ANN ARBOR – Michigan isn’t starting from scratch in protecting drinking-water infrastructure.

The Michigan Department of Environment, Great Lakes and Energy recommends that water utilities implement a substantial list of cybersecurity protections.

Among them are strong passwords, multifactor authentication, software and hardware updates, continuous network monitoring, offline backups, employee cybersecurity training and incident-response plans.

Of particular importance following the latest attacks, the state recommends separating operational-technology networks from conventional information-technology systems and limiting connections between critical operational equipment and the public Internet.

But there is an important distinction between recommending cybersecurity protections and requiring them.

EGLE says cybersecurity assessments aren’t currently mandated under the federal Safe Drinking Water Act.

nstead, they are highly recommended.

Michigan regulates roughly 1,400 community public water supplies, ranging from major municipal systems serving hundreds of thousands of residents to much smaller local utilities.

That raises questions extending far beyond the nine systems targeted in the latest attacks.

How many Michigan water utilities have completed cybersecurity assessments?

How many have fully separated their operational technology from ordinary computer networks?

How many still have industrial equipment accessible through the public Internet?

And should minimum cybersecurity standards become mandatory for infrastructure as essential as drinking water?

Michigan Has Resources To Help Water Systems

Michigan has spent years developing a statewide cybersecurity response structure.

The Michigan Cyber Command Center coordinates cyber incident response and investigations and works with state agencies and federal partners including the FBI and the federal Cybersecurity and Infrastructure Security Agency.

Michigan also operates MiCyberCorps, a reserve of trained civilian cybersecurity professionals that can assist government agencies, educational institutions and businesses during serious cyber incidents.

The Michigan Department of Technology, Management and Budget also administers federal State and Local Cybersecurity Grant Program funding.

Eligible projects can include vulnerability scanning, penetration testing, endpoint protection, backup systems, multifactor authentication and assessments involving industrial-control and operational-technology systems.

The latest attacks therefore raise another question:

Were the nine targeted water systems already taking advantage of those resources?

OpenAI Offers Michigan Cybersecurity Help

OpenAI has offered cybersecurity assistance to Michigan following the attacks, according to the Detroit Free Press.

Exactly what the artificial-intelligence company is offering remains unclear.

It was not immediately clear Saturday whether Gov. Gretchen Whitmer’s administration had accepted the offer or whether OpenAI is proposing technology, cybersecurity personnel, threat-analysis capabilities, training or some combination.

Those questions are particularly interesting because OpenAI is developing a major economic presence in Michigan.

The company is associated with the enormous planned data center development in Saline Township and was one of six companies signing Whitmer’s Michigan Affordability and Responsible Growth Pledge in July.

OpenAI therefore isn’t simply an outside technology company volunteering assistance. It is becoming a significant participant in Michigan’s technology and infrastructure economy.

Michigan Cybersecurity Companies Could Play A Role

Michigan also has its own cybersecurity industry capable of helping local governments strengthen their defenses.

DTMB maintains a roster of cybersecurity vendors selected through a competitive state process to perform independent cybersecurity assessments for local public entities.

Michigan-based companies on the list include CyberforceQ in Plymouth, Dewpoint in Lansing, Merit Network in Ann Arbor, OpTech in Troy, Rehmann Technology Solutions in Saginaw, Securely Yours in Bloomfield Hills and UHY in Farmington Hills.

The state’s assessment program can include vulnerability analysis, recommendations for security improvements, incident-response planning and continuing cybersecurity advisory services.

Protecting water-system industrial controls, however, can require specialized expertise beyond conventional information-technology security.

That could increase demand for cybersecurity professionals who understand both computer networks and the operational technology controlling physical infrastructure.

Nine Attacks Leave Michigan With Questions

Michigan’s drinking water remained safe.

But that doesn’t mean the attacks were inconsequential.

They exposed questions about how well the state’s roughly 1,400 community water systems are prepared for attackers increasingly interested in the computers controlling physical infrastructure.

Michigan officials now need to determine how attackers reached the nine targeted systems, whether they gained control of any operational equipment, whether any SCADA environments were penetrated and whether attackers retained access.

They also need to determine whether the affected utilities had undergone cybersecurity assessments and whether they were following state and federal recommendations before the attacks occurred.

And Michigan must decide whether cybersecurity assessments and minimum security protections for water infrastructure should continue to be voluntary.

OpenAI’s offer adds another question: What exactly is the company proposing, and will Michigan accept it?

MITechNews will seek answers from the Whitmer administration, EGLE, Michigan cybersecurity officials, OpenAI and Michigan cybersecurity companies.

But one question may matter more than all the others:

Did the attackers simply test Michigan’s defenses — or did they find a way back in?