• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»Cyber threats to Europe’s grid: Utilities rethink strategy
Tech News

Cyber threats to Europe’s grid: Utilities rethink strategy

September 11, 2022No Comments6 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Cyber threats to Europe’s grid: Utilities rethink strategy
Share
Facebook Twitter LinkedIn Pinterest Email

On 26 August this year, Montenegro’s state infrastructure was hit by an “unprecedented” cyber attack, and national government officials expressed alarm.  

“Certain services were switched off temporarily for security reasons, but the security of accounts belonging to citizens and companies and their data have not been jeopardised,” public administration minister Maras Dukaj announced on Twitter.   

This is only the most recent of a series of large-scale assaults on European grids, systems, subsystems, equipment, software and services. In an article for a leading electricity industry magazine, Bernard Montel, Europe, Middle East and Africa (EMEA) security strategist and technical director at Tenable Corp, outlined the growing threat of cyber attacks on utilities by both state actors and criminals.  

Montel expressed particular alarm because the amount of digitisation currently under way throughout the industry “brings together previously separate systems and allows attackers to exploit weak points in one before moving across to another”. Tenable counts many EU-based utilities among its key clients. 

Hackers constantly seek out ways to use any vulnerabilities in a system to their maximum advantage. This is as much a problem for consumers as it is for commercial enterprises. Concerns about weak control systems are now adding to the stresses created by hacker attacks on systems, such as physical destruction, electronic jamming or creating a denial of service.

Existing supervisory control and data acquisition (Scada) hardware is primitive. PlugInAmerica.org director Ron Freund said: “It doesn’t handle the simple faults gracefully, and is not reliable, much less scalable.  But it also is not yet on the internet, so is inaccessible, for the most part. In fact, it’s scary how primitive some of these systems still are.” 

For the past several years, hackers have been aiming their attacks at vulnerabilities in electrical systems. In the case of charging stations, some of these soft spots are located inside the station itself, others are located inside the equipment that controls connections between the grid and the station, and others still are inside assets that sit on the grid side of the system, and these are mostly owned by utilities.  

See also  German startups could use more venture capital, but Germany’s government has a plan – DailyTech

To understand the threat, consider the variety of attacks that have targeted European-based wind power companies Deutsche Windtechnik, Enercon and Nordex. In three separate incidents, the hackers’ focus was different – malicious actors stopped the flow of electricity; identity theft was perpetrated; and payments for electricity were stolen.  

In most cases, such attacks can result in service disruptions affecting customers, and loss of revenue for electricity providers and/or asset owners.

In response to the evolving threats to critical infrastructure, the European Union (EU) has called for the utility sector to bolster its cyber security hygiene and posture. The European Commission is backing up this call to action with €100m of funding, which utilities can use to support and improve their cyber security hygiene and strengthen their defences. The funds can also be used to help utility companies recover from cyber attacks and build resilience into their core systems. 

It might be useful to compare this approach to what the US is doing. The federal government there is providing $335m for utilities to support, develop and implement cyber security plans, train personnel and buy equipment. This investment is intended to help modernise the nation’s critical infrastructure while protecting it from cyber threats, helping to reduce the likelihood of disruptions to essential services.  

Carey Smith, president and CEO of Parsons Corporation, a technology-focused defence, intelligence, security and infrastructure engineering firm, said: “Utilities are taking steps to harden their systems against cyber threats by investing in security measures and in operations. These changes come as utilities face an evolving threat in the landscape.

See also  Austrian knowledge agency accused of promoting malware, conducting cyber assaults

“In recent years, there have been several high-profile cyber attacks against critical infrastructure, each reminding us that utilities must prepare to defend themselves against sophisticated and well-resourced threats. This is a vital investment in security and will help protect critical infrastructure from the ever-increasing threat from nation states, terrorists and criminal actors.” 

Utilities rely on operational technology (OT) to administer their facilities and systems, provide services to customers, collect billing information from meters, control demand response devices, and coordinate their operations with other utilities. The companies that generate, transmit or deliver electricity are in a rapidly changing environment. They face the ever-increasing demands on a grid that transmits rising quantities of intermittent power sources – solar, wind, and other renewable resources.

Utilities are trying to optimise their operations and get more performance out of existing equipment to deal with the demands of renewable resources.  

Smith added: “Utilities are starting to rethink their approach to cyber security. Traditionally, they have focused on protecting their OT from external threats. However, as the grid becomes more complex and interconnected, utilities recognise the need to take a more holistic approach to cyber security.”

All this additional optimisation, performance improvement and coordination requires utilities to do a much better job at monitoring and controlling ever-increasing numbers of connected devices across their growing OT systems.  

As part of this, they must modernise and upgrade their OT networks, which includes integrating OT with information technology (IT) networks to create a more unified and efficient operation. However, while the benefits of converging a utility’s IT and OT networks under a single operational umbrella brings efficiencies, rising security threats and evolving security and privacy requirements come into play.  

As such, a growing network of experts say it is critical for utilities to consider security at every stage of an OT or IT network integration project – from design and implementation to ongoing management and monitoring.  

See also  EU Cyber Resilience Act sets global standard for connected products

Parsons Corporation’s critical infrastructure cyber team applies a converged approach to the security and resilience of OT and IT technology networks. Its approach includes these key elements: 

  • Establish a clear security strategy and governance framework up front: Define roles and responsibilities for security across the organisation and be sure to consider security in all decision-making steps related to the OT and IT network integration project. 
  • Conduct a comprehensive risk assessment: Identify and assess risks associated with integrating the OT and IT networks and develop mitigation plans accordingly.  
  • Design security into the new architecture: Build security into the system design from the start, rather than trying to bolt it on later.  
  • Implement strong authentication and authorisation mechanisms: Ensure that only authorised users have access to specific parts of the system and that all user activities are  logged and monitored properly.  
  • Adopt a defence-in-depth approach: Implement multiple layers of security controls to protect against various threats.  
  • Incorporate security testing and validation: Test the system’s security regularly to ensure it is functioning properly and that all vulnerabilities are addressed.   
  • Provide and require cyber security training and awareness for personnel: Personnel who question odd or unusual items are the first line of cyber defence.  
  • Adopt controls for, and protection of, the supply chain: It is a good idea to vet suppliers’ personnel (including subcontractors) and any computers or other devices used or bought through the suppliers. 
  • Build a redundant and resilient converged OT and IT system: To ensure high availability, it is important to build OT systems to a fault tolerance standard.  

Source link

Cyber Europes Grid rethink strategy threats Utilities
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How To Make Curated Content A Winning Element Of Your Content Strategy

September 24, 2023

Nine Signs You May Need To Rethink Your Company’s Prices

September 19, 2023

Meet Aleph Alpha, Europe’s Answer to OpenAI

August 30, 2023

25 Years Ago Steve Jobs Launched the First iMac—and the Strategy That Saved Apple

August 18, 2023
Add A Comment

Comments are closed.

Editors Picks

Acast acquires podcast database Podchaser – DailyTech

July 18, 2022

StrikerVR is Launching Its Most Affordable VR Gun Accessory Yet

September 5, 2022

New prime minister Liz Truss urged to press on with IR35 and loan charge policy reviews

September 7, 2022

GameStop lays off staff, CFO as it focuses on crypto and NFTs

July 8, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.