Partner Perspectives  Connecting marketers to our tech communities.
7/22/2015
07:00 PM
Steve Grobman
Steve Grobman
Partner Perspectives
50%
50%

Out of Aspen: State of Critical Infrastructure Cybersecurity, 2015

The good, bad, and potentially worse of critical infrastructure protection.

There has been a significant post-9/11 focus on securing critical infrastructure systems – many of which pre-date the Networked Age and were potentially more vulnerable to attack than newer networked systems. Cyber-attacks on critical infrastructure systems have not yet resulted in the loss of human lives. And yet a number of recent events suggest that a closer look at the state of critical Infrastructure cybersecurity is necessary to determine progress and unfulfilled needs.

The annual Aspen Security Forum takes place this week in Aspen, CO. This two-day line-up of national security panels and 1:1 discussions presents a great forum to gauge the state of critical infrastructure cybersecurity. In cooperation with the Aspen Institute, Intel Security surveyed security professionals in energy production, financial services, transportation, telecommunications, and many government functions to determine what progress has been made, and what areas require greater attention.

Our survey results revealed the good, the bad, and the potentially worse of critical infrastructure protection:

·       The good news: no catastrophic loss of life and an improved confidence in critical infrastructure cyber security postures

·       The bad news: cyber-attacks are real, increasing, and capable of real, substantive damage to our critical infrastructure

·       The potentially ugly: attacks are likely to become fatal and could escalate from the digital to physical realms.

First, consider the good news.

Respondents demonstrate a significant degree of confidence in the state of their cybersecurity posture – confidence registered by both satisfaction in their security defenses and a perceived decline in vulnerability to attacks in recent years. Half of respondents considered their organizations “very or extremely” vulnerable three years ago. By comparison, 27 percent believe that their organizations are currently “very or extremely” vulnerable today.

Eighty-four percent are “satisfied” or “extremely satisfied” with the performance of their own security tools such as endpoint protection, network firewalls, and secure web gateways. If anything, the greatest threat to critical infrastructure appears to be human rather than technical. As we’ve seen in other areas, the most common cause of successful attacks on critical infrastructure is human error – users falling victim to social engineering such as spear phishing.

This confidence does not mean that they are complacent.

More than 70 percent think the threat to their organizations is escalating. Almost 9 out of 10 experienced at least one attack in the last three years that caused some damage, disruption, or data loss, with a median of close to 20 attacks per year. Forty-eight percent believe it likely to extremely likely that a critical infrastructure cyber-attack will result in human fatalities in the next three years.

While they continue to look at further investment in various security areas, the vast majority think that greater cooperation and public-private partnerships with national and international agencies are important to keep pace with the escalating threat landscape.

What form would these joint activities take? Well, the top rated suggestions were joining a national or international defense council to share threat intelligence and defense strategies, taking coordinated direction on cyber defense, or even national legislation that requires cooperation with government agencies. The majority of respondents felt that their own government as well as international agencies could be valuable and respectful partners in cybersecurity, and many were open to sharing network visibility if it was deemed vital to national or global cyber defense.

However, one caution was that more than three-quarters of the security professionals supported the use of national defense forces to retaliate in response to a fatal critical infrastructure attack within the country. Given that only a third think that nation-state security services are behind the serious attacks on their organization, identifying a target for retaliation is problematic. Even if a nation-state is responsible, how do you conclusively determine the source of the attack, when it is using code borrowed or bought from organized crime in one country and servers spread across 5 other countries?

It is essential for the public and private owners and managers of critical infrastructure to act now. Nobody wins if a digital conflict escalates into conventional, kinetic conflicts between nations. Developing successful public-private cooperation today will help us avoid military escalation scenarios tomorrow.

Steve Grobman is the chief technology officer for Intel Security Group at Intel Corporation. In this role, Grobman sets the technical strategy and direction for the company's security business across hardware and software platforms, including McAfee and Intel's other security ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Empathy: The Next Killer App for Cybersecurity?
Shay Colson, CISSP, Senior Manager, CyberClarity360,  11/13/2018
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18805
PUBLISHED: 2018-11-16
PointOfSales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
CVE-2018-18806
PUBLISHED: 2018-11-16
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
CVE-2018-16396
PUBLISHED: 2018-11-16
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
CVE-2018-18755
PUBLISHED: 2018-11-16
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
CVE-2018-18756
PUBLISHED: 2018-11-16
Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.