The Iranian cybersecurity threat is a good reminder for the energy sector to embrace a prevention mindset – Utility Dive
The following is a contributed article by Benny Czarny, CEO and founder of cybersecurity firm OPSWAT.
President Trump's unexpected and controversial decision to kill Qassim Suleimani, an Iranian Major General in the Islamic Revolutionary Guard Corps, was met with immediate speculation about Iran's capacity to strike back. While opinions differed on the retaliatory timeframe and targets, almost all of the talking heads agreed that America's digital assets, especially those powering critical infrastructure, are at severely heightened risk of cyberattack in this post-Suleimani world.
Iran's cyber capabilities are relatively well-known and improved steadily in the latter part of the 2010s. The Center for Strategic and International Studiesexplains that "years of constant engagement with Israeli and Saudi Arabia have improved Iran's cyber capabilities, and experience with covert action gives Iran the ability to conceptualize how cyberattacks fit into the larger military picture."
A big part of the Iranian cybersecurity threat is its strategic prioritization of high risk, high reward critical infrastructure targets essential to the American way of life. In fact, a new report by Wired revealed that a hacking groupaffiliated with Iran and its proxies has been probing American electric utilities for the past year.
While security analysts don't believe that Magnallium, the identified hacking group backed by Iran, has the ability to break down the front door of a grid's control center, it's clear that the reconnaissance needed to eventually do so is underway, and was even before Suleimani's death.
If there's perhaps one mutually agreed upon benefit to come out of the Suleimani killing,it's the heightened dialogue on critical infrastructure cybersecurity. While U.S. power companies are much more secure now then they were a decade ago, vulnerabilities continue to be identified at the same time threats continue to increase in frequency and sophistication.
That's why as we begin this next decade, the energy industry must prioritize cybersecurity training for employees at every level of their organization and embrace a holistic Zero Trust approach that emphasizes prevention strategies over reactive detection methods.
As public and private enterprises look to new cybersecurity solutions to mitigate the risks, global cybersecurity spending is expected to grow to $133.8 billion by 2022,according to International Data Corporation. The White House's 2020 budget alone includes more than$17.4 billion for cybersecurity-related activities, a 5% increase over 2019.
However, we'll need to do more than throw money at the issue.
The problem lies in the fact the energy sector has become an increasingly attractive target both for nation-states like Iran engaged in geopolitical campaigns as well as profit-motivated criminal syndicates. That's largely due to the fact that much of our nation's energy sector is built upon a tangle of legacy industrial control systems that were intentionally designed as closed, 'air-gapped' systems.
But perhaps the greatest vulnerability is the human element. While many energy companies are addressing remote device and network risks, basic security awareness and training often feels like it lags behind.
As we enter the next decade, executive leadership at energy organizations will need to take a hard look at their existing systems, their security practices, and most importantly, their attitudes towards how they approach cybersecurity.
And because threats can now come from anywhere, any piece of connected technology must be treated as potentially malicious. This is the essence of a "Zero Trust" prevention-first mentality one in which trust is never implied and the legitimacy of every file, every device, and every network connection is always questioned.
All employees be they executives, control engineers or accountants must develop a deeper appreciation that any interaction with technology can open a door to a potential cyberattack. It's imperative that CI organizations prioritize cybersecurity training for all employees, emphasizing that every person who interacts with technology also plays an important role in protecting mission critical infrastructure.
To truly prepare for the increasing sophistication and frequency of cyberattacks targeting energy infrastructure, the burden will rest squarely on the shoulders of executive leadership to take the lead in showing that all employees, regardless of their role or responsibility, are aware that any interaction with technology has the potential to unleash the next Stuxnet, or worse.
What comes from the Suleimani killing from both a cyber and physical perspective remains to be seen. But Iran and its proxies aren't the only cyber threats that America's energy sector will face in the decade to come.
To mitigate risk, energy stakeholders must begin to make the mindset shift from detection to prevention, for once an attack on energy is underway, it could be too late to respond.
View original post here:
The Iranian cybersecurity threat is a good reminder for the energy sector to embrace a prevention mindset - Utility Dive
- Khamenei of Iran Denounces Negotiation With U.S. but Seems to Leave Door Ajar - The New York Times - February 7th, 2025 [February 7th, 2025]
- Iranian supreme leader vows to respond in kind if US acts on threats against Iran - The Times of Israel - February 7th, 2025 [February 7th, 2025]
- Iran supreme leader criticizes proposed nuclear talks with US, upending push to negotiation - The Associated Press - February 7th, 2025 [February 7th, 2025]
- Trump says hes given advisers instructions for Iran to be obliterated if it assassinates him - The Associated Press - February 7th, 2025 [February 7th, 2025]
- Trump Issues Sanctions on Iran, Threatens to Obliterate It if Hes Killed - Truthout - February 7th, 2025 [February 7th, 2025]
- Iran's first drone carrier joins the Revolutionary Guards' fleet - Reuters - February 7th, 2025 [February 7th, 2025]
- As Trump Makes Overtures, Iran Weighs Its Next Move - Bloomberg - February 7th, 2025 [February 7th, 2025]
- Iran is willing to give Trump diplomacy 'another chance', senior Iranian official says - Reuters - February 7th, 2025 [February 7th, 2025]
- Iran daily urges Pezeshkian to respond promptly to Trumps overtures - - February 7th, 2025 [February 7th, 2025]
- How Close Is Iran to a Nuclear Weapon as Trump Eyes a Deal? - Bloomberg - February 7th, 2025 [February 7th, 2025]
- Maximum pressure returns as Iran reacts to Trumps offer of talks - Amwaj.media - February 7th, 2025 [February 7th, 2025]
- UN rapporteur urges Iran to halt imminent execution of Kurdish woman - - February 7th, 2025 [February 7th, 2025]
- Iran has never pursued nuclear weapons, says President Pezeshkian - the voice of vietnam - February 7th, 2025 [February 7th, 2025]
- Iran Unveils Drone Carrier Warship in Threat to US - Newsweek - February 7th, 2025 [February 7th, 2025]
- Study debunks nuclear test misinformation following 2024 Iran earthquake - The Hub at Johns Hopkins - February 7th, 2025 [February 7th, 2025]
- Deep Dive: Syria spillover for Iran moving towards the Caucasus - Amwaj.media - February 7th, 2025 [February 7th, 2025]
- Trump says he wants to negotiate a nuclear deal with Iran after imposing maximum pressure - CNBC - February 7th, 2025 [February 7th, 2025]
- Iran says verifying its nuclear programme is an 'easy task' - Reuters - February 7th, 2025 [February 7th, 2025]
- Trump Torpedoed the Iran Nuclear Deal. Now Hes Calling for Another One. - The New York Times - February 5th, 2025 [February 5th, 2025]
- Iran praises US for cutting foreign aid funding as it looks for a Trump message on nuclear talks - The Associated Press - February 5th, 2025 [February 5th, 2025]
- Iran calls for OPEC to unite against potential US oil sanctions - Reuters - February 5th, 2025 [February 5th, 2025]
- Denying US and Israel are planning a strike, Trump says he wants a deal with Iran - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Sharper: Iran and the Axis of Upheaval - Center for a New American Security - February 5th, 2025 [February 5th, 2025]
- Donald Trump signals wish to hold talks with Iran over nuclear deal - The Guardian - February 5th, 2025 [February 5th, 2025]
- Iran says its foreign policy driven by interests after Trump voices readiness to talk - Reuters - February 5th, 2025 [February 5th, 2025]
- Denying Iran All Paths to a Nuclear Weapon: Trump Reimposes Maximum Pressure Against Tehran - Foundation for Defense of Democracies - February 5th, 2025 [February 5th, 2025]
- Trump Has a Rare and Short Window to Solve the Iran Problem Heres How - War On The Rocks - February 5th, 2025 [February 5th, 2025]
- Trump reimposes 'maximum pressure' on Iran, aims to drive oil exports to zero - Reuters - February 5th, 2025 [February 5th, 2025]
- Trump signs memo aiming to block Iran from achieving nuclear weapon - Reuters - February 5th, 2025 [February 5th, 2025]
- Donald Trump Reveals Dead-Man's Switch in Case of Iran Assassination - Newsweek - February 5th, 2025 [February 5th, 2025]
- Trump reimposes 'maximum pressure' on Iran, aims to drive oil exports to zero - VOA Asia - February 5th, 2025 [February 5th, 2025]
- Exclusive: US 'aware' of reports Iran trying to ship missile propellant chemical from China - VOA Asia - February 5th, 2025 [February 5th, 2025]
- Trump Restores Maximum Pressure on Iran - The American Conservative - February 5th, 2025 [February 5th, 2025]
- Shukriya Bradost on the Kurds Struggle in Iran - Middle East Forum - February 5th, 2025 [February 5th, 2025]
- Iran welcomes Trumps foreign aid cuts as both sides hint at nuclear negotiations - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Peace through strength when it comes to supporting Israel and confronting Iran - JNS.org - February 5th, 2025 [February 5th, 2025]
- Trump says reports hes working with Israel to blow Iran into smithereens are greatly exaggerated - New York Post - February 5th, 2025 [February 5th, 2025]
- What a second round of maximum pressure Iran sanctions means for shipping - Lloyd's List - February 5th, 2025 [February 5th, 2025]
- US believes Iran looking at potential ways to quickly build nuclear bomb report - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Trump pressure on Iran positive for VLCC rates but with lag effect - Lloyd's List - February 5th, 2025 [February 5th, 2025]
- Iran reformists urge concessions in attempt to reconnect to west - The Guardian - February 5th, 2025 [February 5th, 2025]
- Iran foreign minister: attacking our nuclear sites would be 'one of biggest mistakes US could make' - Reuters.com - February 5th, 2025 [February 5th, 2025]
- Iran's new-found pragmatism in the face of Trump - Le Monde - February 5th, 2025 [February 5th, 2025]
- Trump calls for 'nuclear peace agreement' with Iran rather than blowing country 'to smithereens' - Fox News - February 5th, 2025 [February 5th, 2025]
- Trump orders Iran to be obliterated if it kills him, but open to meeting its leader - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Trump calls for work on new Iran nuclear deal to begin 'now' - The New Arab - February 5th, 2025 [February 5th, 2025]
- Paul Mauro: Trump is putting Iran back in a box where they belong - Fox News - February 5th, 2025 [February 5th, 2025]
- Trump, Netanyahu to discuss war in Gaza, along with Iran, Arab relations - VOA Asia - February 5th, 2025 [February 5th, 2025]
- 2 IDF reservists, one of them in Iron Dome unit, arrested on suspicion of spying for Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- On GPS: Is Iran weaker than ever? - CNN - January 27th, 2025 [January 27th, 2025]
- Bolton: there is no question in my mind Iran may take action against me - MSNBC - January 27th, 2025 [January 27th, 2025]
- Is Iran inching closer to recognizing Taliban rule in Afghanistan? - Amwaj.media - January 27th, 2025 [January 27th, 2025]
- Online gold platforms thrive in Iran as economic pressures mount - - January 27th, 2025 [January 27th, 2025]
- Who is John Ratcliffe, the Iran hawk heading the CIA? - - January 27th, 2025 [January 27th, 2025]
- Iran says weighing Trump factor, insists on nuclear talks only | Iran International - - January 27th, 2025 [January 27th, 2025]
- 2 IDF reservists, one of them from Iron Dome unit, arrested on suspicion of spying for Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- Iran's judiciary denies release of convicted tycoon Babak Zanjani - - January 27th, 2025 [January 27th, 2025]
- Israel boosts F-16s with $80M upgrades amid rising tensions with Iran - The Jerusalem Post - January 27th, 2025 [January 27th, 2025]
- US ties crucial for Iraq, separate from relations with Iran, says Iraqi FM - Kurdistan24 - January 27th, 2025 [January 27th, 2025]
- Trump urged to rethink nixing security for US ex-officials under threat from Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- Iraq Is a Key Test of Trump's Willingness to Counter Iran - Business Insider - January 27th, 2025 [January 27th, 2025]
- In Iran, One-Third of Patients Refrain from Purchasing Medication - Iran Focus - January 27th, 2025 [January 27th, 2025]
- Iran News: Iranian Arms Smuggling to Hezbollah Disrupted Amid Growing Tensions in Syria - National Council of Resistance of Iran (NCRI) - January 27th, 2025 [January 27th, 2025]
- BCFIF Calls on UK to Act Against Imminent Executions of Political Prisoners in Iran - Iran News Update - January 27th, 2025 [January 27th, 2025]
- Trump Revokes Security Detail for Pompeo and Others, Despite Threats From Iran - The New York Times - January 26th, 2025 [January 26th, 2025]
- How Iran Lost Before It Lost: The Roll Back of Its Gray Zone Strategy - War On The Rocks - January 26th, 2025 [January 26th, 2025]
- Iran's foreign minister meets the Taliban in the first visit to Kabul in 8 years - ABC News - January 26th, 2025 [January 26th, 2025]
- Iran Review - 48th Session of Universal Periodic Review - Welcome to the United Nations - January 26th, 2025 [January 26th, 2025]
- New Russia-Iran Treaty Reveals the Limits of Their Partnership - Carnegie Endowment for International Peace - January 26th, 2025 [January 26th, 2025]
- How quickly could Iran build its first nuclear weapon? Look at China - Bulletin of the Atomic Scientists - January 26th, 2025 [January 26th, 2025]
- Mastermind of Iran's US influence effort appointed head of ministry think tank - - January 26th, 2025 [January 26th, 2025]
- Iran is 'pressing the gas pedal' on uranium enrichment, IAEA chief says - Reuters - January 26th, 2025 [January 26th, 2025]
- Trump said set to appoint Steve Witkoff to manage Iran nuclear file - The Times of Israel - January 26th, 2025 [January 26th, 2025]
- Donald Trump ("Abu Ivanka") and the Gulf States Vs. Iran - The Globalist - January 26th, 2025 [January 26th, 2025]
- Trump to appoint Steve Witkoff as Iran envoy: Report - Anadolu Agency | English - January 26th, 2025 [January 26th, 2025]
- Trump says Iran deal would be 'really nice', bucks hawks - The New Arab - January 26th, 2025 [January 26th, 2025]
- Trump says he hopes not to have to support Israeli attack on Iran - - January 24th, 2025 [January 24th, 2025]
- Trump: Would be nice to solve problems with Iran without Israeli strikes - The Times of Israel - January 24th, 2025 [January 24th, 2025]
- From Iran to European nations: What does the world expect from Trump? - Israel Hayom - January 24th, 2025 [January 24th, 2025]
- The Farda Briefing: Iran Talks Tough But Signals Openness For Negotiations With U.S. - Radio Free Europe / Radio Liberty - January 24th, 2025 [January 24th, 2025]