720-891-1663

Even Critical Infrastructure is on its Own for Defending Against Cyber Threats

CISA fired a third of its staff in an effort to save money. Key people there said screw you, I am leaving. Now CISA is trying to hire new people (it would require a very strange logic for competent people to apply right now). The president came up with this half baked strategy to assist critical infrastructure that he is testing in Texas – but it only lasts for six months.

Historically, the top priority for CISA on the civilian side was critical infrastructure, but with losing 1,500 or more people, that is probably only a dream right now.

According to the National Association of State Chief Information Officers (NASCIO), they (states and local governments) don’t have the funding, support or staff to do the job either.

There are two scenarios when it comes to critical infrastructure that should keep you up at night.

The first is if hackers just shut it off – like water, power or gas. Typically these outages only last a few hours to a day or two and are pretty localized.

The other is if hackers hack into the infrastructure and figure out how to damage it. Think of the US/Israel Stuxnet attack. That was pretty sophisticated but that was 15 years ago. Automation is much more widespread now and security, to be blunt, sucks, so I would suggest this is EASIER now, not HARDER.

Earlier this summer we saw – at least what the government admitted to – attacks from likely Iran sponsored hackers go after more than a hundred water utilities.

What if that was only a test to understand what the response would be.

Unfortunately, in an effort to save money, critical infrastructure has a huge amount of IT (technically called OT) that is publicly connected to the Internet. Alternatively, a lot of it is connected via a cell phone – technically a cellular modem. Even more of it lives in places like by the side of the road in a metal box. Security is limited to a padlock or similar access controls. We know this because the hackers have already gone after them.

More of them live in a “vault”. These vaults have nothing to do with security. It is a term to describe a concrete box buried just below the ground, with a manhole cover (personhole?) for easy access. It may have a key or it may not require one because, after all, who would want to attack critical infrastructure.

Much of the software that runs in these remote devices, often something called a programmable logic controller, resembles the level of compute power less than what you might find in a modern iPad. Many are decades old. Some are not even supported any more – if the manufacturer is still in business. You get the idea.

While I mentioned water, electric and gas, I did not mention Telecommunications, hospitals and transportation. For those, the attacks are low tech. Find an exposed fiber optic cable bundle, take your cordless Sawz-All and poof, you have a major outage. China and Russia have been doing this on a larger scale to undersea cables. The only good news about this attack is that you cannot cut a cable remotely. You can fry the software remotely though. When it comes to transformers, hackers need to figure out how to overload them. While this requires some knowledge, it does not require a PhD. The Department of Energy’s Idaho National Labs has a YouTube video of them demoing this (not the how, just the result). Due to this thing called AI data centers and the fact that we don’t make any large transformers in the US, it could take 1-3 years to get a replacement. CISA has come up with a Rube Goldberg Band-Aid for this, but it won’t scale. If you fry a handful of transformers, the Band-Aid will probably (key word probably) work. If the hackers fry a significant number across the country, that is a problem. And hospitals, well we know all about that from cyber attacks. A hospital without water has a problem. Or IT? Many can run on generators for a little while. When that fails they literally have to move patients to another hospital. What happens with at at scale? Where do you move patients to?

States are trying but they don’t have the money. New York announced a $9 million grant program. Spread across 150 drinking and waste water facilities. Spread evenly, that $60,000 per. Do you think that is enough to solve the problem.

My prediction is that it is going to get worse before it gets better and governments are going to need to figure out if they care whether the “lights go out”. Their constituents sure do.

If you are a small to medium critical infrastructure provider and you are ready to improve the odds, it is highly unlikely the government, at any level, is going to save you. Please contact us if that makes sense to you.

Credit: Cybersecurity Dive

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *