Defending Our Water – Defending Our Lives

Dean Ford, Virginia “Ginger” Wright (program manager for Cyber-Informed Engineering (CIE) · Idaho National Laboratory (INL)), Andrew Ohrt (Resilience Practice Area Lead · West Yost)

BSides Las Vegas 2025 · Day 1

Overview

This water and wastewater panel connects public health, civil engineering scale, and cyber risk through the lens of cyber-informed engineering (CIE)—a discipline, championed in the session by Ginger Wright (Idaho National Laboratory), that asks engineers to treat digital adversary effects as first-class inputs to physical and process outcomes. Andrew Orth (West Yost Associates) grounds the discussion in utility operations: source water, treatment, distribution, booster stations, SCADA, and the staggering fragmentation of U.S. water systems (~151,000 systems by one definition cited in the talk, with most people served by a long tail of small systems). A third billed panelist, Dean Ford, is absent due to a work emergency but contributes slides and prior BSides LV history referenced by the moderators.

Watch on YouTube

Visual summary for Defending Our Water – Defending Our Lives by Dean Ford, Virginia “Ginger” Wright, Andrew Ohrt
Visual summary for Defending Our Water – Defending Our Lives by Dean Ford, Virginia “Ginger” Wright, Andrew Ohrt

Key moments

  1. 2:00 Andrew Orth and Ginger Wright introduce water/wastewater scope and cyber-informed engineering as limiting physical impacts of cyber attacks.
  2. 10:00 Walkthrough of water sourcing, treatment, distribution, and wastewater return—scale of mains and local system fragmentation.
  3. 24:00 AWWA State of the Water Industry discussion: cybersecurity climbing priority lists, especially for medium/large utilities.
  4. 28:00 Regulatory framing: SDWA cybersecurity assessments, state overlays, litigation on one-size requirements, WRRO/NERC analogy.
  5. 30:00 INL story: IT/cyber and engineering silos; missing conversations linking digital compromise to worst-case physical consequences.
  6. 46:00 CIE headline principles: consequence-focused design and engineering controls that cap damage even if digital layers fail.
  7. 78:00 Booster pump cloud-control tabletop: adversary options (stop, over-pressure, rapid cycling) and $20 time-delay relay mitigation.
  8. 92:00 Idaho DEQ grant scoring incentive: points for cyber-informed engineering in municipal water project proposals.

Defending Our Water – Defending Our Lives

Speakers: Andrew Orth, West Yost Associates (water/wastewater engineering consulting); Ginger Wright, Idaho National Laboratory (OT/cybersecurity, cyber-informed engineering); Dean Ford (contributing slides only—unable to attend); panel includes moderator/participant references to Josh and others from the same BSides track

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=NzqhQjzImEA

Overview

This water and wastewater panel connects public health, civil engineering scale, and cyber risk through the lens of cyber-informed engineering (CIE)—a discipline, championed in the session by Ginger Wright (Idaho National Laboratory), that asks engineers to treat digital adversary effects as first-class inputs to physical and process outcomes. Andrew Orth (West Yost Associates) grounds the discussion in utility operations: source water, treatment, distribution, booster stations, SCADA, and the staggering fragmentation of U.S. water systems (~151,000 systems by one definition cited in the talk, with most people served by a long tail of small systems). A third billed panelist, Dean Ford, is absent due to a work emergency but contributes slides and prior BSides LV history referenced by the moderators.

The session is long, conversational, and frequently interactive—audience questions on regulation (EPA, states, CISA), vendor opacity, rail parallels, AI data centers and water stress, and how to communicate scary truths without FUD. The emotional through-line is pragmatic optimism: utilities increasingly identify as defenders, Safe Drinking Water Act assessments put cyber on recurring industry surveys, and engineering controls—sometimes inexpensive—can bound worst-case physical consequences even when IT/OT intrusions occur.

Background

▶ Watch: Andrew Orth and Ginger Wright introduce water/wastewater scope and cyber-info... (2:00)

Orth introduces himself as a water/wastewater-only engineer with West Yost Associates (~250 people, California-based firm; he lives near Lake Superior, noting it holds about 10% of the world’s fresh surface water). Wright introduces CIE as a strategy to make adversary actions fail to achieve consequential effects by designing limits on what digital control can do to pumps, chemistry, pressure, and public safety.

The panel repeatedly references earlier track talks (Josh, Bryson, Emma/others) about threat narratives and video materials; those specifics are not fully reproduced in this bundle, but the meta-point matters: water security communication must balance truth and empowerment without collapsing into vendor FUD or complacent reassurance.

Orth walks the water cycle for lay and technical audiences: watershed capture, treatment, pumping, mains (from 2 inch to 48 inch typical range cited, with exceptions up to ~10 ft diameter), storage, distribution to homes and hospitals, then wastewater collection, treatment, and discharge. He emphasizes wastewater as a resource recovery story (“contribution” language from Sacramento utility education) and cites stress cases: Met Council releases and Hawaii beach closures when conveyance fails—boil-water orders and EPA engagement appear as downstream governance consequences.

Scale statistics appear throughout: ~500 systems serving ≥100k people, ~500 at 50k–100k, ~9k between 3,300 and 50k (3,300 tied to ~1,000 connections at 3.3 people/connection rule-of-thumb). Water systems are local; interties exist but are rarely exercised because reversing flow can move sediment and create operational risk (Bay Area example).

Key Findings

▶ Watch: AWWA State of the Water Industry discussion: cybersecurity climbing priority ... (24:00)

1) Cyber rises on utility priority surveys. Orth presents AWWA State of the Water Industry themes: cybersecurity climbs into top issues by 2025, with medium/large systems ranking cyber investment as a top priority; small systems lag but the aggregate trend improves.

2) Regulation is dynamic and contested. The Safe Drinking Water Act is described as requiring cybersecurity assessments on a five-year cadence, with states layering annual requirements in some cases. Litigation involving Iowa, Missouri, Arkansas, AWWA, and NRWA is summarized as pushing back on one-size constraints for tiny systems versus megacity systems. A proposed Water Risk and Resilience Organization (WRRO) is discussed as a NERC-like model potentially overseen by EPA—with Ginger noting legislation has been pending for years.

3) CIE closes a recurring gap: IT/cyber teams protect digital layers while engineers/operators own physical reliability, often without shared consequence models. INL’s origin story for CIE: assessments found missing bridging conversations—“what is the worst physical outcome if adversaries achieve full control of this digital surface?”—and therefore mis-prioritized controls.

4) Two headline principles dominate twelve: Consequence-focused design (engineer to cap worst-case physical/process outcomes under adversary control) and controls that reduce attack avenues/damage (explicitly not perimeter absolutism). A third cultural pillar, cybersecurity culture, is described as aligning executives, engineers, operators, and cyber staff on what must never happen.

5) Engineering ethics intersect CIE. Licensed engineers cite public health/safety/welfare paramountcy and an ethical duty not to practice on systems you do not understand—used rhetorically to justify cross-training and humility.

6) Vendor constraints impede understanding. Purchase agreements may forbid inspection of critical equipment, blocking the joint cyber+engineering analysis needed for rigorous failure imagination.

7) Practice story: booster pumps + cloud control. A classroom-style scenario explores cloud-based pump control: adversaries could stop pumps, over-pressurize, rapid-cycle motors to induce thermal damage, or attack chemistry if in scope—then narrows scope (chemistry not cloud-controlled in the scenario). A time-delay relay (~$20) is offered as a physical-rate limit on command changes, synergizing with SOC monitoring—defense in layers.

8) Cost and adoption: Orth argues much CIE value is in the first 80% with modest incremental engineering review; some mitigations are thousands of dollars at pressure-zone scale, applied selectively to highest-consequence areas (e.g., hospital zones). Idaho DEQ grant scoring that awards points for CIE is highlighted as an incentive alignment case.

9) Incidents and perception: Discussion touches Oldsmar (narrative disagreements acknowledged), Aliquippa, Mules/Abernathy Texas cases, and a Wired article recommendation. Public CNN amplification caused Minnesota parents to worry about Florida events—an example of nationalized fear without system coupling.

10) Data centers and water stress: Orth revises an earlier aside—some utility/data-center relationships do carry contractual teeth when cooling or water availability slips. Carlsbad groundwater difficulty illustrates why “just drill a well” is not a universal backup plan. The panel points attendees to a next-day track talk on AI data centers as simultaneous threat and fix (as teased in-session).

11) OSINT + LLMs as a double-edged reconnaissance tool: Orth mentions asking an LLM what PLC model a named utility might use—sometimes right, sometimes wrong—and always reporting outcomes. The anecdote is less about model magic than about readily available OSINT pressure on OT footprints, nudging IT managers when public data exposes gaps.

12) Implementation scaffolding: Orth references a CIE implementation guide described as ~1,200 questions—intentionally overwhelming as a prompt for structured thinking across principles and lifecycle stages rather than a linear checklist to complete in one sitting.

Technical Deep Dive

▶ Watch: INL story: IT/cyber and engineering silos; missing conversations linking digi... (30:00)

Cyber-informed engineering mechanics

CIE is not “more firewalls.” It is process-aware security: map critical functions, identify cyber-enabled failure modes (including subtle ones—Ginger warns failure is not only “off,” but unsafe speed, vibration, accelerated wear, or chemistry drift). The approach leverages engineering fluency in functionality, safety, and reliability—quantities operators already manage.

Lifecycle insertion points

Orth maps water project design milestones (PDR, 30%, 60%, 90%, IFC/commissioning) and argues 60% design is a CIE sweet spot because control and electrical drawings exist but capital is not fully committed. A client lesson: by 90%, much spend is sunk—changes become change orders. Therefore, red-team-style design reviews should run early.

“Mission commander” attack rehearsal

West Yost/INL collaboration described a commander/attack cell structure to review process flow diagrams as attack surfaces, improving communication to utilities and yielding RFP language embedding CIE requirements.

Manual operations and “day without SCADA”

Operators can be license-bound and resist exercises that feel like risking credentials; nonetheless, planned resilience and active defense are highlighted for brownfield systems.

Physical analog protections

Examples include pressure sensors wired out-of-band from PLCs directly into motor controls so adversaries cannot spoof safety inputs through the PLC alone.

Rail analogy for “digital vuln, physical bound”

A questioner working in light rail raises vendor-managed environments and limited visibility. The panel responds with a train protocol vulnerability anecdote (recent press described qualitatively): digital exposure mattered, but physical and operational protections still bounded harm—a CIE parable transferable to water pump fields and yard safety culture.

Demo / Proof of Concept

▶ Watch: CIE headline principles: consequence-focused design and engineering controls ... (46:00)

There is no exploit demo. The booster pump scenario functions as a tabletop engineering walkthrough: audience proposes adversary moves; panelists respond with physics limits, response times (~two hours truck roll cited for some restores), and 18-month pump replacement timelines for severe damage—then introduces time-delay relays and monitoring partnerships with SOC analysts who should consult engineers before dropping automated command blocks.

Defensive Implications

▶ Watch: Idaho DEQ grant scoring incentive: points for cyber-informed engineering in m... (92:00)

For utility executives, the actionable thesis is to fund cross-functional consequence modeling before buying cloud control features that compress operator labor without compressing risk. For state regulators, Idaho-style grant scoring is a template: move maturity with money, not only mandates. For federal stakeholders, the WRRO discussion frames industry-owned standards with EPA alignment as a potential stability mechanism—pending legislation.

For cyber teams, stop delivering password-length lectures without plant context; instead request failure workshops that engineers can recognize as HazOp-adjacent. For vendors, right-to-inspect and supportable security architectures are systemic issues—procurement should treat black boxes as risk acceptance items, not defaults.

Storytelling without FUD

Josh (moderator/track lead, as referenced) discusses stakeholder-specific messaging: the same water-hammer story may motivate engineers yet alarm neighbors inappropriately. The panel argues scary topics require packaged mitigations—$2k–$10k fixes paired with narratives—to avoid paralysis or cynicism after years of vendor-driven alarm fatigue.

Key Takeaways

  • Water is hyper-local yet nationally sensitized; fear travels faster than hydraulic coupling.
  • Cyber is now a top-tier utility concern in industry surveys—especially in larger systems.
  • CIE bridges digital attacks to physical consequence caps using engineering primitives.
  • Design-stage intervention beats retrofit panic; 60% design is a leverage point.
  • Inexpensive physical controls (e.g., time-delay relays) can bound digital abuse rates.
  • Trust, training, and grants may beat FUD for sustained adoption.
  • Vendor inspection limits remain a structural barrier to rigorous analysis.

About the Speaker(s)

Andrew Orth is a water/wastewater engineer with West Yost Associates, working nationwide on risk/resilience assessments and CIE adoption support. Ginger Wright represents Idaho National Laboratory work on OT cybersecurity and leads CIE training content at the event (scheduling noted mid-panel). Dean Ford contributed slides but was absent live. Orth mentions a book co-authored with Dan Groves, published through AWWA, aimed at accessible case-study storytelling for utility audiences (per closing remarks). Additional names (Josh, Bryson, Emma, Manish, Andy Bachmann) appear as referenced track participants rather than primary speakers in this recording. Bundle metadata lists Speakers: Unknown; names and affiliations are taken from the session audio.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A long-form critical-infrastructure panel that explains cyber-informed engineering clearly and gives memorable engineering-boundary examples, but it is policy/process theater more than new technical research.

Heather Calloway (CISO) — MUST SEE

This is board-relevant critical infrastructure content: it ties cyber risk to public health outcomes, procurement, grants, and engineering ethics—without pretending firewalls alone solve plant safety.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025