Hiển thị các bài đăng có nhãn metrics. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn metrics. Hiển thị tất cả bài đăng

Energy Firms Not Ready for Cyber Insurance?


Or so says corporate underwriter and veteran cyber insurance provider, Lloyds of London, in a BBC article last week:
Any company that applies for cover has to let experts employed by Kiln and other underwriters look over their systems to see if they are doing enough to keep intruders out. Assessors look at the steps firms take to keep attackers away, how they ensure software is kept up to date and how they oversee networks of hardware that can span regions or entire countries.
Sadly, as the article goes on to say:
After such checks were carried out, the majority of applicants were turned away because their cyber defenses were lacking.

The article notes a great uptick in the last year in the number of energy sector firms seeking cyber coverage, but it doesn't posit a reason for the sudden rush.  Questions immediately spring to mind:
  • What is the audit or investigation like that Lloyds puts applicant through? 
  • What is examined?  
  • Who is interviewed?  
  • Is this only data/privacy breach cyber insurance being discussed or is business continuity also on the table?
  • Are any technical tools used?  
  • Are 3rd party risks evaluated?
  • Etc.
And for me the biggest two: what are the key indicators insurers look for that tell them that an organization is on the ball cyber security-wise and worth the risk of insuring?  And where is the line drawn, above which an organization is secure enough?

I am confident someone knows the answers to these questions, but I haven't been able to find him/her yet. But when I do, it'll be to tease out the most common energy-sector-specific shortcomings and then roadmap to an insurable state.

Here's the URL for the full article: http://www.bbc.com/news/technology-26358042

Image credit: Govtech.com

DOE's C2M2 is Growing Up Fast

There's been a ton of work accomplished since DOE handed the C2M2 flame to former FERCer Jason Christopher.  This program has now been leveraged at hundreds of enterprises and now gives you three flavors of Cybersecurity Capability Maturity Model (C2M2) to choose from now.

You can download any/all of the models right this minute if you are so inclined:


In addition, there are a number of new supporting resources for organizations at some stage of the C2M2 consideration or implementation process:

  • C2M2 FAQ - helps answer whether or not a C2M2 self-assessment is right for your organization (ab: sounds a little too much like a Cialis commercial to me)
  • C2M2 Facilitator Guide - provides step-by-step guidance for organizations that want to perform their own internal self-assessments (with or without a 3rd party)
  • C2M2 toolkit for all three models (electricity, oil & natural gas, and sector-neutral) based on MS Excel and Word, so it can be used by any organization. (Toolkits are provided by request only—email C2M2@doe.gov for more information.)

Lastly, this just-released bulletin tells you how DOE, NIST and DHS see the C2M2 and the Critical Infrastructure Security Framework (CSF) playing complementary roles.

So much good stuff.  Between all of the above and the Olympics, this should keep you off the streets and out of trouble until Spring finally shows up.

Moving Beyond Technical: Use Security Governance Strategies to Integrate Security with the Mission

If like me you've come to the conclusion that a tech-centric strategy can only get us so far in energy sector cyber risk management, then you might want to see some of the source materials I've come across in my explorations.

The two I'll point to in this post are from Carnegie Mellon University's CERT program and PricewaterhouseCoopers' cybersecurity consulting practice.  What they have in common is that they are both several years old.  This is not VC or DARPA-funded cutting edge stuff.  It's human behavior stuff, and as such, it's not on an upgrade path anything like iOS, Android, or "Next Generation" firewalls. But neither are these concepts rapidly deployable, as you'd be hard put to find them put into practice widely at many utilities in 2013.
Nevertheless, for those wanting to achieve and communicate improvement in ours and other critical infrastructure sectors, here are some excerpts I've pulled out for you to consume more quickly.

Starting with definitions, this come via the CERT work, citing NIST SP800-100 - Information Security Handbook: A Guide for Managers:
Security Governance is the process by with senior leaders direct and control an organization to establish and sustain a culture of security in the organization's conduct, including behaviors, capabilities and actions. It includes establishing and maintaining a framework and supporting management structure and processes to provide assurance that security strategies:
  • Are aligned with and support business objectives 
  • Adhere to policies, standards, and internal controls 
  • Provide assignment of authority and responsibility 
All of this with the objective of managing cyber risk to the tolerances desired by that organization.
Then from PwC, instructing CISOs to "Define business objectives"
Collectively, the organization’s business objectives form the single most important driver of the security strategy. They are the basis of the arguments you will be using to communicate the business case for change and will help you prioritize initiatives based on business need. When determining your security strategy planning process, take care that it is explicitly mapped to the business objectives you have identified and carefully defined in terms of the benefits that will be used to measure project success.
More from PwC, coaching CISOs, this one's attributed to the then-CISO of Radianz, Lloyed Hession, now at Bridgewater Associates: "If you can’t talk ROI, the boardroom isn’t listening"
There are two types of metrics used by the CISO: those based on security criteria and those based on business goals. Those based on security criteria are a useful intradepartmental tool for evaluating performance, but they do not translate to the boardroom. For example, knowing the number of attacks detected or thwarted may be useful in evaluating your incident response and detection processes, but they tell the executive nothing about the dollar return on his security investment. 
Core message I get from these sources: align, align, align ... security policy with business objectives, and always translate 1's and 0's bits to 1's and 0's dollars/euros/pesos, etc.  There's much more if you want to sink your teeth into this.

Links: 


Smart Grid Security 2012 Highlights and 2013 Look Forward


As a chronic complainer re: the lack of grid security metrics (see post from nearly 2 years ago: "Smart Grid Security Truth: You Can't Do What You Don't Measure"), this has been the most amazing and surprising year for me.

By far the most important development this year was that it began with only a few specific guidance documents from NIST and NRECA) and is now ending with a comparative landslide of guidance, including some directly aimed at helping utilities assess their current security posture and plot future courses for improvement.

I documented most of these in an October post but for those who missed, forgot or avoided it, here are the new ones for North America published in 2012:

And similar guidance development activities are motion elsewhere. The European Network and Information Security Agency (ENISA) has produced its Smart Grid Security Recommendations and a number of other helpful documents.  And I've also heard of early but promising work happening now in India and Japan; perhaps we can look forward to guidance from those geographies in 2013.

I'm not going to talk about 2012 cyber security breaches although there some big ones. You can find plenty of pixelated coverage on those elsewhere. However, looking at this giant infographic (thanks to colleague Steve O for the link) of a survey of hundreds of electric sector personnel by critical infrastructure consultancy Zpryme indicates that most folks see both more spending on security and more attention paid to better securing the operational technology (OT) side of the utility house. That syncs well with my own notes from the field this year.

So in 2013 I'll be watching (and hopefully, getting hands-on with) utilities putting themselves through the some of the measurement and metrics programs listed above. Will also continue my clarion call, along with an increasing number of partners in Federal and State agencies, for utilities to take a fresh look at their own Security Governance models as I/we believe there are many substantial gains awaiting those who do.

Image credit: Da Vinci's "Vitruvian Man" is in the public domain

Electric Sector Security Metrics Mother Load

Not all are technical metrics, nor are they all technically, metrics.

But in the space of just a few months this summer, North American electric utility executives and their security leadership have seen a spate of new guidance documents published that intend to help them manage, monitor, and measure the effectiveness of their cyber risk mitigation strategies and controls.

Where once there was just the cross-sector ISO 27000 series to steer your security course by (or for Federal folks, FISMA), there are suddenly a near handful of freshly minted how-to manuals at their disposal:
DOE's Electricity Subsector Cybersecurity Maturity Model (June 2012)
Metrics for utilities to use to baseline and gauge effectiveness
DOE’s Electricity Subsector Risk Management Process (May 2012)
Helpful translating cybersecurity into risk management framework 
NARUC's Cybersecurity for State Regulators (June 2012)
Questions utilities will be asked by their state public utility commissions
NIST’s NISTIR 7628 Assessment Guide (Aug 2012)
And if you live in or keep an eye on California, then there’s the metrics work and data privacy rules of the California Public Utilities Commission (CPUC) to consider. It’s working collaboratively with the three big investor owned utilities (IOUs) to bring Smart Grid metrics to fruition, and despite some initial skirmishing, seems resolute in adding security metrics to the mix.

So now maybe the guidance utilities need most is: with limited resources already maxed out on NERC CIP related activities, how to select and implement the best and most helpful pieces from the list above.

Ironic, is it not, to hear the SGSB describe a flood of security metrics in our industry?

Conference Alert: A Risk Management-Focused GridSec

Things have been changing over the course of half a dozen or so GridSec conferences the last 3 years:
  • Increasingly, a risk management vs. pure compliance approach to security is in evidence at utilities
  • Practical, business-oriented metrics and measurement mechanisms are being developed and used to increase visibility and understanding of current state and challenges, and to facilitate prioritization
  • Describing security requirements and incidents in language more accessible to management and more aligned with core utility values and business drivers, including safety and reliability
  • More attention to Operational-side issues
What attendees will experience at the upcoming summit will be an update on the evolution of grid security, privacy and compliance issues that reflects the evolution of the bullet-ed points of the above.

The details you need to get/be there:

  • When: 22-24 Oct 2012
  • Where: PG&E head office, 77 Beale Street, San Franciso, CA
  • Web page for more info and reg: HERE

Lots of great speakers are lined up and the hallway talk is always interesting too. Hope you can make it.

Mid 2012 GAO Update on Grid Security ... and a Mea Culpa

Before teeing up the most recent GAO report on electric sector cybersecurity, I'd like to use this pixelated platform to speak back to a quote attributed to me last week that raised the hackles of some utility professionals (and it should have).

First, I'm neither a security-focused PR flack for the electricity industry, nor a gotcha journalist trying to capture eyeballs by vilifying utilities and scaring readers. Rather, I'm a member, supporter, advocate, and hopefully, sometimes, a constructive critic of the enterprise of keeping the grid safe and secure while updating it for the 21st century.

So here's the thing: a recent interviewer quoted me as saying senior management doesn't have a very good understanding of their security posture. While I'm sure I've said something like this a hundred different ways on the blog, it's never been intended as an insult or attack, but rather as observation of the current state of affairs at many but not all utilities. The way  this was captured and framed in the article, however, losing nuance and a few other qualifying words along the way, it definitely came off as a blunt attack ... and I'm not the only one who noticed. Sorry about that ... wasn't my intent.

However, support for this type of generic observation comes from things everyone in the industry already knows, and that the GAO lists on the highlights page of its July 2012 report. Here are the last 4 challenges, partially addressing utilities, partially the larger industry ecosystem:
  • A focus by utilities on regulatory compliance instead of comprehensive security
  • A lack of security features consistently built into smart grid systems
  • The electricity industry did not have an effective mechanism for sharing information on cybersecurity and other issues
  • The electricity industry did not have metrics for evaluating cybersecurity (AB: of course I'll come back to this one before the post is over!)
All of these things make sense to folks who've either been in a utility or have worked with utilities and/or regulators for some time. There's a logical history to each of them that explains where they came from and why they remain challenges to be solved. 

And you'll note (and it angers some of the more concerned security pundits when I say this), that whatever US utilities have done so far has apparently been enough to keep cyber attackers from having major successes to date.

As this post is now getting too long and trying to do too many things, let's end with another invocation on the benefits of business-oriented metrics, this time courtesy of the GAO itself:
... Having metrics would help utilities develop a business case for cybersecurity by helping to show the return on a particular investment. Until such metrics are developed, there is increased risk that utilities will not invest in security in a cost-effective manner, or have the information needed to make informed decisions on their cybersecurity investments.
The GAO, I think, comes from a similar position, in some ways anyway, as this blog. The cited report mentions not just shortcomings but positive actions taken so far. The GAO, the SGSB (this blog) and plenty of other groups and individuals simply want to see utilities and the industry be safe and successful while they modernize to meet the demands of our times. Neither are interested in criticism for criticism's sake, but only to suggest better possible methods. I'll leave it at that for now.

2 Control Systems Metrics Movers/Shakers: Jim Brenton and Joe Weiss

The more metrics the merrier, I say. After yesterday's post on IDC's take on energy sector cybersecurity metrics, let's pivot to control systems, where the three most important things are:
  1. reliability
  2. reliability, and
  3. reliability
... and where what passes for cybersecurity in IT realms just doesn't cut the mustard.

First see this NEW POST from Joe Weiss on how to begin wrapping your head around what control systems metrics could look like.

Then I'd recommend Jim Brenton's PRESENTATION at GridSec earlier this year on a new group that's formed to look at developing security (or should I say reliability and resiliency) metrics for the Bulk Electric System (BES).

OK, that's it, this is a short one. You can go back to what you should have been doing all along.

New IDC Report Takes Measure of Energy Security Metrics


They had me with the title: "Methods and Practices: Creating a Metrics-Based Security Culture".  It seems IDC must have used a key word optimizer app designed to discover the best title based on the complete works at the Smart Grid Security Blog.

I can't vouch for the utility of this report because I haven't read it.  But I do know lead IDC energy and security analyst Usman Sindhu because we've been discussing grid security topics since we met back when he was still at Forrester Research.

Jesse Berst and the SmartGridNewsers did a nice little intro to it HERE.

The price may not be right for you, though maybe your company already has a subscription with IDC that will let you see it for free. Or maybe you can negotiate a "friends price" with Usman, the economy being somewhat iffy at the moment.

Photo credit: Steven Harris on Flickr.com