You are here

What the ONWASA Ransomware Incident Can Teach about Responsible Disclosure

What the ONWASA Ransomware Incident Can Teach about Responsible Disclosure

Created: Wednesday, November 14, 2018 - 22:16
Categories:
Cybersecurity

As previously discussed by WaterISAC (including at its web page here and during its October Cyber Threat Briefing), the Onslow Water and Sewer Authority (ONWASA) experienced a ransomware attack in mid-October that impacted its IT networks. ONWASA provided many of the details of the attack in a press release issued just two days after the infection occurred, giving other members of the water and wastewater sector as well as of the larger critical information critical information to protect their own networks from similar activity. An article in Security Week lauds ONWASA for taking such action, noting that the utility’s swift, responsible, and transparent action also helped to calm customers who may have feared their water supply was in danger. The article also notes that ONWASA should be given credit for having segmented its networks and having firewalls and malware/anti-virus software in place that helped contain the ransomware’s spread. Security Week.