Critical Infrastructure Security
,
Geo Focus: The United Kingdom
,
Geo-Specific
Government Tight Lipped Over Possible Iranian Hack, Experts Complain
Operational technology security leaders are calling on the British government to release technical details of a cyberattack last month that took a small power plant offline for four days.
See Also: How to Bridge the IT-OT Divide in Building Security
So far, the government’s public statements have “been very limited, and hopefully, we’ll find out more soon,” Markus Mueller, field CISO at operational technology security company Nozomi Networks, told ISMG.
The British government should follow the example of the Polish national Computer Emergency Response Team, which published a comprehensive technical breakdown of last year’s three-pronged attack on the Polish energy grid, attributed to Russian hackers.
“That’s the gold standard now for what good reporting looks like,” said Mueller.
By contrast, the British government had not publicly disclosed any details. “We’ve heard reports that the attack path was an exposed PLC, but we haven’t heard that from a government or official source,” Mueller said.
Programmable logic controllers are computerized devices used in industrial plants to automate mechanical or electrical processes. A PLC controls physical actuators like motors and valves to run factory machinery, water treatment plants, or commercial building systems.
Other experts said that the public statements from the British government to date seem designed to assuage public fears, since they disclose one data point about the target: That it was “tiny, especially compared to what most of us would class as a ‘power plant/station,'” according to Energy Minister Michael Shanks.
Shanks added that officials had “briefed energy CEOs and shared further advice with companies on the steps they should take to stay secure.”
A British government spokesperson said GCHQ, the British equivalent of the NSA, had also taken part in the briefing. One report attributed the attack to the Cyb3rAvengers, a threat group linked by the U.S. government to the Iranian Revolutionary Guard Corps.
“We need more details,” agreed Donald McFarlane, an advisory board member for Xcape, Inc., a managed IT and security services provider. “What was the attack path? What was actually affected on the OT side and what [type of attack] caused it? Was a PLC directly exposed to the internet? … What control would have broken the attack chain?”
Public statements were so vague, McFarlane told ISMG, that it wasn’t even clear whether OT infrastructure had been breached at all, or whether “operators [had] shut the plant down defensively after an IT compromise.”
“Don’t tell me this was historic and then redact the history,” he added.
McFarlane urged the British government to follow Washington’s lead: “In the case of all these OT attacks, including against the water systems, they [DHS’ Cybersecurity and Infrastructure Security Agency] have released a series of joint cybersecurity advisories that have been extremely helpful in providing information on TTPs, IOCs and other information that operators can use to assess how to defend against these attacks,” he said.
The CISA advisories proved that it was possible to “protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account,” McFarlane concluded.
Target Was Likely a ‘Peaker Plant’
Shanks’ comments and similar remarks from anonymous government officials reported by the British media suggest to Nozomi Networks’ Mueller that the power facility attacked was a “peaker plant” – a small but reliable power source grid operators can call on quickly when demand is higher than expected, or supply is lower, for example due to the variability of renewable generation caused by weather. But that was an assumption, he acknowledged.
The time of the outage – four days according to the Telegraph – was also suggestive, Mueller said. Peaker plants have PLCs running ancillary systems, like water as a coolant for example, as well as the primary control system running the main turbine or boiler. “If you do incident response,” he said, “one of those [ancillary] systems getting hit with the attacks that we’ve seen in the U.S. [on PLCs], lines up to about a four-day outage.”
The attackers were highly opportunistic, he said, and it was unlikely they had deliberately targeted that facility. Targeting a particular power plant, “that’s hard to do,” Mueller said. “That takes social engineering. It takes reconnaissance and profiling,” none of which the hackers appeared to have used, he said.
Indeed, Mueller said, it was possible that they did not know that the PLC was part of a power plant at all. “A PLC at a peaker plant that has a well and a [water] tank, will be configured very similar to what a water utility configuration would be,” he explained.
The plant fell below the minimum wattage above which operators have to report cyber incidents, according to the U.K.’s Daily Telegraph, which broke the story over the weekend.
“What has our attention here is not the size of the generator,” said Denis Calderone, CTO of cybersecurity firm Suzu Labs. “A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked,” he said in an email.
Click Here For The Original Source.
