Keeping Cyber-Secure: What Special Districts Need to Know [Government Technology] - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
April 15, 2022 Newswires
Share
Share
Post
Email

Keeping Cyber-Secure: What Special Districts Need to Know [Government Technology]

Government Technology

Apr. 14—Cybersecurity should be a major concern for special districts, which often handle critical services like wastewater treatment, drinking water and emergency response.

Far from being too small for notice, small, less-resourced critical infrastructure operators can be tempting to ransomware attackers. Cyber extortionists often would rather hit an array of easier targets than pursue bigger payouts from wealthier but more robustly defended organizations, said Chris Krebs, former Cybersecurity and Infrastructure Security Agency (CISA) director and currently founding partner of cybersecurity advisory firm Krebs Stamos Group.

"If I'm an economic, rational actor, as a cyber actor ... I'm not looking for a whale necessarily," Krebs said during an April 12 e.Republic* webinar. "I'm probably shopping in volume here and going after multiple targets that may not have had the resources or the manpower to really get the level of security up to what they would have liked" due to budget and revenue constraints.

Cyber extortionists may also count on providers of vital services doing whatever it takes to get back up and running, fast.

And foreign adversaries may target such operations in efforts to cause widespread disruption and panic. Just this week, the Ukrainian government said it defused a Russian cyber attack that would have cut off electricity to 2 million people if successful, per the Associated Press.

TACKLING THE CYBER RISK

Webinar attendees indicated that cyber threats are not abating.

In a poll conducted during the event, 39 percent of 62 respondents said the volume of cyber threats in their district had risen during 2022 and 29 percent said volume remained at 2021 levels. Another 29 percent were "unsure," and only 3 percent reported threats decreasing.

Krebs said that districts should pay particular attention to how the security of their operational technology (OT) and industrial control system (ICS) configurations. Districts need to ensure they understand exactly how their system integrators, original equipment manufacturers (OEMs) or other vendors are keeping everything safe and to question anything that seems amiss.

"Work through, like, 'Wait a second, how are these things remotely managed? And why is that exposed to the Internet like that? Why the heck do we have a default password sitting on that box?'" he said.

Districts need to put similar attention on their cloud service providers, too.

"A lot of the providers that are out there right now aren't necessarily up to speed or up to snuff," Krebs said.

REACTING TO RANSOMWARE

Ransomware attacks remain a high-priority threat, Krebs said. Thirty-eight percent of 68 respondents to a webinar poll named ransomware one of "the most common cyber threats" they face.

Krebs advocated for not paying ransom so as to deny perpetrators profit. Paying also can fail to give victims the expected relief, because extortionists aren't necessarily strong providers of customer support and because decryption keys may fail to work or may work slowly.

Special districts hit by cyber incidents should contact their lawyers for advice as well as alert their bosses, the FBI and CISA, Krebs said. The latter reporting would become obligatory for critical infrastructure owners and operators under a to-be-implemented law.

"Don't try to hide these events. It only gets worse for you down the road," Krebs said.

The federal government ranked low on webinar respondents' lists of who they'd turn to for help following a cyber incident impacting their districts.

The 48 webinar members who responded to this poll question favored reaching out to existing partners: 40 percent said they would contact third-party vendors with which they already had contracts and 40 percent would contact cyber insurance providers.

They were next-most likely to contact state IT or cybersecurity agencies (38 percent), followed by local ones (35 percent) and federal (27 percent). Twenty-three percent of respondents would contract a third-party vendor specifically to help handle the incident, and only 15 percent would turn to federal, state or local law enforcement.

FIGHT PHISHING, NOT EMPLOYEES

Not all important cyber threats are sophisticated ones. Eighty-two percent of 68 respondents named "phishing" as one of their most common threats.

Some organizations try to train employees to be alert to such schemes by sending fake phishing emails and seeing who's tricked into clicking a risky link. Some penalize employees who succumb or assign them to more cyber awareness training.

But Krebs said a stronger approach is to adopt defensive measures that reduce how much damage could occur from an employee making a mistake.

"You should be able to put your employees in a position where they can't turn over their credentials, or if they do turn over their credentials — like the password — it shouldn't matter, because you have other security processes in place," Krebs said.

That includes adopting robust forms of multifactor authentication (MFA), such as those using authenticator apps or hardware tokens as the additional authentication measure. MFA that relies on texted one-time passwords risk being intercepted by savvy criminals.

RESOURCES FOR SPECIAL DISTRICTS

The high number of respondents who listed phishing as a common threat underscores that it's not enough for defensive tools to have been developed against a line of attack, Krebs said. Organizations can still struggle to adopt them at scale.

Federal supports like CISA's cybersecurity coordinators and various money streams can help, however.

Alongside tapping any remaining COVID-19 funds and money from the Infrastructure Investment and Jobs Act, special districts can likely find a variety of grants from organizations like FEMA that are aimed at cybersecurity initiatives, Krebs said. Special districts can also gain insights from high-level federal strategy documents that may give insights that they can apply to their own setups.

* e.Republic is Government Technology's parent company.

___

(c)2022 Government Technology

Visit Government Technology at www.govtech.com

Distributed by Tribune Content Agency, LLC.

Older

Notice of Annual General Meeting

Newer

Dental Insurance Market Global Industry Trends, Share, Size, Growth, Opportunity and Forecast 2022-2027: A US$ 290.5 Billion Market by 2027 – ResearchAndMarkets.com

Advisor News

  • When new investment trends emerge, Gen Z is most likely generation to be first in
  • Could ‘plain English’ become an advisor’s secret weapon?
  • IRI urges Senate action on 403(b) parity legislation
  • Three estate planning ideas to protect your clients and their wealth
  • What advisors must know about accessible client documents
More Advisor News

Annuity News

  • NUNN INTRODUCES BILL TO CUT RED TAPE, GIVE IOWANS CLEARER INSURANCE INFORMATION
  • NAIC working group pressed to accelerate annuity illustration overhaul
  • State Auditor James Brown Kicks Off Life Insurance Awareness Month With Policy Locator Tool
  • Wink: Annuity sales post strong Q2, led by MYGAs and structured products
  • Legacy Marketing Group partners with Malibu Life USA for annuity launch
More Annuity News

Health/Employee Benefits News

  • An Application for the Trademark “UHCCARECONNECT” Has Been Filed by UnitedHealth Group Incorporated: UnitedHealth Group Incorporated
  • Findings from University of Colorado Anschutz in Hypertension Provides New Insights (Blood Pressure Control Among Adherent vs Nonadherent Medicare Patients With Hypertension): Cardiovascular Diseases and Conditions – Hypertension
  • DeKalb County employees will still have insured access to GLP-1s
  • New York approves small, individual insurance plan rate hikes for 2027
  • AM Best Affirms Credit Ratings of Ping An Health Insurance Company of China, Ltd.
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • AM Best Affirms Credit Ratings of Zurich Insurance Group Ltd and Its Main Rated Subsidiaries
  • Best’s Market Segment Report: AM Best Maintains Stable Outlook on China’s Non-Life Insurance Segment
  • Understanding Nonequity Split-Dollar
  • Life insurance loans: what to do when a client shows interest in one
  • Do You Qualify for Any of September's Class Action Settlements?
Sponsor
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
  • MassMutual Ascend Surpasses $2 Billion in Lifetime Advisory Annuity Sales, Reflecting Continued Momentum in RIA Channel
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.