Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

FERC, DOE to hold Security Investments for Energy Infrastructure Technical Conference

Tuesday, March 5, 2019

The Federal Energy Regulatory Commission and the United States Department of Energy have scheduled a joint technical conference to discuss current cyber and physical security practices used to protect energy infrastructure and possible federal and state incentives for related security investments.

According to a notice issued on February 4, the Security Investments for Energy Infrastructure Technical Conference will be led by one or more FERC Commissioners and DOE senior officials. Its agenda addresses two high-level topics: types of current and emerging cyber and physical security threats, and how federal and state authorities can facilitate investments to improve the cyber and physical security of energy infrastructure.

In a supplemental notice issued on March 1, the agencies noted that the Commission has adopted a "well-developed set of mandatory and enforceable reliability standards that set baseline protections for both cyber and physical security of the bulk electric system" as well as "policies that allow for the recovery of prudently incurred costs to comply with those mandatory reliability standards." The supplemental notice describes the technical conference as aimed at better understanding:
  1. the need for security investments that go beyond those measures already required by mandatory reliability standards, including in infrastructure not subject to those standards (e.g., natural gas pipelines);
  2. how the costs of such investments are or could be recovered; and
  3. whether additional incentives for making such investments are needed, and if so, how those incentives should be designed.
The supplemental notice describes two panels, the first of which will discuss types of cyber and physical security threats to energy infrastructure, particularly electric transmission, generation, and natural gas pipelines, as well as best practices for cyber and physical security mitigation beyond those measures already required by mandatory reliability standards and industry and government engagement needed to address these matters. The second panel will explore how federal and state authorities can provide incentives and cost recovery for security investments in energy infrastructure, particularly electric transmission, generation, and natural gas pipeline infrastructure

The federal agencies' Security Investments for Energy Infrastructure Technical Conference has been scheduled for on March 28, 2019.

FERC Order 848, cyber security and reliability

Thursday, July 19, 2018

U.S. energy regulators have issued an order directing the nation's electric reliability organization to strengthen its standards for the mandatory reporting of cyber security incidents.

Federal law authorizes the Federal Energy Regulatory Commission to regulate significant aspects of the bulk electric system's reliability. The Commission's jurisdiction over reliability covers the nation's electric reliability organization, North American Electric Reliability Corporation (NERC), which is charged with developing and submitting mandatory reliability standards for the Commission for approval.

Following increased concern over cybersecurity and hacking affecting utilities, in 2017 the Commission issued a Notice of Proposed Rulemaking proposing to direct that NERC develop enhanced Cyber Security Incident reporting requirements. At that time, then-current reliability standards generally required responsible entities to report Cyber Security Incidents only if they have “compromised or disrupted one or more reliability tasks. But the Commission expressed a concern that this reporting threshold "may understate the true scope of cyber-related threats facing the Bulk-Power System, particularly given the lack of any reportable incidents in 2015 and 2016." As a result, the Commission proposed requiring NERC to develop and submit modifications to its reliability standards, to require the reporting of cyber security incidents that compromise, or attempt to compromise, certain security infrastructure.

On July 19, 2018, the Federal Energy Regulatory Commission issued its Order No. 848. Through that order, the Commission adopted its own proposal to "improve awareness of existing and future cyber security threats and potential vulnerabilities." As described by the Commission, Order No. 848's directive consists of four elements:
  1. responsible entities must report Cyber Security Incidents that compromise, or attempt to compromise, a responsible entity’s Electronic Security Perimeter (ESP) or associated Electronic Access Control or Monitoring Systems (EACMS);
  2. required information in Cyber Security Incident reports should include certain minimum information to improve the quality of reporting and allow for ease of comparison by ensuring that each report includes specified fields of information;
  3. filing deadlines for Cyber Security Incident reports should be established once a compromise or disruption to reliable BES operation, or an attempted compromise or disruption, is identified by a responsible entity; and
  4. Cyber Security Incident reports should continue to be sent to the Electricity Information Sharing and Analysis Center (E-ISAC), rather than the Commission, but the reports should also be sent to the Department of Homeland Security (DHS) Industrial Control Systems Cyber Emergency Response Team (ICS-CERT). Further, NERC must file an annual, public, and anonymized summary of the reports with the Commission.
The Commission directed NERC to submit these modifications to its reliability standards within six months of Order No. 848's effective date.

Report on US electric grid physical security

Wednesday, March 28, 2018

Since a 2013 rifle attack on a critical electric power substation in California, the U.S. electric power sector has generally moved toward greater physical security for critical assets, according to a report published by the Congressional Research Service. But the report says bulk power security "remains a work in progress," and suggests further investment -- and policy reforms -- may follow.

The report published on March 19, 2018 -- NERC Standards for Bulk Power Physical Security: Is the Grid More Secure? -- begins with the premise that securing the electric power grid is among the nation's highest priorities for critical infrastructure protection. It notes that a 2013 rifle attack on an electric transmission substation in California which caused widespread power outages also broadened policy attention from cybersecurity to encompass the physical security of assets critical to the power grid.

In response, Congress enacted legislation to strengthen power grid physical security and to facilitate its recovery from disruption. Section 1104 of the Fixing America’s Surface Transportation (FAST) Act contains provisions to protect or restore the reliability of critical electric infrastructure or defense of critical electric infrastructure during a grid security emergency. The Federal Energy Regulatory Commission (FERC) and the nation's electric reliability organization NERC also took action to develop new reliability standards for the physical security of bulk power critical infrastructure.

But physical security risks may persist. The report references a September 2016 rifle attack on a Garkane Energy Cooperative transformer substation in Utah as illustrating this persistence. The report notes that while it is probably accurate to conclude that the grid is more physically secure than it was in 2013, "it has not necessarily reached the level of physical security needed based on the sector's own assessments of risk.

The report notes Congress's continued concern about the physical security of the electric grid. It identifies possible areas for further policy focus as including "security implementation oversight, cost recovery, hardening vs. resilience, and the quality of threat information."

Meanwhile, cybersecurity has remained a priority. An October 2017 FERC report describing the results of its audits of regulated companies' cybersecurity protection processes and procedures noted that most met the applicable mandatory standards. But earlier this month, NERC fined an anonymous utility $2.7 million for alleged violations of reliability standards in connection with a data security breach, and the U.S. Department of Homeland Security issued warnings about Russian hackers targeting computer systems controlling energy and other critical infrastructure.

Interest in shoring up the security of energy infrastructure and systems -- both from physical attacks as well as cyber threats -- appears poised to drive continued discussions, regulation, and investment.

US warns of Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure

Thursday, March 22, 2018

The U.S. Department of Homeland Security has warned that for at least two years, Russian government cyber actors have targeted government entities and multiple U.S. critical infrastructure sectors, including the energy, nuclear, commercial facilities, water, aviation, and critical manufacturing sectors.

In a joint Technical Alert issued March 15, 2018 by the Department of Homeland Security's U.S. Computer Emergency Readiness Team (US-CERT) and the Federal Bureau of Investigation, the agencies warned of a "multi-stage intrusion campaign by Russian government cyber actors." The report follows an October 2017 alert by computer security firm Symantec of a re-emergence of a sophisticated cyber espionage group known as "Dragonfly."

According to the government agencies' report, the Russian cyber threat actors seem to have deliberately targeted specific organizations, as opposed to pursuing targets of opportunity. In an initial "staging" phase, the campaign used tools like malware, watering holes, and spear phishing to gain access to small commercial facilities' networks -- typically peripheral organizations like trusted third-party suppliers whose networks may be less secure. For example, the threat actors sent emails with malicious attachments appearing to be personnel resumes or contract documents. Clicking on links in the attachments exposed the victims to malware or data harvesting. In a subsequent phase, the threat actors made further use of the staging targets' networks as "pivot points and malware repositories" for use in targeting their final intended victims.

The report says that these Russian government cyber actors used this hacked access for network reconnaissance and collection of information pertaining to Industrial Control Systems (ICS). It describes multiple instances of threat actors accessing workstations and servers on corporate networks that contained data output from control systems within energy generation facilities.

Cyber security is now a significant concern, both domestically and abroad. A February 2018 report by the U.S. intelligence community described the targeting of national security information and proprietary information from US companies and research institutions involved with defense, energy, finance, dual-use technology, and other areas as "a persistent threat to US interests." Last month, U.S. electric grid reliability regulators imposed a $2.7 million penalty on an unidentified utility for its violations of mandatory reliability standards in connection with a data security breach -- the largest fine to date associated with U.S. utility cybersecurity regulation. In that case, a third-party contractor hired by the utility allegedly copied protected data from the utility's network to the contractor's unsecured network -- where it was accessible online without the need to enter a user ID or password, and where it was in fact accessed by one or more unknown outside entities.

In 2014, reports emerged that Russian hackers had found flaws in solar panel monitoring software that, if left unfixed, could allow malicious actors to damage the electric grid. Foreign state-sponsored cyber attacks in 2016 and 2017 against Ukraine and Saudi Arabia targeted multiple sectors across critical infrastructure, government, and commercial networks, causing disruption to Ukrainian energy distribution networks.

NERC fines utility $2.7 million for cyber breach

Friday, March 9, 2018

The electric reliability organization responsible for the grid spanning much of North America has penalized an unidentified utility $2.7 million for its violations of mandatory reliability standards in connection with a data security breach. The penalty may be the largest fine to date associated with U.S. utility cybersecurity regulation.

NERC, or the North American Electric Reliability Corporation, is charged by U.S. law with ensuring the reliability of the nation's bulk power system. NERC establishes reliability standards for the bulk electric system, which are approved by the Federal Energy Regulatory Commission, and takes action to monitor and enforce compliance with its reliability standards.

On February 28, 2018, NERC filed with the Commission a Notice of Penalty regarding what it described as noncompliance by an "Unidentified Registered Entity (URE)", following a settlement between the anonymous utility and regional reliability group Western Electricity Coordinating Council (WECC).

Some of the details of the underlying fact pattern are protected from public disclosure as Critical Energy Infrastructure Information or CEII. But NERC's public filing says the settlement arose from WECC's determination and findings that the anonymous utility violated two of NERC's Critical Infrastructure Protection or CIP cybersecurity standards. According to NERC's report, the utility received a report that an outside "white hat security researcher" had found data publicly available online which appeared to be protected information associated with the utility.

Following this tipoff, an investigation by the utility and regional reliability group WECC revealed that a third-party contractor hired by the utility had copied data from the utility's network environment to the contractor's network environment, where it was no longer subject to the utility's visibility or control -- in violation of the contractor's authority. While the data was on the contractor's network, a subset of live utility data including over 30,000 records was accessible online without the need to enter a user ID or password for a period of 70 days. These records included some associated with the utility's Critical Cyber Assets, such as servers storing user data, systems controlling physical access within the utility's control centers and substations, and supervisory control and data acquisition or SCADA systems. System logs showed unauthorized access to this data set by both the white hat researcher and unidentified IP addresses.

According to the Settlement Agreement, the anonymous utility neither admitted nor denied the violations, but agreed to pay a $2,700,000 penalty and take other compliance actions. This may represent the largest fine to date for violations of NERC's CIP standards. While federal penalty policy encourages self-reporting of violations and having an internal compliance program in place -- as the anonymous utility did -- the settlement notes that the utility "was not fully transparent and forthcoming with all pertinent information detailing the data exposed in the incident." In particular, the settlement says the utility did not initially provide WECC with all the data fields exposed in the incident. These factors, combined with a finding that the violations posed a serious and substantial risk to the reliability of the bulk power system, led WECC to set the penalty amount at $2.7 million, which NERC subsequently approved.

By federal rule, the penalty will be effective upon expiration of the 30-day period following the penalty notice's filing with the Federal Energy Regulatory Commission or, if FERC decides to review the penalty, upon final determination by FERC.

US intelligence threat assessment on cyber, energy, infrastructure risks

Friday, February 16, 2018

The U.S. intelligence community has released an unclassified report presenting its assessment of the global context and how threats could affect U.S. actions. The latest Worldwide Threat Assessment finds increasing risk of cyber attacks and threats to U.S. infrastructure, as well as impacts from climate change.

The 28-page report released February 13, 2018, Statement for the Record: Worldwide Threat Assessment of the US Intelligence Community, describes a variety of global and regional threats.

While a disclaimer notes that the order of topics addressed does not necessarily imply the relative importance or magnitude of threats covered in the report, the first category of global threat addressed is cyber threats. According to the assessment, "The potential for surprise in the cyber realm will increase in the next year and beyond as billions more digital devices are connected — with relatively little built-in security — and both nation states and malign actors become more emboldened and better equipped in the use of increasingly widespread cyber toolkits. The risk is growing that some adversaries will conduct cyber attacks — such as data deletion or localized and temporary disruptions of critical infrastructure — against the United States in a crisis short of war. "

Illustrating this threat, the report notes that state-sponsored cyber attacks against Ukraine and Saudi Arabia in 2016 and 2017 targeted multiple sectors across critical infrastructure, government, and commercial networks, including disruption of Ukrainian energy-distribution networks. The report projects that in the next year, "Russian intelligence and security services will continue to probe US and allied critical infrastructures."

The report also notes the complex global foreign intelligence threat environment facing the U.S. in 2018. While it identifies penetrating the US national decisionmaking apparatus and intelligence community as primary objectives for numerous foreign intelligence entities, the report notes that "the targeting of national security information and proprietary information from US companies and research institutions involved with defense, energy, finance, dual-use technology, and other areas will remain a persistent threat to US interests."

The report cites U.S. Energy Information Administration forecasts that 2018 West Texas Intermediate and Brent prices will average $58 and $62 per barrel, respectively, compared to $98 and $109 in 2013. Noting that oil prices have remained low since 2013, the report observes that oil-exporting countries continue to suffer from low prices, and that "their economic woes are likely to continue, with broader negative implications. Subdued economic growth, combined with sharp increases in North American oil and gas production, probably will continue putting downward pressure on global energy prices, harming oil-exporting economies." The report describes impacts of low oil prices on countries including Venezuela, Saudi Arabia and other Persian Gulf oil exporters, Angola, Nigeria, Russia.

The report also notes the existence and impacts of climate change. It observes, "Challenges from urbanization and migration will persist, while the effects of air pollution, inadequate water, and climate change on human health and livelihood will become more noticeable. Domestic policy responses to such issues will become more difficult — especially for democracies — as publics become less trusting of authoritative information sources."

According to the assessment, "The impacts of the long-term trends toward a warming climate, more air pollution, biodiversity loss, and water scarcity are likely to fuel economic and social discontent — and possibly upheaval — through 2018." It notes that the "past 115 years have been the warmest period in the history of modern civilization , and the past few years have been the warmest years on record." It cites extreme weather events in a warmer world as having the potential for greater impacts in the future, as well as increased challenges to government prompted by environmental concerns or water scarcity. The report also notes that nearly half the world's international river basins are exposed to gaps in the agreements governing water supply and dam development, exacerbating this concern.