Few, if any, of the industrial control systems used today were designed with cybersecurity in mind. Meanwhile, Australia's critical information infrastructure has never been more vulnerable . . .
It took no more than a simple engineering error, a software malfunction and a communication failure to cause the largest blackout the world has ever seen - the massive power outage that hit 40 million people in eight US states and 10 million people in Ontario, Canada, on August 14, 2003.
Terrorists, schmerrorists. Bin Laden or his cohorts might have wet dreams about bringing the West to its knees, but it was a failure of the IT folks assigned to fixing the energy management system to speak to the operations folks, that helped cost the US and Canadian economies more than $US30,000 million.
And the bad news is, much of both Australia's and the United States's critical infrastructure may be every bit as vulnerable to such happenstance today - let alone concerted terrorist attack - and will remain so as long as CIOs fail to take the time to investigate and fully understand their organizations' vulnerabilities, particularly within the supervisory control and data acquisition (SCADA) and energy management system (EMS) operational networks now interconnected with IT.
So at least says the man who delivered the keynote address at the Geospatial Information & Technology Association's GITA 2004 Conference in Melbourne last August - Dick Lord, CEO of the Steadfast Group. Lord, a member of the US Department of Energy Office of Electric Transmission and Distribution Blackout Forum, says in the past such operational systems worked in isolation. Nowadays they are linked in a variety of ways to the business IT network. "That places them clearly under the purview of the CIO," Lord says. "But how many CIOs have taken the effort and time to grasp an understanding of how those systems work?
"I'm an electrical engineer and I spent much of my earlier career in the SCADA/EMS world. My former operational colleagues don't understand IT any better than IT folks understand SCADA/EMS. We have to remedy that," Lord says.
Infrastructures are inextricably interrelated, Lord points out. If the electricity fails, then reservoir water pumps cease to work. If telecommunications fail then operators in different companies or locations cannot communicate in an emergency. One water company in the US went to great lengths to ensure several sources of water for a city, only to leave itself vulnerable because the pumps were serviced by a single power feed that ran through the desert. And the human effort can undo the best laid critical infrastructure protection plans, as in the case of the US control room that installed complex security at the front door, only to be undone by controllers wedging the back door open so they could go outside to smoke.
When the Russian mafia can reportedly "crash" Telstra's Alice Springs local network, leaving a city of 23,000 people without e-mail for more than five hours in an apparent case of net blackmail - as they did in September - the vulnerabilities should be enough to strike fear into the heart of any self-respecting CIO.
Suddenly, what the Americans have taken to calling homeland security or critical infrastructure protection (CIP) is firmly within the purview of the CIO. Suddenly, says enterprise security firm Symantec CEO John Donovan, the CIO has been elevated to this role of protecting something greater than the IT aspects of the organization.
"I hate to reference September 11, but it's a constant point of reference, in that that was the time when there was this fundamental change in the philosophy over what the role should be for the CIO within organizations," Donovan says. "That was probably the point, even though it didn't actually change the threat landscape, when a lot of organizations saw there was a connection between information security, critical infrastructure and their company.
"And I guess what people realized was the obvious thing: The private sector is actually responsible for greater than 50 percent of the critical infrastructure."
Indeed many once public utility networks are now in private hands. The outsourcing of critical infrastructure and mission critical information services once solely the responsibility of government has only heightened the risk. Since Telstra operates an extensive network of coaxial cable, microwave radio, optical fibre, digital radio concentrators, mobile phone cells, submarine cables and submarine fire cables, just about all of Australia's telecommunications interconnect at some point with Telstra's infrastructure. Yet the Senate inquiry into the Australian telecommunications network has pointed to the inherent risk to service standards in the neglect and inevitable decay of that infrastructure. They complain that far from infrastructure protection being an issue, Telstra - which has seemed to be intent on reducing capital expenditure and boosting bottom line profits in preparation for privatization in recent times - has trouble keeping its services going in heavy rain.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Enterprise Wireless WLAN Security
Achieving the impossible: Unlimited application scalability
Security Inside Out
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Solve Exchange Mailbox Storage Issues Once and for All
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Email Archiving 101—Customer Case Study
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
- White PaperWhat you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.
- White PaperJoin Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00
Texas uni announces the Institute for Cyber Security.The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state. - +
Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00
Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions. - +
International Challenges in PCI Security 20 November, 2008 09:15:00
In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective. - +
PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00
Quality assurance plan targets security assessors and scanning vendorsThe PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
Vignette Announces 2008 Excellence Awards 21 November, 2008 10:50:00
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 20 November, 2008 17:34:00
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 20 November, 2008 12:06:00
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 20 November, 2008 12:04:00
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 20 November, 2008 12:02:00
|
||
|
||
|
|
||
|
Radicati Market Quadrant 2008 on Corporate Web Security
An Analysis of the Market for Corporate Web Security Solutions, revealing Top Players, Mature Players, Specialists and Trail Blazers. Read on to discover who makes the grade.














