The playbook simulates a cyberattack on the energy industry to educate regulators, utilities, and IT and OT security experts.
Cyberattacks against the energy sector have shifted from targeting information technology (IT) to operational technology (OT) as attackers aim to disrupt critical infrastructure. This change is forcing companies to rethink how they would detect and remove threats without affecting operations.
To offer guidance, Siemens has published "Simulating a Cyberattack on the Energy Industry: A Playbook for Incident Response," which demonstrates the response to a cyberattack on a fictional electric utility that leads to a citywide blackout. The idea is to inform cybersecurity, IT, and OT teams of how they should collaborate and make decisions in a high-stress situation.
More than half (54%) of global utilities anticipate an OT attack within the next 12 months, the Ponemon Institute reports, and 64% say sophisticated attacks are a top challenge. Further, Siemens explains in its whitepaper, OT infrastructure is "significantly more vulnerable" than IT infrastructure, and breaches affecting OT have a more destructive effect on operations.
More than one-third (35%) of utilities have no response plan. This playbook outlines the incident response process: preparation for an attack, identifying a breach, containing damage, removing the threat, enacting recovery, and documenting lessons learned from the incident.
Read more details and view the full playbook here.
Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "The Perfect Travel Security Policy for a Globe-Trotting Laptop."
About the Author(s)
You May Also Like
The fuel in the new AI race: Data
April 23, 2024Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024