Home > Security News > Critical infrastructure security grim, study finds
Security News:
EMAIL THIS

Critical infrastructure security grim, study finds

By Marcia Savage, Features Editor, Information Security magazine
10 Nov 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A recent study by Secure Computing Corp. paints a gloomy picture of cybersecurity readiness in critical infrastructure industries.

As a community, we've come to look at cybersecurity as not just viruses or worms, but securing the communication fabric that protects the physical infrastructure we need to live and breathe.
Phyllis Schneck,
vice president of research integration, Secure Computing

According to the study, which surveyed 199 security experts and industry representatives, most industries that make up the critical infrastructure are not prepared for cyberattacks. More than half of the respondents said that utilities, oil and gas, transportation, telecommunications, chemical, emergency services and postal/shipping sectors were not prepared.

Thirty-three percent of survey respondents identified the energy industry as the biggest target for a cyberattack. They also pointed to energy as the most vulnerable and the industry that would have the worst consequences if breached. The financial services industry was the only sector survey most participants considered prepared.

More than 50% of North American participants said cyberattacks on critical infrastructure have already begun, while 14% expect a major exploit to occur in the next year.

Earlier this year, a CIA senior analyst said at a SANS Institute conference that cyberattacks disrupted power equipment in several regions outside the U.S., including one that caused a multi-city power outage. The SANS Institute reported the disclosure in a Jan. 18 newsletter.

Audio download: Critical infrastructure security:
Securing the nation's critical infrastructure systems: Senior Technology Editor Neil Roiter interviews Brian Ahern, president and CEO of Industrial Defender, which specializes in the security of critical infrastructure systems. The nation's critical infrastructure providers have been called onto the carpet. Recently, a house subcommittee delivered a blistering appraisal of the deficiencies in power companies security posture. Coming on the heels of a GAO report that Tennessee Valley Authority power plants are vulnerable to cyber attack, the congressional tongue-lashing raised questions about what power, oil and gas, chemical, water and transportation companies are doing to secure their systems. In this podcast, we ask Brian Ahern, president and CEO of Industrial Defender, which specializes in the security of critical infrastructure systems, about the state of security in these vital sectors and the special challenges these companies face.

Survey respondents cited cost and apathy as the top obstacles to improving cybersecurity in vital industries.

The study surveyed security and network operators in industries that make up the critical infrastructure, along with security experts in law enforcement and other fields. The research, released Monday, was conducted in August and September in the U.S., Canada and Europe.

The problems highlighted in the survey stem from the fact that the Supervisory Control and Data Acquisition (SCADA) systems used in industries, such as energy, evolved -- like the Internet -- with the focus on availability and speed rather than security, said Phyllis Schneck, vice president of research integration at San Jose-based Secure Computing. They also weren't intended to be remotely accessed, which introduces vulnerabilities, she said.

"As a community, we've come to look at cybersecurity as not just viruses or worms, but securing the communication fabric that protects the physical infrastructure we need to live and breathe," she said.

Addressing the problem will first require an understanding of how industrial control systems interface with IT systems and the Internet, Schneck said. Then, it will require understanding the impact of upgrading legacy control systems and something the industry is actively working on -- designing traditional IT systems so they can protect critical infrastructure.

Secure Computing, which McAfee Inc. is in the process of acquiring, recently announced three new signature file types for SCADA-specific protocols into its Secure Firewall. Other vendors offering security tailored for industrial control environments include Foxborough, Mass.-based Industrial Defender Inc., which specializes in SCADA systems security.

SearchSecurity radio:

In September, the U.S. House Energy and Commerce Subcommittee on Energy and Air Quality held a hearing to discuss draft legislation to help secure the nation's electric grid from cyberthreats. Published reports indicate the legislation would broaden the authority of the Federal Energy Regulatory Commission (FERC).

"I believe America is disturbingly vulnerable to a cyberattack against the electric grid that could cause significant consequences to our nation's critical infrastructure," Rep. Jim Langevin (D-R.I.), chairman of the House Homeland Security Subcommittee on Emerging Threats, Cybersecurity and Science and Technology, said in a prepared statement released in September. "Virtually every expert that I've discussed these matters with -- across government and throughout the private sector -- shares this assessment."

Legislators have criticized the energy industry's response to the Aurora hacking test conducted at the Idaho National Laboratories in 2007, which caused a generator to self-destruct. Despite a federal advisory to mitigate the vulnerability exploited in the test, a FERC audit of 30 utilities found that "the vast majority had not complied," according to Rep. John Dingell (D-Mich.), chairman on the Committee on Energy and Commerce.



Tags: Security Industry Market Trends, Predictions and ForecastsEmerging Information Security ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Industry Market Trends, Predictions and Forecasts
M86 buys Web security gateway vendor Finjan
Information Security Decisions 2009: Presentation downloads
Bruce Schneier on outsourcing, awareness training
Marcus Ranum on cyberwarfare, infosec careers
McAfee survey finds faults in midmarket enterprise security
Email archiving vendor sues Gartner over Magic Quadrant
Information Security magazine October issue PDF
Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
Information Security magazine Security 7 Award winners
Security Squad: Privacy gone awry
Security Industry Market Trends, Predictions and Forecasts Research

Emerging Information Security Threats
Modern malware, stealthy botnets, adapt quickly, expert says
New ransomware Trojan pushes victims to buy software
Bruce Schneier on outsourcing, awareness training
US-CERT warns of BlackBerry snooping software
Marcus Ranum on cyberwarfare, infosec careers
Researchers find thousands of flawed embedded devices
Enterprise botnets contain thousands of malware variants
Nuke and pave to eradicate botnets
Rand study urges caution on cyberwarfare attacks
Hathaway joins Harvard to contribute to DOD project

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
backscatter body scanning  (SearchSecurity.com)
marketecture  (SearchSecurity.com)
NCSA  (SearchSecurity.com)
Palladium  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts