Navigant Research Blog

Cybersecurity Pros Are Hiding the Breaches: This Must Stop

— May 31, 2017

Even the security good guys are failing us. That’s the upshot from the new survey of cybersecurity experts conducted by Bromium, a cybersecurity firm based in Cupertino, California.

The company surveyed attendees at the RSA Conference 2017 and others as part of a combined extended study and found startling results:

  • On average, 10% of security professionals said they had paid a ransom or hid a breach without telling their team members (5% at RSA, 15% in the extended study). Note: some 638 million ransomware attacks took place in 2016, which implies that tens of millions of such attacks are likely going unreported.
  • On average, 35% of security professionals said they went around, turned off, or bypassed their own corporate security settings (38% at RSA, 32% in extended study of United States and United Kingdom security professionals).

The folks at Bromium said the results “kind of blew their minds.” No kidding. This level of failure to act is shocking. But on further analysis, perhaps understandable. The bad guys have both the incentives and easy access to the tools needed to break into servers and cause havoc.

For grid operators, this is not good news. An updated U.S. News & World Report article last year noted it took hackers just 22 minutes to get employees at an electric facility north of Seattle to bite on phishing emails. It was only an exercise, but proved the point that the grid is vulnerable and that humans are often the weakest link.

Security Fatigue

One of the root causes among cybersecurity professionals for this lack of diligence is security fatigue, as pointed out in a TechRepublic story. The National Institute of Standards and Technology (NIST) defines this fatigue as “weariness or reluctance to deal with computer security.” The author recommends that companies reduce such fatigue by boosting the relevance and importance of security alerts to an IT team and emphasizing the need for constant security vigilance.

It is hard to argue with that recommendation. However, I would take things a step further: institute regular focused training on how to combat threats combined with controlled drills or testing, like the one at the plant near Seattle. It is unacceptable that people we need to trust have such careless attitudes and avoid actions in the face of threats. It is hard to admit, but we are in far deeper trouble on this front than imagined. We must do better.


Patch or Perish: NERC-CIP and the Lesson of the WannaCry Worm

— May 16, 2017

Last Friday and over the weekend, thousands of computers were infected with the Wana Decrypt0r 2.0 or WannaCry worm. The rapid spread of this malware was due to its ability to seek out other computers on the same network, be that at work or a cafe, and then infect those systems as well. Once a computer is infected, the user’s system files are encrypted and they are given the choice to lose their files or pay a bitcoin ransom of $300. The worm interface motivates the user by not only threatening the imminent loss of data, but also upping the ransom. Racketeering and extortion are now fully a part of life in cyberspace.

(Source: Securelist)

NERC-CIP Guidelines Work

Unfortunately, there is no equivalent of RICO on the Internet. However, for the electric utility industry, there are enforceable guidelines that are designed specifically to prevent this kind of event from affecting the stability of the grid. North American Electric Reliability Corporation (NERC) guidelines for Critical Infrastructure Protection (CIP)-007-6 R2 state the following:

“A patch management process for tracking, evaluating, and installing cyber security patches for applicable Cyber Assets. The tracking portion shall include the identification of a source or sources that the Responsible Entity tracks for the release of cyber security patches for applicable Cyber Assets that are updateable and for which a patching source exists.”

The policy further states:

“At least once every 35 calendar days, evaluate security patches for applicability that have been released since the last evaluation.”

Cybersecurity Housekeeping

Over a month ago, Microsoft released a critical security bulletin update, MS17-010, which specifically stated, “This security update is rated Critical for all supported releases of Microsoft Windows.” The means to use this exploit effectively were freely available to hackers (and others) via information leaked from the National Security Agency (NSA).

The alert was issued by Microsoft on March 14 and the outbreak became widespread on May 12, indicating that all utilities could have reviewed and updated their patch management systems during the intervening period. Electric utilities were also protected by other systems that provide them with a defense-in-depth strategy.

NERC-CIP 007-R1 states that:

“Where technically feasible, enable only logical network accessible ports that have been determined to be needed … disabling or restricting (others).”

Researchers know that the initial component of the worm was designed to scan the local network for systems that have TCP port 445 open and are able to act as a gateway to the Internet using the DoublePulsar backdoor. This backdoor was used to retrieve the ransomware and install it on the local computer.

The CIP guidelines require that ports that are not necessary, as well as those that are known to be vulnerable, be blocked. It is common knowledge among cybersecurity practitioners that port 445 should be blocked at the firewall level as well as on the computer. Any entity that performed this basic level of cybersecurity housekeeping would have prevented infection of their systems.

Standards Frameworks Work, Too

Good cybersecurity is not just a product of having the latest firewalls and security systems in place; it is also the product of having a program in place, like adherence to CIP standards, that sets a policy and specific procedures that must be followed. Companies and organizations that do not adopt a standards framework, such as CIP, will increasingly be at the mercy of Internet racketeers and extortionists.


Blog Articles

Most Recent

By Date


Clean Transportation, Digital Utility Strategies, Electric Vehicles, Energy Technologies, Finance & Investing, Policy & Regulation, Renewable Energy, Smart Energy Program, Transportation Efficiencies, Utility Transformations

By Author