Expert Articles
Boosting Cybersecurity in the Energy Industry
Reported by dh2i.com
By Don Boxley, Co-founder and CEO, DH2i
As industries worldwide sent their workforces home to work remotely over the last few months due to the coronavirus, the World Economic Forum (WEF) published words of warning to the utilities and the energy industry. The article was written by Leo Simonovich, vice president and global head of industrial cyber and digital security at Siemens, and was aptly called “Why COVID-19 is making utilities more vulnerable to cyberattack—and what to do about it.”
While reopening in many U.S. locations means that some workers are starting to abandon their safe home bases to reenter the traditional work environment, Simonovich’s perspective is no less important. He highlighted challenges that have intensified due to the global pandemic, including the fact that new “weak points in organizations’ infrastructure”—due to the fact that many have been working from home and some are still doing so at least some of the time—are more easily exploited by cyber attacks.
Workers may be moving back toward business as usual, but the Pandora’s box has already been flung open through the remote work of the past few months, which changed workflows and broke down certain security measures that had been in place when employees were working in-house.
“The rush to remote systems, understaffed facilities and new ways of working,” Simonovich noted, left utilities companies, and thus their customers around the country, more vulnerable to cybercrime. As he writes, “Working from home makes some security practices impossible”:
“Home-based work increases exposure to cyber-risks. Less-reliable internet connections, social engineering attacks against employees and their families, and honest mistakes made in unfamiliar workflows are all new potential risks. Partner companies will also face increased cyber exposure.”
The worst-case scenario that the Siemen’s executive paints is that hackers will figure out how to access “critical plant production and grid networks from homes,” which ups “the risk of a possible second-wave crisis: rolling outages and safety events at a time when keeping the lights on matters most.”
Insecure New Reality
As Utility Dive reported last month with the pandemic in full swing, utility systems’ increased connectivity creates “a dark side in that it introduces new entry points and, by extension, increased vulnerability. As networks become more distributed, they become increasingly susceptible to hacking and cyberattacks.”
The added risks for the energy industry and grid resiliency are coming from multiplied vulnerabilities that have been created by remote work, even if workers have now moved back on site, with attacks now potentially “coming both from inside and outside the walls” of the company’s cyber defenses.
Even if the remote work is taking place less frequently now, periodic home-based work can still make utility companies vulnerable to poor Internet connections that are easy to hack, user errors that expose corporate networks, and third-party security breaches. If a utility company gets hacked, there can be global consequences that go far beyond the walls of the company. T&D World reported that “Resiliency is no longer something we desire; it is essential…Water, communications, national defense, health systems and financial networks all depend on an extremely reliable electric infrastructure.”
Shoring Up the Grid
It’s important for the energy industry to understand what needs to be done to increase grid security and during workplace changes due to COVID-19. Whether remote workers are at home full-time or periodically, the fact that the industry now has more people who have worked virtually (or may still be doing so) creates potentially catastrophic situations that could hurt millions of customers, leaving them “powerless” quite literally.
The first step to avoiding this fate is to deploy software-defined perimeter (SDP) software. SDP relies on “zero trust” architecture, which in practice means that when utility employees are working remotely with their devices, they won’t be privy to unrestricted network access. Instead, their access will only extend to specific applications—and IT must sanction those—for datacenter and cloud applications.
Application-level access avoids the types of security gaps that network-level access creates, which makes SDP technology very valuable in terms of cybersecurity. SDP software creates a “secure by default” environment that prevents lateral attacks and protects grid resiliency.
I don’t need to tell you how major the crisis would be if sections of the grid were to lose power due to a cyberattack. To decrease these risks during the COVID-19 era, SDP is the key to utility companies regaining the needed protection during such unprecedented times.
About the author:
Don Boxley Jr is a DH2i co-founder and CEO. Prior to DH2i ( www.dh2i.com ), Boxley spent more than 20 years in management positions for leading technology companies, including Hewlett-Packard, CoCreate Software, Iomega, TapeWorks Data Storage Systems and Colorado Memory Systems. Don earned his MBA from the Johnson School of Management, Cornell University.
