Hiển thị các bài đăng có nhãn awareness. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn awareness. Hiển thị tất cả bài đăng

Calls for Enhanced Enterprise Security Governance Starting to Steamroll


Though I've been approaching this issue from a sector-specific perspective for years, lots of what's been in the news lately (and I mean lately) is intended for all technology-enabled sectors. Which pretty much means every business and every organization that intends to maintain consistent and reliable operations in the near and mid-term future.

First off, and with origins that predated the Target breach that's credited with generating most of this activity, was DOE's Energy Advisory Committee giving thumbs up in May to a paper on this topic on Security Governance. It proposes that DOE pursue potential upgrades to how energy companies organize and run themselves from a security perspective. Titled: EAC Recommendations for DOE Action Regarding Implementing Effective Enterprise Security Governance - Outline for Energy Sector Executives and Boards, among other things, this paper lists the following "Characteristics of Effective Security Governance":
  • Clearly defined responsibilities from the board of directors to senior leadership to employees 
  • Presence of an active Security Governance board comprised of senior stakeholders from across 
  • the company 
  • An executive owner of enterprise security: with purview over IT, OT and physical security policy designated CSO or similar 
  • Striving for 100% alignment with of security with business/mission 
  • Using measurement of key indicators to increase awareness and drive improvement (with 
  • maturity tools like DOE's ES-C2M2

Then there's this from Reuters in May: Exclusive: U.S. companies seek cyber experts for top jobs, board seats, which emphasizes the concept of getting the security chief out of IT:
While a CISO typically reports to a company's chief information officer (CIO), some of the hiring discussions now involve giving them a direct line to the chief executive and the board, consultants and executives said. After high-profile data breaches such as last year's attack on U.S. retailer Target Corp, there is now an expectation that CISOs understand not just technology but also a company's business and risk management.
The Securities and Exchange (SEC) commissioner recently added his voice as well. In SEC Commissioner Calls on Corporate Boards to Address Cybersecurity, Commissioner Luis Aguilar  expresses his hope for governance improvements this way: “One would expect that corporate boards and senior management universally would be proactively taking steps to confront these cyber-risks.”

Then, from the International Association of Privacy Professionals online journal, there was Cybersecurity in the Boardroom: The New Reality for Directors, which included a list of recommendations, some of which have particular relevance for security governance and culture:
  • Develop a high-level understanding of cyber-risks facing the company through briefings from senior management and others
  • Ensure that the company has at least one committee that is responsible for overseeing and understanding cybersecurity issues, controls and procedures
  • Facilitate a culture that views cybersecurity as a business issue that all employees should understand and participate in. As part of that, companies should consider employee training and awareness programs
  • Include a cyber-expert on the company’s board of directors or receive regulator reports from a cybersecurity expert that are discussed at board meetings
So, as you can see, what once felt like a voice in the wilderness is now becoming a chorus.  Or you could say a trickle is becoming a deluge.  No matter the metaphor, will a little help from the Federal Government, and a lot more from The Real World, enterprise security governance is beginning to get the attention it deserves.

Image credit: Peter Skelton



Singer & Brookings on the Security Governance/Ownership Vacuum

Analyst and author Peter Singer of the Brookings Institute has a new book out intended for everyman. And everywoman. To include particularly those types who consider themselves non technical, or as I've heard cyber folks in DOD refer to them - tech immigrants (vs. typically younger tech natives).

The net he casts is wide enough to captures senior government and business leaders too.  Below are excerpts from a recent interview with CNN/Fortune that really resonated with me, with particular applicability to our sector:
"Stop looking for others to solve it for you, stop looking for silver bullet solutions, and stop ignoring it." 
"I would argue that there's no issue that's become more important that's less understood than cyber. You can see this gap in all sorts of areas, including on the business side." 
"Cybersecurity and cyberwar questions are going to be with us as long as we use the Internet, so we have to stop being scared and start figuring out how to manage it. And when I say "we," I mean it's not just for the IT crowd anymore." 
"First, the people that sit in the C-suite, the people sitting on the Supreme Court, the people who are generals -- they likely didn't use computers when they were in college." 
"It's about getting the human side of this right -- the people and the processes and the way they fit in with the technology." 
"Whether you're working in the IT department or you're a lawyer or you're working in operations or wherever, you're increasingly going to be dealing with cybersecurity questions, whether it's managing people who work on them or figuring out how to protect yourself and your company from threats to your intellectual property, to your services, to your contract negotiations, or deciding "how much should I spend on this in my budget? Who should I be hiring?"
And for me this is the biggest / best one, especially for energy sector execs and boards:
"Most worrisome to me is the notion that this is for the IT crowd. This is for the nerds to handle. That's how it's been treated before: 'I don't understand this stuff so I'm going to hand it over to the techies' First, that's an abdication of leadership. Secondly, the IT crowd understands the software and hardware, but they don't understand the wetware. They don't understand the humans and the organizations and the ripple effects around them that are equally, and in many cases more, important."
It's a great roll-up of many of the awareness, leadership and governance concepts you've seen on this blog, but in a more visible medium.  Hope it sells well and gets read by lots of folks.

Co-authored by Singer and Allan Friedman, the book is called Cybersecurity and Cyberwar: What EveryOne Needs to Know.

ICS Electric Utility Attack Video and Aegis to the Rescue


SANS Securing the Human - ICS Attacker
The excellent security-mined people at the SANS Institute have produced an 8 minute video that walks you through a control systems attack.  The money they saved by using animation instead of Matt Damon or Morgan Freeman was put to good use as you'll see. For such an esoteric subject, this is a first rate video. For more info please visit the Securing the Human site at http://www.securingthehuman.org/

Meanwhile, to calm you down after the video gets your heart rate up, you should start learning about a new tool that's set for release at the upcoming SANS SCADA Summit. It's called Aegis and it's not an anti-ballistic missile system.  It's a testing tool to help ensure systems communicating with one of the most common SCADA and controls systems communications protocols, DNP3, are harder to attack.

You can ready more about Aegis here: http://www.automatak.com/aegis/

And more about the SANS ICS Summit here: http://www.sans.org/event/north-american-ics-scada-summit-2014

A Novel Approach to Grid Cybersecurity Awareness


Not long ago I was in a meeting with the CIO of a large electric utility and when I inquired as to the cybersecurity awareness of the board of directors, was told it had recently skyrocketed.

Why the sudden shift I asked?  Had the company just endured a serious and/or highly public breach? Nope, things had been mercifully static on that front. A classified threat briefing by DHS? No, not that either. Well, what was it then?

Apparently one board member had read the latest Tom Clancy book, Threat Vector and once exposed to Clancy's fictional vision of how the US could be brought low through largely cyber means, it changed his thinking. Spoke in language he could understand, and captured his imagination too. It soon spread to the rest of the board.

Now comes former Senator Byron Dorgan with a cautionary novel of his own, and this one is much more grid-centric, from the title on. I later read Threat Vector myself ... 900 pages or so if I remember right, looking for power sector specific attacks and breaches and they were few. I've read some of the reviews of Gridlock, though, and in it the US grid is front and center and not doing so well.

Dorgan and co-author David Hagberg don't have anywhere near Clancy's readership, not close. But if an executive in your company were to happen upon a copy, well, apparently it's quite a page turner, and you might have a new, more cybersecurity-aware board to work with in a few weeks.


The Things I've Seen Series: Part 2 - Execs Exempted



Last week I posted on an encouraging trend I witnessed over the past 2 years: the emergence in some utilities of security governance boards comprised of security and privacy leaders, often a rep from legal or compliance, and senior stakeholders representing different business lines.  Soon after it went live, I received multiple corroborations from friends in the field who have seen the same thing in their patches. This is all goodness.

But there are other, less uplifting trends you should be aware of if you're not already. I've seen senior executives who have not once met with their cybersecurity leaders and who feel they have no reason to do so. I've had senior state regulators tell me that they haven't really thought about cybersecurity until very recently. 

And I've heard that in some organizations that have tried to raise awareness through spear phishing themselves, there's often a correlation between seniority and the worst offenders clicking on dangerous links. Match that with the fact that senior management often has heightened access to some of the most sensitive corporate data, and you've got a recipe for big trouble. 

Sometimes when I’ve asked about security awareness and training efforts at utilities I’ve found that the executive suite has exempted themselves because they’ve got more important things on their plates. No doubt the most senior personnel are deliberating on the most pressing challenges and opportunities facing their organizations. It all comes down to how we weight and value security. 

When mid-level and junior personal see their senior leaders opting out of security training, the cultural signals are unmistakable: security awareness and preparation in this company/organization are not on the same plane as safety, reliability, compliance, efficiency, etc. That approach was fine in the past, but I'm not sure I like the kind of future it portends. Let's work to make a better one.

Declaration of Independence and Intent

I've been warming up and working in this space for years now, and if you've been a Smart Grid Security blog subscriber or an intermittent visitor, you may have noticed an evolution in cyber security thinking of sorts. Well, with changing the world as my goal, it's time to stop treading water and start swimming like I mean it. I just left IBM in order to bring a new type of security advisory service to energy sector organizations. Here’s a brief version of the concept:
You often hear that culture change is the hardest thing to accomplish in an organization. That may be, but to help put our sector’s cybersecurity preparations on a better course, I’m developing an approach focused on increasing organizational awareness and improving internal communications about the security issues that matter. It begins with senior leadership, extends throughout the enterprise and doesn’t stop until it reaches service providers and the supply chain. Most engagements will begin with an in-depth orientation briefing for senior stakeholders, followed by periodic meetings and dedicated hours of access so that I can be a resource whenever my input is needed.

You may already know how much I like measurement. Well, I also like forecasting the future, and when we're several years into this campaign, you'll be able to measure its success by the growing number of cybersecurity-engaged CEOs and Boards in our sector. You'll see them take steps to bridge the culture and communications gap with their increasingly senior security leadership, who themselves will be eschewing technical jargon for the lingua franca of business. You’ll also see more state regulators able to credibly fulfill their cybersecurity oversight roles and responsibilities.

You might ask: Is this a formula for guaranteed success? How hard will it be to to pull this off? To which I turn to Niccolo Machiavelli, a friendly Italian man to whom I was introduced during my professional military studies at the Air Force Academy long ago:
"There is nothing more difficult to take in hand, more perilous to conduct, or more uncertain in its success, than to take the lead in the introduction of a new order of things."
So in case I haven't made it perfectly clear yet, the bar by which to measure success for this enterprise is extraordinarily high: setting into motion a new order of things in utility cyber security awareness and communications, as well as in the organizations that regulate them.

I left IBM just over one week ago after a great four year run. We parted on good terms and I maintain excellent collaborative relations. I left to to pursue something I can only fully do with the freedom of being on my own. But of course I can't really do all of this by myself. I'm going to need all kinds of partners, helpers, advocates, and clients to sustain this mission. Improving cybersecurity awareness and communications in our sector promises to be difficult but immensely satisfying work. Please join me.

SANS cyber security awareness training for eager utility employees ... and their regulators

I recently stumbled upon some excellent online training materials from the well respected SANS Institute that could be quite useful to you and your organization.

In a series of online modules, many of them tailored to the particular needs of utilities, SANS "Securing the Human" courseware seems to be an easily digestible, self-paced way to get important cyber security awareness messages across to a large number of users.

Note: NERC CIP content here is constructed around version 3, so with newer versions now approved by NERC and FERC, SANS will want to update certain modules accordingly. But 99% of the material is right on the mark, and would be appropriate for electric sector personnel outside the US as well.

Wherever you fit in the ecosystem, whether you're an executive or a rank and file worker bee, whether you're in a utility, a regulatory agency, a vendor, or just a user of digital technology who wants to stay safe, recommend you check it out.

---------------

SANS URL:

http://www.securingthehuman.org/utility/index

Grid Security Keynote of Note at May 2013 ISO Conference

Since you can't be everywhere, there's the SGSB (which can).  Former Seattle City Light CISO and current Verizon control systems security ace Ernie Hayden gave a keynote presentation at the recent ISO New England and New York ISO Energy Conference held in Boston, and we've got it for you.

If you don't know ISO, it stands for Independent System Operator, a term which is often used interchangeably with another acronym: RTO, or Regional Transmission Organization. In North America, these organizations are like referees and traffic cops, trying to keep the peace among utilities and ensure the smooth and reliable flow of appropriately priced electricity across multi-state regions.

It's good to see Security get such a prominent platform at a high profile industry event like this. Certainly a sign of the times.  Ernie's slides will take you through the past, 2013/present and future of grid security, and though some of the info would clearly benefit from his accompanying narration, a lot of this works quite well as is. And if you really want the audio, then I'm sure Ernie will agree to come to you and do it again, as long as you treat him right.  URLs below.

-----------

Ernie Hayden deck

http://www.isoenergyconference.com/pdf/Ernie-Hayden-Keynote.pdf

Conference home page

http://www.isoenergyconference.com

Cyber Achilles Heal Afflicts Electric Sector (and other) Senior Leaders


Just for fun, let's begin with a few quotes from an article in yesterday's Wall Street Journal of the mind-blower variety:
Executives are disconnected from reality when it comes to IT and security.
Top leaders seem particularly inclined to do things their IT departments warn against, such as opening email from unfamiliar senders, or clicking on links.
During ... simulated attacks, top executives are 25% more likely to click on the links that in a real attack could install malware. One reason ... is that most senior leaders skip company programs on developing cautious email habits.
You can visit this WSJ page below for the full article and attribution.

But wow. What a cyber Achilles Heal we've got if the folks with access to the most important, most sensitive info in our companies are the easiest to scam into coughing it up.

Now pair these statements (like pairing wine with food) with my own recent experience with a large North American electric sector organization. Security staff acknowledged they had self phished the company once and found a strong correlation with elevated rank and dangerous behavior. 

As in, senior management personnel were much more likely than others lower down in the organization to click on the dumbest things, and even fill out and submit forms requesting login credentials, etc. The results were so damning there weren't sure they'd do it again.

Let me repeat and underline that last part: execs were more likely to fill out and submit forms requesting login credentials, etc.

This is pretty alarming, even for a non-alarmist. Time to wake em up or throw in the towel. Let's go for the former. 

Full article here: http://online.wsj.com/article/SB10001424127887323463704578497592337997354.html?KEYWORDS=%22security%22

Image credit: v3im.com

Great Video: Latest Utility CEO on Cybersecurity


Another CEO joins the emerging chorus of senior energy sector executives not just tuned in to the strategic nature of cybersecurity and privacy challenges in the Smart Grid era, but willing to speak out about it. Also hits some good notes re: supply chain issues as well.

Thanks to Jessie Knight, Chairman and CEO of San Diego Gas & Electric (SDG&E). And hat tip to IBM colleague Tracy A and SmartGridNews.com for sending me this.