NFPA Journal - Spring 2021 - 31
monitoring, said Jessica Chevreaux,
the cybersecurity program manager at
M.C. Dean and a co-author of the FPRF
report. The reverse is also true: few IT
people know much about building systems, she said. Training on both sides
about how to work together to holistically protect a company's digital assets
is essential but is not yet widespread.
" The HVAC and fire systems engineers don't necessarily speak the
same language as the IT people, and
they definitely don't understand each
other's systems and vulnerabilities, "
Chevreaux said. " This is such a new
concept that there isn't necessarily
even a structure in place within companies to handle it. There isn't really
anyone bridging that gap. "
Security fundamentals
With cybersecurity in building systems
still in its infancy, experts hope that
projects like the FPRF's can provide the
framework necessary to put building
security on a solid track.
" Success is going to come down to
getting the fundamentals right from
the beginning, " Robinson said. That
includes providing clear, actionable
guidelines on what's known as " cyber
hygiene, " such as network segmentation, minimum system and security
requirements for wireless or passwords,
authentication mechanisms, and training workforces to better understand the
threat and their responsibilities.
" This educational piece has to
be part of everyone's thinking and
everyone's planning, " said Alkemper, of
FM Global. " We have to start thinking
of this as a threat like any other threat.
Your building can burn down, yes.
Things can get hacked, so be ready. If
you plan for it and anticipate it, this
can be managed. "
Experts also see a need for additional
guidance from codes and standards,
including possibly from NFPA. Currently, there are at least 16 NFPA
standards with cybersecurity references, including NFPA 72®, National
Fire Alarm Signaling Code®, which
includes guidance and requirements to
address cybersecurity for equipment,
software, firmware, tools, and installation methods, as well as the physical
security and access to equipment, data
KNOWLEDGE RACE
GETT Y IMAGES
In the realm of building and systems hacking,
the good guys have to work doubly hard to
stay a step ahead of the bad guys
Examples of hackers infiltrating building systems become more
numerous by the day, and include everything from pranksters
hacking baby cameras to spy on families to nation states seizing
control of and sabotaging a nuclear enrichment plant. Hackers
have targeted smart thermostats to infiltrate a casino database,
hacked parking garage printers to access a residential high-rise,
and even hacked the operational systems of the Australian corporate headquarters for Google.
Perhaps the best-known breach involving a building system
occurred in 2013 when cybercriminals used credentials for the
HVAC system to break into the customer service database of the
retail giant Target. Some 40 million credit card numbers were
stolen, resulting in
Target paying an $18.5
Losses from building systems
million multistate setattacks could be even worse if not
tlement in 2017-the
for the fact that many hackers don't largest ever for a data
yet have the knowledge or foresight breach. More recently,
hackers have targeted
to breach those systems.
medical devices, such
as blood pressure monitors and telemetry monitors, to gain access to hospital networks.
The vulnerabilities have led, in part, to an epidemic of ransomware
attacks on US health care facilities-nearly 800 such attacks were
launched against US hospitals in 2019, according to Emsisoft.
And those are only the ones we know about. " For every successful ransomware attack you read about in the news, there are five
others that you never hear about because companies don't want
it getting out that their facilities were compromised due to a vulnerability or a lapse of judgment, " said Phil Owen, the director of
information assurance and cybersecurity at M.C. Dean.
The security experts I spoke with believe that loss numbers from
building systems attacks could be even worse if not for the fact
that many hackers don't yet have the knowledge or foresight to
breach those systems-the concept of smart sprinklers and alarms
Cybercriminals used HVAC system credentials
to access a customer service database at retail
giant Target in 2013.
is just as new for the hackers as it is for some facility managers.
Last November, M.C. Dean outfitted a two-story office building
with the range of connected infrastructure found in modern buildings-fire systems, elevator controls, IP cameras, Wi-Fi devices,
HVAC, and more-and invited more than 60 teams of hackers from
around the world to try to infiltrate it. One of the most interesting
outcomes, Owen said, was how little attention the attackers paid
to the building's fire safety systems; none of the teams seemed to
view these vulnerable systems as a worthwhile target.
" If they had, they could have owned those systems pretty easily, "
said Ken Donaldson, the information systems security manager at
M.C. Dean.
Owen said that the hacker teams skewed young and most likely
didn't yet have a sufficient understanding of how these fire systems work to mount an attack. " Attacking automation systems is
not a neophyte game; it's the older, more experienced professional
who is going to understand how to do that, " he said.
But it's not going to stay that way for long. With each successful
breach of a large corporation like Target, or with every lucrative
ransomware attack on a hospital, it's a certainty that hackers will
study these methods and devise even more innovative methods
for capitalizing on previously overlooked vulnerabilities.
" I think we're all assuming that the bad side is still on a learning
curve, " said Jens Alkemper, the director of cyberresearch at the
insurance firm FM Global. " But as that's happening, the defense
side has to be working to shorten its learning curve as well. We
have to be ready for this, because it's coming. " -J.R.
N F PA . O R G / J O U R N A L * NFPA JOURNAL
Cybersecurity feature_1Q 2021 SJS APPROVED FINAL.indd 31
| 31
1/29/21 2:20 PM
http://nfpa.org/JOURNAL
NFPA Journal - Spring 2021
Table of Contents for the Digital Edition of NFPA Journal - Spring 2021
Contents
NFPA Journal - Spring 2021 - Cover1
NFPA Journal - Spring 2021 - Cover2
NFPA Journal - Spring 2021 - 1
NFPA Journal - Spring 2021 - 2
NFPA Journal - Spring 2021 - 3
NFPA Journal - Spring 2021 - Contents
NFPA Journal - Spring 2021 - 5
NFPA Journal - Spring 2021 - 6
NFPA Journal - Spring 2021 - 7
NFPA Journal - Spring 2021 - 8
NFPA Journal - Spring 2021 - 9
NFPA Journal - Spring 2021 - 10
NFPA Journal - Spring 2021 - 11
NFPA Journal - Spring 2021 - 12
NFPA Journal - Spring 2021 - 13
NFPA Journal - Spring 2021 - 14
NFPA Journal - Spring 2021 - 15
NFPA Journal - Spring 2021 - 16
NFPA Journal - Spring 2021 - 17
NFPA Journal - Spring 2021 - 18
NFPA Journal - Spring 2021 - 19
NFPA Journal - Spring 2021 - 20
NFPA Journal - Spring 2021 - 21
NFPA Journal - Spring 2021 - 22
NFPA Journal - Spring 2021 - 23
NFPA Journal - Spring 2021 - 24
NFPA Journal - Spring 2021 - 25
NFPA Journal - Spring 2021 - 26
NFPA Journal - Spring 2021 - 27
NFPA Journal - Spring 2021 - 28
NFPA Journal - Spring 2021 - 29
NFPA Journal - Spring 2021 - 30
NFPA Journal - Spring 2021 - 31
NFPA Journal - Spring 2021 - 32
NFPA Journal - Spring 2021 - 33
NFPA Journal - Spring 2021 - 34
NFPA Journal - Spring 2021 - 35
NFPA Journal - Spring 2021 - 36
NFPA Journal - Spring 2021 - 37
NFPA Journal - Spring 2021 - 38
NFPA Journal - Spring 2021 - 39
NFPA Journal - Spring 2021 - 40
NFPA Journal - Spring 2021 - 41
NFPA Journal - Spring 2021 - 42
NFPA Journal - Spring 2021 - 43
NFPA Journal - Spring 2021 - 44
NFPA Journal - Spring 2021 - 45
NFPA Journal - Spring 2021 - 46
NFPA Journal - Spring 2021 - 47
NFPA Journal - Spring 2021 - 48
NFPA Journal - Spring 2021 - 49
NFPA Journal - Spring 2021 - 50
NFPA Journal - Spring 2021 - 51
NFPA Journal - Spring 2021 - 52
NFPA Journal - Spring 2021 - 53
NFPA Journal - Spring 2021 - 54
NFPA Journal - Spring 2021 - 55
NFPA Journal - Spring 2021 - 56
NFPA Journal - Spring 2021 - 57
NFPA Journal - Spring 2021 - 58
NFPA Journal - Spring 2021 - 59
NFPA Journal - Spring 2021 - 60
NFPA Journal - Spring 2021 - 61
NFPA Journal - Spring 2021 - 62
NFPA Journal - Spring 2021 - 63
NFPA Journal - Spring 2021 - 64
NFPA Journal - Spring 2021 - 65
NFPA Journal - Spring 2021 - 66
NFPA Journal - Spring 2021 - 67
NFPA Journal - Spring 2021 - 68
NFPA Journal - Spring 2021 - 69
NFPA Journal - Spring 2021 - 70
NFPA Journal - Spring 2021 - 71
NFPA Journal - Spring 2021 - 72
NFPA Journal - Spring 2021 - 73
NFPA Journal - Spring 2021 - 74
NFPA Journal - Spring 2021 - 75
NFPA Journal - Spring 2021 - 76
NFPA Journal - Spring 2021 - 77
NFPA Journal - Spring 2021 - 78
NFPA Journal - Spring 2021 - 79
NFPA Journal - Spring 2021 - 80
NFPA Journal - Spring 2021 - Cover3
NFPA Journal - Spring 2021 - Cover4
https://www.nxtbook.com/nxtbooks/nfpa/journal_2024winter
https://www.nxtbook.com/nxtbooks/nfpa/journal_2024fall
https://www.nxtbook.com/nxtbooks/nfpa/journal_2024summer
https://www.nxtbook.com/nxtbooks/nfpa/journal_2024spring
https://www.nxtbook.com/nxtbooks/nfpa/journal_2023winter
https://www.nxtbook.com/nxtbooks/nfpa/journal_2023fall
https://www.nxtbook.com/nxtbooks/nfpa/journal_2023summer
https://www.nxtbook.com/nxtbooks/nfpa/journal_2023spring
https://www.nxtbook.com/nxtbooks/nfpa/journal_2022winter
https://www.nxtbook.com/nxtbooks/nfpa/journal_2022fall
https://www.nxtbook.com/nxtbooks/nfpa/journal_2022summer
https://www.nxtbook.com/nxtbooks/nfpa/journal_2022spring
https://www.nxtbook.com/nxtbooks/nfpa/journal_2021winter
https://www.nxtbook.com/nxtbooks/nfpa/journal_2021fall
https://www.nxtbook.com/nxtbooks/nfpa/journal_2021summer
https://www.nxtbook.com/nxtbooks/nfpa/journal_2021spring
https://www.nxtbook.com/nxtbooks/nfpa/journal_20201112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20200910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20200708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20200506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20200304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20200102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20191112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20190910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20190708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20190506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20190304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20190102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20181112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20180910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20180708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20180506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20180304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20180102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20171112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20170910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20170708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20170506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20170304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20170102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20161112
https://www.nxtbook.com/nxtbooks/nfpa/journal_201610_sprinkler
https://www.nxtbook.com/nxtbooks/nfpa/journal_20160910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20160708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20160506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20160304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20160102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20151112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20150910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20150708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20150506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20150304
https://www.nxtbook.com/nxtbooks/nfpa/journal_201501
https://www.nxtbook.com/nxtbooks/nfpa/journal_20141112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20140910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20140708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20140506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20140304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20140102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20131112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20130910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20130708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20130506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20130304
https://www.nxtbook.com/nxtbooks/nfpa/journal_20130102
https://www.nxtbook.com/nxtbooks/nfpa/journal_20121112
https://www.nxtbook.com/nxtbooks/nfpa/journal_20120910
https://www.nxtbook.com/nxtbooks/nfpa/journal_20120708
https://www.nxtbook.com/nxtbooks/nfpa/journal_20120506
https://www.nxtbook.com/nxtbooks/nfpa/journal_20120304
https://www.nxtbookmedia.com