governmental bodies shall be open to the public for inspection and copying as set forth in sections 610.023 to 610.026, and all public votes of public governmental bodies shall be recorded as set forth in section 610.015.

9 of 24

 The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 6 USC 681 – 681G

  • (1) Covered cyber incident reports.
  • (A) A covered entity that experiences a covered cyber incident shall report the covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred.
  • (B) Limitation. The Director may not require reporting under subparagraph (A) any earlier than 72 hours after the covered entity reasonably believes that a covered cyber incident has occurred.
  • (2) Ransom payment reports.
  • (A) In general. A covered entity that makes a ransom payment as the result of a ransomware attack against the covered entity shall report the payment to the Agency not later than 24 hours after the ransom payment has been made.
  • Regulations pending

10 of 24

Common Cyber Threats

  • Phishing Attacks – Fraudulent emails tricking employees into providing credentials.
  • Ransomware – Malware that locks systems and demands ransom.
  • Insider Threats – Employees misusing access to compromise security.
  • Unpatched Software – Vulnerabilities exploited by hackers.

11 of 24

Phishing Attacks

12 of 24

Phishing Attacks (cont.)�Chris Hemsworth Thor Virus

13 of 24

Phishing Attacks (cont.)

14 of 24

Phishing Attacks (cont.)

Training:

15 of 24

Phishing Attacks (cont.)

Training:

16 of 24

Ransomware – Malware that locks systems and demands ransom.

On October 3, 2024, American Water detected a cyberattack on its computer systems, including its customer billing platform. The attack temporarily disrupted the company's ability to process payments and send bills. However, it did not impact water and wastewater services.

Timeline of the attack

Detected unauthorized activity on October 3

Activated incident response protocols, engaged cybersecurity experts, and notified law enforcement

Publicly disclosed the cyberattack on October 7

Paused billing operations and disconnected key

systems Began investigating and reconnecting systems

17 of 24

Ransomware – Malware that locks systems and demands ransom (cont.)

  • American Water’s Security Incident: Ransomware or Something Else?
  • Forescout Research - Vedere Labs and Don Sears, Senior Cybersecurity Editor | October 14, 2024
  • Summary
  • American Water recently disclosed a cybersecurity incident
  • Billing systems and customer care operations are impacted
  • The company reported no negative impact or safety concerns
  • While ransomware is possible, the cause is still inconclusive
  • The US water industry has had seven known security incidents in last 18 months

18 of 24

Ransomware – Malware that locks systems and demands ransom (cont.)

  • Since 2017, the water industry has increased its internet exposure of OT/ICS
  • Recommendations for water utilities:
    • Identify and patch vulnerable network devices
    • Segment the network to prevent lateral movement and infection spread
    • Monitor network traffic for signs of intrusion, lateral movement or payload execution

19 of 24

Insider Threats – Employees misusing access to compromise security.

  • Employees = # 1 Asset - # 1 Threat, Contractors too
  • Preform a Comprehensive Critical Systems Analysis
    • SCADA, IT, OT
    • E-mail, Servers
    • Accounting, Document Management Systems
    • Quickbooks, Notification Systems,
    • Cloud systems
    • Computers, Phones, Cell Accounts
    • Online Accounts
      • Credit cards
      • Banking
      • Facebook
      • Website

20 of 24

Best Practices for Employee Security

  • Employees level access
    • Anyone needing access has their own PW – User level Not Administrator.
      • Tracks access
      • Accountability
      • Secure PW, Rotate, PW Manager
      • 2 Factor
      • Disney Story
  • Enforce Role-Based Access Controls (RBAC) – Limit access based on job roles.
  • Conduct Background Checks Before Hiring Employees.
  • Provide Ongoing Security Awareness Training.
  • Secure Physical Access with Keycard Entry and Surveillance.
  • 5. Establish Clear Security Policies and Reporting Procedures.

21 of 24

Best Practices for Cybersecurity

  • Use Strong, Unique Passwords and Enable Multi-Factor Authentication (MFA).
  • Keep Software and Systems Updated with Latest Security Patches.
  • Train Employees to Recognize and Report Phishing Attempts.
  • Regularly Back Up Critical Data and Store It Securely.
  • Implement Network Segmentation to Isolate Critical Systems.

22 of 24

Regulatory Considerations

  • Missouri Sunshine Law – Ensuring transparency while protecting sensitive data.
  • Federal Compliance – EPA and DHS guidelines for utility security.
  • Data Protection Regulations – Secure handling of customer and operational data.

23 of 24

Incident Response Plan

  • Identify and Contain the Security Threat.
  • Notify Authorities and Affected Parties.
  • Restore Systems from Secure Backups.
  • Conduct a Post-Incident Review and Strengthen Security Measures.

24 of 24

Conclusion

  • Cybersecurity and employee security are ongoing priorities.
  • Stay informed, train employees, and adopt best practices.
  • Resources:
  • - Cybersecurity & Infrastructure Security Agency (CISA)
  • - American Water Works Association (AWWA) Security Best Practices
  • Missouri Public Utility Security Guidelines

Doug Silvius: ddsilvius@martinpringle.com

doug@silvius.org

          • 816-268-8962 Direct Dial Office
          • 816-516-7816 Cell
  • Questions?