Showing posts with label Smart Grid. Show all posts
Showing posts with label Smart Grid. Show all posts

Thursday, April 7, 2016

Energy Sector Sees Dramatic Rise in Successful Cyber Attacks


Portland, OR – April 7, 2016 – Tripwire, Inc. today announced the results of a study conducted for Tripwire by Dimensional Research. The study, which was carried out in November 2015, assessed cyber security challenges faced by organizations in the energy sector. Study respondents included over 150 IT professionals in the energy, utilities, and oil and gas industries.

When asked if their organization had experienced a rise in successful cyber attacks in the last 12 months, seventy-seven percent of the respondents in Tripwire’s study replied, “yes.” In addition, more than two-thirds of the respondents (sixty-eight percent) said the rate of successful cyber attacks had increased by over twenty percent in the last month.

“It’s tempting to believe that this increase in attacks is horizontal across industries, but the data shows that energy organizations are experiencing a disproportionately large increase when compared to other industries,” said Tim Erlin, director of IT security and risk strategy for Tripwire. “At the same time, energy organizations face unique challenges in protecting industrial control systems and SCADA assets.”

Additional findings from the study include:

• Energy executives were more than twice as likely to believe their organization detected every cyber attack (forty-three percent) than nonexecutives (seventeen percent).

• In the last 12 months, seventy-eight percent of the respondents said they experienced a cyber attack from an external source, and thirty percent have seen an attack from an inside employee.

• Forty-four percent of the respondents indicated they have not gathered enough information to identify the sources of cyber attacks on their organizations.

• Nearly one-fourth (twenty-two percent) of the respondents admitted their organizations do not have business processes to identify sensitive and confidential information.

“ Detecting attacks successfully is the midpoint of the overall process,” Erlin continued. “Energy organizations need to invest in greater prevention and forensic tools to decrease the rate of successful attacks and fully investigate those they can’t prevent.”

According to the Department of Homeland Security, the energy sector faces more cyber attacks than any other industry. Despite these escalating risks, the energy sector faces serious challenges responding to security threats effectively. For example, the results of the North American Electric Reliability Corporation’s (NERC) GridEx III "cyberwar games" revealed significant challenges with the cyber threat intelligence practices of grid operators.

In addition to this study, Tripwire conducted a survey of 200 security professionals attending RSA Conference 2016. When asked if a cyber attack would cause physical damage to critical infrastructure in 2016, eighty-three percent of the respondents replied, “yes.” In addition, seventy-three percent of respondents to this second survey said critical infrastructure providers are more vulnerable to ransomware attacks than other organizations.

For more information about the survey please visit Tripwire.

Related Books

NEW! Cyber Security for Industrial Control Systems: From the Viewpoint of Close-Loop

Cybersecurity for Industrial Control Systems: SCADA, DCS, PLC, HMI, and SIS

Security and Privacy in Smart Grids

Data Privacy for the Smart Grid

Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations

Thursday, January 29, 2015

Nine Questions to Ask to Improve IoT Risk Management

(BUSINESS WIRE)--As connected devices infiltrate the workplace—some with IT’s knowledge and some without—both value and risk can increase significantly. Global IT association ISACA has released new guidance urging companies to ask nine critical questions as they grapple with the Internet of Things (IoT).

ISACA recommends companies address:
1. How will the device be used from a business perspective, and what business value is expected?
2. What threats are anticipated, and how will they be mitigated?
3. Who will have access to the device, and how will their identities be established and proven?
4. What is the process for updating the device in the event of an attack or vulnerability?
5. Who is responsible for monitoring new attacks or vulnerabilities pertaining to the device?
6. Have risk scenarios been evaluated and compared to anticipated business value?
7. What personal information is collected, stored or processed by the IoT device?
8. Do the individuals whose information is being collected know that it is being collected and used, and have they given consent?
9. With whom will the data be shared?

These questions are particularly critical given that 43 percent of enterprises are leveraging IoT already, or have plans to do so in 2015, according to ISACA’s IT Risk/Reward Barometer survey.
“Connected devices are everywhere—from obvious ones, like smart watches and Internet-enabled cars, to ones most people may not even be aware of, such as smoke detectors,” said Robert Stroud, CGEIT, CRISC, international president of ISACA and vice president of strategy and innovation at CA Technologies. “Often, organizations can be using IoT without even realizing it—which means their risk management stakeholders are not involved and potential attack vectors are going unmonitored.”

ISACA’s free (after registration) “Internet of Things: Risk and Value Considerations” guide was released today as a free download at www.isaca.org/internet-of-things. The paper includes dos and don’ts for the IoT, and outlines the types of risks organizations must consider.

Related Books

Unit and Ubiquitous Internet of Things

Smart Grid Security: An End-to-End View of Security in the New Electrical Grid

Data Privacy for the Smart Grid

Security and Privacy in Smart Grids

Monday, January 26, 2015

Critical Infrastructure Executives Complacent about Internet of Things Security


Surveys aren't as bad as listicles for clickbait, but there so seem to be a lot of them, most requiring surrender of sufficient information to quality as a sales lead. Still, they do generate some thought, and the summaries are sufficient to get the key points. Here's a  survey summary on attitudes of critical infrastructure execs on IoT dangers.

Friday, March 28, 2014

Who knows what evil lurks in the Internet of Things?

According to a recent article in CIO, the Internet of Things is creating a scary world. And to think Cisco has started advertising it on TV.

Be frightened. Be very frightened. What you don't know can hurt you.

So, rather than curse the darkness of impending IoT doom, read Unit and Ubiquitous Internet of Things.

Written by Huansheng Ning, it
  • Introduces essential IoT concepts from the perspectives of mapping and interaction between the physical world and cyber world
  • Outlines a fundamental architecture for future IoT, based on the IoT layered model, topological structure, various existence forms, and corresponding logical relationships
  • Presents specific case studies that illustrate various application scenarios
  • Establishes an IoT technology system based on the knowledge of IoT scientific problems
  • Provides an overview of core technologies, including basic connotation, development status, and open challenges

Monday, March 17, 2014

Critical Stuxnet-level Vulnerabilities Discovered in UK Power Plants

It was reported on Friday that three critical vulnerabilities were discovered in UK power plants.

"The security and integrity of Industrial Control Systems (ICS) should be a global concern," said TK Keanini, chief technology officer of Lancope. "The reality is that if these systems were ever vulnerable and reachable via the Internet, they are likely already compromised – simple as that.  Not only should these companies patch the system but care should be taken to investigate the systems integrity. Advanced malware can sometimes install itself and fooling the patching software into thinking it has already been patched – like a Jedi mind-trick "These are not the droids you are looking for" manner.

"Infiltration of these systems is just one step of the larger picture. These industrial facilities must also make it harder for the adversary to remain hidden as they perform their operations. Raising the cost for your adversary to operate is the critical factor these days as infiltration is almost inevitable. Remember the people attacking these ICS systems are the type of people who do not want to be identified."

"These are critical vulnerabilities that allow a remote attacker to gain complete control over systems running Yokogawa CENTUM CS3000 by sending just a few packets to the vulnerable system," said Tom Cross, Lancope's director of security research. "The availability of functioning exploits in the Metasploit framework means that its easy for attackers to target these vulnerabilities. It is extremely important that operators of Yokogawa CENTUM CS3000 install the available security updates immediately.

"It's important to emphasize that the software that controls industrial plant facilities can have serious security vulnerabilities just like any other kind of software. Although we like to think that these systems aren't connected directly to the Internet, it has happened, and often, there are indirect links through back office networks that exist because of the need for the business to monitor its plant operations. Ultimately, its valuable for vulnerabilities like these to be discovered, disclosed, and patched. Identifying and fixing vulnerabilities is part of the process of making these systems more resilient to attack. Frankly, there is much more work to be done in the Industrial Control Systems area before we can have a high degree of confidence that these systems are well protected."

For more on ICS and SCADA security, see these books and articles:

Handbook of SCADA/Control Systems Security

Cybersecurity for Industrial Control Systems: SCADA, DCS, PLC, HMI, and SIS

Smart Grid Security: An End-to-End View of Security in the New Electrical Grid

Security and Privacy in Smart Grids

"SCADA Security: What Is an Industrial Control System?"

"SCADA Security"



Tuesday, April 23, 2013

IoT, IPv6: IT Issues? Security Problems? Anything?

A recent issue of Networkworld teased The Internet of Things: Coming to a Network Near You on its cover.

We’ve been following, and publishing books on, IoT for a long time now. Speakers at last week’s Infosecworld mentioned IoT, along with Smart Grid, in sessions and keynotes. My question is, does anyone really know or care? Based on readership of articles and excerpts we’ve published and book sales, I’d say no.

Yet, like IPv6, another topic that doesn’t seem important to many people, IoT is going to become an IT problem, and an major security issue as well. It’s not just your smart refrigerator telling you to pick up milk on the way home from work. As the Smart Grid rolls out with essentially billions of sensor nodes, and vehicular networks, bandwidth demands will jump sharply and Big Data will inundate everything.

As a test, here are some books, articles, and excerpts covering IoT, IPv6, and Smart Grid. I’m going to monitor to see if there’s any increase in interest.

Articles and Excerpts
Internet of Things: A Context-Awareness Perspective
http://www.ittoday.info/Articles/Internet-of-Things/Internet-of-Things.pdf
The Internet of Things in the Cloud: A Middleware Perspective
http://www.ittoday.info/Articles/Middleware_IoT.htm
Communication Middleware for the Internet of Things
http://www.ittoday.info/Articles/Middleware_IoT.htm
Smart Grids
http://www.ittoday.info/Articles/Smart_Grid.htm
Basic IPv6 Security Considerations
http://www.infosectoday.com/Articles/Basic_IPv6_Security_Considerations.htm

Books

Unit and Ubiquitous Internet of Things
http://www.crcpress.com/product/isbn/9781466561663
The Internet of Things in the Cloud: A Middleware Perspective
http://www.crcpress.com/product/isbn/9781439892992
The Internet of Things: From RFID to the Next-Generation Pervasive Networked Systems
http://www.crcpress.com/product/isbn/9781420052817
Security in an IPv6 Environment
http://www.crcpress.com/product/isbn/9781420092295
IPv6: An Introduction and Overview
http://www.ittoday.info/Articles/Migration-to-Ipv6/Migration-to-Ipv6.htm
Handbook of IPv4 to IPv6 Transition: Methodologies for Institutional and Corporate Networks
http://www.crcpress.com/product/isbn/9780849385162