Hiển thị các bài đăng có nhãn cyber security. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn cyber security. Hiển thị tất cả bài đăng

Energy Security Postscript and Next Chapter

Long-time readers of the SGSB might have wondered if they'd ever see another post. Me too. After producing an average of 1+ posts per week since its inception 5 years ago, I cut way back after leaving IBM in 2013 to give myself more time to focus on consulting. And now there's a new development to report.

4 month ago I shuttered my security strategy business and began my first day on the job at Idaho National Laboratory (INL). It's one of the Department of Energy's national labs, and it's the one most squarely positioned at the intersection of energy infrastructure and national security. Let's call that energy security.

My INL title: Senior Cyber & Energy Security Strategist - may sound a little pretentious, but it pretty accurately captures what I was hired to do. If you visit the lab's home page or the INL Twitter feed it seems like nuclear energy research and related nuclear work are its dominant activities. But while nuclear energy research and fuels fabrication were its origin in the 1940's and its historic mission, with the help of its massive and remote test range that includes grid-scale transmission, distribution and communications assets, the lab I just joined does a ton of research and applied work on power and industrial control systems, Smart Grid and wireless communications, cyber and physical security and resilience, renewables, microgrids, energy storage and more.

Nuclear energy R&D, and full nuclear fuel lifecycle work (including non proliferation) will always be a significant part of that nation's requirements, and the INL mission, but nuclear energy is arguably the most reliable portion of our non fossil fuel baseload, but INL is quietly becoming something much more - and more important - than its nuclear legacy might suggest.

Without going into too much detail, the lab's customers now include not just DOE's nuclear energy organizations, but also DOE's renewables, resilience and cyber-physical security components too. DHS has become a major customer, as the lab hosts the ICS-CERT cyber security overwatch function for the US grid and other critical infrastructures, and performs other leading edge cyber and physical security roles as well. DoD is a very large customer too, for energy, security and communications test functions, rounded out by direct work with utilities and energy and telecom technology suppliers.

In short, INL in 2014 is not the lab many people think it is. While it's yet to update its image online, a visit to Idaho Falls quickly confirms that this is one of the nation's preeminent Energy Security lab resources. Nuclear energy is and likely always will be a key element, but without making much noise about it, INL has become so much more, and I'm very very lucky to be a part of it.

------------------------------

Postscript to the Postscript post: Though my blogs are in suspended animation, I continue to speak in public, and albeit more frequently and tersely, on Twitter @andybochman. As the Twitter profile reveals, I continue to work out of my home office in Boston while hitting the road most often for DC, and of course, now, Idaho.


An Eerie and Early Visualization of the Internet of Things (IoT)

I've got a short story to recommend to you. It's cerebral without being overly literary. It's got action, though no cyber-physical grid attacks. There's no shooting. No lives lost. No outages. But is there ever a lot going on! In fact, I'm pretty sure it's a parody of sorts of what may be coming our way in the not-very-distant future.

Titled "Water,' it was published last year by author and futurist, Ramez Naam.

Here's what the ad-free, neural-implanted main character experiences walking down a street in NYC:
Civic systems chattered away. The sidewalk slabs beneath his feet fed a steady stream of counts of passers-by, estimates of weight and height and gender, plots of probabilistic walking paths, data collected for the city planners. Embedded biosensors monitored the trees lining the street, the hydration of their soils, the condition of their limbs. Health monitors watched for runny noses, sneezing, coughing, any signs of an outbreak of disease. New York City’s nervous system kept constant vigil, keeping the city healthy, looking for ways to improve it.

And there's a nice IoT breach for you, too, with extra padding for general readers:
In a windowed office above the financial heart of Manhattan, a tiny AI woke and took stock of its surroundings. Location—check. Encrypted network traffic—check. Human present—check. Key . . . . Deep within itself, the AI found the key. Something stolen from this corporation, perhaps. An access key that would open its cryptographic security. But one with additional safeguards attached. A key that could only be used from within the secure headquarters of the corporation. And only by one of the humans approved to possess such a key. Triply redundant security. Quite wise. 
Except that now the infiltration AI was here, in this secure headquarters, carried in by one of those approved humans. Slowly, carefully, the infiltration AI crawled its tiny body up the back of the silk suit it was on, toward its collar, as close as it could come to the human’s brain without touching skin and potentially revealing itself. When it could go no farther, it reached out, fit its key into the cryptographic locks of the corporation around it, and inserted itself into the inner systems of Pura Vita enterprises, and through them, into the onboard processors of nearly a billion Pura Vita products on shelves around the world.
Cyber and physical consequences ensue and cascade. You can and should read the whole 5K word story HERE.

While I've got you in the mood, less creative but still informative is a non fiction article I found via Twitter this morning: "Internet of Things is 'Scary as Hell'".  In short-strokes, it's more "insecure by design" coming our way. And see if the expert guidance on what to do in your home doesn't faintly echo IT/OT power sector security advice:
Secure your environment. And don't have your alarm system, your heating and air conditioning system, on the same internal network as your PCs. If they are easily hacked -- and they are -- and attacked, you don't want them to be on the exact same network.
Many people seem excited about what's going to happen when everything talks with everything else. Me, I'm no luddite, but even without taking the manifold security and privacy considerations into account, I'm not sure IoT represents a step forward for our species.  Anyway, no matter, it's coming soon to a theater near you.  And maybe "Water" will be too.

Where do Today's Electric Utility CEOs come from, and what do their Origins Mean for Grid Security?


I remember once thinking, naively perhaps, that most utility CEOs must have come up through the ranks, like generals in the military, with hands-on operational engineering experience garnering them the respect of their peers and subordinates along the way.

When I shared that concept last year with a 40-year industry veteran who'd done his time in generation and T&D, he schooled me saying that while that used to be the case, it's not the norm today.  He said more often you'll find someone with a finance background, often imported from sectors outside power.

Well, I got another round of schooling on this subject this week from former state commissioner and current consumer advocate Nancy Brockway, who has made her presence known on this blog before, in: "The State of the States and Smart Grid Security." Well she's back, and whether you agree with her or not, and allowing for exceptions, I think you definitely should hear what she has to say about the origins of senior utility leadership in 2014:
Transaction-oriented finance and legal sector professionals have displaced engineers in the executive suites of most utilities. The big shift to deal-making occurred in the wake of the existential shocks of the late 20th century over cost over-runs, the end of cheap oil, and the growing recognition of the environmental costs of utilities. 
Look back a century or more to the pioneers of the utility industry and you'll see a public interest value system that could and often did accompany the build out of utility territories and even accompanied mergers and acquisitions. Read 2004's Insull: The Rise and Fall of a Billionaire Utility Tycoon by Forrest MacDonald, for more background. 
But economies of scale were pretty-well exhausted by the 1960s. Bigger was no longer better for customers. And an anti-regulation "winner takes the hindmost" political climate did not reward a utility executive's greater effort to serve the public. Rather, it rewarded ever more sophisticated schemes to funnel profits up to the executive suite.
Regulators have to push for what they see as the public interest. To do their jobs with any responsibility in these circumstances, they can no longer sit back and merely act as a brake on occasional excesses. Too often they have to define the public good and demand it from utility management.

I am not sure that a workable redefinition of the roles and responsibilities of management and regulators can happen without a wholesale cultural shift away from "Greed is Good." My opposition to pre-approval of cyber security spending comes from the sense that if the utility drags its heels or does only what it needs to satisfy regulators, that just demonstrates that utility execs do not see security as fundamentally necessary for their personal financial success.
Sort of begs the question of how Gordon Gekko would weigh security investments vs. security risk, and you know what, I don't know the answer.  But we know GG types thrive on risk and reward. 

That's not exactly what I had in my mind previously, imagining conservative, retired military, former boy or girl scouts, with steady hands on the tiller of some of the absolute most important critical infrastructure organizations in the country.

Hopefully, experience and acumen with fine tuning financial risk/reward equations will most often translate to similarly savvy understanding of and action on operational risks ... including one that's increasingly material and the raison d'etre of this blog.

Photo credit: ABC news

Conference Alert: SmartSec Europe 2014


There's not much time left, but here's an exciting conference for if you're not going to Distributech in San Antonio, but still want to visit a historic city with picturesque waterways.

Location: Amsterdam
Dates: 29-30 January 2014
For more info, click HERE
To register, click HERE

Bonus #1: My friend Johan Rambi and grid security superstar Annabelle Lee will be speaking

Bonus #2: All SmartSec attendees are invited to stay on one more day to help set the course for Europe's new ISAC and situational awareness organization, DENSEK.  It convenes at 1000 hours on Friday the 31st at the same venue.

And in case you're wondering DENSEK includes but is not focused on Denmark. DENSEK stands for Distributed ENenergy SEcurity Knowledge ... capiche?

Photo credit: The Travis Caulfield Travel Blog

Whitsitt on What's Up with the NIST CSF

Before you click through on the link provided below, I have to tell you that this write-up is not just about the NIST Critical Infrastructure Security Framework (CSF), but it's also a review of the current state of the security profession/practice/belief system, depending on your vantage point.

Penned by Jack Whitsitt of EnergySec, who among other things helped design the cyber security policies for the Transportation Security Agency (TSA) when it was just getting started. Be forewarned: Jack is no ordinary security guru. Because he's a practicing artist too, he brings both hemispheres to this challenge, and as a result, his perspectives and insights are unlike what you'll likely encounter anywhere else.


I particularly like that he begins with a 15 point description of the "problem space", something that might have helped the CSF initiative itself get off to a better start. Points 1-3 establish an overall tone of realism that includes references to money and outcomes:
  1. We are failing at cybersecurity
  2. We are investing heavily in cyber security
  3. Our organizations are getting breached at unacceptable rates
Doesn't sound like a status quo anyone interested in national security would want to maintain much longer. Or the CEO of large power company, for that matter.

I particularly like point 11, which I'll paraphrase below to suit our purposes:
A more likely way of getting at the cultural and business underpinnings of cyber security would be to start with business outcome objectives and then elicit a framework to meet those objectives. AB - now here's the magic part: Do this while assuming a lack of a dedicated security team and without making references to cyber security specific technologies. 
As Jack continues, this allows the discussions to remain in plain-English business language, which means the business folks, advocating for their business objectives, remain active participants in the conversation and the solution formulation process throughout.

There is a ton more to like in his comprehensive treatment of the subject matter.  You'll find the full piece, "My comments to NIST on the Preliminary Cybersecurity Framework" right HERE.

Security at the Edge of the Grid


We used to be very concerned about traveling too close to the edge of the world, remember?  Then some smart math and science guys figured out, surprisingly, Earth has no edge, so we were free to move about about the globe.

Now as we approach the end of the beginning of the Smart Grid era, what began as an initiative to add visibility, flexibility, and yes, smarts all over the grid is now seeing change accelerate close to the points of consumption.

Of course, amid all the excitement about innovation in distributed generation, distribution automation, energy efficiency, demand management, microgrids, storage, etc., one could forget that there's some basic housekeeping to attend to in the categories of power regulation and security.

The former, which includes maintaining the quality of electricity and keeping dangerous phenomena like harmonics in check, has been the province of utilities and ISO/RTOs and that's not going to change.  Ever increasing percentages of distributed generation are, in anything, going to make utilities' capabilities in this area even more essential to safe and reliable power delivery.

The other housekeeping item, now that it's 2013/2014 and not 1963/1964, is that all the new edge devices have several attributes in common:

  • They send, receive and store data
  • They constrain access to their data and/or services to certain other systems
  • They receive control signals, sometimes from humans (think: iPhone apps) and sometimes from other systems (think: Nest thermostats)

Of course this is an oversimplification, but astute readers will notice that the integrity of all of these activities depends entirely on capabilities from the security domain.  My job as part of Greentech Media's new Grid Edge Executive Council (see my humble logo above nestled among the titans) is to ensure less-than-sexy security attributes are baked into the functional requirements of all the new products that plan to participate in this edgy arena.

That way, when 2023/2024 arrives, we'll be powering our homes, businesses and country with power we can depend upon.

Because Excercise is Good for US, GridEx II is Coming


In case you've been wondering what kind of shape our North American grid incident response and information sharing system is in, now's your chance to find out.  You can click HERE for more details on what's coming up and register to participate if you're an asset owner one of the other types of orgs that have an official role to play.
  • When: 13-14 November
  • Where: North America
  • Dress: Business Casual
While you're here, here are a few other items of possible interest:
  • You can read a decent GridEx II intro HERE, from the NYTimes
  • Findings and recommendations from the first GridEx begin on page 10 of the After Action Report
  • Click HERE for news on a recent disruptive control system cyber attack on a tunnel traffic system in Israel
Poster image courtesy of Crossfit.com

Several Scenes from EnergySec Summit 2013

Click for much Gibber ... I mean, bigger
Was in Denver not far from flooded Boulder last week at the 9th annual EnergySec Summit ... my first.  I'm sure we'll be seeing more articles and posts from EnergySec scribes and some of the other 150 or so attendees soon, but wanted to get my observations out.

I missed a number of presentations due to a mid day arrival on Wednesday and missed a few others to field a few intermittent phone calls, but got to hear most of them (my apologies to speakers not covered below).

First off, Patrick Miller and Steve Parker, EnergySec Presidents past and present, were both outstanding ringmasters and herders of wandering speakers.


Great to see Jack @sintixerr, @SharlaArtz, @LisaNCW Carrington and nearly see @Slad3G Griffin. And the amazing Tweetwall (center screen in picture above) facilitated audience participation, both in the room and globally, scrolling thoughtful 140 character contributions and snarky, succinct broadsides on the unsuspecting speakers! Hashtag for a replay of sorts is #ESS13.

Here's a summary of the talks I caught:
  • Andrew Plato (Anitian) on his Rapid Risk Assessment approach, with special and humorous emphasis urging native security speakers to learn and use business language (maybe RosettaStone or Duolingo can help them with this)
  • Julie Soutuyo (Tennessee Valley Authority) shared her experiences helping make TVA, faced with an onslaught of real-world cyber threats while having to address both FISMA and NERC CIP compliance regs, a more resilient organization
  • Russell Thomas (George Mason University) aka @MrMeritology took us through a Texas Heat Wave movie plot of his own creation to illustrate how a balanced scorecard risk management framework could save the day. Look for it in theaters in 2015!
  • Michael Toecker (Digital Bond) aka @mtoecker provoked the crowd with a great talk on bridging the divide between control systems operators and cyber security pro's, and had us ready to see his concepts on a mock up of an actual operator display. Sadly, he said that will have to wait to next time.  Meanwhile, as SpongeBob would say,  you're free to use your IMAGINATION
  • Chris Sistrunk (Entergy) aka @chrissistrunk, an unabashed squirrel lover, showcased his extraordinary SCADA test lab, described how he built it, the many benefits it confers upon his coworkers at Entergy, and gave practical advice on how folks in the audience could jumpstart their own labs projects
  • Jacob Kitchel (Industrial Defender) walked us through a DevOps approach to improving IT operations in control systems environments. He listed many helpful tools along the way, and made mention of ID's tools near the end. Not entirely security related ... and like Chris's before it, the audience seemed to eat it up.
  • Gib Sorebo (SAIC) gave by far the most business oriented talk, focusing on what security practitioners in the audience need to know to better communicate security risks and requirements to their senior leadership, board members, and shareholders. He also described mature governance structures and business-risk based cybersecurity strategies
  • Nadya Bartol (Utility Telecom Council) walked us through an exploration of the mesmerizing complexities of ICS supply chain security and shed some light on emerging tool that may help utilities get a handle on this challenge: IEC 62443 2-4
  • Spencer McIntyre (SecureState) - two key terms in this one for me: Zigbee, the low power networking standard used in AMI smart meters, and its evil twin: KillerBee, a "practice Zigbee exploitation framework". Good discussion on the current state and some of the continuing security issues with smart meters
Lastly, following University of Houston professor, Dr. Art Conklin's energetic opening, I moderated a Town Hall-style discussion on "Workforce Development in the ICS Workplace." We hit a lot of different notes over the course of several hours, and jointly investigated questions on how to build a robust pipeline of skilled operational security (OT) Security practitioners for utilities.  I'll leave you with this image from my preso, which attempts to depict the current cultural and language divide one finds in many utilities. Just so you know, some of us are working hard to finish these bridges!


Got to go now ... Next year's in Austin!

A Novel Approach to Grid Cybersecurity Awareness


Not long ago I was in a meeting with the CIO of a large electric utility and when I inquired as to the cybersecurity awareness of the board of directors, was told it had recently skyrocketed.

Why the sudden shift I asked?  Had the company just endured a serious and/or highly public breach? Nope, things had been mercifully static on that front. A classified threat briefing by DHS? No, not that either. Well, what was it then?

Apparently one board member had read the latest Tom Clancy book, Threat Vector and once exposed to Clancy's fictional vision of how the US could be brought low through largely cyber means, it changed his thinking. Spoke in language he could understand, and captured his imagination too. It soon spread to the rest of the board.

Now comes former Senator Byron Dorgan with a cautionary novel of his own, and this one is much more grid-centric, from the title on. I later read Threat Vector myself ... 900 pages or so if I remember right, looking for power sector specific attacks and breaches and they were few. I've read some of the reviews of Gridlock, though, and in it the US grid is front and center and not doing so well.

Dorgan and co-author David Hagberg don't have anywhere near Clancy's readership, not close. But if an executive in your company were to happen upon a copy, well, apparently it's quite a page turner, and you might have a new, more cybersecurity-aware board to work with in a few weeks.


Conference Alert: EnergySec and NESCO Town Hall next Week


Ok, so usually I'm giving a heads-up about some conference or seminar you might want to know about, or even attend. But this time I'm saying that, but also revealing I'll be there too.

And I note, in the town where Peyton Manning recently threw 7 TD passes in one game and one can easily procure Rocky Mountain Oysters, I'll be joining luminaries from industry and a number of utilities too.

Here are the deets:

  • Where: Magnolia Hotel, Denver, CO
  • When: 17 - 19 September, 2013
  • What: Lots of stuff. Agenda HERE
  • How: Easy. You can still register HERE

For your edutainment, I'll be moderating a town hall style discussion about the current state and future of the cyber security workforce in the energy sector. We'll be considering full life (as in human life) cycle issues, from birth to tablet training, from kindergarten to college curriculum, from entry level security practitioners to ICS forensics wizards and all the way up the managerial stack to CSOs and CISOs.

Hope to break some new ground and capture some new ideas we can share with all and will do here on the SGSB during and/or right after. Will also tweet whenever possible using the hashtag #ess13.

Hope to see some of you there!

Photo credit: Daily Mail online

The Things I've Seen Series: Part 2 - Execs Exempted



Last week I posted on an encouraging trend I witnessed over the past 2 years: the emergence in some utilities of security governance boards comprised of security and privacy leaders, often a rep from legal or compliance, and senior stakeholders representing different business lines.  Soon after it went live, I received multiple corroborations from friends in the field who have seen the same thing in their patches. This is all goodness.

But there are other, less uplifting trends you should be aware of if you're not already. I've seen senior executives who have not once met with their cybersecurity leaders and who feel they have no reason to do so. I've had senior state regulators tell me that they haven't really thought about cybersecurity until very recently. 

And I've heard that in some organizations that have tried to raise awareness through spear phishing themselves, there's often a correlation between seniority and the worst offenders clicking on dangerous links. Match that with the fact that senior management often has heightened access to some of the most sensitive corporate data, and you've got a recipe for big trouble. 

Sometimes when I’ve asked about security awareness and training efforts at utilities I’ve found that the executive suite has exempted themselves because they’ve got more important things on their plates. No doubt the most senior personnel are deliberating on the most pressing challenges and opportunities facing their organizations. It all comes down to how we weight and value security. 

When mid-level and junior personal see their senior leaders opting out of security training, the cultural signals are unmistakable: security awareness and preparation in this company/organization are not on the same plane as safety, reliability, compliance, efficiency, etc. That approach was fine in the past, but I'm not sure I like the kind of future it portends. Let's work to make a better one.

The Things I've Seen Series: Part 1 - Utility Security Governance Boards


In the final moments of Blade Runner, Rutger Hauer's character, close to death, tells Harrison Ford: "I've seen things you people wouldn't believe."

Over the course of the next several posts I'm going to go through some of my sanitized field notes and let you see things you may or may not believe, some good, some not so good.  Nothing quite as cosmic as what Hauer relates in his final moments, but probably should be interesting if you're in or work with the industry.

Let's start off the series on a positive note with the formation of Security Advisory Boards.  Investor Owned Utilities (IOUs) typically have a number of boards: executive, safety, governance, audit & compliance, etc. However, you can dig through annual reports and review the investor information sections on company web sites for a long time and you likely won't find much if anything relating to cybersecurity risk strategies, concerns or activities.


Yet in visits to utilities over the past 2 years I came upon half a dozen or so that had either assembled a representative group of various executives and functional leads to talk about cybersecurity from an enterprise-wide perspective, or were getting ready to do so.  Members tended to include the CIO, the head of cybersecurity, the head of physical security, leadership from different functional areas, and one or two more senior executives.

Some of the potential benefits include improved flow of communications between different parts of the company, more business input into security policy and planning, and better understanding across senior management about current security status, emerging requirements, and new threat types.

Perhaps some of these utilities made this move according to their own logic.  Others, possibly, noticed a recommendation for standing up security governance boards in DOE's 2012 ES-C2M2, which you can download HERE.

My hunch is the percentage of utilities with security focused boards of any kind is in the single digits, maybe the low single digits. Nevertheless I am heartened by what seems to be a nascent trend. For utility CEOs or boards who want to respond to regulator calls for more oversight and activity on cyber, this is one inexpensive, non disruptive way they to begin.

Image credit: Assolutamente ma anche no Tumblr

Declaration of Independence and Intent

I've been warming up and working in this space for years now, and if you've been a Smart Grid Security blog subscriber or an intermittent visitor, you may have noticed an evolution in cyber security thinking of sorts. Well, with changing the world as my goal, it's time to stop treading water and start swimming like I mean it. I just left IBM in order to bring a new type of security advisory service to energy sector organizations. Here’s a brief version of the concept:
You often hear that culture change is the hardest thing to accomplish in an organization. That may be, but to help put our sector’s cybersecurity preparations on a better course, I’m developing an approach focused on increasing organizational awareness and improving internal communications about the security issues that matter. It begins with senior leadership, extends throughout the enterprise and doesn’t stop until it reaches service providers and the supply chain. Most engagements will begin with an in-depth orientation briefing for senior stakeholders, followed by periodic meetings and dedicated hours of access so that I can be a resource whenever my input is needed.

You may already know how much I like measurement. Well, I also like forecasting the future, and when we're several years into this campaign, you'll be able to measure its success by the growing number of cybersecurity-engaged CEOs and Boards in our sector. You'll see them take steps to bridge the culture and communications gap with their increasingly senior security leadership, who themselves will be eschewing technical jargon for the lingua franca of business. You’ll also see more state regulators able to credibly fulfill their cybersecurity oversight roles and responsibilities.

You might ask: Is this a formula for guaranteed success? How hard will it be to to pull this off? To which I turn to Niccolo Machiavelli, a friendly Italian man to whom I was introduced during my professional military studies at the Air Force Academy long ago:
"There is nothing more difficult to take in hand, more perilous to conduct, or more uncertain in its success, than to take the lead in the introduction of a new order of things."
So in case I haven't made it perfectly clear yet, the bar by which to measure success for this enterprise is extraordinarily high: setting into motion a new order of things in utility cyber security awareness and communications, as well as in the organizations that regulate them.

I left IBM just over one week ago after a great four year run. We parted on good terms and I maintain excellent collaborative relations. I left to to pursue something I can only fully do with the freedom of being on my own. But of course I can't really do all of this by myself. I'm going to need all kinds of partners, helpers, advocates, and clients to sustain this mission. Improving cybersecurity awareness and communications in our sector promises to be difficult but immensely satisfying work. Please join me.

Motivation through Compensation: Paying Utilities to Upgrade Cyber Defenses

Now we're getting somewhere!  The long submerged topic of "who should pay" for electric utility cyber security improvements has just breached the surface and is now bobbing up and down in clear daylight.

A recent article in Bloomberg documents several large US utilities' efforts to recover current and future cyber security investments the same way they get paid for other infrastructure programs: by getting clearance from their state utility commissions to approve these expenses in their rate cases.

Actually rate payers (aka electricity customers) will pay one way or another, as they should, for the essential service that makes our modern lifestyles possible.  Possible methods of payment include:
  • Absorbing the costs to their businesses and their lives associated with brown outs or black outs or electricity quality issues stemming from successful attacks on control centers or systems
  • Paying more every month to cover some, most or all (TBD) of their utilities' cyber-protection expenses
  • Or, as Pepco CIO Doug Myers said, as cited in the Bloomberg article, allowing utilities to be reimbursed through federal grants
This concept was articulated more formally by Michael Daniel, special assistant to the President on Cybersecurity, when he included rate recovery as one of a number of cyber incentive strategies for critical infrastructure providers:
Rate Recovery for Price Regulated Industries — Agencies [DHS, Commerce, Treasury] recommended further dialogue with federal, state, and local regulators and sector specific agencies on whether the regulatory agencies that set utility rates should consider allowing utilities recovery for cybersecurity investments related to complying with the Framework and participation in the Program.
As this blog often reiterates, we have to acknowledge and accept the costs of living in a technology-enabled world, where the impulse to cyber secure important services must become every bit as natural as physically securing our more tangible valuables.

Else, I have a nice cave I'd like to show you. And no, it doesn't have wifi.

First Look at Cyber Security Incentive Ideas, Companion to NIST's Framework Work

I'll oversimplify this to keep it short, but the President kicked all of this off earlier this year in wake of failed cyber security legislation efforts in 2010 (GRID Act) and 2012 (Cybersecurity Act of 2012).

The two primary vectors on this project have included:

  1. Having NIST lead the charge to develop a new cyber security framework (i.e., pattern, roadmap, guidance) made up of references to existing guidance that seem to work well. On twitter this effort is tagged #NISTCSF
  2. A parallel initiative to develop incentives that might improve the business case for being more proactive on cyber security.
The incentive categories were just made public, and so far include :
  • Cybersecurity Insurance
  • Grants
  • Process Preference
  • Liability Limitation
  • Streamline Regulations
  • Public Recognition
  • Rate Recovery
  • Cybersecurity Research
Liability and insurance are going to be the thorniest.  And rate recovery help, if workable, sounds promising.

You ran read The Hill's coverage and the original White House text via URLs below, as well as check out the current status and next activities related to the framework.

----

URLs

The Hill

http://thehill.com/blogs/hillicon-valley/technology/315795-white-house-publishes-preliminary-list-of-cybersecurity-incentives

White House

http://www.whitehouse.gov/blog/2013/08/06/incentives-support-adoption-cybersecurity-framework

NIST CSF

http://www.nist.gov/itl/cyberframework.cfm

Rapidly Approaching Training Alert: SANS Control Systems Security

Depending on where you sit at the cyber security table, this might be for you or someone in your org.

Here's how the SANS folks describe it:
A rising number of cyber threats impacting industrial systems have increased the urgency to address security challenges for Industrial Control Systems. Learn how to develop an effective and comprehensive cyber security strategy and equip yourself with the technical know-how and skills to apply in these unique applications. Cyber security is an important element to achieve highly reliable and safe operations. SANS Hosted ICS training courses equip both security professionals and control system engineers with the knowledge and skills they need to safeguard these important systems.
Available classes: SCADA Security Training, Critical Infrastructure and Control System Cybersecurity, and Assessing and Exploiting Control Systems

OK now the details:

  • What: SANS Industrial Control Systems Training
  • When: 12-16 August 2013
  • Where (Generally speaking): Washington DC
  • Where (More specifically) : the Westin hotel in Georgetown
You can register here: http://www.sans.org/event/ics-security-training-washington-dc and if you use this code you'll get a discount: SANSICS_SGSB5

Major SPIDERS (DOD Secure Microgrid) Update

This post just in from Mr. Harold Sanborn, Program Manager at Construction Engineering Research Lab (CERL), US Army and technical manager for the SPIDERS Joint Capability Technology Demonstration (JCTD).  I've removed most of the defense industry speak from a longer version you can find on the DOD Energy Blog.  FYI SPIDERS = an ongoing DOD distributed energy program and the acronym stands for Smart Power Infrastructure Demonstration for Energy Reliability and Security. ab

Here's Harold:

SPIDERS Phase I has finished the "history tour" as we codify and publish the lessons learned.

SPIDERS results demonstrated additional capability for Joint Base Pear Harbor Hickam, including:
  • Synchronizing with the utility service power signal while pushing electricity back on to the base distribution system
  • Operational viewing of other circuits in the substation in addition to the one controlled by the micro-grid, and
  • Power factor improvements and the opportunity to test generators at load

The Navy customer (Navy Facility Command Pacific/Hawaii) provided positive and constructive feedback throughout the technical and operational demonstrations at Joint Base Pearl Harbor Hickam (JBPHH). The only item where Navy utility folks have any residual concerns for on-going operations and maintenance is keeping their workforce trained and ready to employ SPIDERS and dealing with new technology after the buzz wears off. Our contractor (Burns & McDonnell) continues the dialog of training and post contract support. Two devices at JBPHH have had heat related challenges, and we're recommending we paint the boxes white instead of Navy utility brown.

To date, there isn't a system owner. Controls, hardware and software are not static and require some continuing education and occasional attention. DoD will face this challenge across the board as we take a collection of electrical appliances and make them a systems engineered smart grid. Oops, did I say smart grid?  I meant distributed energy management system. The good news is SPIDERS showed the truth in our motto: do no harm. During our operational demonstration, the software "burped" and the system went back to traditional stand alone back up power. The amazing thing: the 24/7 operators (blue collar Navy civilian) saw the system degrade in their 24/7 ops center without tripping loads or causing other electrical problems. Their after action dialog shows true customer values: a system that does what it says it will do. 

Cyber security critiques continue to bubble in the background. Growing areas of concern were anticipated, just not the ramp rate by which DoD is expecting trouble. PACOM (a combatant command and one of two SPIDERS Operational Managers) has invested many dollars and man hours in working closely with DHS and DOE labs to promote a comprehensive set of industrial controls cyber protection test(s). Phase I SPIDERS didn't require external hacking as part of the operational demonstration, yet in the end, we performed a cyber experiment that showed promise in our path forward. Phases II (Fort Carson CO) and III (USMC Camp Smith HI) offer expanded cyber experimentation and we plan to stay current with DoD and DHS process to validate their application in the real world of installation industrial controls.

Overall, most folks still fail to recognize the energy security value of micro-grids. To answer the question of worth for micro-grids, phase III SPIDERS will work to communicate with the local utility service, and provide ancillary services when connected to the utility service; and also offer other measurements to adjust power quality and controls while waiting for the anticipated utility outage so that the security aspect of islanding comes into play. 

Life cycle configuration management of smart systems might need a DoD PM to solve deployment issues. Frankly, it isn't an ownership definition that challenges DoD, although that's often the red herring slow thinking folks suggest. Ownership needs simple definitions that already exist in DoD. Accountable, physical, and custodial owners of distributed energy management systems will likely need to agree on metrics to begin programming for their responsibilities.

The take away, no, the bottom line is that smart systems are coming and we can manage those if we apply just a modicum of intellectual activity up front. SPIDERS isn't the first micro-grid. SPIDERS is a systems engineered solution using hardware and controls to insert new technologies to installation transmission and distribution systems to enable more energy security from existing and planned assets. How much is it worth? I'll answer that question in a future post. HS

SANS cyber security awareness training for eager utility employees ... and their regulators

I recently stumbled upon some excellent online training materials from the well respected SANS Institute that could be quite useful to you and your organization.

In a series of online modules, many of them tailored to the particular needs of utilities, SANS "Securing the Human" courseware seems to be an easily digestible, self-paced way to get important cyber security awareness messages across to a large number of users.

Note: NERC CIP content here is constructed around version 3, so with newer versions now approved by NERC and FERC, SANS will want to update certain modules accordingly. But 99% of the material is right on the mark, and would be appropriate for electric sector personnel outside the US as well.

Wherever you fit in the ecosystem, whether you're an executive or a rank and file worker bee, whether you're in a utility, a regulatory agency, a vendor, or just a user of digital technology who wants to stay safe, recommend you check it out.

---------------

SANS URL:

http://www.securingthehuman.org/utility/index

RFP Alert: Security Advisor Sought for New England Utility Commissions

No sooner had I posted on the need for more state utility commissions to ensure access to quality cyber security guidance, when an RFP with this exact goal in mind came across my desk (figuratively speaking). So without further delay, your attention please:

The region of 6 northeastern US states collectively referred to as "New England" and boasting the highest per-capita concentration of Dunkin Donuts is seeking one very well qualified energy and cyber security professional to help guide them for a six month period commencing in mid September.

The New England Conference of Public Utilities Commissioners, Inc. (NECPUC) has issued an RFP for which responses are due NLT 5 pm August 8, 2013. I provide the URL to the RFP below but to save you an unnecessary trip, here are the qualifications required if you or your small firm want to even be considered for the job:
  • Background and knowledge of utility sector industrial control system and business operations
  • Knowledge and expertise in computer systems security and related physical security issues
  • Certified Information Systems Security Professional or similar computer security management certification preferred
  • U.S. Government security clearance of “Secret” or higher preferred
  • Engineering and/or information technology degree and training preferred
  • Knowledge of NERC CIP standards
  • Certified Information Systems Security Professional, Certified Information Security Manager or similar computer security management certification preferred
  • Ability to drive throughout New England visiting public utility commissions and utilities will be required (ab add: must be a confident driver in snow)
Does that sound like you?  If so, recommend you get started on your proposal. The New England state commissions are eager to get started!

(If not, but you think you know a qualified candidate, pleasure forward this on to them stat - thanks.)

------------------------------------

URL for NECPUC RFP:

http://www.aesp.org/associations/5980/files/RFP%20for%20Cyber%20Security%20Consultant%20FINAL.pdf

URL for previous SGSB post on PUCs and cyber security:

http://smartgridsecurity.blogspot.com/2013/07/to-secure-your-state-grid-first-know.html

To Secure Your State Grid, First Know Your Public Utility Commission (UPDATED)

19 July 2013 UPDATE: Significant clarification just in from Terry Jarrett, Commissioner of Missouri's Public Service Commission and Chairman of the Committee on Critical Infrastructure at NARUC:
Actually, the NARUC Critical Infrastructure Committee's main focus has been cyber security for the past two years that I have been chairman. Last fall at our annual meeting, incoming NARUC president Phil Jones declared cyber security to be one of the themes of his presidency. To say that cyber will be given more attention in Denver than in the past simply is not factual. 
Thank you Terry.  I'll leave the original post below intact so you can see to what Terry was referring, but please keep his clarification in mind as you do.  ab

-- -- -- -- --

The Advanced Energy Economy Institute (AEE) has a great new site for helping you navigate your way around any of the 50 US states' energy landscapes, including commission leadership, energy portfolio mix, legislation and more. One topic you won't read much about, however, at least not without doing some substantial digging, is cyber security preparedness.

As readers of the SGSB may recall, we've done shout outs to California and Texas, both states having cyber security knowledgable professionals on their Public Utility Commission (PUC) staff, and there are a couple of other states now similarly equipped. Many other states, however, haven't yet made a modest level of cyber security capability a requirement.

With the Business Roundtable (BRT) issuing guidance earlier this year for how organizations should better organize themselves to meet the rising cyber security risks they face, to a recent report drawn from mega-insurer Lloyds of London's survey of CEOs and Board of Directors at the world's top companies showing they now consider cyber security among the top three risks facing their companies, you could say it's well past time for all organizations, and particularly those with public authority and responsibility like state utility commissions, to ensure they are well informed.

Lastly, you should note that the national body representing the interests of state commissions in Washington, NARUC, has demonstrated excellent leadership producing not just one, but two versions of practical cyber security guidance for commissions in the past year. NARUC will be holding its annual summer meetings in Denver next week and I understand cyber security is going to be given much more attention than it's received in the past.  Hmm, maybe this is a good chance to jump-start your commission's cyber security program ....


URLs referenced:

AEE
http://pucportal.aee.net/

CPUC
http://www.cpuc.ca.gov/NR/rdonlyres/D77BA276-E88A-4C82-AFD2-FC3D3C76A9FC/0/TheEvolvingRoleofStateRegulationinCybersecurity9252012FINAL.pdf

Business Roundtable
http://businessroundtable.org/uploads/studies-reports/downloads/Final_More_Intelligent_More_Effective.pdf

Lloyds of London
http://www.lloyds.com/news-and-insight/risk-insight/lloyds-risk-index

NARUC Guidance
http://www.naruc.org/grants/Documents/NARUC%20Cybersecurity%20Primer%202.0.pdf

NARUC Summer Meeting
http://summer.narucmeetings.org/