Convergence & Digitalisation Create Problems For Energy Utilities

The convergence of previously separate sectors around renewable smart grids is creating an expansive energy value chain with widely divergent cyber security practices and vulnerabilities, eroding organisational control over energy security.

A failure to consolidate cyber security practices and policies across this new diverse value chain could result in cyber attacks causing operators severe financial and reputational damage. Fear of cyber attacks has already been found to affect consumer take-up of smart meters and poor security could hamper the success and adoption of smart grids. 

The scale of the threat is demonstrated by a recent rise in ransomware attacks targeting energy networks; from pipelines to power grids. 

Weak Links In The Energy Value Chain

Smart grids are driving the convergence of the energy and technology sectors to create efficient, flexible grids that balance supply and demand based on live data. This renders energy grids dependent on the security practices of a wide variety of third-party technology companies; from cloud providers to smart infrastructure suppliers.

The result is that responsibility for grid security is increasingly dispersed among a wider array of organisations than ever before.

Any infrastructure is only as secure as the weakest link in its supply chain, and this ever-expanding green energy ecosystem creates a bigger patchwork of cyber security vulnerabilities. Many of these suppliers now need continued access to their customer energy networks to perform remote maintenance and monitoring of energy assets, creating more potential vulnerabilities. And new energy infrastructure often interfaces with legacy infrastructure which was never designed for connectivity.

If the old, centralised energy grids resembled large walled castles with just a few gateways, the current energy system more closely resembles a multitude of mini castles with many intricate interconnections between them.

Edge Devices Create A Porous Perimeter

Edge devices such as smart appliances to sensors on grid infrastructure. These are made by an array of technology suppliers with varying standards of security, creating a diverse and distributed array of potential attack vectors.

This is further compounded by the fact that some manufacturers are sacrificing security for speed to market and rushing out new smart appliances with limited security features. As our energy security can no longer be centrally controlled, we now require new security frameworks to inform and incentivise best practice across an increasingly decentralised, disparate value chain. 

The Need For A Holistic Security Framework

Without direct control over energy security, grid operators must use cyber security frameworks to assess business risk across all cyber, digital and data projects and enforce best practice among all partners and suppliers. These frameworks should be based on best-practice standards such as IEC 62443.

Cyber security should be baked into procurement and partnership programmes from the outset so that all potential suppliers and partners are carefully vetted for compliance with security standards. Imposing cyber frameworks on Tier 1 suppliers would create a cascade of best practice cyber security as each tier of suppliers enforces the same standards on lower tiers. 

New digital or data projects should not be introduced in silos without considering their potential impact on risk across the organisation. All digital, data and cyber projects should instead be interconnected from the start so that security is baked in at design stage and risks can be continuously assessed as new technologies are added. For example, reports found that some electricity generation is vulnerable to ransomware attacks because of clean energy infrastructure that was designed without security in mind. Cyber risk assessments cannot be a one-off exercise at implementation stage but must be monitored and managed across the lifecycle of all energy assets. 

Rather than focusing narrowly on cyber risks, organisations should also get an integrated overview of business risk across all digital and data projects so that diverse digital ecosystems can be monitored and managed as a single ‘system of systems’. 

Organisations also need to manage all third-party remote monitoring and maintenance of energy infrastructure with strict user permissions to validate and verify user identities before granting access to energy networks. Any service providers with responsibility for energy data or remote access to infrastructure must be strictly vetted against a checklist of criteria.

The widening array of edge devices from mobile apps to smart meters opening new vulnerabilities to energy systems requires that all suppliers are thoroughly vetted to ensure they conduct continuous monitoring and patching of devices throughout their lifecycle.  

Steven O’Sullivan is Head of Smart Cybersecurity at Enzen 

You Might Also Read:

Process Sensor Cyber Security Is A Vital Issue:

 

« How To Improve Cyber Security Visibility & Control
Georgia Must Bolster Resilience To Information Warfare »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Backup Systems

Backup Systems

Backup Systems is a leading backup and disaster recovery systems provider across the UK.

Reblaze Technologies

Reblaze Technologies

Reblaze provides the world’s best security technologies in a cloud-based website security platform.

Korea Internet & Security Agency (KISA)

Korea Internet & Security Agency (KISA)

KISA is committed to improving the competitiveness, reliability and security of Internet information and knowledge in Korea.

Cybernetic Global Intelligence (CGI)

Cybernetic Global Intelligence (CGI)

CGI is a global IT Security firm that helps companies protect their data and minimize their vulnerability to cyber threats through a range of services such as Security Audits and Managed Services.

Vdoo

Vdoo

Vdoo provides an end-to-end product security platform for automating all software security tasks throughout the entire product lifecycle.

Genians

Genians

Genians provides the industry’s leading Network Access Control (NAC) solution, which ensures full visibility of all IP-enabled devices regardless of whether they are wired, wireless, or virtual.

EvoNexus

EvoNexus

EvoNexus is a technology startup incubator with locations in San Diego, Orange County, and Silicon Valley.

Data Theorem

Data Theorem

Data Theorem is a leading provider in modern application security. Its core mission is to analyze and secure any modern application anytime, anywhere.

Y-PARC

Y-PARC

Y-PARC is a center of excellence for cybersecurity, precision industries and medtech, fostering innovation and development and support for startups.

cleverDome

cleverDome

cleverDome has created the first community built and proven model that redefines the standards for protecting the most confidential data and information of consumers in the cloud.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

AdvIntel

AdvIntel

AdvIntel is a next-generation threat prevention and loss prevention company launched by a team of certified investigators, reverse engineers, and security experts.

Deutsche Gesellschaft für Cybersicherheit (DGC)

Deutsche Gesellschaft für Cybersicherheit (DGC)

As a leading provider of cyber security, DGC supports companies in taking advantage of the opportunities offered by the digital transformation – and in minimizing the associated risks.

Readynez

Readynez

Readynez is the digital skills concierge service that helps you ensure your workforce has the tech skills and resources needed to stay ahead of the digital curve.

Klarytee

Klarytee

Protect your data wherever it goes. Klarytee is a SaaS platform that builds security into sensitive content to enable granular control in AI, public cloud and SaaS.

Deimos

Deimos

Deimos is a technology, cloud, hybrid and multi-cloud focused, professional services company. Our expertise and focus is on cloud native Developer and Security Operations.