Cybersecurity for operational technology: Part 3

Issue 7 2021 Information Security, Industrial (Industry)


Bryan Baxter.

According to a recent World Economic Report, the Covid-19 pandemic has increased our reliance on the global supply chain, while the Internet has accelerated the digitisation of business processes(1). To remain competitive, manufacturing companies are increasing their reliance on suppliers to help adopt 4IR innovations such as artificial intelligence, machine learning, IoT and big data.

This has exponentially increased risks from a cybersecurity perspective. As supply chains have become integrated, interconnected and increasingly complex, supply chain cyber-attacks are on the increase as they are very effective. Suppliers are most likely the second or third biggest risk in terms of cybersecurity.

The SolarWinds hack

A supply chain attack targets third-party suppliers who already have access to their customers’ systems. This is easier than trying to hack customers’ systems directly. This is effective as it hides the malware inside trusted software which is then distributed to thousands of customers.

A recent example is the SolarWinds hack, one of the largest ever recorded cyber-attacks(2). SolarWinds provides tools for thousands of organisations to monitor their IT networks and infrastructure systems. Early in 2020, hackers used an inadvertently sent out software update to customers that included the hacked code(3). The exploit created a backdoor through which hackers could gain access to customers’ IT systems.

Hackers could then access system files, exfiltrate or alter data and impersonate user accounts. The backdoor could also be used to install more malware, allowing them to escalate and maintain their hold on IT systems. The malware went undetected for months. This affected up to 18 000 customers, including critical agencies in the US government. More than 80% of the targets were Fortune 500 companies, i.e. Microsoft, Cisco, Intel and Deloitte.

This was a complex attack and required material resources. Nation-state hackers are believed to have been responsible, i.e. Russia’s Foreign Intelligence Service, known as the SVR. The real danger to enterprises is that once this approach has been used, it is out in ‘the wild’ and can be re-used or modified by other groups with far fewer resources.

Supply chain attacks are only one of the cyber risks from third-party suppliers. Here are a few more to take note of:

• New vendors and technologies are emerging all the time. IoT devices are a major concern as the focus is mass-producing low-cost connected devices, not protecting customers from cybersecurity threats.

• Support staff accessing your systems on-site or remotely with insecure connections or devices. This can introduce malware or open your systems to new vulnerabilities.

• Insecure software development can result in software being installed that can be easily exploited. This is especially risky with Internet-facing systems.

• Improperly trained support staff who neglect to apply basic security configurations.

• Insecure configurations of cloud and or software as a service are also common.

Assessing the risks

Regular risk assessments need to be conducted on third-party providers to address all the potential risks that they can introduce to your organisation. This will identify, assess, measure and monitor any risks associated with the relationship. The next step is to implement mitigating controls to address the risks. Third-party providers need to be effectively managed throughout the whole ‘vendor lifecycle’, from selection and on-boarding to off-boarding. Suppliers need to be challenged about their approach to cybersecurity and what security certifications and frameworks they have adopted. If they develop software or are a cloud or SaaS provider, they should have mature, secure development processes and apply cloud security principles(4).

Secure development applies fundamental, sound and secure software development practices based on established best-practice documents from organisations such as BSA, OWASP and SAFECode(5). If they do not have anything in place, they should commit to a prioritised roadmap to improve their cybersecurity posture.

Procurement and IT should build a cyber-reputation scorecard and avoid suppliers with a poor record. This will require effective and regular threat intelligence. Threat intelligence is information that helps organisations understand, identify, prevent and respond to security threats(6). Supplier contracts should be updated to address cybersecurity and introduce penalties if breaches result from negligence.

Targeted cybersecurity training should be conducted for OT and procurement staff. Adopting a best-practice cybersecurity framework is important. This provides an holistic view of what is needed and will help establish your organisation’s current level of maturity and provide a roadmap for improvement going forward. This will be covered in detail in the next article.

For more information contact Bryan Baxter, Wolfpack Information Risk, +27 82 568 7291, [email protected], www.wolfpackrisk.com

References

(1) WEF, 2021 Advancing Supply Chain Security in Oil and Gas: An Industry Analysis http://www3.wweforum.org/docs/WEF_Advancing_Supply_Chain_Security_in_Oil_and_Gas_2021.pdf

(2) Business Insider, 2021 - The US is readying sanctions against Russia over the SolarWinds cyber attack. Here’s a simple explanation of how the massive hack happened and why it’s such a big deal, https://www.businessinsider.com/solarwinds-hack-explained-government-agencies-cyber-security-2020-12?IR=T

(3) Chatham House, 2021 - The SolarWinds hack: A valuable lesson for cybersecurity, https://www.chathamhouse.org/2021/02/solarwinds-hack-valuable-lesson-cybersecurity?gclid=EAIaIQobChMIhOT948Lp8gIVGqd3Ch0fTw0_EAAYBCAAEgJjZvD_BwE

(4) Cloud Security Alliance, https://cloudsecurityalliance.org/

(5) NIST, 2021 - Secure Software Development Framework, https://csrc.nist.gov/projects/ssdf

(6) ZeroFOX, 2021 - What is External Threat Intelligence, https://www.zerofox.com/blog/what-is-external-threat-intelligence/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...