Describe the network security of the industrial automation industry and their customers in a single statement. Lol.
How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.
CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.
Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.
When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.
Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together.
At some point it just became standard industry practice is my guess.
Government is supposed to respond to these things and create incentives to correct. Telling a small municipality to do something without a carrot ir stick does nothing.
In this instance someone else will be providing the stick.
The one and only exception is the military, because lives are literally on the line in a way that is not at all abstract.
Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there would be a very different attitude around the work.
There are better run governments than we have in the US.
The contempt for the state is a self-fulfilling prophecy. The state is incompetent because many of us believe it is inevitable that it will be. Compensation is just a part of it; coherent administration with continuity is even more important.
The people who climb to the top aren’t the ones who took a risk and got the reward. Quite the opposite, they’re the ones who learned to play the game and didn’t upset the power structure by rocking the boat. No one is going to tell the emperor he has no clothes when the path to power is political and has no grounding in reality.
Highly conscientious, intrinsically motivated people will do the right thing in any environment. And those people don’t last long in political/bureaucratic environments where the incentives are misaligned.
>In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing.
Federal employment is merit based. Advances are earned, not doled out to the teacher's pet or the ass-kisser with the most perfect pucker. You have no idea what you're talking about.
I have no idea where you or anyone else got the idea that a government employee has no responsibility or incentives and works strictly for political ends and even worse, where none are willing to speak up. You clearly have no experience in that space and should focus your comments on things that you better understand through direct experience.
>And those people don’t last long in political/bureaucratic environments where the incentives are misaligned.
This is bullshit and you are grossly misinformed. Plenty of people fight the polarization of the system on political lines from within the system. They use the laws that are in place in order to prevent systemic abuses. They may not win every internal fight but they do go to battle for the right reasons.
You just have no idea.
Notably everything in the comment you replied to applies equally to the public and private sector. They are neutral observations about systemic motives and the associated perverse incentives.
Also it's not clear to me that any of the utilities in question have anything to do with the federal government so I'm not sure why you dragged them into this.
Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.
Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.
I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.
> failed to anticipate not only these infrastructure breach
They've been warning them for close to two decades.
Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.
Passing the buck to the Federal Government is not understanding the problem.
> finger-pointing isn't going to fix it.
Your entire comment was finger pointing…
Passing the buck to the Federal Government is not understanding the problem.
"I think Minnesota is behind it."
The first quote makes it the state's responsibility to secure local water systems, which I'm not sure that it is. The second makes it at least sound like the state of Minnesota is the entity running the attack on local water systems within their state, which is off in paranoid conspiracy territory.
Trump was absolutely wrong.