Port disruption and a discussion of maritime and OT.
Nov 15, 2023
auto_awesome
Guest Austin Reid of ABS Group discusses cyber risk and threats to Maritime Transportation Systems. Topics include a cyber incident disrupting Australian ports, the Sandworm attacks on Ukraine's power grid in 2022, the Department of Energy's simulated cyberattack competition, and cyber and electronic threats to space systems. The podcast also explores the launch of Shield's Ready campaign to enhance critical infrastructure security and resilience, and the cybersecurity challenges in the maritime industry.
Establishing proper cyber defenses and resilience in critical infrastructure systems is crucial, as demonstrated by the Sandworm cyber attacks on Ukraine's power grid in 2022.
The maritime industry faces challenges in securing complex international maritime transportation systems (MTS) due to different safety standards, regulatory compliance issues, and the need for information sharing among various stakeholders.
Deep dives
Sandworm attacks against Ukraine's power grid
The podcast discusses the Sandworm cyber attacks carried out against Ukraine's power grid in 2022. Sandworm, operated by the GRU's Unit 74455, gained access to the OT environment and exploited end-of-life HITACHI Energy Micro SCADA control systems, enabling the attackers to trip breakers in electrical power distribution substations. The attack highlighted the coordination of cyber and kinetic operations, as it coincided with a Russian missile campaign. This attack, along with others, demonstrated the importance of establishing cyber defenses and resilience in critical infrastructure systems.
Cybersecurity and maritime transportation systems
The podcast features a conversation with Austin Reed, a senior consultant at ABS Group, regarding cyber risks and threats to maritime transportation systems (MTS). Reed emphasizes the challenges faced in securing complex international MTS networks involving various stakeholders. He highlights the need for proper information sharing, tackling regulatory compliance issues, and navigating different safety standards across nations. The podcast also mentions recent ransomware events affecting port facilities and vessels, underscoring the importance of cybersecurity measures and incident response planning in the maritime industry.
The five critical controls for industrial control systems (ICS)
The podcast highlights the five essential controls for securing industrial control systems (ICS) based on insights from real-world incident response cases and assessments. The first control focuses on ICS-specific incident response planning, highlighting its significance in effectively addressing operational, regulatory, and security requirements during incidents. The second control emphasizes the need for a defensible architecture tailored to specific scenarios, prioritizing segmentation and preventing compromise of critical systems. The third control involves ICS network monitoring, enabling detection of system-to-system interactions and potential threats. The fourth control stresses the importance of secure mode access, specifically multi-factor authentication and defense-in-depth approaches. Lastly, the fifth control highlights the value of a comprehensive vulnerability management program, focusing on addressing pertinent vulnerabilities that add risk to the ICS environment.
Shield's Ready campaign and cyber-physical coordination
The podcast introduces Shield's Ready, a campaign launched by the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Emergency Management Agency (FEMA) to enhance the security and resilience of critical infrastructure in the United States. The campaign emphasizes proactive measures to prepare and build resilience in critical infrastructure systems, including identifying critical assets, assessing risks, planning and exercising, and adapting and improving. The podcast also discusses the coordination of cyber attacks with kinetic operations in hybrid warfare scenarios, highlighting the need for integrated cyber defenses and physical capabilities to mitigate threats to both virtual and physical aspects of armed conflicts.
A cyber incident disrupts Australian ports. Sandworm and Ukraine's power grid: 2022 attacks. Department of Energy hosts simulated cyberattack competition. CISA, FEMA, and Shields Ready. Cyber and electronic threats to space systems. Four cyber phases of a hybrid war. Guest Austin Reid of ABS Group discusses cyber risk and threats to Maritime Transportation Systems (MTS). On the Learning Lab, catch an encore of Dragos CEO Robert M. Lee and Mark Urban about the five critical controls for ICS.