Department of Energy strategy aims to make power systems more resilient to hacking
Full article782 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The strategy will serve as a roadmap for the new Office of Cybersecurity, Energy Security, and Emergency Response, for which President Donald Trump’s fiscal 2019 budget requests $96 million.
Citing an increase in criminal and nation-state hackers targeting the energy sector, the Department of Energy has released a five-year strategy to cut down on the risk of power-supply disruptions resulting from cyber incidents.
“Despite improving defenses, it has become increasingly difficult for energy companies to keep up with growing and aggressive cyberattacks,” the document states.
The department is trying to change that dynamic through a strategy to boost threat-sharing with the private sector, curb supply-chain risk, and accelerate research and development to make energy systems more resilient to hacking.
The strategy will serve as a roadmap for the new Office of Cybersecurity, Energy Security, and Emergency Response, for which President Donald Trump’s fiscal 2019 budget requests $96 million.
“Today, any cyber incident has the potential to disrupt energy services, damage highly specialized equipment, and threaten human health and safety,” Bruce Walker, an assistant secretary of Energy, wrote in the plan’s preface.
The document acknowledges the risk of cascading power disruptions due to the interconnectivity of the country’s energy systems. As a result, the department is looking to improve its response ability to cyber incidents, which it says “may require a different set of resources, personnel, and skills than traditional energy disruptions.”
DOE officials also want to expand the department’s Cybersecurity Risk Information Sharing Program, which shares threat data with the private sector, and set up a virtual “malicious code repository” for organizations to exchange a trove of malicious files for analysis.
Alongside DOE’s cybersecurity efforts, regulators and lawmakers have moved to make the grid more resilient to hacking.
A ruling issued last month by the Federal Energy Regulatory Commission requires utilities to implement security controls on everyday electronics like laptops and flash drives that interact with “low-impact” systems. Legislation currently before the House of Representatives, meanwhile, would set up a voluntary DOE program for testing the security of ICS products.
The DOE strategy follows a Department of Homeland Security advisory in March that Russian government hackers had been collecting data on industrial control systems (ICS) in the U.S. energy sector as part of a two-year hacking campaign.
Such reconnaissance on the ICS that underpin the power sector is one thing, but documented cases of malware tailored to attack those systems are much rarer. The last decade has seen just a handful of them, with one example coming last August when hackers caused an oil and gas plant in Saudi Arabia to shut down.
ICS security specialists have drawn lessons from each of those high-profile malware incidents, and regulations in recent years have strengthened cybersecurity considerably in the energy and nuclear sectors.
More Scoops
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.
House intel bill includes provisions on state and local threat intelligence, election security, AI
Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/deparment-of-energy-cyber-resiliency-strategy/