Hiển thị các bài đăng có nhãn risk management. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn risk management. Hiển thị tất cả bài đăng

Energy Firms Not Ready for Cyber Insurance?


Or so says corporate underwriter and veteran cyber insurance provider, Lloyds of London, in a BBC article last week:
Any company that applies for cover has to let experts employed by Kiln and other underwriters look over their systems to see if they are doing enough to keep intruders out. Assessors look at the steps firms take to keep attackers away, how they ensure software is kept up to date and how they oversee networks of hardware that can span regions or entire countries.
Sadly, as the article goes on to say:
After such checks were carried out, the majority of applicants were turned away because their cyber defenses were lacking.

The article notes a great uptick in the last year in the number of energy sector firms seeking cyber coverage, but it doesn't posit a reason for the sudden rush.  Questions immediately spring to mind:
  • What is the audit or investigation like that Lloyds puts applicant through? 
  • What is examined?  
  • Who is interviewed?  
  • Is this only data/privacy breach cyber insurance being discussed or is business continuity also on the table?
  • Are any technical tools used?  
  • Are 3rd party risks evaluated?
  • Etc.
And for me the biggest two: what are the key indicators insurers look for that tell them that an organization is on the ball cyber security-wise and worth the risk of insuring?  And where is the line drawn, above which an organization is secure enough?

I am confident someone knows the answers to these questions, but I haven't been able to find him/her yet. But when I do, it'll be to tease out the most common energy-sector-specific shortcomings and then roadmap to an insurable state.

Here's the URL for the full article: http://www.bbc.com/news/technology-26358042

Image credit: Govtech.com

Where do Today's Electric Utility CEOs come from, and what do their Origins Mean for Grid Security?


I remember once thinking, naively perhaps, that most utility CEOs must have come up through the ranks, like generals in the military, with hands-on operational engineering experience garnering them the respect of their peers and subordinates along the way.

When I shared that concept last year with a 40-year industry veteran who'd done his time in generation and T&D, he schooled me saying that while that used to be the case, it's not the norm today.  He said more often you'll find someone with a finance background, often imported from sectors outside power.

Well, I got another round of schooling on this subject this week from former state commissioner and current consumer advocate Nancy Brockway, who has made her presence known on this blog before, in: "The State of the States and Smart Grid Security." Well she's back, and whether you agree with her or not, and allowing for exceptions, I think you definitely should hear what she has to say about the origins of senior utility leadership in 2014:
Transaction-oriented finance and legal sector professionals have displaced engineers in the executive suites of most utilities. The big shift to deal-making occurred in the wake of the existential shocks of the late 20th century over cost over-runs, the end of cheap oil, and the growing recognition of the environmental costs of utilities. 
Look back a century or more to the pioneers of the utility industry and you'll see a public interest value system that could and often did accompany the build out of utility territories and even accompanied mergers and acquisitions. Read 2004's Insull: The Rise and Fall of a Billionaire Utility Tycoon by Forrest MacDonald, for more background. 
But economies of scale were pretty-well exhausted by the 1960s. Bigger was no longer better for customers. And an anti-regulation "winner takes the hindmost" political climate did not reward a utility executive's greater effort to serve the public. Rather, it rewarded ever more sophisticated schemes to funnel profits up to the executive suite.
Regulators have to push for what they see as the public interest. To do their jobs with any responsibility in these circumstances, they can no longer sit back and merely act as a brake on occasional excesses. Too often they have to define the public good and demand it from utility management.

I am not sure that a workable redefinition of the roles and responsibilities of management and regulators can happen without a wholesale cultural shift away from "Greed is Good." My opposition to pre-approval of cyber security spending comes from the sense that if the utility drags its heels or does only what it needs to satisfy regulators, that just demonstrates that utility execs do not see security as fundamentally necessary for their personal financial success.
Sort of begs the question of how Gordon Gekko would weigh security investments vs. security risk, and you know what, I don't know the answer.  But we know GG types thrive on risk and reward. 

That's not exactly what I had in my mind previously, imagining conservative, retired military, former boy or girl scouts, with steady hands on the tiller of some of the absolute most important critical infrastructure organizations in the country.

Hopefully, experience and acumen with fine tuning financial risk/reward equations will most often translate to similarly savvy understanding of and action on operational risks ... including one that's increasingly material and the raison d'etre of this blog.

Photo credit: ABC news

Thoughts on "Risk and Responsibility in a Hyperconnected World"

Hat tip to Tim Dierking of Aclara for spotting and forwarding this January 2014 World Economic Forum / McKinsey report: "Risk and Responsibility in a Hyper-connected World." Tim pointed to a couple of excellent sections on cyber resilience and future scenarios which you'll find within, but I'm going to call out a different selection for your immediate consumption.

This below is taken directly from the McKinsey summary, which while not energy-sector specific, is right on the money, IMHO, on the culture, leadership and organizational dynamics aspects of what's needed to do security right in 2014+.  Here you go:
A CEO-level issue 
Given the trillions of dollars in play, the stakes are high. And given the range of social and business issues that cyber resiliency affects—for example, intellectual property, regulatory compliance, privacy, customer experience, product development, business continuity, legal jurisdiction—it can only be addressed effectively with active engagement from the most senior business and public leaders. 
Even improving cybersecurity capabilities within a single institution requires collaboration across a host of business functions. Operational managers must assess which information assets are most valuable. Privacy and compliance functions have to evaluate the impact of losing customer data. Decisions about how much to monitor employee access to sensitive data have major HR implications. And procurement must negotiate security requirements into vendor contracts. 
Given the scale of impact and the degree of coordination and cultural change required, progress toward cyber resilience requires active engagement from the CEO and other senior leaders. They have to make clear they expect the following:
  • an honest, granular assessment of existing capabilities and risks, given their business model
  • alignment on the most important information assets and a clear approach for providing them with required protection
  • a road map for getting to a scalable, business-driven cybersecurity operating model
  • a well-practiced set of skills for responding to breaches across business functions
Sustaining the pace of innovation and growth in the global economy will require resiliency in the face of determined cyberattacks. Only CEOs and senior public leaders can solve the problem, because of the strategic and organizational-change issues that need to be resolved.
And so continues the exhortation for senior business and government leaders to take more ownership of the security risk challenge.  It's not easy.  In fact, in the overly technical ways it's usually presented to them, it's overwhelming and way out of their comfort zone.

For the umteenth time: Security leaders need to meet them more than halfway by speaking plain-English business language and as much as possible converting technology and security risk into dollars and cents to be gained or lost. Clarity and persistence are the keys here, as there are no gold, silver, or bronze bullets to hasten the process.

The summary and full report can be found HERE




Special Conference Alert: Risk Management-Focused NARUC Annual Meeting


This NARUC Annual Meeting is called "Managing Risk: Protecting Consumers and Critical Assets" and yours truly will have the honor of participating as a panelist.

As per usual, here are basics:
  • Where: Orlando Hilton Bonnet Creek, FL
  • When: 17-20 November 2013
  • To Register: click HERE
Here's a press release for more flavor, and here's the agenda.

The Sunday afternoon panel I'm on is called: "Risk Management in Action: Challenges and Opportunities for Implementation", and here's the narrative description of what we'll be discussing:

There’s a lot of talk about the benefits of risk management processes to address cybersecurity, but how familiar are we with the actual implementation of these processes? Come hear panelists discuss the resources necessary to implement and maintain risk management processes for cybersecurity of our critical infrastructure. What are the bottom line impacts on owners’ and operators’ resources for implementing risk management? Hear from subject matter experts about the opportunities and challenges.

Should be great.  Hope some of you can make it.

Photo credit: TripAdvisor.com

Heads-Up: The 2013 ICS Cybersecurity Summit is Closing In


We talked about this conference and many of its concerns a few weeks ago at the EnergySec Summit, and among things, got a great presentation showing how one utility has built and gotten great value from its OT security test-bed.

There's going to be a talk on test-beds plus a bunch of other great presentations at the annual "Joe Weiss" summit, so if you have interest, and the ability to get there,  I highly recommend you do.

Here are the basics:
Dates: 21-24 October 2013 
Venue: Conference location: GTRI Conference Center, 250 14th Street NW, Atlanta, GA 30318 
LINK for more info and to register 
LINK to register
Photo credit: Jomi Thomas Mani @ Flickr.com

NERC CIPs Catching up to iPhone Version Numbers


OK, imagine an auction barker: "Bids opening at NERC version 3, do we have a version 3? ..."

"Yes! How about version 4?" Etc.

Well, according to Honeywell's NERC CIP guru Tom Alrich (of the famous, eponymous and quite helpful blog), it now appears that the next version of the CIPs to which utilities must comply will be neither version 4 nor  5 but rather version 6!

I was stunned as were many of the those in online attendance. Tom explains his reasoning on the EnergySec webcast and much more, which you can see HERE. There's a lot of helpful information for utilities of all sizes dispensed in this hour long piece, with some deep dives into the ramifications of high, medium, and low risk assets.

Now, depending on whether we get an iPhone 5s or 6 next month, it's clear that NERC will not allow the CIP versions to lag far behind.

----------------------------

Attended most of this webinar online, but hat tip to my former colleague and (hopefully) current friend, Nebraskan Dave Hemsath of IBM for sending me the replay.

Photo credit: KCRW.com

To Secure Your State Grid, First Know Your Public Utility Commission (UPDATED)

19 July 2013 UPDATE: Significant clarification just in from Terry Jarrett, Commissioner of Missouri's Public Service Commission and Chairman of the Committee on Critical Infrastructure at NARUC:
Actually, the NARUC Critical Infrastructure Committee's main focus has been cyber security for the past two years that I have been chairman. Last fall at our annual meeting, incoming NARUC president Phil Jones declared cyber security to be one of the themes of his presidency. To say that cyber will be given more attention in Denver than in the past simply is not factual. 
Thank you Terry.  I'll leave the original post below intact so you can see to what Terry was referring, but please keep his clarification in mind as you do.  ab

-- -- -- -- --

The Advanced Energy Economy Institute (AEE) has a great new site for helping you navigate your way around any of the 50 US states' energy landscapes, including commission leadership, energy portfolio mix, legislation and more. One topic you won't read much about, however, at least not without doing some substantial digging, is cyber security preparedness.

As readers of the SGSB may recall, we've done shout outs to California and Texas, both states having cyber security knowledgable professionals on their Public Utility Commission (PUC) staff, and there are a couple of other states now similarly equipped. Many other states, however, haven't yet made a modest level of cyber security capability a requirement.

With the Business Roundtable (BRT) issuing guidance earlier this year for how organizations should better organize themselves to meet the rising cyber security risks they face, to a recent report drawn from mega-insurer Lloyds of London's survey of CEOs and Board of Directors at the world's top companies showing they now consider cyber security among the top three risks facing their companies, you could say it's well past time for all organizations, and particularly those with public authority and responsibility like state utility commissions, to ensure they are well informed.

Lastly, you should note that the national body representing the interests of state commissions in Washington, NARUC, has demonstrated excellent leadership producing not just one, but two versions of practical cyber security guidance for commissions in the past year. NARUC will be holding its annual summer meetings in Denver next week and I understand cyber security is going to be given much more attention than it's received in the past.  Hmm, maybe this is a good chance to jump-start your commission's cyber security program ....


URLs referenced:

AEE
http://pucportal.aee.net/

CPUC
http://www.cpuc.ca.gov/NR/rdonlyres/D77BA276-E88A-4C82-AFD2-FC3D3C76A9FC/0/TheEvolvingRoleofStateRegulationinCybersecurity9252012FINAL.pdf

Business Roundtable
http://businessroundtable.org/uploads/studies-reports/downloads/Final_More_Intelligent_More_Effective.pdf

Lloyds of London
http://www.lloyds.com/news-and-insight/risk-insight/lloyds-risk-index

NARUC Guidance
http://www.naruc.org/grants/Documents/NARUC%20Cybersecurity%20Primer%202.0.pdf

NARUC Summer Meeting
http://summer.narucmeetings.org/

Boxing the Fundamental Assumptions of Cybersecurity Risk Management


Here's something to wrap your head around (or more literally, put in your head) as you head to NIST on April 3rd to make your contribution to the Critical Infrastructure Cybersecurity framework development processes, an effort begat by the recent Presidential Executive Order.

Many in our community love to talk about risk management as the common sense, business oriented antidote to the mandatory and therefore inflexible and slow moving instructions in the NERC CIPs.

You could certainly put me at least half in that camp.  Well, after reading THIS sharp Brookings paper from Ralph Langer and Perry Pederson, that half of me is feeling a little wobbly.


Want to see if you can handle it?  Let's see you go for a round with them.  They begin with a jab -- the DHS definition itself:
The following is a definition of risk-based decision making from appendix C of the Department of Homeland Security’s risk Lexicon: “risk-based decision making is defined as the determination of a course of action predicated primarily on the assessment of risk and the expected impact of that course of action on that risk.”
And then counter with a flurry of lefts to some assumptions, a series of rights to some more, and finish with a big left to the whole foundation upon which cyber risk management normally rests:
The basic assumption embedded in this and all risk formulae is that unknown future events of an unknown frequency, unknown duration, unknown intensity, from an unknown assailant, with unknown motivations, and unknown consequences are quantifiable. Consequently, if one thinks s/he can measure the risk, the mistaken conclusion is that one can manage the risk.
I'm trying to not be overly swayed by this one article, but certainly it's going to be something I try to keep in main memory while at the workshop.  Hope it helps inform your thinking too.

BTW (late addition): I just realized this post ends on a bit of a down note and I don't want to leave you there.  If you can make it to page 8 you'll find Pederson and Langer pivoting towards their recommended solutions to replace risk management-based decision making.  You'll see these fall into 3 P's: Politics, 2) Practicality and Pervasiveness.  I myself haven't made it there yet but intend to before nightfall ... tomorrow.

---------------
P.S. have you ever tried boxing? I have a little, and it's a blast, and super hard, and exhausting.  But you know one thing it's easier than?  That's right, you've got it.

Photo credit: Wikimedia Commons

Heralding the Dawn of Critical Infrastructure Security Metrics


You may like this blog because of its emphasis on business-oriented security metrics and measurement. Or you may loathe it for the same reason (though if you do, you shouldn't still be visiting much).

Can't measure, can't manage. On this we agree, right?

So ... we're two weeks past the Presidential executive order (EO) that kicked off a new round of meetings that will ultimately produce a new NIST framework for grid security. You can read about the goals for this thing, including the RFI process HERE.

Thanks for EnergySec's Patrick Miller who tweeted yesterday that this round of work is designed, among other things, to produce metrics that can be used to assess the current security posture of your organization.

To whit, "The Framework should include flexible, extensible, scalable, and technology-independent standards, guidelines, and best practices, that provide:
Metrics, methods, and procedures that can be used to assess and monitor, on an
ongoing or continuous basis, the effectiveness of security controls that are
selected and deployed in organizational information systems and environments in
which those systems operate and available processes that can be used to facilitate
continuous improvement in such controls."

Bravo. Also I note and you'll see, in a section called Current Risk Management Practices, these highly metrics-suggestive questions:.
  • How do organizations define and assess risk generally and cybersecurity risk specifically?
  • To what extent is cybersecurity risk incorporated into organizations’ overarching enterprise risk management?
  • What standards, guidelines, best practices, and tools are organizations using to understand, measure, and manage risk at the management, operational, and technical levels?
You can see where this is leading, can't you? I'll plan to be at the first framework development meeting that's open to industry, and will be including my 2 cents in the RFI process as well. Recommend you do same. 

Heard that meeting might be on April 3 and will confirm or revise accordingly.

Photo credit: Wikimedia.org

Alrich on Distributech's 2013 Cybersecurity Focus Panels

I couldn't make it to the panel sessions but fortunately Tom Alrich could and did. Here's are his short-takes on 3 different panels:
Substation Integration and Automation: The Cybersecurity Landscape is Changing - Didier Giarratano of Schneider Electric discussed Role Based Access Control (RBAC) and how to do good job applying RBAC to the challenges of substations. Anthony Eshpeter of SUBNET Solutions discussed “Complexities of Substation Cyber Security”. He provided a very good, lucid discussion – pointing out the need for solutions like those SUBNET sells but without ever making a sales pitch. Bradley Tips of Cisco addressed “Real-world Deployment of Network Security for NERC CIP Compliance”. A good overview of what CIP requires for a substation these days.
Smart Grid Cybersecurity and Standards-based Integration - This session was very well attended. Leading off was Elizaveta "Liza" Malashenko of the California Public Utilities Commission. Both Andy and I have bloggedabout her (and her staff’s) excellent papermaking the case for state regulation of Smart Grid cyber security, and for using a risk-based approach in doing so (in contrast with the NERC CIPs' more prescriptive approach, which also don’t apply to distribution). Elizaveta is a very poised and articulate spokeswoman for this position; judging from the crowd that came up to greet her afterwards, she seems on her way to rock-star status.
Following Elizaveta was Valentine Emesih of CenterPoint Energy, who discussed and showed screens from a product they have developed with Siemens called Utility Operations Center Cybersecurity Manager. It seems to be a very well-designed “dashboard” to let EMS operators – without specialized cyber security training – be notified of security events and be clearly told what needs to be done for each one (I’m simplifying a lot). The third speaker was Ed Hedges of Kansas City Power and Light, on “Innovative Methods and Solutions Drive KCP&L’s End-to-End Smart Grid Program”. This was an excellent overview of KCP&L’s Smart Grid rollout, including some very honest discussion of lessons learned.
You vs. Security: Can you Keep Up? - We got off to a very rousing start with Joseph Fisher of Affinity IT Security addressing what utilities should be doing to achieve real cyber security, not just CIP compliance. He provided a good schematic of all the important domains of cyber security, and discussed what each one means. I don’t think there was any particular idea I hadn’t heard before, but it was very valuable to have all the pieces tied together.\
He was followed by PwC consultant Jon Stanford (formerly with BPA and a longtime member of the CSO 706 Standards Drafting Team). Jon’s topic was “Today’s Advanced Malware Threat” and he provided a great in-depth discussion of the many types of malware attacks in recent years and the different tools available to address them – as well as the processes and procedures that need to drive any effective anti-malware program. The last speaker was Adam Bosnian of Cyber-Ark Software, discussing the need to secure administrator and shared accounts.

So there you go, and thanks to Tom for providing the next-best-thing to being there. BTW, Tom's a bit of a NERC CIP expert, and you can find his latest observations on his new blog right HERE. When you get there be sure to bookmark it for future reading.

EEI on Electric Sector Cybersecurity, late 2012

David Batz (rhymes with yachts, not cats) is in a good position to know what he's talking about when he says:
Utilities are taking actions to mitigate and manage cybersecurity threats.
As Cybersecurity Director for the Edison Electric Institute (EEI), a DC-based industry advocacy firm that represents the interests of the vast majority of investor owned utilities in the US, Batz is emminently credible as he spends just about every waking hour working with utilities, various Federal and state regulators, and the companies that serve the sector.

At a recent conference in Arlington, VA Batz shared some observations on the state of electric sector cybersecurity preparedness that I liked.  Here's one:
In today’s world, cyber attacks and cyber hacking have become monetized and different ventures are using cyber attacks as a ways to generate income .... This poses a problem for law-abiding citizenry and creates a problem for the electric sector.

And also this on the prospect of Smart Grid technology having some potential for positive security outcomes:
There are opportunities to enhance the visibility by the utility into the operational state, particularly for the distribution network, to be able to say, there is an outage at this location and very quickly respond to the outage.
For its members, EEI has recently launched a "Threat Scenario Project" which identifies major threats and recommends mitigation approaches for each. Its motivation and origin:
To continue an engagement between the CEO, the CFO, the chief security officer [and] the chief information officer to say where are we doing well, where are we doing less well [and] what makes sense in terms of resource allocation.
That puts EEI in familiar SGSB territory, for in order to assess performance on cybersecurity (or any other) objectives from a business perspective, you have to know a few things, with some precision, like:
  • Where you are now
  • Where you want/need to be
  • What the gaps are between the baseline and roadmap milestones
  • What you need to do, as an organization, to fill those gaps, and get to the next level
With a bloom of Smart Grid security maturity models and other guidance docs this year, it's good to see EEI right in the thick of it. HERE's the article for you.

Is the Smart Grid a Homeland Security Problem?

Last week I had the privilege of being on a IEEE/Department of Homeland Security (DHS) panel discussing the topic: Smart Grid: A Homeland Security Problem or Not? Talk about a title that begs the question.

My sharp co-panelists hailed from DHS, the Utilities Telecom Council (UTC), MIT, the University of Vermont and MITRE, and we were masterfully moderated by Emily Frye, also of MITRE.

Anyway, all I want to say here is that we got a great question from an audience member (and it was a very interactive audience!) that we were hard pressed to answer. It went basically like this:
If each utility was somehow given an infusion of $1 million (Dr. Evil's preferred amount) what would be the best, most security impacting way for them to spend it?
Several of us gave it a shot, and of course I went to metrics, saying the lack of widely agreed-upon security metrics means many if not most utilities would lack the information required to help them answer this question. In retrospect, even though there wasn't any overt booing, that wasn't very helpful.

More helpful by far, though too late for the conference goers, came an answer the next day from my friend,  colleague, and previous SGSB co-blogger Jack Danahy. Jack said he would recommend every utility (and companies in all sectors for that matter) to use the money to perform an inventory. Figure out and document, some for the first time, exactly what they have in terms of networks, systems, devices, apps and data. 

As someone like Yogi Berra, Mark Twain or Will Rogers once said, "You can't secure what you don't know you have."  Clearly, you can't manage risk or even begin to prioritize your actions until you have established a baseline of what needs protecting.

Wish I had thought of that at the right time. Anyway, there's the answer for you.  And you can see Jack in his role of IBM's Director of Advanced Security, interviewed by Bloomberg TV, HERE.

And of course the answer to the question in question, the title of the panel session and this post, is yes and no, for all the reasons we've previously explored at length, if not ad nauseum, on this blog.

Conference Alert: A Risk Management-Focused GridSec

Things have been changing over the course of half a dozen or so GridSec conferences the last 3 years:
  • Increasingly, a risk management vs. pure compliance approach to security is in evidence at utilities
  • Practical, business-oriented metrics and measurement mechanisms are being developed and used to increase visibility and understanding of current state and challenges, and to facilitate prioritization
  • Describing security requirements and incidents in language more accessible to management and more aligned with core utility values and business drivers, including safety and reliability
  • More attention to Operational-side issues
What attendees will experience at the upcoming summit will be an update on the evolution of grid security, privacy and compliance issues that reflects the evolution of the bullet-ed points of the above.

The details you need to get/be there:

  • When: 22-24 Oct 2012
  • Where: PG&E head office, 77 Beale Street, San Franciso, CA
  • Web page for more info and reg: HERE

Lots of great speakers are lined up and the hallway talk is always interesting too. Hope you can make it.

Attacks on Energy Equipment Vendor like Attacks on Defense Contractor


In 2009 reports emerged that attackers had breached defense contractor systems and stolen data related to the F-35 Joint Strike Fighter. Not knowing what was seen and what was stolen, it means we may always have some uncertainty about how much adversaries know about this plane's combat capabilities and other secrets.

In 2011 we got news that the same contractor was attacked again, albeit this time, perhaps, with less success.

Now comes a network breach of a major critical infrastructure telemetry and control systems manufacturer and it sounds like they may have lost some of the design specs and software at the heart of one of their most important and widely deployed systems.

Systems used by electric utilities, gas utilities and some of the largest oil companies in the world.

How much the company itself knows or will come to know about the scope of the loss may never be known. But as with the F-35 above, current and future users of its equipment, now have a new dose of uncertainty they're going to have to (risk) manage somehow.

In a perfect world, of course the best approach is to prevent these breaches in the first place. But at least they detected them and can initiate  forensics and emergency response plans.

You can read various accounts here:
As well as a Telvent press release announcing a new approach to securing itself and its systems.

Photo credit: Horia Varlan @ Flickr.com

More Datapoints on the Current State of Electric Sector Cybersecurity Governance


In March we covered the preliminary CyLab report on the state of cross sector Security governance and one of the things it taught me was that electric sector cybersecurity professionals are not alone in their quest to improve/increase the level of interaction and communication with senior executives in their companies, including the CEO and Board of Directors (BoD).

Other than financial services sector companies, whose reputation for being in the lead on security and privacy governance matters is corroborated, none of the other sectors covered (IT/Telecom, Energy/Utilities, Industrial) fares particularly well.

Well, the final Carnegie Mellon/CyLab report is out now, and it provides a lot more detail into which to sink one's teeth. You can begin with the press release HERE, or move straight into the 28-page full report HERE.

But with your limited time in mind, electric sector reader, I've cherry picked a few salient nuggets for your more rapid consumption. First, an opening statement:
Interestingly, none of the energy/utilities sector respondents indicated that they have a Chief Risk Officer (CRO) even though their risks are high. The energy/utilities sector also places a much lower value on board member IT though their risks are high. The energy/utilities sector also places a much lower value on board member IT experience than the other sectors, which is puzzling since their operations are so dependent upon complex experience than the other sectors, which is puzzling since their operations are so dependent upon complex supervisory control and data acquisition (SCADA) systems.
Interesting: connecting IT experience with a foundation for grasping control systems security fundamentals. Certainly better than having no information systems background. And I didn't know CRO's where rare in large utilities. Maybe the utilities that participated in this survey are not representative of the larger population for some reason. But I would have thought CROs were commonplace, even if their attention wasn't trained on cybersecurity risks.

Now lets go straightaway to electric sector conclusions:
  • The energy/utilities and IT/telecom respondents indicated that their organizations never rely upon insurance brokers to provide outside risk expertise, while the industrials sector relies upon them 100%
  • Energy/utilities and IT/telecom sector boards are not adequately reviewing cyber insurance coverage
  • The energy/utilities sector places a much lower value on board member IT experience than financial, IT/telecom, and industrials industry sectors
And let's conclude with this recommendation, since it squares so nicely with one of the oft-repeated themes of this blog:
Review existing top-level policies to create a culture of security and respect for privacy
This CyLab report is an interesting complement to the recently release IBM CISO Survey, the results of which were discussed HERE last month. I'm always glad to add others' takes on how our sector is faring, even if the findingss are less than glowing. The truth, as they say, and presuming it's present to some degree in these reports, will set you free. Hopefully free to make things better.

Image credit: Magnetbox at Flickr.com