The Race to Reengineer Cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


It took six days for Colonial Pipeline Co.’s 5,500-plus miles of connected refined petroleum supply infrastructure from Houston to New York City, to come back on line after a May 7, 2021 ransomware cyberattack forced the company to shut down operations and pay $4.4 million for restoration. 

The Wall Street Journal reported that a criminal hacker group gained control of the pipeline system, which supplies about 45% of refined petroleum products to 14 East Coast states, by compromising one of the company’s virtual private networks. As blowback from the breach rippled across the nation in the following days, fuel shortages sparked long lines and panic buying at some gas pumps amid fears the pipeline could be offline indefinitely.

“We’re continuing to see that evolution of people targeting systems because of a growing awareness of the potential impact.”

—Nick Andersen, Deputy Director, Cybersecurity and Infrastructure Security Agency

After trading the ransom for a decryption tool from the hackers that did not work properly, then-Colonial Pipeline Co. CEO Joseph Blount, who has since retired, called paying the ransom “the hardest decision I’ve ever made in my career.” In a National Public Radio interview, he added, “If owning that de-encryption tool gets you there quicker, then it’s the decision that had to be made. It was the right decision to make for the country.”

For many cybersecurity experts, the incident was a “big wakeup call” to a brewing war over how to protect cyber data and their real-world assets, says Lucian Niemeyer, CEO of the Bethesda, Md.-based smart building nonprofit Building Cyber Security. In early June, he joined representatives from the National Academy of Construction, National Academy of Engineering, and United Engineering Foundation in Washington, D.C., to discuss shoring up engineering defenses at the ground level.

“We’ve determined there has to be, for the engineering community a recognition of risk, regardless of what the owner wants, and that’s important,” said Niemeyer in his opening address at the inaugural National Cyber Safety Summit, with about 50 invited attendees. “There has to be a subset of controls that are mandatory. They’re just like an electrical system. You’ve got to put in certain technologies with certain protections.”

In an agenda featuring cybersecurity experts from around the country and a keynote address by Nicholas M. Andersen, acting director of the Cybersecurity and Infrastructure Security Agency, a unit of the U.S. Dept. of Homeland Security, attendees were guided on how cyber threats can manifest into public safety risks via compromising operating systems that manage water, energy, transportation, healthcare and telecommunications.

Andersen called data breaches by criminal groups “almost every bit as concerning” as attacks from foreign nations. He said he believes bad actors are more likely to target infrastructure systems because they don’t understand how damage to such systems can quickly compound. “At least the nation state actors are prepositioning [themselves] within the infrastructure, and they’re aware [of what] they’re engaging,” he said. “Criminal groups that we continue to see engage in the space, or potential ransomware actors, don’t all the time know the consequence of where they’re engaging,”

Andersen added that “In some ways, they are actually less responsible of an actor within this space. We’re continuing to see [an] evolution of people targeting systems because of a growing awareness of the potential impact.”


Looking for quick answers on construction and engineering topics?
Try Ask ENR, our new smart AI search tool.

Ask ENR



GET STARTED



Lucian Niemeyer
Edd Gibson Jr
Nicholas Andersen

panel of senior experts from the National Security Agency

Cyber Security Summit speakers (top, l to r) Lucian Niemeyer, Edd Gibson Jr. and Nicholas Andersen; and a panel of senior experts from the National Security Agency. U.S. Cyber Command and U.S. Defense Dept.
Photos courtesy Cyber Security Summit

 

Engineering Cybersecurity Standards

After the Colonial Pipeline ransomeware attack, the U.S. Dept. of Energy released recommendations on securing clean energy systems across the nation’s electricity grid titled Cybersecurity Considerations for Distributed Energy Resources on the U.S. Electric Grid.

In a call-to-action document released following the summit, the National Academy of Engineering urged that the construction industry should build on such recommendations to create engineering standards for cyber safety. It notes that engineering standards, professional licensure and insurance “did not develop in isolation.” They all “evolved together—each driven by catastrophe, each reinforcing the other, and each expressing the same underlying social compact between the profession and the public it serves.”

The engineering academy added in a statement: that today’s built environment consists of “no longer purely physical objects …[but] cyber-physical systems—hospitals, schools, water treatment plants, transportation, robotics, and energy systems [that] all rely on networked controls, building automation, [internet of things] devices, and cloud-connected infrastructure.”

According to the academy, keeping such systems safe requires establishing a new standard of care “owned by the design and construction professions” that is “integrated into licensure, codes and contracts,” such as fire, structural, and electrical safety, with support from insurance companies for “pricing risk reduction and treating failures as professional negligence.”

“The key issue is that this is not a one-part solution. It’s going to take people from all walks of life in our industry to make this happen.”

—Edd Gibson Jr., CEO, National Academy of Construction

The standard would be reinforced through “inspection, commissioning, and handoff with documented owner training,” According to the group, there is no time to waste in adopting such a standard, “while stakeholders have opportunity to shape standards” and not react to catastrophe.

National Academy of Construction President and CEO Edd Gibson Jr. said that making progress on the report’s action items requires involved participants from across the industry.

“The key issue is that this is not a one-part solution,” he said. “It’s going to take people from all walks of life in our industry to make this happen.” Gibson said the mission includes educating people entering the construction industry and those already in the workforce.

“It’s going to take contractors, designers, especially the owners understanding what kind of issues that their facilities may face, and obviously governments involved trying to protect the general public,” he stated. “It’s tough when these things go slow, but that’s what it takes because there are so many people who have to be engaged with it.” He termed the cyber risk “a clear and present danger for our country.”

 

The AI “X” Factor

According to a filing with the California Attorney General’s office, Turner Construction on Aug. 18 notified about 6,098 individuals of a data breach that caused their information—such as bank account information, dates of birth, salaries and Social Security numbers—to be illegally pulled from the contractor’s systems between July 2 and July 15 by ransomware group Payouts King.

The hacker claimed in a post online that the information accessed also included engineering documents, contracts, non-disclosure agreements, some passport numbers and military project files.

In a statement provided to ENR, a Turner spokesperson noted that cybersecurity is a “growing challenge” for every organization. “The increasing use of technology across the construction industry makes protecting systems, information and projects more important than ever,” said the spokesperson. “Upon discovering unauthorized access to certain systems, Turner engaged leading third-party cybersecurity and forensic experts to investigate. We took steps to further protect our systems and continue to conduct a detailed review of the incident.”

Turner said the experience “reinforces the importance of preparation, resilience, and having the right resources and relationships in place before an incident occurs.” For the company, a leading data center contractor, the incident also reinforces the importance of open communication throughout an event, the spokesperson said.

“no single company should control the future. It also means a global response is necessary, requiring new partnerships to raise security standards.”

—100 technology firms in open letter to policymakers and tech sector executives

As much as artificial intelligence has made knowledge more accessible, it has also given bad actors more tools for destruction, Andersen told summit attendees. “We’re continuing to see significant pivots, where we’re not only seeing malicious cyber actors that are continuing to target our infrastructure … [but also that] the level of knowledge required to do this” is lower, he pointed out. “We have not done ourselves any favors because we have made personal technology in particular so open and available.”

Last month, data center hyperscalers Google, Microsoft and OpenAI joined a group of 100 tech firms in an open letter to their industry executives and to public policymakers calling for greater cyber defenses around AI assets and infrastructure, which are expected to exceed $1 trillion in value by 2029, according to market intelligence firm International Data Corp. The letter served as another warning that the U.S. is already behind in the race to secure AI development. As its technology improves, cyberattacks using AI will become more sophisticated, adding that “status quo” security measures “won’t be enough.”

Public services such as hospitals, water treatment plants and electrical grids “are at risk for a national security crisis waiting to happen,” noted the letter.

The group called for empowering more cyber defenses using AI to make security tasks “faster, cheaper and better,” adding that cyber capabilities are advancing globally. “That can be a net positive: No single company should control the future. It also means a global response is necessary, requiring new partnerships to raise security standards and find new solutions to emerging cyber threats,” said the letter.

Niemeyer, one of 20 new members appointed to U.S. Energy Secretary Chris Wright’s cybersecurity advisory board, added: “We’ve got a lot of work to do. It’s dense.”

——————————————————-


Click Here For The Original Source.