First Water. Then Energy. Now Airports?

Hacky hacky hacky hits the more traditional sources…or does it?

Suspected Iranian hackers have recently hacked water and energy systems.

So it seems to be a relief that the Manchester Airports Group was hacked by what seems to be a traditional hack.

“According to officials, the unauthorised intrusion took place over the weekend, though it was quickly contained once detected. The vast majority of the breached records stemmed from traveller sign-ups for terminal Wi-Fi networks. Additional compromised data was linked to auxiliary services, including, advance parking reservations, executive lounge passes and fast-track security access bookings.”

This doesn’t SEEM to be a critical infrastructure attack, since this focused on customer data (wi-fi, parking, lounges) rather than operations data (air traffic control).

But who knows?

Energy and International Critical Infrastructure

I have previously noted that water is part of the United States’ critical infrastructure, and has been designated as such by the U.S. government.

But there are fifteen other critical infrastructure segments, including energy:

“The energy infrastructure is divided into three interrelated segments: electricity, oil, and natural gas. The U.S. electricity segment contains more than 6,413 power plants (this includes 3,273 traditional electric utilities and 1,738 nonutility power producers) with approximately 1,075 gigawatts of installed generation. Approximately 48 percent of electricity is produced by combusting coal (primarily transported by rail), 20 percent in nuclear power plants, and 22 percent by combusting natural gas. The remaining generation is provided by hydroelectric plants (6 percent), oil (1 percent), and renewable sources (solar, wind, and geothermal) (3 percent). The heavy reliance on pipelines to distribute products across the nation highlights the interdependencies between the Energy and Transportation Systems Sector. 

“The reliance of virtually all industries on electric power and fuels means that all sectors have some dependence on the Energy Sector. The Energy Sector is well aware of its vulnerabilities and is leading a significant voluntary effort to increase its planning and preparedness. Cooperation through industry groups has resulted in substantial information sharing of best practices across the sector. Many sector owners and operators have extensive experience abroad with infrastructure protection and have more recently focused their attention on cybersecurity.”

And no, there’s not an omission. Nuclear is a separate sector.

And obviously the United States is not the only country dependent on energy, as residents of the United Kingdom found out.

“It seems that the Iranians were successful in taking a UK power plant for four days back in July….

“[H]ackers believed to be affiliated with the Iranians were behind the attack. British officials declined to identify the site for security reasons, and the government has described it only as a small-scale energy generator….

“the target was a small gas-fired ‘peaker’ plant. These facilities are designed to provide additional electricity when demand rises or when other sources are producing less power.”

Brian Harris speculates that programmable logic controllers (PLCs) were the target, as they were in the U.S. water cybersecurity attacks.

When critical infrastructure components are online, everything is a potential target.

Don’t Trust

I’ve previously noted that too many identity/biometric companies use the same word—trust—in their marketing. Resulting in non-differentiated sameness and uniformity.

Even though the technical underpinnings behind the companies’ solutions have moved away from the ideas of firewalls, trusted networks, and trusted devices. In today’s mandated zero trust environment, everyone—including your chief engineer—must prove their rights to access information. Every. Time.

Zero trust is even stricter than the Reagan-era “Trust, but Verify.” Which is a 2026 cybersecurity expert’s worst nightmare.

And to truly embrace zero trust in both technological and business contexts, customers must demand that vendors prove themselves continuously.

Some customers don’t make such demands, but others do. I know of a national agency that had been with a vendor for years…and then decided that it was a good idea to learn what the other vendors were offering. After hearing the others, the customer let the original vendor (my then employer) make its own pitch. For a variety of reasons they switched vendors…but haven’t switched since.

If your customers insist on continuous trust evaluation, how can you as a vendor continuously re-earn that customer trust?

Water, Programmable Logic Controllers, Iran, and Critical Infrastructure

Here in the southwestern United States, water or the lack thereof may be so contentious that we blithely say that we have to fight for it.

Meanwhile, things happen.

“Water and wastewater utilities in at least seven states have now reported cybersecurity incidents involving Internet-facing programmable logic controllers (PLCs), according to the FBI and the Environmental Protection Agency (EPA)….Specific states were not named.”

But at least four incidents HAVE been explicitly named.

“Meanwhile, Minnesota officials announced this week that at least 30 community water systems across the state were hit with malicious cyber activity, and an investigation is ongoing there….

“Four Minnesota city water organizations publicly announced cyber incidents, but others are unidentified. Braham’s water plant went temporarily offline; Plymouth announced impacts to automated controls and cellular-connected equipment at water towers and lift stations; South St. Paul announced a cybersecurity incident on automated controls; and Maple Plain declared a temporary emergency.”

Now perhaps this is just a bunch of instances of kids messing around.

Beavis and Butt-Head at Hoover Dam.

Or perhaps it’s something else.

“The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).”

Yes, Iran. You may recall that we are at war with them.

This brings these incidents into the realm of critical infrastructure. Among our 16 critical infrastructure sectors is the water and wastewater sector.

“In the United States, there are approximately 152,000 public drinking water systems, including 50,000 community water systems, and more than 16,000 wastewater treatment systems. Over 80 percent of the U.S. population receives their potable water from these drinking water systems, and about 75 percent have their sanitary sewerage treated by these wastewater systems. 

“The Water and Wastewater Systems Sector is vulnerable to various threats, including physical attacks, cyberattacks, and contamination with harmful agents. Such incidents could result in widespread illness, casualties, and service disruptions, significantly impacting public health and economic stability.”

Messing up someone’s computer is bad enough. But messing up their glass of drinking water is devastating. And whether the damage is done by a state-sponsored terrorist or by Beavis, you want to prevent it from happening.

Google Gemini.

Is It Harder to Monitor Confidential Data Transfers?

In the pre-digital days, if you wanted to transfer confidential data you had to hand-carry it.

Now it is possible to track movements of confidential data digitally.

If data moves off a laptop you can track it.

Google Gemini.

Unless it moves off a laptop or a smartphone that you’re NOT monitoring.

Oops.

Is Your Identity/Biometric Firm Too Busy Putting Out Fires to Install a Sprinkler System?

It’s the classic case of paralysis by overwhelmedness. (Not officially a word, but bear with me here.)

Your identity/biometric firm needs experienced product marketing contract help because you are drowning in work. But because you’re drowning in work you can’t take the time to set up that contract.

Bredemarket can help you contract with Bredemarket.

Now there are certain things that Bredemarket can’t do. Well, Bredemarket could do them, but you (understandably) won’t let me.

  • I can’t create my own contract with you. Actually I can, and I have with some clients, but your company probably requires that I use your contract, which I don’t have.
  • I can’t enroll myself as a vendor in your purchasing system. Trust me, that would be dangerous. Hmm…net 5 terms at $1,000 per hour?
  • I can’t onboard myself into your other internal systems. If I could, that would be a major security flaw.

But there are things that I can do to make your life easier when you onboard Bredemarket as a contractor/vendor…especially if you are an identity/biometric firm.

  • You don’t have to explain to me what a bifurcation or ridge ending are. I’ve been working with fingerprints since 1994 and know these things.
  • You don’t have to teach me how to spell NIST. While the 1985 interchange standard was before my time, I’m familiar with every ANSI/NIST standard since 1993 to the present day.
  • You don’t have to explain to me what a “factor” and a “modality” are. Heck, I wrote the book on factors and modalities.
  • You don’t have to create a briefing book. Just let me ask the questions and we’ll figure out the scope together.

So I can meet your partway. Then we’ll realize our mutual goal of making your products prominent and making the competitive products look weak.

So let’s talk and move the process forward.

Oh, and the title of this post was suggested by Google Gemini. AI is only a tool, but sometimes it’s a very effective tool. Sometimes.

So What About OMB M-22-09?

In a previous post I looked at the Biden Administration Executive Order 14028 – Improving the Nation’s Cybersecurity, including its championing of Zero Trust Architecture (ZTA) and least-privilege access.

During the Biden Administration, the Office of Management and Budget issued a related memorandum, M-22-09 (PDF), that dictated a particular approach. Again, ZTA was emphasized.

And the OMB proposed an action plan:

This memorandum requires agencies to achieve specific zero trust security goals by the end of Fiscal Year (FY) 2024. These goals are organized using the zero trust maturity model developed by CISA. CISA’s zero trust model describes five complementary areas of effort (pillars) (Identity, Devices, Networks, Applications and Workloads, and Data), with three themes that cut across these areas (Visibility and Analytics, Automation and Orchestration, and Governance).

Naturally I’m interested in the identity part.

Agencies must employ centralized identity management systems for agency users that can be integrated into applications and common platforms.

Agencies must use strong MFA throughout their enterprise.

  • MFA must be enforced at the application layer, instead of the network layer.
  • For agency staff, contractors, and partners, phishing-resistant MFA is required.
  • For public users, phishing-resistant MFA must be an option.
  • Password policies must not require use of special characters or regular rotation.

When authorizing users to access resources, agencies must consider at least one devicelevel signal alongside identity information about the authenticated user.

Did the Federal Government accomplish the OMB M-22-09 identity objectives?

Sort of.

  • While some agencies mostly moved to centralized systems, some legacy systems didn’t transition.
  • Authentication moved away from weak MFA (such as sending an SMS to a device as the second factor).
  • Device signals aren’t fully implemented. Using one example, dynamically blocking access in real-time if a virus is detected is NOT fully operational. But this is challenging when you consider all the computers, smartphones, and other devices (including Internet of Things devices) that are managed.

But the government said (in a 2024 Impact Report) that the government performed well.

In effect, OMB M-22-09 is now a legacy document since the 2024 deadline has passed. But it’s still referenced, somewhat, in government cybersecurity efforts.

Are you meeting your prospects’ zero trust needs?

If Bredemarket can help you with strategic and tactical analysis, content, and proposals that address the zero trust architecture, set up a free meeting with me to discuss your goals.

About the Operational Zero Trust Architecture Portions of Executive Order 14028

Phishing-resistant government systems are no longer a “nice-to-have,” but are now a federal mandate. Government agency information technology (IT) leaders are compelled to meet Zero Trust Architecture (ZTA) mandates.

One such mandate is Executive Order 14028 – Improving the Nation’s Cybersecurity, originally issued by President Joe Biden in 2021. Although portions of this executive order were subsequently modified by Executive Order 14306, the impetus toward ZTA remains.

As you can see from the sections quoted below, the Federal Government agency emphasis focuses on:

  • Zero Trust Architecture, which supersedes the prior notion that the “internal” portions of a network can be trusted. Threats can come from anywhere.
  • Securing cloud implementations, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Least-privilege access, in which each user (this was when users were assumed to be human) only has the privileges they require.

Section 3, Modernizing Federal Government Cybersecurity

(a) To keep pace with today’s dynamic and increasingly sophisticated cyber threat environment, the Federal Government must take decisive steps to modernize its approach to cybersecurity, including by increasing the Federal Government’s visibility into threats, while protecting privacy and civil liberties. The Federal Government must adopt security best practices; advance toward Zero Trust Architecture; accelerate movement to secure cloud services, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS); centralize and streamline access to cybersecurity data to drive analytics for identifying and managing cybersecurity risks; and invest in both technology and personnel to match these modernization goals.

(b) Within 60 days of the date of this order, the head of each agency shall…

(ii) develop a plan to implement Zero Trust Architecture, which shall incorporate, as appropriate, the migration steps that the National Institute of Standards and Technology (NIST) within the Department of Commerce has outlined in standards and guidance, describe any such steps that have already been completed, identify activities that will have the most immediate security impact, and include a schedule to implement them…

(c) As agencies continue to use cloud technology, they shall do so in a coordinated, deliberate way that allows the Federal Government to prevent, detect, assess, and remediate cyber incidents. To facilitate this approach, the migration to cloud technology shall adopt Zero Trust Architecture, as practicable. The CISA shall modernize its current cybersecurity programs, services, and capabilities to be fully functional with cloud-computing environments with Zero Trust Architecture….

(i) Within 90 days of the date of this order, the Director of OMB, in consultation with the Secretary of Homeland Security acting through the Director of CISA, and the Administrator of General Services acting through FedRAMP, shall develop a Federal cloud-security strategy and provide guidance to agencies accordingly. Such guidance shall seek to ensure that risks to the FCEB from using cloud-based services are broadly understood and effectively addressed, and that FCEB Agencies move closer to Zero Trust Architecture.

Section 10, Definitions

(k) the term “Zero Trust Architecture” means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy based on an acknowledgement that threats exist both inside and outside traditional network boundaries. The Zero Trust security model eliminates implicit trust in any one element, node, or service and instead requires continuous verification of the operational picture via real-time information from multiple sources to determine access and other system responses. In essence, a Zero Trust Architecture allows users full access but only to the bare minimum they need to perform their jobs. If a device is compromised, zero trust can ensure that the damage is contained. The Zero Trust Architecture security model assumes that a breach is inevitable or has likely already occurred, so it constantly limits access to only what is needed and looks for anomalous or malicious activity. Zero Trust Architecture embeds comprehensive security monitoring; granular risk-based access controls; and system security automation in a coordinated manner throughout all aspects of the infrastructure in order to focus on protecting data in real-time within a dynamic threat environment. This data-centric security model allows the concept of least-privileged access to be applied for every access decision, where the answers to the questions of who, what, when, where, and how are critical for appropriately allowing or denying access to resources based on the combination of sever.

The Bredemarket sales pitch

Can Bredemarket help you describe your zero trust architecture solution? If so, set up a free meeting with me to discuss your needs.

WordPress and Claude: No, Yes, Maybe, No, No…and No

There is a difference between a writer and a content creator. It becomes obvious when you read WordPress’ recent post, “How to Slop Your Content in Five Steps.”

Actually, that’s not the title.

Claude the content creator

Whoever or whatever wrote WordPress’ post used a more AEO-friendly title: “How to Build an Endless Stream of Content Ideas with WordPress and Claude.”

And there are five steps.

  • Step 1: Connect Claude to your WordPress.com website.
  • Step 2: Ask Claude to review your website and find content gaps.
  • Step 3: Ask Claude to prioritize topics and create a content calendar.
  • Step 4: Create Claude-assisted outlines and articles.
  • Step 5: Ask Claude to add the article to WordPress.com.

Bredemarket the writer

Before I discuss these five steps, let me state two things specific to me that may not apply to you.

  • With one glaring exception, the Bredebot project. This is a highlighted experiment to see how far a well-prompted bot will go.

So my specific response to these steps is to consider the gap analysis in step 2. Bots are good at such analysis, but they have to be watched in case they don’t get their facts straight.

But I won’t give Claude the permission to write and post articles, or even any permissions on WordPress. This is a security issue, after all; how do YOU control site access for non-human identities?

In fact, I may not even use Claude for step 2, even if it’s the cool kid this week last I checked. I may use Gemini…or a thousand Bangladesh techies…or a million Pentiums…or Mika.

How you work with outside content creators

But what about you?

Before answering, take the five steps above and change the name “Claude” to Barney…or Bredemarket.

Would you give Barney or Bredemarket that power over your website?

Maybe…or maybe not.

How Bredemarket works with you

In the case of Bredemarket, I usually do NOT have direct access to my clients’ websites, sending them Word documents instead. And in the one instance where I did have website access, I left every one of my drafts in draft mode.

And when I perform a gap analysis, I present my client with choices and ask the client to choose the topic, or at least approve my suggested topic.

Because your website is not mine, or Mika’s…or Claude’s.