Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News
    • Blogs
    • Security Watch

    Critical Infrastructure Unprepared for Attacks

    Written by

    Matthew Hines
    Published November 11, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      I had the opportunity to spend some time last week with Tom Kellermann, a member of the Commission on Cyber Security for the 44th Presidency and a colleague of mine at my full-time employer.

      In a series of interviews with members of the print media about President-elect Obama’s potential policies around cyber-security, Tom repeatedly brought up the issue of protection for critical infrastructure assets, and the need for the government to improve defense of its own operations in addition to pushing private-sector companies to do the same.

      One of the biggest issues to consider would be the potential for attacks that are carried out as part of a multipronged campaign that employs cyber-tactics that target critical infrastructure and follows with attacks in the physical world.

      As in, turn out the lights and invade under the cover of darkness.

      Think that sounds far-fetched? Talk to Tom for a while and you might change your mind. And the people he works with on the Commission represent some of the most influential minds looking at IT security in the federal government and private sectors today.

      To further reinforce the point, Secure Computing has released the results of a new study on cyber-security and its relation to critical infrastructure, and the results are pretty scary.

      According to the survey of roughly 200 security experts, including leaders from the utilities, oil and gas, financial services, government, telecommunications, and transportation sectors, over 50 percent of the officials reported that most critical infrastructure remains vulnerable to cyber-attack.

      An overwhelming majority of the respondents also said they believe that “major attacks” of that type have already begun or will begin within the next year.

      Many of the organizations controlling critical infrastructure have moved to comply with existing security standards, but the majority are still woefully vulnerable to threats, said Rick Nicholson, vice president of research for IDC’s Energy Insights, who authored a white paper based on the survey results.

      “Most utility CIOs believe that their companies will be compliant with relevant standards, but still have a long way to go before being adequately prepared for all cyber-attacks,” Nicholson said.

      Participants in the survey (40 percent) indicated that the financial services sector is likely the best prepared for an attack of all the verticals cited in the research, with the experts expressing their belief that the energy segment remains the biggest target (33 percent).

      Scarily, the energy market was also cited as likely to be the least prepared (30 percent), and at the same time named as the sector where a successful attack would cause the most collateral damage (42 percent), comparatively speaking.

      When asked to highlight the most significant hurdle to improving cyber-security, 29 percent of the experts cited the cost of making new investments. Apathy ranked as the second-most likely reason for a lack of activity, with government bureaucracy and internal issues neck-and-neck for third.

      Among some of the other findings in the Secure Computing report:

      -Some 14 percent of respondents said they believe a major attack will occur in the next year, while only 2 percent said such an exploit would never occur.

      -Roughly 62 percent of North American respondents said their control systems were directly connected to an IP-based network or the Internet. A full 98 percent of respondents believed this makes them more vulnerable.

      -As companies deploy new technologies such as smart meters, sensors and advanced communications networks, they run the risk of increasing their vulnerability unless they include security as an integral part of the projects.

      -During times of economic hardship, organizations are expected to increase their use of “standard” IT platforms, further increasing their vulnerability to attack.

      The accompanying IDC white paper makes four recommendations for critical infrastructure asset owners and operators regarding cyber-security:

      • Perform ongoing vulnerability assessments • Monitor network automation and control systems • Review both IT and operations technology environments • Think beyond regulatory compliance

      Whether these companies decide to undertake this work on their own, or the new administration forces them to do so, we’ll all be better off when a serious change in thinking and strategy among all the involved interests occurs.

      Let’s hope it’s not (another) a major attack on U.S. soil that forces these parties to move forward.

      Matt Hines has been following the IT industry for over a decade as a reporter and blogger, and has been specifically focused on the security space since 2003, including a previous stint writing for eWEEK and contributing to the Security Watch blog. Hines is currently employed as marketing communications manager at Core Security Technologies, a Boston-based maker of security testing software. The views expressed herein do not necessarily represent the views of Core Security, and neither the company, nor its products and services will be actively discussed in the blog. Please send news, research or tips to [email protected].

      Matthew Hines
      Matthew Hines

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×