August 24th, 2021, I will be on an Engineering Infrastructure Resilience Panel discussing Cyber-Physical Security of Critical Infrastructures – Catastrophic Risks and Mitigation Strategies. Panelists will include Walter Grayman, Ali Mosleh from UCLA, Shaikha Al-Sanad from the Kuwait Institute for Scientific Research, Andrew Ohrt from West Yost, John Organek from the EIS Council, and myself. […]
Category: General Topic
Don’t Wait For Government To Enforce Security
Everyone remembers the ugly days following the large ransomware attack on the Colonial Pipeline’s IT infrastructure. Most security experts who know anything about the oil and gas pipeline industry were not surprised. While there were/are recommended security practices from the Transportation Security Agency (TSA), there is no formal regulation of any sort for oil and […]
US critical infrastructure cyber security is backwards – it’s the process that counts not the data
With the never-ending, and too often successful, attacks on critical infrastructure networks, there needs to be a better way to protect control systems and the processes they monitor and control. The fallacy about critical infrastructure cybersecurity is that the Internet Protocol (IP) networks are needed to keep lights on, water flowing, etc. July 28, 2021, […]
Sometimes giving a speech is better than issuing a memorandum
“I believe that this nation should commit itself to achieving the goal, before this decade is out, of landing a man on the moon and returning him safely to the earth. No single space project in this period will be more impressive to mankind, or more important for the long-range exploration of space; and none […]
Results from ThreatConnect webinar on mitigating risks in critical infrastructures and on-going actual risks
July 21, 2021, I participated in a live webinar discussion, hosted by ThreatConnect’s Dan Verton, on mitigating risk in critical infrastructures with Bob Kolasky from DHS CISA and Tim Grieveson from Aveva. The webinar link can be found at ThreatConnect Podcast Ep. 21: Mitigating Cyber Risk in Critical Infrastructures I met Dan in 2001 when […]
ThreatConnect July 21, 2021 webinar on mitigating risks in critical infrastructures
July 21, 2021 from 1-2pm EDT, I will be participating in a live webinar discussion on mitigating risk in critical infrastructures with Bob Kolasky from DHS CISA and Tim Grieveson from Aveva. The link can be found at https://threatconnect.com/mitigating-cyber-risk-in-critical-infrastructure/.
Sensor monitoring technology can make critical infrastructures less attractive targets for ransomware
Ransomware and other IT-originated cyberattacks can affect control systems when IT networks are connected to OT networks or insecure IOT devices are connected to OT networks. Off-line sensor monitoring technology doesn’t stop a ransomware attack, rather the technology is oblivious to the ransomware or IT attack. The off-line process sensor monitoring can provide real time […]
Applying Cryptography to Control Systems
Dale Peterson says let’s not continue to wave our hands about the use of Cryptography in the lower layers of control systems. I agree. He’s proposing that we build on Cryptography use cases as they are known now. That’s a start, but this is where most people reach the end of their knowledge and then […]
It may not be possible to recognize a “Cyber Pearl Harbor” as a cyber event
Ransomware attacks will continue to occur as they are so profitable. Unlike control system cyberattacks, network cyberattacks are short-lived as they do not damage critical hardware which is why network cyberattacks are not a “Cyber Pearl Harbor”. Yet that is the government and industry’s focus. For control systems, it is the opposite. When a control […]