Infrastructure Security in the Age of Ransomware

Stuxnet gave the world a grasp on how real and devastating cyber-security risks in critical infrastructures can be. In the era of industrial IoT and increasingly complex cyber-threats, attacks on public infrastructures, particularly in the energy sector, are becoming frequent.

Critical infrastructure such as electric and water utilities are being temporarily shut down as ransomware plagues corporate systems, causing hours of downtime. The health industry has also fallen victim to these cyber-extortion techniques.

What are the risks?

The risks go beyond operability, financial losses and credibility. Cyberattacks on industrial systems can cross the line into threatening human lives.

“Whether it’s a dam in Rye Brook, or our power grids, our financial institutions, our water systems, or our online networks, these parts of our infrastructure are at risk and are under assault like never before, and we need to do more about it,” US Senator Charles E. Schumer said after Iranian hackers breached the Bowman Avenue Dam near Rye Brook, New York and gained control of the floodgates.

Recently, a German nuclear power plant in Bavaria has admitted that its systems are riddled with malware. In 2015 a hacker managed to enter the systems of a nuclear power plant in South Korea.

However, securing vital systems from multiple attack vectors is a serious challenge that requires joint efforts from international organizations, the private sector, the civil society and, especially, governments. It also presents a set of unique difficulties.

Sophistication of attacks

Cyber-threats are expanding in every way - from attack frequency to scale, sophistication and impact severity. The rate of code vulnerabilities found in dated, internet-accessible software also shows no signs of abating.

"A wide variety of threats ranging from Advanced Persistent Threats (APT), to sophisticated and common malware [are] found in the ICS environment,” the ICS-CERT reports. “Other incidents in the water and commercial sectors involved Internet-facing systems with weak or default credentials."

For instance, Black Energy was a malware toolkit developed to infect Ukrainian power authorities. It overwrites system data to control manual functions such as modifying temperature controls and turning pumps on and off at wind turbines, power transmission grids, oil and gas pipelines. Its goal was to sabotage critical parts of an industrial control computer’s hard drive.

Crypto-ransomware that leverages clever engineering techniques is also on the rise. Almost 10% of ransomware-infected emails sent globally target German users, according to cybersecurity provider Bitdefender.

Compliance

As more IT systems running critical infrastructure organizations connect to the public Internet – such as Industrial Control Systems and SCADA applications – new laws and national cybersecurity strategies are becoming mandatory.

Infrastructure operators must apply state-of-the-art measures to prevent unauthorized access to their technical systems and secure them against data breaches and other incidents, including outside attacks. Otherwise, they can face fines of hundreds of thousands of dollars. But not all organizations are ready to comply -- their current spending may not meet the demands of the new regulations.

Over-Confidence

Despite the increasing number and severity of attacks targeting critical infrastructure, technology and security professionals remain confident in their cyber defenses, studies have shown.

Cyber forensics

Global security executives’ trust in their organization’s cyber preparedness is sometimes unfounded. As proof, most attacks in recent headline-grabbing security incidents were under way weeks or months before initial detection. More than once, the vectors for attack could not be determined because the systems lacked detection and monitoring capabilities. In other cases, engineers did not even know if the problem was caused by a cyber-attack.

Sharing information

Sharing network and defense information with other organizations in the same industry or a national or international agency is often the missing piece of the puzzle. Critical infrastructure operators often loathe disclosing information for fear of damaging their reputation or risk of punishment by the government. But operating in a silo does not help cybersecurity.

In a nutshell, businesses operating public or private infrastructures that want to enhance cyber-security can start by:

▪        Deploying anti-malware software where possible

▪        Preventing unauthorized access to secure locations

▪        Applying application whitelisting to prevent unauthorized applications from running

▪        Deploying a breach detection system

▪        Enabling a USB lockdown on all SCADA environments to stop malware from physically entering the environment

▪        Deploying basic security measures in between network segments, such as firewalls/IPS.

MacWorld

« Air Gapping Critical Process Control Networks
The Nation State Hack-Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

SISA

SISA

SISA is a global forensics-driven cybersecurity solutions company, trusted by leading organizations for securing their businesses with robust preventive and corrective cybersecurity solutions.

Global Station for Big Data & Cybersecurity (GSB)

Global Station for Big Data & Cybersecurity (GSB)

GSB is an interdisciplinary research hub to cover big data, information networks, and cybersecurity.

Avatier

Avatier

Avatier identity management software products automate identity access management, user provisioning and IT governance to ensure information security and compliance.

Futurex

Futurex

Futurex is a globally recognized provider of enterprise-class data encryption solutions.

ShadowDragon

ShadowDragon

ShadowDragon develops digital tools that simplify the complexities of modern investigations that involve multiple online environments and technologies.

SoftLock

SoftLock

Softlock is a regional leader in Information Security providing solutions, consulting, integration and testing services to protect information assets, identities and supporting infrastructure.

Tech-Recycle

Tech-Recycle

Tech-Recycle was formed to help companies and individuals securely, ethically and easily recycle their IT and office equipment. We destroy all data passed to us safely and securely.

GateKeeper Enterprise

GateKeeper Enterprise

The GateKeeper Enterprise software is an identity access management solution. Automated proximity-based authentication into computers and websites. Passwordless login and auto-lock PCs.

Riskaware

Riskaware

CyberAware, by Riskaware, provides business-critical cyber attack analysis and impact assessments using NIST standards aligned with NCSC guidance.

Talion

Talion

Talion aim to reduce the complexity involved in securing your organisation and to give security teams unrivalled visibility into their security operations, so they can make optimal decisions, fast.

Alpha Omega Integration

Alpha Omega Integration

Alpha Omega creates new possibilities through intelligent end-to-end mission-focused government IT solutions.

StrongBox IT

StrongBox IT

Strongbox IT provides solutions to secure web applications and infrastructure.

Nokod Security

Nokod Security

Nokod Security delivers an application security platform for low-code / no-code custom applications and Robotic Process Automation (RPA).

Miggo Security

Miggo Security

Miggo is the first Application Detection and Response (ADR) platform on a mission to stop application breaches.

PayPal Ventures

PayPal Ventures

PayPal Ventures invests in companies at the forefront of innovation in fintech, payments, commerce enablement, artificial intelligence, blockchain and cryptocurrency, regulatory and cyber technology.

Haiku

Haiku

Haiku stands at the forefront of cybersecurity upskilling, leveraging video games to immerse you in a flow state for accelerated, enduring learning.