Cyber security: the risk is real
It has never been more important to protect against threats to cyber security, as this round up of the issues by Charlotte Stonestreet highlights
For any consumer of main stream media, recent events involving the poisoning of former Russian spy Sergi Skripal and his daughter on British soil, in addition to the ensuing diplomatic crisis and deteriorating relationship between Britain and Russia, one of the main issues that has been highlighted is fears of a high-risk cyber attack targeting the UK’s critical infrastructure. According to reports the National Cyber Security Centre (NCSC), a branch of intelligence agency GCHQ, has issued advice to key organisations on boosting security and improving cyber defences. This this follows the NCSC’s recent assertion that the Russian military was “almost certainly” responsible for the ‘NotPetya’ attack in June 2017, which affected Ukraine’s financial, energy and government institutions, and the Trump administration’s accusations that Russia has engineered a series of cyber-attacks targeting US and European nuclear power plants and water and electricity systems.

For those readers who do not operate in the critical water, power or healthcare sectors, all this might seem a world away from your own operation. However, high profile news stories such as this do serve to shine a spotlight on the issue and while the national press might revel in portraying the worse case scenario for the country as a whole, if your operation was subject to a cyber attack would it really be any less devastating on a business level?
And when it comes to cyber security, the risk is only ever going to increase as levels of connectivity increase exponentially across the industrial sector. Indeed, according to a new report by the Institution of Mechanical Engineers, the UK needs to build new levels of resilience and reliability into its electricity networks, including protection against hackers, to support the country’s increasingly digital infrastructure.
The Smart Cities: Technology Friend or Foe? report outlines how in our increasingly digital age, any power cuts could jeopardise our communications, transport, security surveillance, heating, cooling, lighting, water, food supplies and, in an increasingly cashless world, trading.
According to the report, energy companies globally experience about 66 million cyber security events annually, which is 25% more than typical in other industries, and about 90% of published vulnerabilities are medium to high risk.
The Institution is calling on UK Government to urgently look at the demand and reliability of power infrastructure and the requirements of digitally integrated cities.
Dr Colin Brown, director at the Institution of Mechanical of Engineers, said: “As we become more reliant on digital infrastructure, we are becoming more dependent on our electricity network. This means it has never been more important to ensure we have secure and reliable electricity supplies, robust enough to withstand threats from potential hackers and resilient to our changing climate.
{EMBED(960077)}
“We have already seen major hacks of power plants and electricity networks in USA in 2003, when a nuclear power plant in Ohio was disabled by hackers, and more recently in 2015 in the Ukraine where a cyber-attack caused a grid outage which affected 225,000 people. On a grand scale hacks on our electricity networks could lead to chaos and looting of the sort we saw from natural causes in Texas and Florida in the aftermath of Hurricanes Harvey and Irma.
“In order to keep critical infrastructure, transport, communications, security surveillance and working, we need an electricity system which in the future will continue to be reliable 24 hours, 365 days a year. In the coming years, even relatively short interruptions to supply will potentially lead to substantial economic and social problems.”
White noise & targeted attacks
ABB’s Ragnar Schierholz, Head of Cyber Security, ABB Industrial Automation identifies two distinct types of cyber-attack; generic or “white noise” and targeted or “advanced persistent threat”.
{EMBED(960078)}
Both white noise and targeted attacks commonly manifest themselves through the Internet or Enterprise IT network or personal devices and affect the operational technology (OT). Attacks usually start with phishing or perimeter compromise. General attacks come in the form of generic malware from the IT world which exploit system vulnerabilities, usually at Level 5 to Level 3. Targeted attacks come in the form of custom malware designed specifically to target a certain environment and can cut across the control infrastructure from Level 5 to Level 1.
While the consequences of a white noise attack can be limited to moderate damage and as such receive little or no public attention, targeted attacks can have a wider impact and attract much public attention. However, white noise attacks occur at much higher frequency, so the aggregated impact of these is considerable as well.

In March 2017, Microsoft released a patch to fix a vulnerability in one of the internet’s most ancient networking protocols, Server Message Block version 1 (SMBv1) which was reported to them by the NSA after detection of a leak. A month later, the hacker group called The Shadow Brokers released Eternalblue, an exploit for the SMBv1 vulnerability as part of a larger set of attack tools.
Then in May 2017 the WannaCry ransomware outbreak was reported and quickly spread over hundreds of thousands of computers. It targeted computers running the Microsoft operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency of $300 per computer.
The ransomware spread autonomously using the Eternalblue exploit and the SMBv1 vulnerability. A security researcher found a “kill switch” which slowed down the infection rate substantially. However, according to Europol, over 200,000 computers were infected across 150 countries. Nissan Motor Manufacturing in the UK and Renault in France both halted production in an attempt to stop the spread of the ransomware.
Those that were unprepared for an attack left themselves exposed as they were unaware of the status of patches. Many were unwilling to patch a live system or were intimidated by the patch process. The result was that those who fell a year behind were hundreds of patches adrift of a secure system. When the ransomware hit, questions ranged from “Shall we pay?” to “Do we have a backup?” Those organizations that had prepared were simply not affected in any way.

On June 27 2017 a ransomware campaign started in the Ukraine. Initial analyses conclude that it was a member of the Petya family of ransomware and that it is using a modified version of the Eternalblue exploit as well as by credential harvesting on infected hosts. Further analysis by Kaspersky concluded that the similarity to Petya is only superficial, introducing the name NotPetya. A vaccine file is identified which, if found, reportedly causes the ransomware to exit before encrypting any files. The German e-mail provider used in the payment scheme shuts down the e-mail account used for violation of policy. Analyses of the malware and reports from victims indicate that there is no way to decrypt the files encrypted by NotPetya, concluding that it is in fact not a true ransomware but rather a wiper intended for sabotage, disguised as ransomware.
Holistic approach
At Pilz Automation Technology, machinery safety specialist, David Collier highlights the how today’s connected industrial landscape increasingly necessitates looking at machinery safety and cyber security in a holistic manner. In order to respond flexibly to the prevailing threat scenario, there must says Collier be a comprehensive security strategy comprising multiple layers to underpin the protection of safety applications: the core comprises the automation components. This is followed by the network via which these components can communicate with other networks or with an ERP (enterprise resource planning) system, for example. The outermost layer represents the factory, which is shielded from the outside world by a special firewall concept, which creates a so-called demilitarised zone.

The demands that the spheres of IT and automation place on security vary considerably. While the confidentiality of information enjoys top priority in the office environment, in the production sphere data availability comes top of the list because this is a key prerequisite for smooth production processes. The international standard IEC 62443 is designed to bring both security worlds together.
{EMBED(960084)}
For networking, “defence in depth” is recommend. The “zones and conduits” security model is defined in the standard IEC 62443. It envisages dividing an automation network up into different zones in which devices are allowed to communicate with each other. Exchanges of data with devices in other zones are only possible via a single conduit that is guarded by a secure router or a firewall and blocks all irrelevant information.
Another protective measure for safety applications involves arming the safety systems against cyber attacks. The communication data in question has already been subject to multiple safety checks upon transmission and an assortment of methods are used so that manipulation attempts can be identified far sooner by the safe end devices than with other methods of communication. But that alone is not enough. Pilz therefore also continues to work on the security aspect of its products. Aspects such as threat scenarios, strengths and weaknesses of protocols or encryption methods are taken into consideration from the outset.
Paradigm shift
Another company advocating a holistic approach to safety and cyber security is HIMA, where Dr. Alexander Horch, Vice President Research, Development & Product Management, argues that safety-oriented automation solutions in industrial plants must now encompass more than just safe emergency shutdown (ESD); they must also provide effective protection against cyber attacks. This leads to a paradigm shift: Previously, automated systems only had to be designed for safety and then simply checked periodically to verify the initially defined risk reduction. In the future, safety solutions must be regularly adjusted and extended in the interest of security.
Rapidly growing and increasingly professional cyber criminality compels both manufacturers of safety solutions and their users in the process industry to pursue proactive cybersecurity policies and establish integral safety concepts. As part of risk assessment, says Horch,plant operators must weigh the financial expenditures for effective safety and security concepts against the costs of potential shutdowns, which can easily run into the millions. The money invested in cybersecurity, usually only a fraction of the cost of a shutdown, is not wasted – instead, it safeguards the productivity of the entire plant.
As a user, you can opt for the best possible defense by using safety instrumented systems with the fewest possible vulnerabilities. For example, a dedicated operating system specifically developed for safety-oriented applications runs on HIMA’s autonomous SIS controllers. It includes all functions of a safety PLC and omits all other unnecessary functions. There are no software components from third-party software packages and no built-in back doors. That renders typical attacks on IT systems ineffective. The operating systems of the controllers are tested for resistance to cyberattacks during the software development process. That is also ensured by security certification of the development process and by the development processes necessary for functional safety, such as the two-person principle.

However, for plant operators it is not enough to rely on standards-compliant hardware and software. Cyber security is a never-ending task, and it must be developed jointly by plant operators and safety specialists in the conceptual design of new plants or prior to update measures. The minimum requirement for existing plants is an exact analysis of potential cybersecurity weaknesses. Along with technical measures, users must also implement organisational measures, because no existing technology can provide complete protection against new forms of attack.
Cyber security standard
With many companies deploying new devices throughout their plants to improve asset maintenance and optimise operational performance, any malware or flawed security mechanisms that may be present in these devices represents a potential threat to plant security. Connecting devices to cloud-based analytics programs opens additional pathways for external attacks and companies need to take steps to secure IIoT devices from latent malware and use robust security controls that align with industry best practices.
{EMBED(960083)}
Recently, the ARC Advisory Group discussed these challenges with executives from UL, a well-known global safety science organisation that provides advisory, testing, and certification services. UL, which has been active in the industrial space for over 120 years, recently published the UL 2900 Series of Standards that offers testable cybersecurity criteria for IIoT devices. These incorporate guidelines from a variety of well-known standards. UL 2900-2-2, specifically designed for industrial control systems, aligns with IEC 62443 criteria.
Experts from UL have developed the UL 2900 standard with input from major government, academic, and industry. Their goal was to create a standard with broad-based coverage of security issues and support for many different industrial sectors. A key challenge was to ensure that it reflected the requirements of many different industrial cybersecurity standards and guidance documents in use today. For example, UL 2900-2-2 applies some security criteria from IEC 62443 for product testing and process validation.
IPE publishes a weekly eNewsletter, delivering a carefully chosen selection of the latest stories straight to your inbox.
Subscribe here

