Critical Infrastructure Under Siege: Experts Warn of Evolving Threats and Need for Enhanced Cybersecurity
The US House Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection recently held a hearing to examine the evolving threats to critical infrastructure in the wake of the Stuxnet discovery 15 years ago. Witnesses highlighted the importance of reauthorizing the Cybersecurity Information Sharing Act (CISA) of 2015 and the State and Local Cybersecurity Grant Program (SLCGP) to protect critical infrastructure from cyber threats.
Key Takeaways:
- The Stuxnet attack, discovered 15 years ago, was a digital weapon designed to sabotage Iran's nuclear program by targeting industrial control systems, highlighting the potential for malicious code to cause disruption and destruction in the physical world.
- Expert witnesses emphasized the need to treat operational technology (OT) differently from information technology (IT) due to its distinct risks and requirements for defense strategies.
- Private-public partnerships are crucial for defending operational technology, and unified federal guidance on cyber defense strategies is necessary to streamline and resolve overlapping and contradictory messages.
- CISA's effectiveness is limited by its resources and scope, with some witnesses suggesting that the agency can be more effective by modernizing its infrastructure, leveraging public-private partnerships, and focusing on its core mission.
- According to Robert M. Lee, CEO of Dragos, about 95% of cyber spending goes to enterprise IT, while only 5% is dedicated to OT, which poses a significant risk to national security, communities, and revenue generation.
- Kim Zetter, author of "Countdown to Zero Day," noted that while some of CISA's past work has been effective, the agency's limitations and restrictions hinder its ability to provide comprehensive support to critical infrastructure.
- Tatyana Bolton, executive director of Operational Technology Cyber Coalition (OTCC), suggested that CISA can grow in its effectiveness by modernizing its legacy infrastructure, including the Einstein Program and CyberSentry, to stay up-to-date with evolving threats.
Statistics:
- According to Robert M. Lee, about 10% of the country's infrastructure is being monitored for OT security vulnerabilities.
- About 95% of cyber spending goes to enterprise IT, while only 5% is dedicated to OT.
- CISA's resources are limited, and it operates with outdated systems, with witnesses suggesting that modernization is necessary to improve its effectiveness.
- According to Dr. Nate Gleason, Lawrence Livermore National Laboratory, CISA has had success in partnerships with other federal agencies, such as the Department of Energy and the Department of Defense.
Sources:
- House Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection
- Hearing Transcript: "Evolving Threats to Critical Infrastructure"
- Kim Zetter, "Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon"
- Robert M. Lee, CEO of Dragos
- Tatyana Bolton, executive director of Operational Technology Cyber Coalition (OTCC)
- Dr. Nate Gleason, program leader at Lawrence Livermore National Laboratory