Local Tech Expert: ‘No One Cares’ about Cyberattacking the Government

By Hank Russell

A local technology expert with a background in cybersecurity says the latest exploitation of U.S. computer infrastructure by Iranian hackers has been ongoing for years and that is because no one is trained to handle these cyberattacks and “no one cares.”

The Federal Bureau of Investigation (FBI) recently issued a joint press release with the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury warning of a security breach in the government’s programmable logic controllers (PLCs).

According to the aforementioned authoring agencies, the group targeted devices spanning multiple U.S. critical infrastructure sectors, including government services and facilities (including local municipalities), water and wastewater systems, and energy sectors. The authoring agencies previously reported on similar activity targeting PLCs by CyberAv3ngers (aka Shahid Kaveh Group) — a cyber threat actor affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC).

“If owners and operators discover an affected internet-accessible device in their environment, additional technical measures may be necessary to evaluate the risk of compromise,” the authoring agencies stated. “Please engage your cyber incident response plans and contact the authoring agencies and applicable vendors through existing support channels available to customers and integrators to receive support, mitigation, and investigation assistance.”

Ed Eisenstein, CEO of United Network Associates, a cloud service and cybersecurity firm based in Farmingdale, says such attacks “have been occurring for over 20 years.” The problem, he says, is that “warnings have gone out for decades and no one cares.”

He also said that those who are responsible for keeping the country’s technological infrastructure secure “show low priority for technology and do not show signs to change,” adding, “The hacker can walk right in and do whatever they want — even today. Data security and intrusion detection are minimal in those operations. Why do we bother to put out these warnings when no one ever does anything about it?”

Eisenstein explained that when he says “no one cares,” he is describing what he sees as a systemic failure rather than the failure of any one individual or department.

“When I say that no one truly cares, it comes from executives not understanding the technology, management not prioritizing data and systems, and technical staff being ignored when critical updates and infrastructure improvements need to be funded,” Eisenstein said. “That is followed by lawmakers who too often place a low value on data security and infrastructure management.”

According to Eisenstein, these failures reinforce one another and can prevent necessary technology and security improvements from ever being implemented.

“It creates a lockup where changes don’t occur, while the systems grow more vulnerable by the day,” he said. “Then, after a couple of attacks make it through, people become accustomed to the breaches and the warnings. Eventually, the result is exactly what I’ve been saying: no one cares anymore.”

Eisenstein also noted that the U.S. Department of Defense (DoD) recently paused Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which was supposed to go into effect on November 10. This phase, according to Washington Technology, would have required third-party certifications for its cyber and supply chain, but the agency said this would be too costly for small and midsized contractors. Phase 1 — which requires companies to assess their own systems on how they protect unclassified information — is still in place.

“Don’t read that as ‘compliance is off,’” Eisenstein said. “If you’re in the defense supply chain … for any framework, a moved deadline doesn’t change the controls that matter — logging, 24/7 monitoring, and evidence you can produce on demand — that auditors and cyber insurers still expect. Paused isn’t gone, and the organizations that keep building now are the ones that won’t scramble when the deadline snaps back.”