Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Critical Infrastructure Providers Face Politically Motivated Attacks

A Symantec survey finds that half of critical infrastructure providers have experienced politically motivated attacks against their networks.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full photo gallery)
More than half of critical infrastructure providers have experienced politically motivated attacks against their networks. That finding comes from a new survey of 1,580 private businesses in critical infrastructure industries -- defined as industries whose disruption could threaten national security -- conducted by Applied Research for Symantec.

In terms of attack frequency and financial fallout, critical infrastructure respondents said they had experienced a politically motivated attack 10 times in the past five years, resulting in about $850,000 in damages in total. Furthermore, 48% expect more of these attacks in the next year, while 80% expect the frequency of such attacks to increase.

"These numbers are perceptions -- we wanted to get their impressions about what they thought about government protection programs, their awareness and their readiness," said Mark Bregman, chief technology officer at Symantec.

But how do you define an attack as being politically motivated? "Usually, they're stealing something besides money -- often it's intellectual property, to further the competitiveness of a country, or to get into the critical infrastructure to get pre-positioned in case they later want to be ready to disrupt that infrastructure," said Bregman. Other activities may simply focus on gathering intelligence or understanding the nuances of a particular country's critical infrastructure networks.

In terms of network defenses, the energy industry thinks that it is best-prepared to defend against such attacks, while the communications industry is the least prepared. Even so, only one-third of providers feel "extremely prepared" to defend against all types of attacks, and 31% said they were "less than somewhat prepared."

Overwhelmingly, small organizations said they're ill prepared, although perhaps the upside is that they now know it. "It's only recently that small companies realize they're a target as much as big companies," said Bregman.

Interestingly, 90% of respondents reported that they've worked with a government critical infrastructure protection program, and half said they were quite involved. Two-thirds also said that they're willing to work with the government on security issues, and about the same number even view such collaborations favorably.

Such attitudes represent a marked shift from the early days of the government-promulgated critical infrastructure protection committees meant to coordinate security with private industry. Some of that change is due to Stuxnet, which almost overnight made information security a hot-button issue for critical infrastructure providers.

In addition, said Bregman, "in the U.S., the administration has been very outgoing and vocal about the importance of critical infrastructure and protecting it against cyber-attack," especially by appointing Howard Schmidt as cybersecurity coordinator, as well as through multiple speeches by President Obama and others in his administration.

Finally, rather than dictating from on high, the government is carving out a niche as a clearinghouse for useful -- and sometimes difficult to find -- security information and industry best practices. "These programs are not programs in which the government is providing the solution," said Bregman.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
How to Think Like a Hacker
Dr. Giovanni Vigna, Chief Technology Officer at Lastline,  10/10/2019
7 SMB Security Tips That Will Keep Your Company Safe
Steve Zurier, Contributing Writer,  10/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17660
PUBLISHED: 2019-10-16
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/336819/lang/ PATH_INFO.
CVE-2019-11281
PUBLISHED: 2019-10-16
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input...
CVE-2019-16521
PUBLISHED: 2019-10-16
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payl...
CVE-2019-16522
PUBLISHED: 2019-10-16
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. A...
CVE-2019-16523
PUBLISHED: 2019-10-16
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.