Skip to content

自來水公司面臨越來越大的網絡攻擊風險

Ransomware is Everywhere

Over the past few months, there is a feeling that every day a different organization has fallen victim to a ransomware attack. While the idea of a ransomware attack isn’t new, the recent headline-grabbing attacks are exploiting the different products and services that we use on a daily basis. This growing trend of cybercriminals attacking different critical infrastructures has become more lucrative for attackers as they are affecting the way of life which is more devastating for the global community and their victims.

On top of the alarming amount of ransomware attacks, more and more severe vulnerabilities due to remote access have been discovered. This has made it easier for cybercriminals to exploit their targets. One of the most targeted industries that have been affected by poor remote access security is the water utility industry.

Due to the important role of water and wastewater infrastructures in our society, their newly connected systems have become an attractive target for cybercriminals to attack via different attack vectors such as insider and outsider threats and supply chain attacks.

Since the start of 2021, there have been different examples of water plants being successfully attacked by cybercriminals. On January 15th, a water treatment plant in San Francisco was exploited by an attacker who was trying to poison the plant. The cybercriminal gained access by using a former employee’s TeamViewer account credentials. Once the attacker accessed the water plant’s system, they deleted programs that the water plant used to treat drinking water. The attack was only discovered the next day by the water plant and the facility changed its passwords and reinstalled the programs.

A few weeks later another attack on a water plant occurred, and this time it was the Oldsmar Florida water system cyber attack. A hacker gained access into the water treatment system of Oldsmar, Florida, and hijacked the plant’s operational controls. He was able to temporarily drive up the sodium hydroxide content in the water to poisonous levels. Luckily, a plant operator was able to return the water to normal levels.

In 2018, The Department of Homeland Security (DHS) and the FBI warned that the Russian government is specifically targeting the water sector which resulted in the US government forming the Cybersecurity and Infrastructure Security Agency (CISA) to ensure the cybersecurity of critical infrastructure would be prepared for incoming physical threats.

The attack surface of water and wastewater infrastructure will only continue to grow over time. This sparks the priority for stronger cybersecurity and more secure remote access as more water utility organizations will become victims to cyber attacks which could lead to disastrous consequences or even death.

Water Utilities Are an Attractive Target

There are close to 200,00 drinking water systems in the U.S. that provide tap water to nearly 300 million Americans. These water systems are in cities, schools, hospitals, office buildings and other places. When critical water or wastewater systems are exploited by a cybersecurity attack, the malicious activity could result in devastating consequences to public health and safety.

Some attacks on water utilities could cause contamination, operational malfunction, and service outages which would result in potential illness and casualties. Additionally, it could result in a compromise of emergency response teams and possibly impact different transportation systems and food supply. Additionally, on top of attacking the physical water utility equipment, the water plant sector entities are in charge of some critical personal data. This personal data is an extremely attractive target for cybercriminals as seen in previous attacks.

Another example of a successful attack on a water utility is the city of Atlanta ransomware attack. In March 2018, the city of Atlanta and Atlanta Department of Watershed Management employees were unable to turn on their work computers or gain wireless internet access, and two weeks after the attack Atlanta completely took down its water department website “for server maintenance and updates until further notice.” It took Atlanta months to recover and an estimated cost of up to $5 million in recovery efforts, to address the attack.

Remote Access Provides Attackers an Easy Entry Point

If the recent examples of successful attacks on water infrastructures were not evident on the different security threats, now more than ever water utility companies need to get more serious about how they manage remote access.

Over the past decade, the technology behind water infrastructures and utilities has become more interconnected with OT & IoT devices. The different connected devices such as controllers, sensors and smart meters are being used by water utilities to remotely monitor and manage processes. Unfortunately, they are easy targets for cybercriminals to infiltrate.

For water utilities, smart metering can increase efficiency but it comes with its consequences and remote access is a key entry point for successful attacks. Having poor remote access security can allow cybercriminals from both internal and external to gain access to the main operating system remotely and causing severe community health issues like flooding or contaminating water sources.

There is also the issue of smart meters and water appliances that are deployed by water management organizations that can be infiltrated by cyber attacks. If a smart meter is compromised through an attack or reverse engineering, it would allow cybercriminals to potentially access the metering infrastructure which would provide them the ability to attack and move laterally within an organization’s system and networks.

The different vulnerabilities of smart meters brighten the light on the importance and need for better device protection. It is crucial for organizations that are using connected utility devices such as ICS, controllers, smart meters, sensors, etc. to be properly monitored and managed. By understanding who has access, from where they are accessing and irregular activity to a water utility device it will decrease the chance of a successful remote attack on the water systems.

What Water Organizations Can Do

Water and wastewater organizations need to prioritize security and this starts with setting aside the proper amount of resources and attention in protecting their company’s infrastructure and equipment. This process starts with getting a deep understanding of the different security risks that are presented with water and wastewater systems and which steps need to be done to ensure better security.

With the increasing number of successful attacks on water plants and more awareness of the different risks with water utilities, more organizations are slowly starting to understand the significance of implementing the right security practices when it comes to securing their IT and OT systems. As water plants adopt more smart sensors and other IoT devices to automate and modernize their water-based process, it will create new exploitable entry points for cybercriminals to exploit remotely and move laterally within the organization systems.

As water technology continues to advance, so do the different risks that come with it. By adopting more connected technologies and devices it has forced water organizations to connect to the internet which has resulted in more remote access entry points which have caused the increase of security events. This trend has resulted in security teams updating their security approach to one that fits for better remote access security and a new approach for OT security.

While not every water utility company has made the right steps for a more secure water plant, the awareness has led to changes in the water industry. Some companies and cities like The city of Hutchinson have taken a more proactive approach when securing their connected OT equipment with a passive network monitoring solution, specifically designed for OT environments. Now, the city of Hutchinson is securing all their water production, treatment divisions operate and maintain reverse osmosis (RO) water treatment center, 20 water wells, 2 booster pump stations, 4 water storage towers, 2 Class I disposal wells, and all of their groundwater remediation facilities all in one platform.

As water and wastewater organizations continue to become a more attractive target for cybercriminals, it’s best to be prepared for any kind of attack on water utilities by now taking action and mitigating any risks. With a more security-first approach cemented in an organization with the right amount of awareness, water utilizes can continue to expand as their networks do. It is important for decision-makers to consider new security approaches that offer a device-level, security by design that protects their infrastructure for years to come.

To learn more about how SCADAfence protects the water supply of 42,080 Americans in the city Of Hutchinson, Kansas, download the case study here:
https://www.scadafence.com/resource/how-scadafence-protects-the-water-supply-of-the-city-of-hutchinson/

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

為了打擊勒索軟件黑客,耗盡了加密貨幣沼澤

This kind of digital extortion – increasingly viewed as terrorism – would be impossible without the ability to move money around anonymously

Last month, a cybercriminal group penetrated the Colonial Pipeline. This wasn’t just “another” hack, with privacy consequences and threats on personal information. The severe results were shown instantly. Gas supply to millions of Americans was disrupted leading to a spike in gas prices and panic buying causing local fuel shortages in the southeast, and resurfacing old memories of the infamous gas crisis in the US in the late 1970s.

It becomes evident, and not for the first time, that ransomware has the potential to affect the personal lives of innocent citizens tremendously. The problem is worsening by the day as groups improve their ransomware code and collect easy money.

The US authorities responded – a national cyber investigative task force was formed and last night, DOJ told Reuters that US authorities will “give ransomware hacks similar priority as terrorism”. This begs the question, however: will it be possible to stop ransom hacks without treating its originator?

The fact is we’re not looking at this problem holistically. There is one factor making this problem possible, and systemic: cryptocurrency. Ransomware hacks thrive due to the possibility to transfer cryptocurrency easily, rapidly and without leaving traces. The criminals are not required to deal with complex transfers. Gone are the days where hostage-takers demand one million dollars in small-unranked-paper-bills, with a jet on the runway ready to take them to some foreign land where there’s no extradition agreement. All they need is a Bitcoin address, Monero, or ZCash, and a few command lines – and voila – the money lands safely at the hands of the criminals. It’s almost a sterile crime.

In fact, those money transfer machines enable the prosperity of a global crime industry, fueled by corporate extortion funds. For instance, in the case of the Colonial Pipeline, despite the involvement of the FBI and the law authorities, a five million dollar ransom was paid in order to free the systems. Some of the funds were recovered, in an unprecedented operation, and yet, the damage remained.

This is not pocket change. Each win – no matter how financially lucrative – builds on itself and gives these cybercriminals more confidence to fuel the next attack. For example, in dark web forums the phenomenon of “ransomware hack as a service” is gaining popularity, and criminals are offering ransomware for rent. The thieves have become so contented, that they are allowing others to use their tools, while they’re resting safely as ordinary software vendors.

In order to stop terror, we have to stop its funding. However, when it comes to ransomware hacks there is still no internalization of the fact that strict limitations should be put on its primary funding source – cryptocurrencies. The promise for liberty and freedom from censorship made by theoreticians in this field are shattered daily, and instead of a paradise for innocent civilians, we’re left with the opposite – a utopia for criminals. In fact, untraceable cryptocurrencies are the swamp in which the disease of ransomware flourish.

This swamp must be dried up. If governments around the world seriously intend to stop the phenomenon of ransomware hacks, they have to put strict limitations on money transfers via crypto currencies. They must supervise cryptocurrencies the same way they do with cash, bank transfers, diamonds or weapons. Countries should demand users to expose their money sources and prevent them from doing major deals not conducted through the supervised international banking system.

Governments should also implement methods of tracking cryptocurrencies and sound the alarm when illegal activity is detected. If they cannot decide on or implement a system to administer this, governments should consider the unpopular step of complete prohibition of holding and trading cryptocurrency. Drying up of the funding sources for these attacks may be the only viable approach to stop their continued proliferation. If we do not take immediate action to dry those swamps, we will find ourselves in the near future too weak and too ill to recover.

Originally posted on Times of Israel

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

發布的 20 大 PLC 安全編碼實踐

Over the years, PLCs have been insecure by default. Security good practices have been created and adopted for IT which can be seen in OWASP’s Top Ten Vulnerabilities list and Secure Coding Practices report. However, until recently there has not been an emphasis on the different features in PLCs or SCADA for security or how engineers can program PLCs more securely.

Most organization’s PLCs were not connected to the internet or anything outside their industrial control systems or other PLCs. However, the new mindset of  Industry 4.0 of the ongoing automation of traditional manufacturing and industrial practice has created more security risks and threats for OT networks.

Until now most security research that had to do with PLCs was more focused on how to exploit PLCs and how to alter the industrial processes. Luckily insecure PLCs haven’t been highlighted as the key reason for the most recent cyberattacks on industrial organizations. The more common IT threats have been the heart of attacks with targeted ransomware attacks as seen in the Colonial Pipeline attack. Despite only attacking the IT network, the company shut down its OT networks and operations which control its pipelines and distribute fuel as a precaution which resulted in a temporary gas shortage in the United States.

Another example of a recent breach where OT networks were threatened is the water plant in the city of Oldsmar, Fla. This attack showed the potential risks of a cyberattack and the lack of secure programming practices of PLCs could lead to a physical outcome, in this case, poisoning drinking water. These examples are proof that improved and more secure PLCs will lead to becoming the biggest benefit in preventing a process from getting into a bad state.

Top 20 Secure PLC Coding Practices

As our good friend, Jake Brodsky said in his recent S4x20 talk, “No one learns secure PLC coding at school.” The idea that engineers were expected to come out of college knowing the best practices for programming PCLs is a misconception in the industry. According to Jake, there is a massive knowledge gap for the typical engineer who is tasked with programming PLCs which is resulting in more troubles for different ICS security businesses.

The eye-opening talk was the initial spark to create the Secure PLC Programming Practices Project by Jake Brodsky, Dale Peterson, Sarah Fluchs and Vivek Ponnada and is hosted by the ISA (International Society of Automation) Global Cybersecurity Alliance. This new security initiative offers a free downloadable 44-page document that outlines the 20 best practices for engineers that program industrial controls and help improve the security of their systems. Little or no additional software tools or hardware are needed to implement them. They can fit into normal PLC programming and operating workflows.

These are tips and tricks for catching and avoiding problems during the whole lifecycle of the PLC and the application. One of the main goals of this initiative is that PLC vendors will start to integrate or provide templates with their product training to help customers employ these practices when programming their devices.

Here are the key best practices from the list that we feel relate the most to OT security:

Validate and Alert For Paired Inputs/Outputs

If you have paired signals, ensure that both signals are not asserted together. Alarm the operator when input/output states occur that are physically not feasible. Consider making paired signals independent or adding delay timers when toggling outputs could be damaging to actuators (for example, asserting forward and reverse together)

This is important for security reasons because if PLC programs do not account for what is going to happen if both paired input signals are asserted at the same time it could result in the PLCs becoming a good attack vector for cyber criminals. By ensuring that both signals are not asserted together it will help to avoid an attack scenario where physical damage can be done.

Leave Operational Logic in the PLC Wherever Feasible

HMIs provide some level of coding capabilities, originally aimed to help operators enhance visualization and alarming. However, the HMI doesn’t get enough updates to do totallizing or integration. There is also a latency between HMI and PLC which may interfere with the accuracy of such efforts. Furthermore, an HMI will restart far more often than most PLC equipment. It makes sense to keep such accumulators/counters/integrators/elapsed-time counters and so forth there. The HMI can always receive totalizers/counts from a PLC. Thus the operational logic program should rather stay in the PLC to remain complete and auditable.

This practice is beneficial for security because it allows consistency in verifying code changes. HMI coding has its change control apart from PLC, generally not with the same rigor which does not allow system owners to have a complete view and even losing important considerations. HMI’s do not include “forced signals” or changed value lists as PLCs or SCADAs.

Restrict Third-Party Data Interfaces

To strengthen the security of PLCs, it’s highly recommended to restrict the type of connections and available data for 3rd party interfaces. The different connections and data interfaces should be specifically defined and restricted for third parties to be allowed to have read and write capabilities for the required data transfer.

This practice limits the different exposures to 3rd party networks and equipment while authenticating external devices to prevent spoofing. Additionally, it limits the ability for intentional or unintentional modifications or access from 3rd party locations or equipment.

Trap False Negatives and False Positives for Critical Alerts

OT teams should identify the critical alerts and program a trap for those alerts. Most critical alerts for PLCs tend to occur when they are triggered by different conditions.  In some cases, an adversary will attack OT devices by suppressing the alert trigger which could cause a false-negative or false-positive alert. By setting up a trap to monitor the different triggers of alerts it will allow OT teams to detect the alert state for any deviation. A PLC can react much faster than an HMI and can be far more sensitive to these triggers.

By detecting and mitigating false negative or false positives of critical alerts caused by an adversary attack on OT equipment it will allow OT security teams to have a better understanding if their PLC is accessible and being tampered with.

Define a Safe Process State in Case of a PLC Restart

By commanding a PLC to restart in the middle of a working process, there shouldn’t be any issues when it comes to disruption to the process.  Make sure that the process it controls is restart-safe. If it is not practical to configure the PLC to restart-safely, you should define safe process state alerts to ensure that the Standard Operating Procedures (SOP) have clear instructions for setting the manual controls so that the PLC will start up the process properly.

By defining a safe process state it eliminates potential unexpected behavior. The most basic attack vector for a PLC is to force it to crash or restart it. For many PLCs, it is not that hard to do, because many PLCs cannot cope well with unexpected inputs or too much traffic.  For example, the SCADafence research team found a remote CPU DoS vulnerability in Mitsubishi Electric iQ-R Series. This would allow an attacker to send a short burst of specially crafted packets over the MELSOFT UDP protocol on port 5006, which causes the PLC’s CPU to get into fault mode, causing a hardware failure. The PLC then becomes unresponsive and requires a manual restart to recover. This may be uncommon, but it is a basic attack vector if we take into account the malicious behavior of an attacker.

Using The Top 20 Secure PLC Coding Practices

In summary, at least half of these programming recommendations can be summarized as “Validate your inputs.” Many PLC programmers just assume that something physical doesn’t need to be validated. But it is possible to force inputs and it is possible for an HMI to push invalid data to a PLC. Plan for it.

The Top 20 Secure PLC Programming Practices is a great best practices guide that is the work of hundreds of PLC programmers, engineers, and security experts. This is a must-read for every OT security professional and PLC programmer, it is a specific guideline for coding a programmed PLC to help avoid a potential cyber-physical attack.

You can download the Top 20 Secure PLC coding practices document at www.plc-security.com.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

NERC 制定實踐指南以幫助組織評估網絡監控技術

Earlier this month, on June 4th, the North American Electric Reliability Corporation (NERC) released a new practice guide that pinpoints how organizations should integrate network monitoring solutions into industrial operational technology (OT) networks of the electric utility industry.

NERC developed the ERO Enterprise CMEP Practice Guide: Network Monitoring Sensors, Centralized Collectors, and Information Sharing in response to the Department of Energy’s (DOE’s) 100-day plan. The Department of Energy’s initiative is to advance technologies that provide increased visibility, detection, and response capabilities for utilities’ industrial control systems (ICS) and operational technology (OT) networks to better protect the nation’s agencies and infrastructures.

While many government agencies and organizations have already deployed these types of technologies within their OT environments, the NERC anticipates an increase in deployments across the electric utility industry to increase threat detection and incident response abilities due to the DOE 100-day plan. NERC provides an actionable framework for auditing compliance with the CIP Reliability Standards when a registered entity deploys detection and monitoring technologies that include network monitoring sensors and centralized data collectors and may involve the sharing of data collected with third parties.

Additionally, the guide provides ERO Enterprise examples of how to comply with industry standards. This is super helpful as the NERC is aiding organizations with the right framework with compliance monitoring when it relates to the deployment of OT security technology.

We’ve put together an overview of the report and the key takeaways that relate to OT security.

Protecting Cyber Assets

As expected, the guide discusses the importance of the protection of cyber assets. According to NERC, the CIP standards require registered entities to protect Bulk Electric System (BES) Cyber Systems and certain associated Cyber Assets.

For organizations to get a better understanding in the manner in which the CIP standards apply to network monitoring deployments is to determine whether the sensor to be deployed is a Cyber Asset, BES Cyber Asset, and then a BES Cyber System or other types of Cyber Asset subject to requirements of the CIP standards, such as a Protected Cyber Asset (PCA) or Electronic Access Control or Monitoring System (EACMS).

If a sensor does not qualify as a BES cyber system, it may be categorized under CIP requirements depending on how it is used and which environment it is deployed in. Devices that are deployed in high or medium impact can be categorized as protected cyber assets if they are inter-connected with routable protocols within an electronic security perimeter or as electronic access control or monitoring systems (EACMS).

The report ended the section about protecting cyber assets by saying that organizations may not be required to secure sensors that are deployed in an environment with only low-impact BES cyber systems even if they are “performing the functions of an EACMS or other device subjects to the CIP standards.” However, auditors must still assess whether those devices are subject to the requirements of CIP-003-8 concerning electronic access control.

Data Protection with 3rd Parties Access

The report mentions when it comes to the protection of data, the CIP standards require that organizations need to control access to BES cyber system information (BCSI). According to NERC, “Information about the BES Cyber System that could be used to gain unauthorized access or pose a security threat to [it].” The report provided different examples of such data including network topology of the system, security procedures, collections of network addresses, and any information that is not publicly available and could be used to allow unauthorized access or distribution of sensitive data.

NERC recommends that Compliance Monitoring and Enforcement Program (CMEP) teams are urged to identify how their organization determines whether the data collected by its sensors contains BCSI and whether the information is transmitted and accessible by third parties. If BCSI is included in the data, organizations must assess whether the utility has a process in place to authorize access to the designated storage locations for BCSI. Additionally, any potential third-party access to information needs to be also accessed.

The guide also recommends that CMEP teams fact-check a utility’s network monitoring technology deployment by implementing a deep dive review of every system to ensure that no possible vulnerabilities are missed.

Governance for OT Networks

This NERC report is a very detailed framework which industrial organizations especially in the US electric community will start to implement. We expect government agencies to use this guide as a compliance framework for all discussions on passive monitoring technology.

The SCADAfence Platform for OT security, combined with the SCADAfence Governance Portal, helps utility companies ensure that their Bulk Electric System (BES) is secure and reliable according to the North American Electric Reliability Corporation critical infrastructure protection (NERC CIP) standards. The SCADAfence Governance Portal includes a built-in NERC CIP module which provides cross-organizational tracking and measurement of NERC CIP adherence.

To learn how your organization can achieve NERC CIP compliance by using the SCADAfence Governance Portal, download the full whitepaper here: https://www.scadafence.com/resource/nerc-cip-compliance-scadafences-unique-solution-whitepaper/

Having visibility into compliance enables IT and OT departments to centrally define and monitor their organization’s adherence to OT-related regulations and security policies. To learn more about IT & OT compliance, please join us on June 23rd for our joint webinar with Rapid7 as we will cover how to measure compliance over time for standards such as NIST, NERC-CIP, IEC-62443, among others.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

美國行政命令的五個關鍵要點可加強國家網絡安全

It’s no secret that Nation-State attackers are targeting US government agencies and organizations. As seen inthe Solarwinds breach and the more recentColonial Pipeline ransomware attack, cybercriminals are more motivated than ever to harm US government agencies and their infrastructures.

Due to the United States facing different persistent and more sophisticated cyber-attacks,  United States President Joe Biden signed an executive order (EO) on May 12 to improve the cybersecurity of the United States. This executive order seeks to increase its efforts in detecting and responding to different attacks and threat actors in the cyber espionage landscape. 

This executive order outlines the Biden administration’s first step in preventing future cyberattacks that could exploit and diminish federal agencies and supply chain technologies. The executive order is proof of an increasing effort to modernize the US government’s cybersecurity practices. Some would suggest it as a playbook for how different federal agencies should respond to security incidents and how to improve the sharing of exploited information post a data breach.

Additionally, this executive order presents the idea that the US government will play a significant role as a purchaser of different cybersecurity solutions and services to ensure its security and provide investment in the private sector.

As the executive order registers close to 8,000 words, we don’t expect you to have the free time to read it thoroughly. To help, here are the five main key takeaways you need to know:

Improving Software Supply Chain Security

One of the most glaring and important takeaways from this executive order is their effort to improve the security of software. To accomplish this, the US government is setting a baseline of security standards for the development of software sold to government agencies. This requires every security vendor to provide and maintain more comprehensive visibility for their software and strictly enforce their security data that is publicly available.

Through this order, the NIST will issue supply chain security guidance for government bodies. Each government agency must comply with the guidance, and use it for software procurement contracts. The supply chain security guidance must include secure development environments (implementing proper authentication and encryption), using automated tools to validate trusted source code supply chains, checking for vulnerabilities in secure environments and more.

All government agencies must comply with this security guidance. If they are using any security solutions that don’t comply, the solution must be removed. With this security guidance in place, government agencies will be able to quickly determine whether the software was developed securely, based on government standards.

Incident Reporting Requirements for IT & OT Security

The executive order strives to reform how information about threats and incidents is shared by removing contractual “barriers.” The federal government is working with IT and operational technology (OT) service providers that have shown value by providing more insights into cyber threat and incident information on Federal Information Systems. However, until now, there have been major restrictions on limiting the sharing of such threat data with government agencies who are investigating cyber incidents.

The executive order is designed to help surmount this hurdle by enforcing that all government officials review all the current security needs and requirements IT & OT service providers. This will allow the government to recommend different updates guaranteeing that the service providers are collecting and sharing their incident reporting data with any agency with whom they are working with. 

Enhancing Detection of Cybersecurity Vulnerabilities

Another major takeaway away from the executive order is to improve the ability to detect malicious activity on federal networks. The United States Office of Management and Budget will publish a set of requirements for federal civilian agencies to deploy different cybersecurity solutions that will support the detection of possible vulnerabilities.

By enabling different detection and response systems, government agencies will have improved information-sharing capabilities within the federal government. If different agencies adopt slower and less consistent deployment of cybersecurity solutions and practices, it will provide the opportunity for cybercriminals to exploit and expose the different government organizations. With the help of active cyber threat hunting, remediation best practices and incident response services, government agencies will be more equipped for addressing incoming cyber attacks.

By adopting this new approach of detecting cybersecurity risks, the US government should become the leaders in cybersecurity adoption with strong threat detection and incident response in place which is integrated with a concrete intra-governmental data sharing system. 

Modernizing Federal Government Security

Another key takeaway from the executive order is the strong emphasis on modernizing government agencies’ cybersecurity by implementing security best practices. As stated in the order, within 180 days all government agencies are required to adopt multi-factor authentication and encryption “to the maximum extent consistent with federal records laws and other applicable laws.”

Additionally, the executive order also is pushing for government bodies to deploy an endpoint detection and response (EDR) initiative to “support proactive detection of cybersecurity incidents within Federal Government infrastructure”. The modernization of government agencies’ security is coming in the wake of the ongoing efforts by the US government as they are grappling with cybersecurity issues.

Establishing a Cybersecurity Safety Review Board

The Executive Order will establish a Cybersecurity Safety Review Board, which will consist of government and private sector leads. The board will be modeled after the National Transportation Board (NTB) which investigates different events in the transportation sector. The cybersecurity safety review board will convene in the event of a major cybersecurity event to investigate and analyze how the security event occurred, the findings and advise the security recommendations for improving cybersecurity. The Board will report to DHS on how the government can improve response practices. This reviewal process will ensure that lessons learned from each major security event won’t be forgotten.

Similar to the private sector, government agencies have recognized there is a major gap in the standards concerning incident response. The typical organizational response is to handle the incident response on their own terms and too often tag the severity with the known information at the time of the attack. This allows the tagging of a severity incorrectly and the severity will most likely change over time as more information of the security event will come out. To help improve incident responding protocols and understanding the true severity, the executive order is recognizing the importance of establishing a standard incident response “playbook” that will help government agencies to properly respond to different cyber attacks with a more concrete plan. 

Moving Forward

While the executive order is still fresh,  we will witness how the federal government embarks on major organizational changes and initiatives needed to accomplish the goals of the executive order. As cyber threats continue to increase in impact and size, it will be interesting to see how NIST and other agencies will define the requirements needed for federal agencies in the federal supply chain space.

Here at SCADAfence, we are committed to working closely with our agency customers, as well as the technical partners whose integrations our customers rely on. We will continue to work together to help achieve the goals of the executive order and strengthen OT security posture.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

彌合 IT 和 OT 之間的差距以及 Rapid7 和 SCADAfence 合作夥伴關係如何引領潮流

It’s been over a decade since the headline-grabbing Stuxnet virus was introduced and the concept of nation-state-sanctioned cyber attacks was presented by security professionals. The concern about different cyber threats which could exploit and potentially destroy physical assets and even human lives grabbed the attention of different industrial organizations. Cyber attackers’ pursuit of the different vulnerabilities in these organizations’ assets could lead to exploitation in operational technology networks.

Despite the early warnings in 2010, only in the past five years has there been an increase of nation-state attackers becoming more prevalent as seen in the recent Solarwinds attack, which was credited to nation-state actors with alleged Russian ties. Cybercriminals are deploying ransomware attacks as their method of choice when attacking different industrial organizations. Over the past 12 months, there have been different successful ransomware attacks on different industrial industries which include the Colonial Pipeline attack and  SNAKE / EKANS attack.


Figure 1: The rising growth of ransomware attacks

These attacks have put a focus once again on the vital importance for all industrial organizations to secure their Operational Technology (OT) environments. OT networks and devices are the heart of automation for industrial assets and unlike newer technology, they are less segmented by virtue of the older industrial infrastructures connecting to the internet and integrating new services in their equipment.

Industrial organizations have been forced with new obstacles, such as remote access and third-party services, which has created a larger attack surface for cybercriminals to exploit OT networks and organizational physical assets (such as the attack on the city of Oldsmar, Florida.) This increasing attack sector has created a newer approach concerning how to secure OT networks and devices while ensuring the more modern IT security methods don’t create new doors for cybercriminals to exploit. Traditionally OT security teams were not in charge of advanced threats and IT security, and thus the need to converge OT and IT networks and systems are becoming more popular by the day with industrial organizations.

When organizations begin to converge their IT and OT systems, they must align their OT network with the same concrete security controls which are deployed on their IT network. By enforcing the same level of IT security controls on the OT network, it provides industrial organizations the ability to detect and mitigate different cyberattacks with an additional layer of defense. Implementing an effective OT security strategy demands a complete audit trail of security incidents while providing full visibility of any lateral movement in the OT network.

OT Systems Create More Challenges For Security Teams

Nothing in life is a simple task and this is especially true when it comes to securing OT systems and networks. With the increasing usage of IP-based communications with OT devices, there is a bigger challenge between OT & IT teams in understanding who is in charge of securing OT systems. Additionally, securing this space is not an easy task. Many traditional networks that were once disconnected, for example, power plants and water systems, are now connected with cloud-based smart management tools. This has created more security risks as OT technologies are updating with the modern Internet.

As more Industrial Control Systems (ICS) are moving to be digitalized, the result is an increased attack surface which has allowed these systems to become a favorite target for mischievous cyber attacks. Over the past decade, IT environments have quickly evolved to adopt and implement security as a key element of managing IT environments. However, OT hasn’t evolved to the quick pace of the attacks and only now are implementing the right amount of security for OT systems and networks. On top of being late bloomers to adopting and implementing security, OT industrial engineers did not think about security when creating the industrial protocols which have been in place for years.

Moving forward to the present day, the industrial industry has adopted a plethora of protocols that cover productivity and security in the newly adopted smart production environments. These industry protocols have created a massive challenge for asset owners as they are hindered to strive with security due to not having complete visibility of their OT networks and devices, lack of monitoring and not having effective security solutions to detect and respond to security attacks.

On top of not being able to completely secure and monitor OT systems, it’s a challenge for OT teams to have a better understanding of their OT equipment as they are sensitive to network scanning. When an OT system is sent unexpected data or more data than it can handle, it can result in a failing activity log which creates the idea of making monitoring a bit more challenging. Additionally, ICS networks use more PC servers and remote workstations which is a recipe for a more twisted attack surface that is a combination of enterprise services and cyber physical systems. To solve these complex security challenges, the approach that industrial organizations need to take is to adopt security for both fronts and get a better understanding of which systems are more perceptive to OT active monitoring.

How Rapid7 & SCADAfence Help Improve Visibility in OT / ICS Environments

With these different security challenges in place, industrial organizations can surmount the challenges by adopting a security system that provides complete monitoring of OT systems and networks. The security system should provide an assessment of different vulnerabilities in both the IT and OT environments. Security teams need to have a clearer understanding of what is occurring with OT systems and networks and how cybercriminals are designing their attacks to exploit the OT systems through the IT environment. Additionally, industrial operators need a better understanding of all their assets and devices in their production environment, especially in their IT and OT equipment.

To help industrial organizations improve their IT and OT visibility we have partnered with Rapid7. Now, customers can integrate SCADAfence with Rapid7’s leading vulnerability risk management solution to leverage visibility into their OT assets and devices. Additionally, customers gain in-depth information around OT networks and identification of cross-site communications and connections between devices with potentially exploitable vulnerabilities.

By integrating SCADAfence and Rapid7 all under one roof, organizations can detect, assess and mitigate across the IT and OT infrastructures while improving the visibility of all their assets. By automating OT and IT security with SCADAfence and Rapid7, customers are achieving full coverage of their IT and OT systems. This is the right step to accurately defend against cybercriminals and nation-state cyberattacks on operational technology systems.

To learn more about our partnership with Rapid7, please visit: https://l.scadafence.com/rapid7-scadafence-joint-partnership

On top of our joint technical partnership and integration, SCADAfence’s research team is continually working with Rapid7’s on their annual vulnerabilities report. Read the Rapid7 2020 Vulnerability Intelligence Report to learn more about our researchers work in securing physical systems in a digital world and the OT threat landscape.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

“氣隙”的IT和OT?

Following the Colonial Pipeline Ransomware incident, Twitter exploded in to an orgy of blather from people demanding that we “air-gap” ICS. Those righteous keyboard warriors know what is best, I’m sure.

We cannot avoid having a secured connection with the office. But on the other hand, we don’t need ICS networks to be connected to the office 100% of the time. If there are elements in the office that require “real-time” performance, then someone should examine the data flows and why such connections are required. In most cases, the connection could be replaced by a reporting device on the OT side of the network, or it is just someone’s pet project that has no business case.

Office connections should have asynchronous, buffered connections. For example, I visited a pipeline operation similar to Colonial about three years ago. While they operated at a slightly smaller scale, They had a very manual connection between the office and the control room. At the beginning of the shift, the office would hand the operations staff a few sheets of paper with a list of what petroleum products need to move through the pipeline from where to where. The operators do this, and when the shift is up, the operators would generate a report for the office and hand the clerical and planning staff a few sheets of paper with the current results. This was not a huge amount of time-critical data.

So if some executives come to you thumping their chests saying “we must be connected all the time because it’s complex and intricate” –tell them to go fly a kite. They need to get a sense of perspective. By the way, flying a kite is a great way to relax, and feel small, while your kite flies high.

Furthermore, we should all practice network segmentation. This means periodically disconnecting the automated segments of the operation by disconnecting network connections. This gives people proper training and practice for identifying those key network segments so that they won’t be flustered and make mistakes when the real need arises. It also trims the operation down to essential automation so that everyone knows exactly what to expect.

When people work with automation enabled all the time, one should expect the manual skills and understanding of the automated systems to atrophy. If operators and office staff do not fully understand what the automation should do next and how it is supposed to work, how will they be able to determine that something is broken before it is too late?

This practice of breaking automation into semi-automatic subsystems is not just good for security, but also for operational proficiency and diagnostic training. In the case of a pipeline such as this, going back to older methods of faxed fuel orders and the like is also good as a method of cross-checking the automation.

And that brings me back to the people who think these systems cannot possibly operate without the automation. I like automation. I have designed automation over my entire career. But it is important to keep the semi-auto and manual controls available. If the automation or the instrumentation fails, there should be a backup plan of some sort. Assuming that without automation everything falls apart would be like assuming that without an autopilot, a ship would automatically run aground. It won’t. The pilot would end up working a lot harder and the maneuvers may not be as precise, but the ship is in no danger –unless the pilot has forgotten how to operate the ship.

“Air-Gapping” the networks between OT and IT is not practical in most cases. There is a significant Return on Investment for connecting them. But limiting the flow of traffic and practicing procedures for isolating the two is not as crazy as it sounds. Practicing that feature also has a very significant Return on the Investment. It is probably worth doing.

Opinion Disclaimier

The views and opinions expressed in this post are those of the author and do not represent the official policy or position of SCADAfence.

The original post can be found here: https://scadamag.infracritical.com/index.php/2021/05/15/air-gapping-it-and-ot/

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

SCADAfence研究人員發現CODESYS開發系統中的漏洞

There are new vulnerabilities discovered every day, and new patches issued to fix them. As part of our mission to secure the world’s OT, IoT and Cyber Physical infrastructures, we invest resources into offensive research of vulnerabilities and attack techniques. 

SCADAfence’s security researcher Yossi Reuven discovered a new vulnerability in the CODESYS development system. CVE-2021-30186 is a CVSS 8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) vulnerability which is a crafted request that may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.

CODESYS is a development environment for programming controller applications according to the international industrial standard IEC 61131-3. The main product of the software suite is the CODESYS Development System, an IEC 61131-3 tool. 

About the Vulnerability- CVE-2021-30186 

V2 runtime systems are one of the main products offered by CODESYS which provides SDK for the implementation of industrial IEC 61131-3 controllers with a customized PLC runtime system. 

The CODESYS Control runtime system enables embedded or PC-based devices to be a programmable industrial controller. It provides a communication server for communication with clients like the CODESYS Development System. A single crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition. This simple but severe vulnerability can be exploited remotely. 

What SCADAfence Recommends Customers Do

Perform an Industrial Vulnerability Management Process

Please refer to our guide on this topic: https://www.scadafence.com/public-preview-a-comprehensive-guide-to-industrial-device-patching/

Monitor for Unauthorized Network Activity and Exploitation

Some devices will always remain unpatched. Monitoring is an early warning system that allows you to act before attackers have gained full control over your network.

Upgrade to the Latest Firmware

CODESYS is currently working on patches that will fix the following versions of the affected products:

  • CODESYS Runtime Toolkit 32 bit full prior version V2.4.7.55
  • CODESYS PLCWinNT prior version V2.4.7.55. This will also be part of the CODESYS Development System setup version V2.3.9.66.

CODESYS expects the releases of all the versions to be available in early May 2021. When the patch is available, we recommend asset owners consider upgrading the products.

Prevent Unauthorized and Untrusted Access

We recommend that CODESYS customers use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. Additionally, we recommend adopting a Firewall or VPN (Virtual Private Networks) tunnel to protect and separate the control system network from unauthorized access from other networks and unsecured remote access. 

Special Thanks & Recognition

The SCADAfence Research team would like to thank the CODESYS team for the collaboration and a speedy vulnerability reporting process.

CODESYS has published the advisory ( 2021-06) and released a firmware update to part of the product line.

SCADAfence is committed to continued research of offensive technologies and the development of new defensive technologies.

If you want to try out the SCADAfence Platform and uncover all of the vulnerabilities in your OT network, we will be glad to help you.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

殖民地管道襲擊加劇了燃料管道的關閉,並突出了對提高OT安全性的需求

On May 8th, news broke that Colonial Pipeline, one of the largest fuel pipelines in the US, was forced to stop all operations due to falling victim to a ransomware attack. The attack on Colonial Pipeline, which supplies close to half of the oil and gas used on the East Coast, is just the latest example of why cybercriminals target the oil and gas sectors. 

Colonial Pipeline Struck by Ransomware

According to a report by The Wall Street Journal, Colonial Pipeline, the operator of the biggest gasoline pipeline in the United States was forced to shut down operations late May 7 following a ransomware attack. The cybercriminals threaten to roil energy markets and upend the supply of gas and diesel to the East Coast. 

Colonial Pipeline is a key passage for the eastern half of the United States.  It’s one of the main sources of gasoline, diesel and jet fuel for the East Coast with a capacity of close to 4 million barrels a day.  They published a statement Saturday saying they were victims of a ransomware attack that affected their corporate IT network.  This attack didn’t exploit their operational network that controls its pipelines and distributes fuel which is separate from the corporate network. Colonial Pipeline announced they did indeed shut down the pipelines as a precaution to prevent the attack from spreading.

Initial thoughts led many people in the security industry to believe that this was another attack by a foreign government. However, Bloomberg published a report on Saturday, May 8th that the attack appeared to be spearheaded by the ransomware group called DarkSide. Known for their “double-extortion” schemes, Darkside took nearly 100 gigabytes of data from Colonial’s network in just two hours on Thursday.

The attackers threatened Colonial Pipeline that if the ransom was not paid, they would leak all the stolen data to the internet, encrypt the data on the attackers’ computers and Colonial’s network would remain locked. It’s not clear how much money the cybercriminals are asking for and how the attackers exploited their network. One thing that is clear, is that this attack is a concrete example that cybercriminals are moving their attention to attacking industrial organizations regardless of size or sector.

Oil & Gas Industry is an Attractive Target 

Over the years, the oil and gas industry has steamrolled into becoming one of the most powerful and economical global industries as it is critical for global and national economies. This has created a major target on their back, as adversaries see these sectors as valuable targets to exploit Industrial Control Systems (ICS) vulnerabilities. In the past, operational technology (OT) needed in oil and gas operations was isolated and “air-gapped,” and today these operational technology networks are connecting more often to different IT infrastructures and to the internet which has created a new door for attacks. The convergence of OT and IT environments in the oil and gas operations has created an endless amount of vulnerabilities from both the IT and the OT environments. There are also emerging risks from Internet-of-Things (IoT) devices and ongoing and growing priorities centered on compliance.

As seen in recent attacks on gas and oil organizations such as Pemex and Colonial Pipeline, it is justifying how attackers have gained an interest in the industry from understanding the different behaviors to how to exploit the organizations. This has resulted in oil and gas organizations needing to protect against any method of cyberattacks to ensure the global economy and civilian safety is not affected due to an attack.

Protecting Oil and Gas Operations

While in the case of the Colonial Pipeline attack, the details of how the adversaries successfully exploited their corporate network are not public yet, it has brightened the light that now is the time for gas and oil organizations to implement a strong OT security strategy. 

Last month, the NSA released a report describing the importance of protecting industrial control systems (ICS) and operational technology (OT) from cyber attacks. In the report the NSA states, “Without direct action to harden OT networks and control systems against vulnerabilities introduced through IT and business network intrusions, OT system owners and operators will remain at indefensible levels of risk.”

Additionally, the NSA report expressed that organizations and operators need to protect critical operations. “While OT systems rarely require outside connectivity to properly function, they are frequently connected for convenience without proper consideration of the true risk and potential adverse business and mission consequences. Taking action now can help improve cybersecurity and ensure mission readiness.”

Before the NSA released this report of their recommendations, many oil and gas organizations have taken the right measures to secure their OT systems and networks.  Over the last seven years, SCADAfence has been working with many critical infrastructure organizations, including oil & gas operators to ensure their OT networks are safe. We provide them with full network visibility, accurate detection of any anomalous behavior and malicious activities – including anomalies that originate from ransomware attacks.

Oil Example diagram in app

The above diagram shows how SCADAfence helps organizations in the Oil & Gas and pipeline industries to have full visibility between their IT and OT networks. This lets them know where the attack vectors are located and they can identify all of the connections between these networks with pinpoint accuracy. This approach has helped hundreds of organizations to successfully mitigate any anomalous activities on their operational networks, which can later turn into a cyber attack.

In an Operational Technology World, Failing to Plan = Planning to Fail

Basic cybersecurity practices can help to prevent these attacks going forward. This includes getting visibility into the entire network, as it’s hard to protect what you cannot see. Additional security practices include network segmentation or even micro-segmentation if possible, and getting continuous network monitoring is even more crucial in preventing similar attacks going forward. 

Numerous oil & gas operators have already adopted continuous network monitoring and threat detection technologies to gain increased visibility into their OT networks and keep their critical infrastructure networks secure. 

With this holistic approach, of network monitoring, anomaly detection, remote access visibility, and compliance, many oil & gas organizations are already reducing 95% of their risk level of future attacks.

A key element of these solutions is that they are all agentless, not intrusive, and can perform superhuman tasks at a fraction of the cost of one human worker.

If your organization is looking into securing their industrial networks, download our case study with a fortune 100 Oil & Gas Industry Leader to learn how SCADAfence provides complete visibility in their OT networks and provides real-time threat detection of any malicious activities.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

強生(Johnson&Johnson)等製藥公司每天都遭受來自國家攻擊者的網絡攻擊

As each day passes, so does the increasing amount of security risks with the cybersecurity attack vector. Every organization can easily fall victim to another cyber threat, but recently, the pharmaceutical industry has become a prime target.

The increasing number of attacks on pharmaceutical organizations is due to the ongoing COVID-19 vaccine development and distribution and this has resulted in the pharmaceutical sector becoming the most attractive industry for cybercriminals. A successful vaccine has become one of the most valuable intellectual properties for cyber attackers. Beyond attacking the pharmaceutical formula, its data on testing the drug trials have become a tempting target for nation-state attackers

A recent example of pharmaceutical companies being attacked is when the Wall Street Journal reported that North Korean state attackers have targeted pharmaceutical companies in the U.S., including Johnson & Johnson. This sparked the Chief Information Security Officer at Johnson & Johnson to say in an interview that they are experiencing attacks from nation-state threat actors “every single minute of every single day.”

This tale isn’t new as in late 2010 North Korean threat actors reportedly targeted UK-based vaccine maker AstraZeneca whose vaccine was co-developed with the University of Oxford. The attack method was spear phishing via social media intending to inject malware by way of offering AstraZeneca employees fake job offers.

The attack surface of pharmaceutical organizations will only continue to grow and the need for better cybersecurity will become more of a priority as more pharma companies will fall victim which could result in disastrous consequences.

Pharma A Prime Cyber Attack Target

The pharma industry is no stranger to being targeted by attackers. Pharmaceutical companies suffer more breaches than any other industry as a result of malicious activity with an average breach resulting in a loss of over 5 million dollars according to the 2020 Cost of a Data Breach Report. Nation-state attackers are induced to target pharmaceutical firms for financial profit, which was one of the main goals for the cybercriminal group who launched the reportedly North Korean government-sponsored attacks.

Cyber espionage is now being recognized as another influential reason for state-sponsored attackers attempting to gain technological advantage for their countries’ economies. The pharmaceutical industry’s key components are based on innovation with comprehensive R&D investments, intellectual property, and patented data. Anytime any data or property is affected or exploited by an attack it can result in devastating losses which can erode patient and consumer trust.

The 2019 attack on German drug conglomerate Bayer is an example of cyber espionage by a state-sponsored attack. Bayer fell victim to a cyberattack from the Chinese threat actor group known as Wicked Panda. The attackers used the Winnti malware, which makes it possible to access a system remotely and then pursue further exploits once in the system.

Pharmaceutical Intellectual Property Attacker’s Favorite Target

Sensitive information and data are not the only attractive targets of pharma companies that hackers are looking to exploit and gain access to. Nation-state hackers have their eyes on a different prize, intellectual property. Protecting intellectual property has always been a priority for the pharmaceutical industry.

Pharmaceutical products are typically only protected by patent for seven years in the United States, and this data could help foreign generic drug manufacturers to be more ready for the expiration of the patent. For example, Chinese nation-state hackers are targeting US pharmaceutical companies to gather information and share it with Chinese companies to offer an advantage against their western competitors.

The years of research and development into developing new pharmaceuticals have attracted hackers to exploit intellectual property somewhat enticing. Recent attacks have targeted intellectual property such as information related to the development of a vaccine or other medical mitigation measures.

Another risk that many pharmaceutical companies experience is that the technology used in their manufacturing systems is much older than the internet, which results in systems being extremely insecure. They were originally designed as ‘air-gapped’, or isolated systems and not built to confront any cybersecurity attacks. For pharmaceutical companies, any size attack by an adversary can result in loss of productivity and availability of physical devices. This can lead to safety issues, reputation, financial losses, and even death.

To fight off different attacks, and the possible exploitation of vulnerabilities, organizations and more specifically enterprises need to address the need to secure the crucial intellectual property while understanding which devices and technologies are at risk. This starts with increasing awareness of nation-state attacks and adopting a more proactive approach to cybersecurity.

What Pharmaceutical Firms Can Do

Pharmaceutical firms need to allocate the right amount of attention and resources to understand what they can do to protect the company’s data and system. The first step is understanding the different risks that come with pharmaceutical manufacturers and systems and what steps are needed to ensure better security.

With the increased attention and awareness of state-sponsored attacks over the past few years, pharmaceutical companies now are understanding the importance of implementing the right security practices when it comes to securing their IT and OT systems. As pharmaceutical manufacturers move forward digitally and continue to modernize their processes with more robotics and IoT technologies, this creates new entry points for attackers to exploit and move laterally within an organization’s system and servers.

In the past, most manufacturers were using stand-alone systems, but with the advancement of technology, they are increasing their connections to the internet to allow third-party contractors and vendors to gain access to work with their equipment. This has forced the security teams at pharmaceutical companies to change their approach to securing their product.

While not every pharmaceutical company has changed its security approach, there has been a massive increase in awareness which has led to changes in the industry. Some companies, like Taro and Rafa, have taken a more proactive approach when securing their connected OT environments with a passive network monitoring solution, specifically designed for OT environments. This has allowed them to have full visibility into their network, reduce the risk of operational downtime, improve their network security and comply with demanding industry regulations.

As pharmaceutical organizations continue to be on the radar for cyberattacks, now is the time to take action and detect and mitigate any risks. Having the right approach and strategy in place with the right blend of awareness and technology, pharmaceutical organizations can now implement the right approach to securing their data, servers, and intellectual property against cyber attacks.


How SCADAfence Discovered Targeted Ransomware In A Pharmaceutical Facility

SCADAfence’s Incident Response team recently assisted a big pharmaceutical company with an industrial cybersecurity emergency. This research has been published with the goal of assist organizations to plan for such events and reduce the impact of targeted industrial ransomware in their networks.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.