Print this page
Tuesday, 04 April 2017 22:17

Water UK sets out cyber security principles

Water UK, the body which represents all the UK water companies at both national and international level,  has produced a set of principles and recommendations to help its members address the risks posed to water and waste water services by cyber related threats.

Introducing the guidance, Water UK said the fast pace of the risks from and understanding of cyber threats means that the industry needs to be constantly reviewing and revising its practices.

The report from the Water UK Cyber Security Good Practice Group, produced in collaboration with Defra and the National Cyber Security Centre, sets out six good practice principles:

Principle 1: To have robust and accountable cyber security governance

Principle 2: To proactively manage cyber risk and compliance

Principle 3: To ensure all our people are cyber aware with suitable training and communication

Principle 4: To make best use of good threat intelligence

Principle 5: To improve incident response

Principle 6: To proactively manage procurement, third parties and the wider supply chain

Outside organisations pose “real and tangible threat to water industry”

Commenting on Principle 6, the guidance says that outside organisations pose a real and tangible threat to the water industry and its ability to remain resilient to cyber-attack. This may be through partnerships or joint ventures, supply chain or sub-contractors or a more informal information sharing arrangement.

Water UK says it is important that the organisation concerned addresses these risks and manages their relationships with all third parties. Consideration should be given to procurement, contract management and supply chain management. The consideration should include both an assessment of the suppliers with greatest risks in both cyber and general information management.

Water UK went to explain that the UK water industry provides a unique challenge when it comes to implementing cyber security, commenting:

“The combination of critical national infrastructure, complex investment cycles and legacy hardware, alongside an evolving regulatory framework means that most companies are now juggling priorities to address the risks identified alongside other significant investments. “

”As part of ongoing development, an electronic toolbox of resources and base materials will be made available to water companies in early 2017.”

In March Defra separately published its Water Sector Cyber Security Strategy 2017-2021 summarising what water and sewerage companies need to do to reduce the risks of cyber attacks.  

 Click here to download Water UK's Cyber security principles for the water industry