• 2 days Shell Oil Trading Head Steps Down After 29 Years
  • 3 days Higher Oil Prices Reduce North American Oil Bankruptcies
  • 3 days Statoil To Boost Exploration Drilling Offshore Norway In 2018
  • 3 days $1.6 Billion Canadian-US Hydropower Project Approved
  • 3 days Venezuela Officially In Default
  • 3 days Iran Prepares To Export LNG To Boost Trade Relations
  • 3 days Keystone Pipeline Leaks 5,000 Barrels Into Farmland
  • 3 days Saudi Oil Minister: Markets Will Not Rebalance By March
  • 3 days Obscure Dutch Firm Wins Venezuelan Oil Block As Debt Tensions Mount
  • 4 days Rosneft Announces Completion Of World’s Longest Well
  • 4 days Ecuador Won’t Ask Exemption From OPEC Oil Production Cuts
  • 4 days Norway’s $1 Trillion Wealth Fund Proposes To Ditch Oil Stocks
  • 4 days Ecuador Seeks To Clear Schlumberger Debt By End-November
  • 4 days Santos Admits It Rejected $7.2B Takeover Bid
  • 4 days U.S. Senate Panel Votes To Open Alaskan Refuge To Drilling
  • 4 days Africa’s Richest Woman Fired From Sonangol
  • 5 days Oil And Gas M&A Deal Appetite Highest Since 2013
  • 5 days Russian Hackers Target British Energy Industry
  • 5 days Venezuela Signs $3.15B Debt Restructuring Deal With Russia
  • 5 days DOJ: Protestors Interfering With Pipeline Construction Will Be Prosecuted
  • 5 days Lower Oil Prices Benefit European Refiners
  • 5 days World’s Biggest Private Equity Firm Raises $1 Billion To Invest In Oil
  • 6 days Oil Prices Tank After API Reports Strong Build In Crude Inventories
  • 6 days Iraq Oil Revenue Not Enough For Sustainable Development
  • 6 days Sudan In Talks With Foreign Oil Firms To Boost Crude Production
  • 6 days Shell: Four Oil Platforms Shut In Gulf Of Mexico After Fire
  • 6 days OPEC To Recruit New Members To Fight Market Imbalance
  • 6 days Green Groups Want Norway’s Arctic Oil Drilling Licenses Canceled
  • 6 days Venezuelan Oil Output Drops To Lowest In 28 Years
  • 6 days Shale Production Rises By 80,000 BPD In Latest EIA Forecasts
  • 7 days GE Considers Selling Baker Hughes Assets
  • 7 days Eni To Address Barents Sea Regulatory Breaches By Dec 11
  • 7 days Saudi Aramco To Invest $300 Billion In Upstream Projects
  • 7 days Aramco To List Shares In Hong Kong ‘For Sure’
  • 7 days BP CEO Sees Venezuela As Oil’s Wildcard
  • 7 days Iran Denies Involvement In Bahrain Oil Pipeline Blast
  • 9 days The Oil Rig Drilling 10 Miles Under The Sea
  • 10 days Baghdad Agrees To Ship Kirkuk Oil To Iran
  • 10 days Another Group Joins Niger Delta Avengers’ Ceasefire Boycott
  • 10 days Italy Looks To Phase Out Coal-Fired Electricity By 2025
Alt Text

Can Oil Majors Continue To Beat Estimates?

As oil prices claw their…

Alt Text

EU Aims To Reform World’s Biggest Carbon Market

The European Union is divided…

Ronke Luke

Ronke Luke

Ronke Luke has experience advising senior executives (including at the ministerial level) on initiatives to develop and increase uptake of advanced energy and environmental technologies…

More Info

Successful Cyber Attack In Ukraine Raises Fears Of Further Threats

Successful Cyber Attack In Ukraine Raises Fears Of Further Threats

It’s finally happened. A theoretical major scenario that has worried governments and industry in U.S. and Western Europe has occurred. Power was cut, through a hacker attack, to up to 80,000 customers in Ukraine’s Ivano-Frankivsk region for several hours on December 23, 2015.

Security firm ESET has identified known malware - “BlackEnergy” - as the probable cause. Per, ESET several Ukrainian electricity distribution companies were targeted in the December attack.

Ukraine immediately pointed the finger at Russia. iSIGHT Partners ties SandWorm, the group behind BlackEnergy, to Russia, but no links to the Russian government or specific organizations have yet been made.

The success of this cyber attack on electricity infrastructure raises the stakes and has security and intelligence experts worried.

Two concerns about the Ukraine attacks are first that malware was able to compromise industrial controls, and second the BlackEnergy Trojan appears to have been delivered simply through a spear-phishing email containing compromised Microsoft Office attachments. When one or more email recipients opened the attached Microsoft files, the malicious code executed.

As office automation and industrial control systems have converged, the vulnerabilities of unprotected SCADA and other systems increase. In Europe, the push to adopt smart meters has introduced new weaknesses into power systems.

It is unclear how malicious code delivered through the Ukrainian utilities’ business IT systems affected the industrial controls leading to the power failures. U.S. Department of Homeland Security’s (DHS) ICS-CERT issued an alert that named GE’s Cimplicity HM product, a known vulnerability since 2012, as the “probable initial infection vector for systems running GE’s Cimplicity HMI with a direct connection to the Internet.” Per DHS, GE issued guidance for remediating the flaw in 2013. It’s unclear if any of the Ukrainian utilities had Cimplicity or had fixed the vulnerability. Related: Crashing Oil Prices And Dropping Rig Count Take Their Toll On U.S. Output

So could such an attack happen in the U.S. or Western Europe? Theoretically, yes.

The U.S. government and industry has focused on hardening the power grid and other critical infrastructure. The country is more secure than in 2007 when the threat potential was first demonstrated in a test.

In November 2015, the U.S. completed GridEx III - its third simulated exercise of physical and cyber attacks on U.S. electricity infrastructure. Nearly 10,000 individuals and 315 organizations including power generators, transmission firms, and government and law enforcement agencies participated in the two day test. A public report is expected in January 2016.

But the government has taken note of the Ukraine hack attack. Per Reuters, The Electricity Information Sharing and Analysis Center (E-ISAC), a U.S. government – industry organization, last week issued an advisory describing the Ukraine black out as the result of "coordinated effort by a malicious actor" and urging its members to "do a better job at implementing multiple layers of defense against potential cyber attacks.” Related: Rig Count: Capitulation?

The UK’s Chancellor of the Exchequer, George Osborne, announced in November 2015 that his country would spend £1.9 billion over five years to build new cyber defenses and offensive capabilities. In his remarks to GCHQ, one of the country’s intelligence agencies, Osborne made note of the need to protect the U.K.’s electricity infrastructure stating that "If the lights go out, the banks stop working, the hospitals stop functioning or government itself can no longer operate, the impact on society could be catastrophic."

Executives prefer to invest in power delivery capabilities and services. Cyber investments, which compete against other capital expenditures, are rather like insurance, however. A utility that suffers a catastrophic cyber attack could face a high bar to explain that it invested sufficiently against a known risk.

Utilities in Europe and the U.S. have been ramping up their protections, but events in Ukraine suggest they may have to pick up their pace, or at a minimum retest the robustness of what they’ve done to-date. Since 2011, the SEC has required U.S. publicly traded firms to disclose cyber incidents and risk. Related: Shocking: ISIS Attacks On Libyan Oil Facilities Visible from Space

It would be surprising if C-Suites and Boardrooms are not taking a second look.

iSIGHT Partners reports that SandWorm has been targeting NATO; U.S. and European government organizations; U.S. academic organizations; and European telecom and energy sector with BlackEnergy. With the success in Ukraine’s power sector, it will likely continue to probe. Utilities are keen to stay ahead of such determined cyber adversaries.

As typically happens after a cyber breach, cyber product vendors and service firms are probably in high demand as companies rush to check and patch all known vulnerabilities. Vendors don’t have a hard sell to showcase new solutions and services. As the Ukraine episode demonstrates, humans can be the weakest link in the cyber security. Insufficient cyber-related education for staff in the utility sector has been noted as a weakness. Firms that offer solutions (training, technology and services) that limit the potential havoc of seemingly innocent employee actions such as inadvertently opening malicious emails should find an eager, welcome audience.

By Ronke Luke of Oilprice.com

More Top Reads From Oilprice.com:

Back to homepage

Leave a comment

Leave a comment

Oilprice - The No. 1 Source for Oil & Energy News