<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Here we go, were they prepared? in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35847#M4521</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Problem with ICS system owners, is that they believe they have done "Security by Obsecurity" so well that folks will never be able to affect them.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That, and air gapping.&amp;nbsp; Airg apping can be extremely effective, but completely falls apart the moment one realizes they can save money by implementing remote support and end up somehow compromising the air gap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although not precisely the same scenario, I use &lt;A href="https://www.risidata.com/Database/Detail/slammer-impact-on-ohio-nuclear-plant" target="_blank" rel="noopener"&gt;Davis-Besse&lt;/A&gt; as my example when I help people work through the risk analysis regarding remote support.&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2020 15:34:31 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2020-05-21T15:34:31Z</dc:date>
    <item>
      <title>Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35837#M4515</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, lots of talks about impending Cyber security attacks on critical infrastructure - but now it has happened in the UK:&amp;nbsp; Were they prepared or was it a case of bottom line, and bury ones head in the sand as usual?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ia.acs.org.au/article/2020/uk-electricity-grid-hit-by-cyberattack.html?_lrsc=8c299fee-c346-4526-8033-2d44e130d99b" target="_blank"&gt;https://ia.acs.org.au/article/2020/uk-electricity-grid-hit-by-cyberattack.html?_lrsc=8c299fee-c346-4526-8033-2d44e130d99b&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 21:19:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35837#M4515</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-05-20T21:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35846#M4520</link>
      <description>&lt;P&gt;Problem with ICS system owners, is that they believe they have done "Security by Obsecurity" so well that folks will never be able to affect them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add to this all the news happening on Covid-19 hacks/scams/etc., folks may be letting their guard down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am curious as there isn't alot of information here on the attack (probably never will be) but the inability to send/receive emails, implies that 1) the hacker disabled the mail system itself, which means they got quite far into the system&amp;nbsp; or 2) they have disabled some ports on the firealls ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article does not say that they cannot create mail....they just cant send it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given either 1 or 2, if I were them, I would be searching my systems for additional malware that may have been downloaded, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my thoughts only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 14:52:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35846#M4520</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-05-21T14:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35847#M4521</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Problem with ICS system owners, is that they believe they have done "Security by Obsecurity" so well that folks will never be able to affect them.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That, and air gapping.&amp;nbsp; Airg apping can be extremely effective, but completely falls apart the moment one realizes they can save money by implementing remote support and end up somehow compromising the air gap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although not precisely the same scenario, I use &lt;A href="https://www.risidata.com/Database/Detail/slammer-impact-on-ohio-nuclear-plant" target="_blank" rel="noopener"&gt;Davis-Besse&lt;/A&gt; as my example when I help people work through the risk analysis regarding remote support.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 15:34:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35847#M4521</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2020-05-21T15:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35848#M4522</link>
      <description>&lt;P&gt;I love Air gapping but unfortunately we had to eliminate when the Accounting folks wanted real time numbers for product costing, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 15:43:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35848#M4522</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-05-21T15:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35852#M4524</link>
      <description>&lt;P&gt;This is nothing more than an amusing non-story from last week's news, which amounts to little more than "random company suffers ransomware attack"...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This quote from &lt;A href="https://www.theregister.co.uk/2020/05/15/elexon_cyber_attack/" target="_blank" rel="noopener"&gt;The Register&lt;/A&gt; about sums everything up:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"A complex and vital market mechanism, any failure in the BSC &lt;U&gt;would cause severe headaches for accountants trying to reconcile their figures&lt;/U&gt;. The financial side of the UK's electricity market is, however, well insulated from the wiggly amps making their way along the nation's cables."&amp;nbsp;&lt;img id="smileylol" class="emoticon emoticon-smileylol" src="https://community.isc2.org/i/smilies/16x16_smiley-lol.png" alt="Smiley LOL" title="Smiley LOL" /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The company involved is effectively a financial middleman brokering deals between the UK's National Grid and the power generating companies. They are in no way, shape or form considered "critical infrastructure".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't believe the hype!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 19:28:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35852#M4524</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2020-05-21T19:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Here we go, were they prepared?</title>
      <link>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35881#M4530</link>
      <description>&lt;P&gt;Thanks for the clarification, however my comments still stand related to companies with ICS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if they are only doing billing/sales/etc. if I were them I would still be doing a deep dive into my systems.&amp;nbsp; If I can stop the email system just think of the other damage that I might be able to do....change the rate (cost) of electricity to be 0.00001 cents per KWH or 100 pounds per KWH......lots of potential for havac.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 14:47:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Here-we-go-were-they-prepared/m-p/35881#M4530</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-05-22T14:47:31Z</dc:date>
    </item>
  </channel>
</rss>

