Jump to content

Recommended Posts

Posted

NOTE: Not a political post: No political replies are expected, nor are they invited.

 

Link: Thames Water’s IT ‘falling apart’ and is hit by cyber-attacks, sources claim - The Guardian

 

“The software we use is older than me, and some of the hardware is older than my dad,” says Siddharth*. He is one of a team fighting a daily battle to sustain ancient IT infrastructure at Thames Water.

 

Sometimes the defences are breached. Thames, the UK’s largest water and waste treatment company, is on a “knife-edge” according to sources, with its resilience in doubt because it depends on an array of creaking – often Victorian – infrastructure.

 

While plenty of attention has been paid to its pipes, trunk mains and sewage overflows, less well understood is another big problem: its computer systems. Some IT systems date back to the 1980s, and have long been declared obsolete.

 

According to sources who spoke to the Guardian, the systems are so antiquated they have been easy for cybercriminals to attack.

 

“The hardware really is properly falling apart in front of your eyes,” says Siddharth, who is in his 20s. “We’ve been keeping machines going by using parts from similar old ones, once those give up the ghost. But we’ve run out of our stores. We’re not just holding things together with tape and glue. We’re actually unable to turn things off, because we find we can’t turn them on again.”...

 

Sounds like supporting IT in a school!

 

:(

  • Thanks 2
Posted

Surely old systems are harder for cybercriminals to attack, unless they use Matthew Broderick’s setup in Wargames? /partly serious

 

“They’ve managed to hack into the UNIVAC, which doesn’t even have a modem?!”

  • Thanks 2
Posted

It's worrying how many big places are using older systems out there with lots of data in them, the smaller orginisations are doing their bit to keep up to date yet in public sector money is been chucked at these bigger places and they are not moving with the times and don't seem to be penalised for the risk in their IT estate.

 

You have to keep moving with the times, yes it costs but there isn't much you can do about it.

Posted
It's worrying how many big places are using older systems out there with lots of data in them, the smaller orginisations are doing their bit to keep up to date yet in public sector money is been chucked at these bigger places and they are not moving with the times and don't seem to be penalised for the risk in their IT estate.

 

You have to keep moving with the times, yes it costs but there isn't much you can do about it.

 

Doesn't seem the bosses of Thames Water had to keep moving with the times though, I'm sure they made more profit hence more bonuses and have any of them been penalized for it?

  • Thanks 3
Posted
NOTE: Not a political post: No political replies are expected, nor are they invited.

 

Link: Thames Water’s IT ‘falling apart’ and is hit by cyber-attacks, sources claim - The Guardian

 

 

 

Sounds like supporting IT in a school!

 

:(

 

I would say worse, as apart from maybe some old laser cutters or bell systems we don't have that many legacy systems that are essentially to the day to day running of the school. Water companies will have a fair amount of industrial automated systems that only run on old OS versions or using ancient codebases. Bit like the banking sector, and I bet the same is happening, that old systems are being cludged to interact with new systems, probably to help cut costs to manage centrally and this is where security has been compromised.

Posted
I would say worse, as apart from maybe some old laser cutters or bell systems we don't have that many legacy systems that are essentially to the day to day running of the school. Water companies will have a fair amount of industrial automated systems that only run on old OS versions or using ancient codebases. Bit like the banking sector, and I bet the same is happening, that old systems are being cludged to interact with new systems, probably to help cut costs to manage centrally and this is where security has been compromised.

 

My experience was somewhat diffrent. It was always a MAJOR battle to update ageing kit ("It's working isin't? So why to we have to spend this large amount of money to get new stuff?" mentality) while at the same time complaining that it's slow, and dirty and there are bits broken. It was a battle I could never win, and I was always "in the wrong"

 

:(

Posted
Bit like the banking sector, and I bet the same is happening, that old systems are being cludged to interact with new systems,

 

Putting corporate greed and mis-management to one side for a moment; it's the Mergers and Acquisitions, and subsequent de-mergers/devestments that really cause the problems when it comes to modernisation and consolidation of banking/utility IT systems. A friends dad was 12 months off completing a *15 year long* project to merge two banks IT systems and processes, when they were suddenly forced to de-merge. From what I understand, he basically quit on the spot. The de-merger took another decade.

 

I worked there briefly as a temp five years into the merger project. There was at least one process that required staff to print an email with some codes, walk across town to a (mostly) mothballed site where a terminal existed, enter the codes, hit print and then walk the length of the building and up a floor to where the last line printer was, collect the print-out and return to the first office to cross check each line against the output of another system running on NT. The building appears to still be moth-balled which suggests that system might still be in place!

Posted
My experience was somewhat diffrent. It was always a MAJOR battle to update ageing kit ("It's working isin't? So why to we have to spend this large amount of money to get new stuff?" mentality) while at the same time complaining that it's slow, and dirty and there are bits broken. It was a battle I could never win, and I was always "in the wrong"

 

:(

 

Oh I don't doubt it. But I think it is a very different proposition from laptops and servers needing to be replaced, to a software that manages and controls a water filtration and pumping system with automated switching and monitoring (i'm making up terms here but you get the idea). No less frustrating to the person trying to get it all updated but it is an order of magnitude more complicated when the hardware is stuck being managed by that piece of software that the manufacturer won't update, or maybe is no longer in business, especially if that software then integrates with other systems that have been hand crafted to talk in an eldritch language long since forgotten by mere mortals.

 

As I said, the only thing I can relate it to is the stories I heard in the banking sector where all the big players were trying to meet modern expectations, while running a backend not updated since the 80s, as well as trying to keep various systems tacked on due to mergers. You had contractors that had been out of work for a decade suddenly rehired due to no one in the current employment pool understanding the tech or coding language, let alone understand the interactions. It was a huge mess, and completely security compromised, as the systems were never envisaged to be publicly accessible.

 

Obviously (to us) the answer is ongoing investment, not just when the doo doo hits the whirly device, and to not be giving out dividends when the infrastructure is teetering and investment is much more important, or even have the government manage nationally important and critical infrastructure, like water management, distribution and treatment. But that is straying towards the P word, so I will stop there.

  • Thanks 1
Posted
Putting corporate greed and mis-management to one side for a moment; it's the Mergers and Acquisitions, and subsequent de-mergers/devestments that really cause the problems when it comes to modernisation and consolidation of banking/utility IT systems. A friends dad was 12 months off completing a *15 year long* project to merge two banks IT systems and processes, when they were suddenly forced to de-merge. From what I understand, he basically quit on the spot. The de-merger took another decade.

 

I worked there briefly as a temp five years into the merger project. There was at least one process that required staff to print an email with some codes, walk across town to a (mostly) mothballed site where a terminal existed, enter the codes, hit print and then walk the length of the building and up a floor to where the last line printer was, collect the print-out and return to the first office to cross check each line against the output of another system running on NT. The building appears to still be moth-balled which suggests that system might still be in place!

Lloyds TSB?

 

I was briefly involved in the merge project. Finding out that they were being forced to separate them was a proper [emoji2962] moment for me.

  • 4 weeks later...
Posted
This highlights the need for stronger cybersecurity in critical services

 

From July next year, it will be a legal requirement for Australian critical infrastructure.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...