Hiển thị các bài đăng có nhãn natural gas. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn natural gas. Hiển thị tất cả bài đăng

Oil and Natural Gas Co's became Primary Attack Targets Last Year


At least according to analysis from cyber security company Alert Logic. This detail and more is captured in a report just released by the US Council on Foreign Relations (CFR).

According to authors Blake Clayton and Adam Segal:
Cyber attacks on energy companies are increasing in both frequency and sophistication, making them more difficult to detect and defend against. Cyber espionage is being carried out by foreign intelligence and defense agencies, even organized crime or freelance hackers.
Attacks affecting the sector over the past several years including Night Dragon, Stuxnet and Shamoon are all given a nod, as are all the past and present legislative efforts to improve cyber security and information sharing functions. On the international front as well (see: foreign relations).

Nothing new here I think, but this is a good Oil & Gas industry-specific rollup of challenges and potentially mitigating solutions.

Announced on a very high news day it may not get much notice, though I've seen it written up in a number of outlets including Reuters and FoxNews.  But timing may be propitious ahead of Department of Energy's efforts to start a cyber security maturity model for Oil & Gas sector shortly. Stay tuned for more on that.

-----------------

URL for CFR report summary with link to full report (8 pages)

http://www.cfr.org/energy/addressing-cyber-threats-oil-gas-suppliers/p30977

-----------------

Photo credit: Peter Carson at Flickr.com

House of Reps Report Reams Utilities on Cybersecurity

Was trying to capture spirit of Jesse Berst's headline on the same subject:
Utilities to FERC: Take your security measures and shove it
That's not very nice, is it?  I think they toned it down with a later change, but this headline was what was in my inbox in this morning's SmartGridNews.com newsletter. The subject is a recent report published by the House of Representatives that's highly critical of electric utilities behavior to date re: grid cybersecurity.

Moving on! The Wall Street Journal's Rachel King did a fine write-up of recent testimony from the CEO of the American Gas Association (AGA), Dave McCurdy. King began by noting that:
The oil and gas sector faces many of the same cyber security challenges as the electric industry. Yet, there’s one major difference between the industries, both of which need to secure software-based industrial control systems from intruders. There are no regulations governing cyber security among the oil and gas companies.
She also heard McCurdy say that no regulations were needed and that the sector’s voluntary approach is working just fine, and:
AGA remains concerned that prescriptive cyber security regulations will have little practical impact on cyber security and, in fact, will hinder implementation of robust cyber security programs.
If you know this subject pretty well, you're aware that there is some interesting psychology and rhetoric going on here. Most agree that mandatory, prescriptive cybersecurity rules are painful to implement and audit, and too slow to adapt to new types of attack. So in a major sense, the AGA CEO's quote is dead on. 

But the rub is that "robust cyber security programs," loosely defined, are not commonplace in the natgas distribution sector, and it's hard to imagine that market forces alone will drive companies to move of the schneid.  And the same dynamic largely holds true for the electric power sector.

The language is getting a little saucy. What's going to give?

URLs for the above, below:

House Report on Electric Grid Cyber Vulnerability

http://markey.house.gov/sites/markey.house.gov/files/documents/Markey%20Grid%20Report_05.21.13.pdf

SmartGridNews.com on Utilities' Unhappiness with Cybersecurity Regulation

http://www.smartgridnews.com/artman/publish/Technologies_Security/Utilities-to-FERC-Take-your-security-measures-and-shove-it-5778.html/?fpt#.UZ4dcSt4ZyE

WSJ: Oil and Gas Lobby Resists Regulation Despite Cyber Risk

http://blogs.wsj.com/cio/2013/05/22/oil-and-gas-lobby-resists-regulation-despite-cyber-risk/

NatGas Cybersecurity getting a lot more Visibility


Thanks to colleague H. Chantz for spotting this article and sending this way.

As has been the case quite a bit this year, once again we are in the realm of SCADA/Control System security. William Rush of the Gas Technology Institute states it plainly, if somewhat dramatically:
Anyone can blow up a gas pipeline with dynamite. But with this stolen information, if I wanted to blow up not one, but 1,000 compressor stations, I could,” he adds. “I could put the attack vectors in place, let them sit there for years, and set them all off at the same time. I don’t have to worry about getting people physically in place to do the job, I just pull the trigger with one mouse click.
There are no NERC CIPs for the gas industry, but with 25-30% of US electric power and a whole lot of home heating coming from gas, it's time to get moving on better securing this infrastructure.

Pipeline operators, now alerted to the fact that sensitive access control information to important subsystems is in the hands of folks outside the industry (and outside the country it seems), need to get moving. And I'm sure they will, but it's a BIG job.

The whole Christian Science Monitor article is HERE.

Photo credit: War News Updates

One Step Closer: Announcing NARUC's Cybersecurity Guide for State Regulators 2.0

My last post on NARUC*, from June of 2012, was on the first version of their cybersecurity guide for state regulators, and the somewhat sprawling piece ended thusly:
I would like to end by saying that this was a document that could never fully please everyone, and if we remember it's a 1.0 version, then in that context it's an ambitious and excellent start. Let's start providing feedback now so that 2.0 can be even better.
Well guess what readers? Some of you and maybe some others provided feedback, so well and fully in fact that we find ourselves fewer than 9 months later with a new and improved 2.0 version, just released by NARUC after announcing it at its Winter Meetings (note sublime, almost hypnotic snowflake animation on landing page).

After reviewing the new document myself, and getting some input from the authors, while there are numerous small changes that help, the main difference seems to be an emphasis on having regulators develop an overarching strategy before diving into more granular elements like orders, requirements and rules.

To me this is creates a nice parallel to what some of the more forward leaning utilities are doing when they work to create security architectures. In both cases, whether on the regulator or the regulated side, the enabling concept is to craft a coherent larger plan before making point enforcement decisions or deploying point security solutions.  Unquestionably sound stuff.

But still there's this (a holdover from version 1.0). Question 28 under Personnel and Policies invites commissioners to ask: "Do you have a Chief Security Officer and do they have explicit cybersecurity responsibilities?"

I would arm the commissioners with the knowledge that while many utilities will reflexively say they have a CSO, that he or she is neither a true C (chief) nor a true O (corporate officer).  When there are more true executive level security chiefs out there, empowered to develop and enforce cybersecurity policy enterprise-wide (IT, Smart Grid and OT) then that will clearly mark a departure from status quo and the beginning of a more proactive, cyber risk management-based utility culture.

And maybe we'll see that called out in NARUC's 3.0 version. But for the moment, I think these folks deserve a pause to refresh. They've been producing high quality guidance at a very rapid pace ... kudos.


* For those unfamiliar with this acronym, it stands for the National Association of Regulator Utility Commissioners.  This is the national body that represents the electric, telecom and water regulating interests of the 50 US states. From a security point of view, NARUC and the state commissioners primarily watch the distribution elements of the grid, whereas the NERC CIPs in North America focus on large generation and transmission assets. You can check out the NARUC site by clicking HERE.