pwr_february-2024 - 24
CYBERSECURITY
The Power Sector's High-Stakes
Battle for Cyber-Resiliency
The power sector's relentless pursuit of an increasingly connected power paradigm
amid an escalating cyber threat landscape demands an urgent, multifaceted strategy for
cybersecurity. Recently, the sector has embarked on innovative methods to tackle
inherent challenges in its evolving quest for a robust cybersecurity posture.
Sonal Patel
I
n 2022, a third party alerted industrial
control systems (ICS) firm Dragos
it had identified a new collection of
malware, PIPEDREAM, that fostered
a " reusable
cross-industry capability "
that could unleash disruptive and even
destructive effects on ICS/operational
technology (OT) equipment. As Dragos
CEO Robert Lee explained to Congress
in March 2023, " Years ago, I often [said]
that I was not worried about the threats
of today because our infrastructure owners
and operators had focused so much
on reliability and safety that it naturally
helped cybersecurity. " But PIPEDREAM,
distinct for its capability to exploit " homogenous
infrastructure, " stunned him.
" Based on Dragos' assessment, PIPEDREAM
was initially targeted toward
energy assets such as liquid natural gas
and electric transmission equipment, " he
noted, " but it can work on almost all OT
environments, ranging from the heating,
ventilation, and cooling equipment in
data centers to control systems used in
next-generation military and weapons systems. "
And while PIPEDREAM was one of
many ICS-specific malwares-following
STUXNET, AURORA HAVEX, BLACKENERGY2,
CRASHOVERRIDE/INDUSTROYER,
TRISIS/TRITON, and INDUSTROYER2
(Figure 1)-it presented " the first realistic
cyber capability that can significantly disrupt
critical infrastructure domestically, " he
said. " It's not capability you can simply
patch away or otherwise prevent. Once
it is in a target's networks, it is a reliable
tool for an attack as it takes advantage
of the native functionality and common
software now deployed across infrastructure
sites. "
PIPEDREAM's identification led Dragos
and its partner to the National Security
Agency (NSA), Federal Bureau of
Investigations (FBI), Cybersecurity and Infrastructure
Security Agency (CISA), and
Department of Energy (DOE), and under
" one of the most significant public-private
24
1. Industrial control systems (ICS) security firm Dragos suggests cyber threats are growing
more frequent and sophisticated. Courtesy: Dragos
partnership wins of all time in cybersecurity, "
the collaborative effort identified,
analyzed, and ultimately reported PIPEDREAM
to the broader infrastructure
community before PIPEDREAM could
make an impact, Lee said. While its proactive
containment represents a victory,
the specter of the insidious malware that
can unleash potentially massive repercussions
remains significant.
One reason is that since 2015, when a
cyberattack prompted power outages in
Ukraine, the power sector has dramatically
ramped up its cybersecurity posture. But
adversaries have been relentless. " In 2017,
the first-ever cyberattack that targeted human
life directly took place in a Saudi Arabian
petrochemical facility by targeting an
OT system, " Lee noted. " Across 2018 to
2021, there were over a dozen new state
actor cyber teams that started targeting
industrial companies directly. "
Attacks have highlighted vulnerabilities
in all parts of the industry. The 2020 SolarWinds
attack, spearheaded by the Russian
Foreign Intelligence Service, exposed
as many as 16,000 computer networks
worldwide, highlighting vulnerabilities in
supplier and manufacturer networks.
Ransomware operations are meanwhile
ramping up, reports security firm
Resecurity. While the energy industry
has seen a " brief, sectoral 'ceasefire'
following the 2021 Colonial Pipeline
ransomware attack, cybercriminals are
once again honing in on energy-industry
www.powermag.com
targets, " it warned in November. " In the
wake of the MOVEit Transfer supply-chain
extortion campaign, which has claimed
over 2,180 victims so far, 2023 may actually
go down in history as the most profitable
year ever for ransomware actors.
The broader trend driving the ransomware
industry's increasing ROI [return
on investment] is the return of 'big game
hunting,' or the targeting of large organizations, "
it said. Operators are now targeting
nuclear, and oil and gas firms, and
" will continue to increase their extortion
demand beyond $7 million, weaponizing
their essentiality to CI [critical infrastructure]
operations, " it said.
A Collective Push Toward
Resilience
For the power sector, cyber threats remain
top-of-mind, but its quest for good
cybersecurity posture has evolved into a
crucial risk management strategy with
several new drivers. For one, significant
security risks are associated with the
changing resource mix. The grid transformation
" is expanding the existing
attack surface due to the use of emerging
technologies, additional communications,
and industrial controls as well as
remote control capabilities, " explains the
North American Electric Reliability Corp.
(NERC), a quasi-governmental compliance
enforcement authority.
Modern cybersecurity, which includes
several security principles and concepts,
POWER | February 2024
http://www.powermag.com
pwr_february-2024
Table of Contents for the Digital Edition of pwr_february-2024
pwr_february-2024 - Cover1
pwr_february-2024 - Cover2
pwr_february-2024 - 1
pwr_february-2024 - 2
pwr_february-2024 - 3
pwr_february-2024 - 4
pwr_february-2024 - 5
pwr_february-2024 - 6
pwr_february-2024 - 7
pwr_february-2024 - 8
pwr_february-2024 - 9
pwr_february-2024 - 10
pwr_february-2024 - 11
pwr_february-2024 - 12
pwr_february-2024 - 13
pwr_february-2024 - 14
pwr_february-2024 - 15
pwr_february-2024 - 16
pwr_february-2024 - 17
pwr_february-2024 - 18
pwr_february-2024 - 19
pwr_february-2024 - 20
pwr_february-2024 - 21
pwr_february-2024 - 22
pwr_february-2024 - 23
pwr_february-2024 - 24
pwr_february-2024 - 25
pwr_february-2024 - 26
pwr_february-2024 - 27
pwr_february-2024 - 28
pwr_february-2024 - Cover3
pwr_february-2024 - Cover4
https://www.nxtbook.com/accessintelligence/POWER/pwr_november-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_december-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_october-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr-re-tech_september-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_september-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_august-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_june-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_july-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_may-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_april-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_march-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_february-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_january-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_december-2023
https://www.nxtbook.com/accessintelligence/POWER/pwr_november-2023
https://www.nxtbook.com/accessintelligence/POWER/power-october-2023
https://www.nxtbook.com/accessintelligence/POWER/re-tech-supp-to-power-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-and-re-tech-supp-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-august-2023
https://www.nxtbook.com/accessintelligence/POWER/power-july-2023
https://www.nxtbook.com/accessintelligence/POWER/power-june-2023
https://www.nxtbook.com/accessintelligence/POWER/power-may-2023
https://www.nxtbook.com/accessintelligence/POWER/power-april-2023
https://www.nxtbook.com/accessintelligence/POWER/power-march-2023
https://www.nxtbook.com/accessintelligence/POWER/power-february-2023
https://www.nxtbook.com/accessintelligence/POWER/power-january-2023
https://www.nxtbook.com/accessintelligence/POWER/power-december-2022
https://www.nxtbook.com/accessintelligence/POWER/power-november-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-October-2022-140th-Anniversary-Supp
https://www.nxtbook.com/accessintelligence/POWER/Power-October-2022-and-Anniversary-Supp
https://www.nxtbook.com/accessintelligence/POWER/power-and-re-tech-supp-september-2022
https://www.nxtbook.com/accessintelligence/POWER/power-september-2022
https://www.nxtbook.com/accessintelligence/POWER/power-august-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-July-2022-Intl
https://www.nxtbook.com/accessintelligence/POWER/power-july-2022
https://www.nxtbook.com/accessintelligence/POWER/power-june-2022-intl
https://www.nxtbook.com/accessintelligence/POWER/power-june-2022
https://www.nxtbook.com/accessintelligence/POWER/power-may-2022
https://www.nxtbook.com/accessintelligence/POWER/power-may-2022-intl
https://www.nxtbook.com/accessintelligence/POWER/power-april-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-April-2022-Intl
https://www.nxtbook.com/accessintelligence/POWER/power-march-2022
https://www.nxtbook.com/accessintelligence/POWER/power-february-2022
https://www.nxtbook.com/accessintelligence/POWER/power-january-2022
https://www.nxtbook.com/accessintelligence/POWER/power-december-2021
https://www.nxtbook.com/accessintelligence/POWER/power-top-plants-supp-december-2021
https://www.nxtbook.com/accessintelligence/POWER/power-november-2021
https://www.nxtbook.com/accessintelligence/POWER/power-october-2021
https://www.nxtbook.com/accessintelligence/POWER/power-september-2021
https://www.nxtbook.com/accessintelligence/POWER/power-august-2021
https://www.nxtbook.com/accessintelligence/POWER/power-july-2021
https://www.nxtbook.com/accessintelligence/POWER/power-june-2021
https://www.nxtbook.com/accessintelligence/POWER/power-may-2021
https://www.nxtbook.com/accessintelligence/POWER/power-april-2021
https://www.nxtbook.com/accessintelligence/POWER/power-march-2021
https://www.nxtbook.com/accessintelligence/POWER/power-february-2021
https://www.nxtbook.com/accessintelligence/POWER/power-january-2021
https://www.nxtbook.com/accessintelligence/POWER/power-december-2020
https://www.nxtbook.com/accessintelligence/POWER/power-november-2020
https://www.nxtbook.com/accessintelligence/POWER/power-october-2020
https://www.nxtbook.com/accessintelligence/POWER/power-september-2020
https://www.nxtbook.com/accessintelligence/POWER/power-august-2020
https://www.nxtbook.com/accessintelligence/POWER/power-july-2020
https://www.nxtbook.com/accessintelligence/POWER/power-june-2020
https://www.nxtbook.com/accessintelligence/POWER/power-may-2020
https://www.nxtbook.com/accessintelligence/POWER/power-april-2020
https://www.nxtbook.com/accessintelligence/POWER/power-march-2020
https://www.nxtbook.com/accessintelligence/POWER/power-february-2020
https://www.nxtbook.com/accessintelligence/POWER/power-january-2020
https://www.nxtbook.com/accessintelligence/POWER/power-december-2019
https://www.nxtbook.com/accessintelligence/POWER/power-november-2019
https://www.nxtbook.com/accessintelligence/POWER/power-october-2019
https://www.nxtbook.com/accessintelligence/POWER/power-september-2019
https://www.nxtbook.com/accessintelligence/POWER/power-august-2019
https://www.nxtbook.com/accessintelligence/POWER/power-july-2019
https://www.nxtbook.com/accessintelligence/POWER/power-june-2019
https://www.nxtbook.com/accessintelligence/POWER/power-may-2019
https://www.nxtbook.com/accessintelligence/POWER/power-april-2019
https://www.nxtbook.com/accessintelligence/POWER/power-march-2019
https://www.nxtbook.com/accessintelligence/POWER/power-february-2019
https://www.nxtbook.com/accessintelligence/POWER/power-january-2019
https://www.nxtbook.com/accessintelligence/POWER/power-december-2018
https://www.nxtbook.com/accessintelligence/POWER/power-november-2018
https://www.nxtbook.com/accessintelligence/POWER/power-october-2018
https://www.nxtbook.com/accessintelligence/POWER/power-september-2018
https://www.nxtbook.com/accessintelligence/POWER/power-august-2018
https://www.nxtbook.com/accessintelligence/POWER/power-july-2018
https://www.nxtbook.com/accessintelligence/POWER/power-june-2018
https://www.nxtbook.com/accessintelligence/POWER/power-may-2018
https://www.nxtbook.com/accessintelligence/POWER/power-april-2018
https://www.nxtbook.com/accessintelligence/POWER/power-march-2018
https://www.nxtbook.com/accessintelligence/POWER/power-february-2018
https://www.nxtbook.com/accessintelligence/POWER/power-january-2018
https://www.nxtbook.com/accessintelligence/POWER/power-december-2017
https://www.nxtbook.com/accessintelligence/POWER/power-november-2017
https://www.nxtbook.com/accessintelligence/POWER/power-october-2017
https://www.nxtbook.com/accessintelligence/POWER/power-september-2017
https://www.nxtbook.com/accessintelligence/POWER/power-august-2017
https://www.nxtbook.com/accessintelligence/POWER/power-july-2017
https://www.nxtbook.com/accessintelligence/POWER/power-june-2017
https://www.nxtbook.com/accessintelligence/POWER/power-may-2017
https://www.nxtbook.com/accessintelligence/POWER/power-april-2017
https://www.nxtbook.com/accessintelligence/POWER/power-march-2017
https://www.nxtbook.com/accessintelligence/POWER/power-february-2017
https://www.nxtbook.com/accessintelligence/POWER/power-january-2017
https://www.nxtbook.com/accessintelligence/POWER/power-december-2016
https://www.nxtbook.com/accessintelligence/POWER/power-november-2016
https://www.nxtbook.com/accessintelligence/POWER/power-october-2016
https://www.nxtbook.com/accessintelligence/POWER/power-september-2016
https://www.nxtbook.com/accessintelligence/POWER/power-august-2016
https://www.nxtbook.com/accessintelligence/POWER/power-july-2016
https://www.nxtbook.com/accessintelligence/POWER/power-june-2016
https://www.nxtbook.com/accessintelligence/POWER/power-may-2016
https://www.nxtbook.com/accessintelligence/POWER/power-april-2016
https://www.nxtbook.com/accessintelligence/POWER/power-march-2016
https://www.nxtbook.com/accessintelligence/POWER/power-february-2016
https://www.nxtbook.com/accessintelligence/POWER/power-january-2016
https://www.nxtbook.com/accessintelligence/POWER/power-december-2015
https://www.nxtbook.com/accessintelligence/POWER/power-november-2015
https://www.nxtbook.com/accessintelligence/POWER/power-october-2015
https://www.nxtbook.com/accessintelligence/POWER/power-september-2015
https://www.nxtbook.com/accessintelligence/POWER/power-august-2015
https://www.nxtbook.com/accessintelligence/POWER/power-july-2015
https://www.nxtbook.com/accessintelligence/POWER/power-june-2015
https://www.nxtbook.com/accessintelligence/POWER/power-may-2015
https://www.nxtbook.com/accessintelligence/POWER/power-april-2015
https://www.nxtbook.com/accessintelligence/POWER/power-march-2015
https://www.nxtbook.com/accessintelligence/POWER/power-february-2015
https://www.nxtbook.com/accessintelligence/POWER/power-january-2015
https://www.nxtbook.com/accessintelligence/POWER/power-december-2014
https://www.nxtbook.com/accessintelligence/POWER/power-november-2014
https://www.nxtbook.com/accessintelligence/POWER/power-october-2014
https://www.nxtbook.com/accessintelligence/POWER/power-september-2014
https://www.nxtbook.com/accessintelligence/POWER/power-august-2014
https://www.nxtbook.com/accessintelligence/POWER/power-july-2014
https://www.nxtbook.com/accessintelligence/POWER/power-june-2014
https://www.nxtbook.com/accessintelligence/POWER/power-may-2014
https://www.nxtbook.com/accessintelligence/POWER/power-april-2014
https://www.nxtbook.com/accessintelligence/POWER/power-march-2014
https://www.nxtbook.com/accessintelligence/POWER/power-february-2014
https://www.nxtbook.com/accessintelligence/POWER/power-january-2014
https://www.nxtbook.com/accessintelligence/POWER/power-december-2013
https://www.nxtbook.com/accessintelligence/POWER/power-november-2013
https://www.nxtbook.com/accessintelligence/POWER/power-october-2013
https://www.nxtbook.com/accessintelligence/POWER/power-september-2013
https://www.nxtbook.com/accessintelligence/POWER/power-august-2013
https://www.nxtbook.com/accessintelligence/POWER/power-july-2013
https://www.nxtbook.com/accessintelligence/POWER/power-june-2013
https://www.nxtbook.com/accessintelligence/POWER/power-may-2013
https://www.nxtbook.com/accessintelligence/POWER/power-april-2013
https://www.nxtbook.com/accessintelligence/POWER/power-march-2013
https://www.nxtbook.com/accessintelligence/POWER/power-february-2013
https://www.nxtbook.com/accessintelligence/POWER/power-january-2013
https://www.nxtbook.com/accessintelligence/POWER/power-december-2012
https://www.nxtbook.com/accessintelligence/POWER/power-november-2012
https://www.nxtbook.com/accessintelligence/POWER/power-october-2012
https://www.nxtbook.com/accessintelligence/POWER/power-september-2012
https://www.nxtbook.com/accessintelligence/POWER/power-august-2012
https://www.nxtbook.com/accessintelligence/POWER/power-july-2012
https://www.nxtbook.com/accessintelligence/POWER/power-june-2012
https://www.nxtbook.com/accessintelligence/POWER/power-may-2012
https://www.nxtbook.com/accessintelligence/POWER/power-april-2012
https://www.nxtbook.com/accessintelligence/POWER/power-march-2012
https://www.nxtbook.com/accessintelligence/POWER/power-february-2012
https://www.nxtbook.com/accessintelligence/POWER/power-january-2012
https://www.nxtbook.com/accessintelligence/POWER/power-november-2011
https://www.nxtbook.com/accessintelligence/POWER/power-october-2011
https://www.nxtbook.com/accessintelligence/POWER/power-september-2011
https://www.nxtbook.com/accessintelligence/POWER/power-august-2011
https://www.nxtbook.com/accessintelligence/POWER/power-july-2011
https://www.nxtbook.com/accessintelligence/POWER/power-june-2011
https://www.nxtbook.com/accessintelligence/POWER/power-may-2011
https://www.nxtbook.com/accessintelligence/POWER/power-april-2011
https://www.nxtbook.com/accessintelligence/POWER/power-march-2011
https://www.nxtbook.com/accessintelligence/POWER/power-february-2011
https://www.nxtbook.com/accessintelligence/POWER/power-january-2011
https://www.nxtbook.com/accessintelligence/POWER/power-december-2010
https://www.nxtbook.com/accessintelligence/POWER/power-november-2010
https://www.nxtbook.com/accessintelligence/POWER/power-october-2010
https://www.nxtbook.com/accessintelligence/POWER/power-september-2010
https://www.nxtbook.com/accessintelligence/POWER/power-august-2010
https://www.nxtbook.com/accessintelligence/POWER/power-july-2010
https://www.nxtbook.com/accessintelligence/POWER/power-june-2010
https://www.nxtbook.com/accessintelligence/POWER/power-may-2010
https://www.nxtbookmedia.com