CyberSecurity SEE

UK Government Hesitant About Power Plant Cyberattack

UK Government Hesitant About Power Plant Cyberattack

Critical Infrastructure Security,
Geo Focus: The United Kingdom,
Geo-Specific

Government Tight-Lipped Over Possible Iranian Hack, Experts Complain

UK Government Hesitant About Power Plant Cyberattack
Power lines on the Kent coast in the southeast of England. (Image: Jevanto Productions/Shutterstock)

In recent developments, leaders in operational technology security have urged the British government to disclose the technical details surrounding a cyberattack that incapacitated a small power plant for four consecutive days last month. Despite the rising concerns, the government has maintained a notable silence on this issue.

Markus Mueller, the field CISO at Nozomi Networks, an operational technology security firm, expressed frustration over the government’s lack of communication. He remarked that public statements have been “very limited,” and voiced hope for a more comprehensive disclosure soon.

Experts have pointed to the Polish national Computer Emergency Response Team as a model for transparent reporting. In the wake of a sophisticated three-pronged attack last year on their energy grid, attributed to Russian hackers, Poland’s CERT published an extensive technical breakdown of the incident. “That’s the gold standard now for what good reporting looks like,” Mueller noted, indicating that the British government could benefit from adopting a similar approach.

Contrastingly, the British government has refrained from providing detailed insights about the attack. Speculations suggest that the breach originated from an exposed programmable logic controller (PLC), a crucial component in the automation of industrial processes. However, this information has not been officially confirmed. Mueller stated, “We’ve heard reports that the attack path was an exposed PLC, but we haven’t heard that from a government or official source.” PLCs are instrumental in controlling mechanisms within industrial environments, ranging from motors to water treatment systems.

Such ambiguity in public communication seemed to be designed to mitigate public anxiety, with Energy Minister Michael Shanks emphasizing that the targeted facility was a “tiny” operation, especially when considering conventional power plants. Shanks further clarified that government officials had been briefed, and additional advice had been provided to energy sector CEOs concerning security measures.

A spokesperson from the British government also indicated that GCHQ, the U.K.’s equivalent to the U.S. National Security Agency, had participated in these briefings. Reports suggest that the attack was orchestrated by a group known as the Cyb3rAvengers, which is reportedly connected to the Iranian Revolutionary Guard Corps.

Donald McFarlane, who sits on the advisory board for Xcape, Inc., a managed IT and security services provider, echoed the call for additional clarity. He emphasized the need to understand the specifics of the attack path, the elements affected within the operational technology framework, and whether the PLC involved had been exposed to the internet. McFarlane criticized the vague official statements, noting that it remained unclear whether the operational technology infrastructure had been breached or if the plant was simply shut down as a defensive measure following an IT compromise.

“Don’t tell me this was historic and then redact the history,” he asserted, calling for the government to adopt a more transparent communication strategy.

McFarlane further urged the U.K. to follow the lead of the United States, where the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) frequently issues cybersecurity advisories relevant to operational technology attacks. He pointed out that these advisories provide much-needed insights into tactics, techniques, and procedures (TTPs) used in such attacks, which can assist operators in better understanding how to bolster their defenses.

According to Denis Calderone, the CTO of cybersecurity firm Suzu Labs, the attack likely targeted a “peaker plant,” a smaller facility designed to supplement power supply during periods of high demand. He noted that while size might not indicate a facility’s security level, attackers often seek vulnerabilities in smaller operations that may lack robust defenses. “A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor,” he said in an email response.

The U.K.’s Daily Telegraph reported that the targeted facility remained below the wattage threshold, which would require operators to report any cyber incidents, underscoring the possible oversight of such smaller establishments.

In conclusion, the lack of detailed communication from the British government regarding this cyberattack raises concerns about national security and the resilience of critical infrastructure. As debate on effective cybersecurity practices continues, experts and authorities alike may need to reassess their approaches to information sharing and transparency, particularly as it relates to the protection of vital utility sectors.

Source link

Exit mobile version