The impact of cybersecurity in the energy industry

Cyber resilience is a challenge for organizations globally and for the electricity industry in particular. Power systems are among the most complex and critical of all infrastructure types and act as the backbone of economic activity.

Large-scale incidents such as blackouts can have socio-economic ramifications for households, businesses and vital institutions. For example, a six-hour winter blackout in mainland France could result in damages totalling over €1.5 billion ($1.7 billion).

In 2018, the World Economic Forum Centre for Cybersecurity and the Platform for Shaping the Future of Energy, Materials and Infrastructure launched the Cyber Resilience in the Electricity Industry initiative to improve the cyber resilience of global electricity infrastructure. This initiative brought together leaders from more than 50 businesses, governments, civil society and academia to collaborate and develop a clear and coherent cybersecurity vision for protecting the power infrastructure.

Building on the first phase of the initiative, the Forum is now developing a unique exchange platform for cybersecurity leaders across the electricity industry in collaboration with Dragos, EDP, Enel, Hitachi Energy, Iberdrola, Naturgy, Ørsted, Schneider Electric, Siemens Energy, Southern and Vestas. This new platform serves as a central hub where industry experts can exchange knowledge, ideas and best practices to improve cyber resilience as a whole.

By bringing together the leading minds in cybersecurity worldwide, the initiative is fostering collaboration and innovation in this critical field, with the ultimate goal of enhancing the security and reliability of the electricity infrastructure that powers the modern world.

What are the challenges of cybersecurity in the energy industry?

The unprecedented pace of technological change driven by the Fourth Industrial Revolution means that health, transport, communication, production and distribution systems will demand rapidly increasing energy resources to support global digitalization and the advancement of interconnected devices.

Digitalization is driving growth and innovation in the electricity industry and has tremendous potential to deliver shareholder, customer and environmental value. However, new technologies and business models affecting operating assets present both opportunities and risks.

In the past, managing these risks had only meant dealing with issues such as component failure or weather damages, while today’s resilience plans must consider cybersecurity-related threats.

Our approach to strengthening cybersecurity in the energy industry

The Cyber Resilience in the Electricity Industry programme focuses on three main pillars:

- Developing scenarios and use cases that industry executives and boards can use to create a culture of cyber resilience and good governance in the electricity sector.
- Improving the implementation of cyber resilience regulations by fostering dialogue between policy-makers and businesses.
- Improving supply chain resilience by establishing standards for cybersecurity roles and responsibilities across all stakeholders involved to ensure that every entity is taking appropriate steps to protect against cyberthreats.

The initiative has published a series of reports to guide chief executives and board members in meeting the unique challenges of managing cyber risks:

- Cyber Resilience in the Electricity Ecosystem: Principles and Guidance for Boards
- Cyber Resilience in the Electricity Ecosystem: Playbook for Boards and Cybersecurity Officers
- Cyber Resilience in the Electricity Ecosystem: Securing the Value Chain

In 2021, following a request from the European Commission (EC) Energy Directorate, the initiative also developed a collection of 15 lessons learned and recommendations for improvement on the new EC Cybersecurity Directive considering the implications of supply chain attacks and other systemic risks for cybersecurity in the energy industry.

Partnering to Safeguard K–12 organizations from Cybersecurity Threats

CISA has released 'Protecting Our Future: Partnering to Safeguard K–12 organizations from Cybersecurity Threats'. The report provides recommendations and resources to help K-12 schools and school districts address systemic cybersecurity risk. It also provides insight into the current threat landscape specific to the K-12 community and offers simple steps school leaders can take to strengthen their cybersecurity efforts.

The report’s findings state that K-12 organizations need resources, simplicity and prioritization to effectively reduce their cybersecurity risk. To address these issues, CISA provides three recommendations in the report to help K-12 leaders build, operate, and maintain resilient cybersecurity programs:

- Invest in the most impactful security measures and build toward a mature cybersecurity plan.
- Recognize and actively address resource constraints.
- Focus on collaboration and information-sharing.

Along with the report, we are providing an online toolkit which aligns resources and materials to each of CISA’s three recommendations along with guidance on how stakeholders can implement each recommendation based on their current needs. To read the full report and to access the toolkit, visit Protecting Our Future: Partnering to Safeguard K–12 organizations from Cybersecurity Threats.

DHS S&T Develops Portable Outdoor Gunshot Detection Technology for Law Enforcement

A new portable Gunshot Detection System can provide critical information about outdoor shooting incidents almost instantaneously to first responders. The system, called SDS Outdoor, was developed in collaboration between the Department of Homeland Security (DHS) Science and Technology Directorate (S&T) and Shooter Detection Systems (SDS) of Rowley, MA.

“Many U.S. gunshot detection technologies are not easily deployed in the field or at temporary locations,” said Dr. Dimitri Kusnezov, DHS Under Secretary for Science and Technology. “This new system can be moved by one or two officers without the need for technicians to transport and set up. This mobile capability will help responders approach gun violence incidents with greater awareness, reducing response times and increasing responder safety.”

The portable system is an enhancement to the current commercial, off-the-shelf Guardian Indoor Active Shooter Detection System. SDS Outdoor uses two factors—the sound and flash of the gunshot—to detect and validate each gunshot, drastically reducing false positives. Most other systems rely principally on sound, which can have higher false positive rates. Moreover, SDS Outdoor can be deployed for temporary events in locations where infrastructure support is not available, such as open-field concerts or pop-up rallies.

Delivery of this mobile system comes after almost two years of development. Prototype testing started in January 2022, and SDS provided a real-time demonstration to a user advisory group in May. It was then tested by S&T’s National Urban Security Technology Laboratory and the First Responder Technology Program team in an Operational Field Assessment at Fort Dix, New Jersey, in November. Feedback from participating law enforcement agencies who participated in the evaluations helped make the system more effective in detecting and alerting responders to gunshots.

“We’ve now transitioned the system to SDS to commercialize the technology and make it available to law enforcement agencies and first responders nationwide,” said Anthony Caracciolo, S&T First Responder Technology program manager. “The new system fills a gap identified by the First Responder Resource Group by extending gunshot detection capabilities to locations that do not support fixed deployments.”

SDS Outdoor also complements other S&T-developed detection and tracking technologies, such as MappedIn Response and Detection of Presence of Life through Walls, giving first responders a more holistic view of what they are dealing with so they can coordinate their responses accordingly.

Your latest issue of Critical Infrastructure Protection & Resilience News has arrived

Please find here your downloadable copy of the Winter 2022-23 issue of Critical Infrastructure Protection & Resilience News for the latest views and news at www.cip-association.org/CIPRNews.

- A Standard to help protect Critical Infrastructure
- Government and Industry Cooperation: More Important Than Ever for Cybersecurity Awareness
- Help2Protect: an eLearning program to counter Insider Threats
- Testing Environments Help S&T and CISA Secure Transportation Infrastructure
- Can responsible AI guidelines keep up with the technology?
- Infrastructure Resilience Planning Framework (IRPF)
- An Interview with Port of New Orleans
- Critical Infrastructure Protection & Resilience North America Preview
- Industry and Agency Reports and News

Download your Critical Infrastructure Protection & Resilience News at www.cip-association.org/CIPRNews

Critical Infrastructure Protection and Resilience News is the official magazine of the International Association of Critical Infrastructure Protection Professionals (IACIPP), a non-profit organisation that provides a platform for sharing good practices, innovation and insights from Industry leaders and operators alongside academia and government and law enforcement agencies.

#CriticalInfrastructureProtection #CriticalInfrastructure #cybersecurity #help2protect #cisa #ciprna #resilience #cooperation

CIPRNA Update Conference Agenda

Critical Infrastructure Protection and Resilience North America will be held in Baton Rouge on 7th-9th March 2023, supported by IACIPP and Infragard Louisiana.

A fanstastic conference agenda addressing some of the big challenges facing CI operator/owners, government, agencies and the broader CI community.

A range of Workshops and Mini-Symposiums help drill deeper into specific sector challenges.

Download the latest CIPRNA agenda at www.ciprna-expo.com/PSG.

Register online at www.ciprna-expo.com/onlinereg

#criticalinfrastructure #criticalinfrastructureprotection #emergencymanagement #cisa #fema #tsa #emergencyresponse #disasterriskreduction #transportsecurity #energysecurity #telecomssecurity #cbrne #cybersecurity #security

TSA detects disassembled gun concealed in two peanut butter jars at JFK Airport

It was a sticky situation in a Transportation Security Administration (TSA) checked baggage screening room at John F. Kennedy International Airport (JFK) when a TSA officer removed two jars of peanut butter, each containing parts of a disassembled semi-automatic handgun artfully concealed inside.

The .22 caliber gun parts were wrapped in plastic and had been jammed into the middle of two plastic jars of peanut butter. The gun’s magazine was loaded with bullets.

When the checked bag triggered an alarm in a Terminal 8 X-ray unit, a TSA officer opened the bag and upon closer inspection uncovered the concealed firearm parts. TSA officials notified the Port Authority Police, who came to the checked baggage room in JFK’s Terminal 8, confiscated the items, tracked down the traveler in the terminal and arrested him.

“The gun parts were artfully concealed in two smooth creamy jars of peanut butter, but there was certainly nothing smooth about the way the man went about trying to smuggle his gun,” said John Essig, TSA’s Federal Security Director for JFK Airport. “Our officers are good at their jobs and are focused on their mission—especially during the busy holiday travel period,” Essig said.

Travelers may transport their firearms for a flight if they have a proper permit and the gun is properly packed. Firearms and firearm parts must be unloaded, packed in a locked hard-sided case and taken to the airline check-in counter to be declared. At that point the airline representative will make sure that the firearm is transported in the belly of the plane. Additionally, replica firearms are prohibited in carry-on baggage and also must be transported in checked luggage.

TSA breaks record for number of firearms at security checkpoints, announces new measures to mitigate threat

Transportation Security Administration (TSA) officers intercepted a record number of firearms brought by passengers to airport security checkpoints in 2022. As of December 16, TSA has stopped 6,301 firearms; more than 88% were loaded. This number surpasses the previous record of 5,972 firearms detected in 2021. TSA anticipates it will prevent about 6,600 firearms in carry-on bags from entering the secure area of airports by the end of 2022, a nearly 10% increase over 2021’s record level.

Firearm possession laws vary by state and local government, but firearms are never allowed in carry-on bags at any TSA security checkpoint, even if a passenger has a concealed weapon permit. In order to reduce the threat of firearms at checkpoints, TSA has increased the maximum civil penalty for a firearms violation to $14,950. TSA determines the penalty amount for a violation based on the circumstances in each case. TSA will continue to revoke TSA PreCheck® eligibility for at least five years for passengers caught with a firearm in their possession. TSA may conduct enhanced screening for those passengers to ensure no other threats are present. Depending on state or local law in the airport’s location, passengers who bring firearms to a checkpoint may be arrested by law enforcement.

“I applaud the work of our Transportation Security Officers who do an excellent job of preventing firearms from getting into the secure area of airports, and onboard aircraft,” said TSA Administrator David Pekoske. “Firearms are prohibited in carry-on bags at the checkpoint and onboard aircraft. When a passenger brings a firearm to the checkpoint, this consumes significant security resources and poses a potential threat to transportation security, in addition to being very costly for the passenger.”

Security by Design: Protection of public spaces from terrorist attacks

In a handbook from the Joint Research Centre brings together scientists, experts and academia for a book that dives deep into how open public spaces can be planned and built in a more secure way, through security by design.

“Security by Design: Protection of public spaces from terrorist attacks” introduces the concept and practical implementation of building security in the design and redesign of public spaces. It does so while providing information on terrorism risk assessment, project planning and management. It proposes innovative technical solutions for the protection of public spaces against terrorist attacks. Security by design is built upon the principles of proportionality, multi-functionality, sustainability, accessibility and aesthetics. It is the complete opposite of the creation of urban fortresses.

Public spaces are vulnerable because they are open, easily accessible and attract a great number of people. They are often referred to as « soft targets ». Their vulnerability lies in the fact that they usually lack specialised protective measures and can then be attacked using simple tactics. Such targets are often chosen by terrorists willing to maximise casualties, attain media coverage and inflict fear in the population. Independent of the rarity of such attacks, their psychological, economic and political impact on society can be disproportionally high. In recent years, public spaces such as shopping centres, markets, places of worship, public transport and entertainment venues have become the target of terrorist attacks across Europe.

The action plan to support the protection of public spaces set out a concrete list of measures to pave the way for effective EU Member State cooperation in the protection of public spaces, while the 2020 Counter-terrorism Agenda for the EU focused on the support to Member States in better anticipating, preventing, protecting and responding to the terrorist threats.

In the Counter-Terrorism Agenda, the book is mentioned as a virtual architectural book on urban design, which can assist authorities in incorporating security aspects in the design or renovation public spaces. While the handbook is not legally binding it does contains relevant information and expert advice. It aims to help address practical concerns of integrating security measures for project teams, security operators, urban planners and anyone involved in public space projects. It will help readers answer questions whether and, if yes, to what extent they may wish to implement protective solutions through design.

You can read the handbook to find out more on how to make public spaces not only safer but also multifunctional, sustainable, beautiful and accessible for all people.

Risk information is everybody's business. Here is why it is a whole-of-society effort

More risk data is produced every day. However, new findings often don't make it out of the scientific silos to the broader public. In the face of false information, it is essential to find new ways of making risk information accessible to everyone.

  • Risk information should provide scientifically sound information, tailored to the everyday concerns of society.
  • Science, private sector, governments, and media need to understand each other’s interests and qualities.
  • A whole-of-society approach calls for all parties to communicate clearly and listen carefully.

Different stakeholders may have different priorities and angles around risk . For example, public leaders may prefer a responsive angle on manifested disasters for strategic reasons, while private developers may not want to stress risks to prevent them from raising a lot of attention.

Establishing collaboration requires dialogues between institutions. This is easily hindered by unclear distribution of responsibilities or language and jargon barriers.

5 ways to enable an all-of-society approach

To create a holistic conversation around risk, stakeholders need to develop strategies for closer collaboration. Here are five enablers that support these dialogues and facilitate effective communication:

1. Building trust

People are willing to collaborate on risk communication when strong relationships are in place. Long-standing partnerships between universities and municipalities, for example, benefit from knowing each other's objectives and differences to build trust and understand each other’s priorities.

2. Clear communication

Clear communication is key when bringing together the private sector, governments, and civil society. Only when all parties understand the different risk scenarios and risk reduction options, can they develop solutions that serve the community. "Knowledge brokers", knowledgeable in various fields, can play an important role in "translating" across sectors and aligning conversations.

3. Financing innovative collaborations

Informative, unbiased risk communication requires independent funding for thorough research and reviewing. Finance for collaboration on risk communication is increasingly important, at a time when independent media are financially constrained by the economic downturn.

4. Understanding each other's needs

Effective collaboration with the media and creative sectors is enabled if all parties understand each other’s needs. For instance, scientists who approach media with interesting stories, written in simple language, show an understanding of media timeframes and requirements. RSuch stories can give insight into how DRR issues affect audiences' everyday lives.

5. Creating incentives

Collaborations can flourish if they clearly benefit all practitioners and rule out reasons for mistrust. Hence, underlining the proactive position of risk communication and the increase in credibility are among the most important steps.

Political figures as well as scientists benefit from early on communication, rewarding them with greater credibility and confidence.

Incentives targeting the private sector may aim at openly informing the greater public about potential risks and in return tailoring their products to meet the consumers' needs.

Within the media and creative sectors, creative and engaging programming that helps audiences feel informed and empowered to act can attract other stakeholders.

Risk communication that serves society

Risk communication should support informed decision-making. Available data needs to be translated into information and actionable knowledge.

Therefore, practitioners of diverse backgrounds need to find new ways of collaboration that highlight shared perspectives, bring together visions, and foster creativity.

Disaster risk is ultimately linked to people's everyday lives and therefore can be explored through a wide range of programming and formats. This is where all stakeholders come together; in providing scientifically sound information, tailored to the everyday concerns of society.

[Source: UNDRR]

NSA, CISA, and ODNI Release Guidance on Potential Threats to 5G Network Slicing

The National Security Agency (NSA), CISA, and the Office of the Director of National Intelligence (ODNI), published Potential Threats to 5G Network Slicing. This guidance—created by the Enduring Security Framework (ESF), a public-private cross-sector working group led by the NSA and CISA—presents both the benefits and risks associated with 5G network slicing. It also provides mitigation strategies that address potential threats to 5G network slicing.

Building upon the work published in the Enduring Security Framework’s Potential Threat Vectors to 5G Infrastructure, the Enduring Security Framework1 (ESF) established a working panel comprised of government and industry experts and conducted an in-depth review of network slicing, a key component of 5G infrastructure. This working panel assessed the security, risks, benefits, design, deployment, operations, and maintenance of a network slice.

For this guidance, a network slice is defined as an end-to-end logical network that provides specific network capabilities and characteristics for a user.

As with any emerging technology, with increased benefits come increased risks. This guidance intends to introduce 5G stakeholders to the benefits associated with network slicing and introduce perceived risks and management strategies that may address those risks.

The guidance builds upon ESF’s Potential Threat Vectors to 5G Infrastructure, published in 2021.

1 12 13 14 15 16 53