cybersecurity

  • Bayshore Networks and GE Digital Expand Partnership to Secure Industrial and Critical Infrastructure Networks

    GE Digital’s OpShield technology to be integrated into Bayshore Networks’ solutions DURHAM, N.C., Feb. 8, 2021 /PRNewswire/ — Bayshore Networks and GE Digital today announced an expansion to their partnership to integrate their solutions to address the growing need to secure industrial and critical infrastructure networks. GE Digital’s OpShield technology will be integrated into Bayshore Networks’ advanced […]

  • 5 Cybersecurity Best Practices to Protect Your OT Systems

    Over the last several years, cyber actors and online criminal gangs have used cyber warfare to disrupt business and infrastructure across the globe. Today, they are becoming even more aggressive and are using their resources to target Operations Technology (OT) and Industrial Control System (ICS) networks. According to the Canadian government’s Canadian Centre for Cyber […]

  • The Airgap Is Not Enough: The Failed Security Perimeter Paradigm in OT Networks

    Operational technology (OT) electronics and networks for manufacturing, energy production, and virtually every other industrial application, are targets for cyberattacks. For infrastructure-related companies, such as power producers, transportation, and water plants, the OT networks are not only the revenue producers, but also important targets for destabilizing national security. Successful attacks can be destructive and costly, […]

  • How to Monitor Assets Remotely Today

    As long as products have had ethernet ports, people have been asking for remote access to them. They believed they could just plug the devices into the internet, and it would all work. At first, there wasn’t necessarily a clear path to making this dream a reality without assistance from the user’s IT department. IT […]

  • NAESB’s First Move to Set Energy Digitalization Standards Heavily Focused on Blockchain, Cybersecurity

    The North American Energy Standards Board (NAESB), a wholesale and retail natural gas and power industry forum comprising 300 corporate members, will initially focus its standards development to support cybersecurity and blockchain out of 11 digital technologies it identified that are quickly transforming the energy space.  The board’s April 2019–formed Digital Committee, which comprises 16 […]

  • Cybersecurity in and for Large Energy Transmission Projects

    Even before the Stuxnet malware program made international headlines in 2010, cybersecurity was an important issue for utility companies. In the aftermath of one of the largest attacks on supervisory control

  • Nozomi Networks Pioneers SaaS Security and Visibility Solution for Dynamic IoT and OT Networks

    SAN FRANCISCO, Oct. 27, 2020 — Nozomi Networks Inc., the leader in OT and IoT security, today introduced Vantage™, an innovative SaaS-based OT and IoT network visibility and monitoring solution designed to meet the evolving requirements of IoT-enabled infrastructures. “Vantage is a game-changer when it comes to simplifying the integration and centralized management of visibility […]

  • The Energy-Sector Threat: How to Address Cybersecurity Vulnerabilities

    Electric-power and gas companies are especially vulnerable to cyberattacks, but a structured approach that applies communication, organizational, and process frameworks can significantly reduce cyber-related risks. In our experience working with utility companies, we have observed three characteristics that make the sector especially vulnerable to contemporary cyberthreats. First is an increased number of threats and actors […]

  • Mixed Reactions on Looming DOE NOPR for Bulk Power System Security

    The Department of Energy (DOE) will issue a notice of proposed rule-making (NOPR) to implement President Trump’s broad bulk power system (BPS) security executive order (EO) “later this fall,” a DOE official confirmed to POWER on Oct. 5. Though the NOPR is delayed beyond the 150-day timeframe set by the EO, various BPS stakeholders are […]

  • Power Sector, Federal Entities Scramble to Close Supply Chain Security Gaps

    Marking another major federal effort to address potential supply chain risks to the bulk power system (BPS), the Federal Energy Regulatory Commission (FERC) on Sept. 17 sought industry’s perspective on a number of important considerations, including possible actions the regulatory body could take to address security gaps. The U.S.-based power sector, meanwhile, has moved quickly […]

  • Cyber Risks Are Top of Mind Throughout the Power Sector

    The electric power sector in the United States has a long history of facing threats to our infrastructure—whether they are natural or man‐made. While cyberthreats are indeed much more complex, particularly when you consider that some of our cyber adversaries are nation states, the industry has a strong foundation of preparedness, resilience, and response. Though […]

  • Hitachi ABB Power Grids joins effort to protect power utilities from cyber threats

    AUGUST 25, 2020 — Hitachi ABB Power Grids is joining with Fortress Information Security (Fortress) as a participant in its Asset to Vendor Network (A2V), which will enable the company to quickly and seamlessly share information about its cybersecurity preparedness with United States and Canada-based power utilities. Leading companies such as American Electric Power (AEP) […]

  • New York Power Authority and Siemens Energy, Inc. to Lead World-Class Cybersecurity Center of Excellence

    Center to Develop Innovative Cybersecurity Best Practices that Will Serve as a Model for Deployment at Other Public and Private Utilities NYPA’s Advanced Grid Laboratory for Energy to Test Cybersecurity Solutions, Pilot New Systems WHITE PLAINS — The New York Power Authority (NYPA) and Siemens Energy, Inc. today announced a new collaboration to develop an […]

  • Lessons From New Jersey on Power Grid Protection

    After Superstorm Sandy pummeled the great State of New Jersey in 2012, more than two million households were without power, many for close to two weeks. A silver lining is that this disaster occurred in the fall, after the heat of summer and before the onset of freezing conditions. With Sandy, New Jersey and the […]

  • NERC: Summer 2020 Reliability Rife With Unknowns

    Despite COVID-19’s impact on power demand, disrupted pre-season generation preparation, and an expected highly active hurricane and wildfire season, industry appears well-positioned to meet peak demand this summer under anticipated weather in nearly all parts of the North American bulk power system (BPS).  Other than in the Electric Reliability Council of Texas (ERCOT), anticipated reserve […]

  • Cybersecurity Is More Important Than Ever Due to COVID-19

    The COVID-19 outbreak has forced many companies to change the way they conduct operations. Leaders have had to divide employees into essential and non-essential categories. Essential employees must report to

  • FERC Orders Delayed Implementation of NERC Reliability Standards

    The Federal Energy Regulatory Commission (FERC) has approved the North American Electric Reliability Corporation’s (NERC’s) motion to defer implementation of seven reliability standards—including for grid cybersecurity—that were slated to become effective this year. In an April 17 order, FERC approved NERC’s April 6 requested motion to defer the implementation of the standards, which have effective […]

  • Managing Modernization: Risks and Rewards of Digital Transformation in the Energy Sector

    In the face of widespread disruption driven by economic, regulatory and consumer forces, the energy sector is increasingly adopting digital technologies to transform the industry and bring it into the future. However, this move to modernization can unintentionally expose organizations to a range of new security threats that must be addressed. Digital Transformation—A Move to […]

  • Live Updates: Power-Related Regulatory Responses to COVID-19

    Federal regulators with oversight over U.S. power matters have issued a series of actions over recent weeks to respond to the potentially devastating impact that COVID-19, the new coronavirus, could have on North American power workforce operations and reliability. POWER will update this post regularly with COVID-19 response news and documents from federal and state […]

  • ICS ATT&CK: Designed to Help Protect from Cyber Attacks

    Earlier this year, MITRE—a not-for-profit organization that works in the public interest across federal, state, and local governments, as well as with industry and academia—officially released the long-awaited industrial control systems (ICS) version of its popular ATT&CK knowledge base. ICS ATT&CK is the group’s response to the unique attack surface that industrial networks are trying […]

  • POWER Digest [March 2020]

    Siemens Buys Out Iberdrola, Readying to Spin Off Gas and Power and SGRE Businesses. Siemens AG will acquire Spanish renewables giant Iberdrola SA’s full 8.1% stake in Siemens Gamesa Renewable Energy (SGRE)

  • Nuclear a Major Focus in Trump’s Latest Budget Request—and 8 Other Takeaways

    Yucca Mountain, the 1987 Congressionally appointed deep geologic repository for spent nuclear fuel (SNF), may be officially dead; transmission assets held by the Tennessee Valley Authority (TVA) and three Power Marketing Administrations (PMAs) will be put up for sale; and hundreds of millions of dollars in unobligated balances for flagship programs like the Advanced Research […]

  • Cybersecurity Experts Warn of New ‘Hardened’ ICS-Specific Ransomware Variant

    A primitive but unique ransomware variant that emerged in mid-December can forcibly stop a number of processes, including multiple items related to industrial control system (ICS) operations, industrial cybersecurity firm Dragos warned in a detailed report on Feb. 3. The ransomware known as “EKANS” (or “Snake,” which is “EKANS” spelled backwards) is “relatively straightforward” as […]

  • FERC Approves New Cybersecurity, Transmission Reliability Standards

    The Federal Energy Regulatory Commission (FERC) on Jan. 23 approved two new reliability standards related to transmission system planning performance and cybersecurity. However, it also proposed to retire 74 reliability standard requirements, which it deemed duplicative or unnecessarily burdensome. Among the spate of actions it took on Thursday, FERC also green-lighted retaining the North American […]

  • FM Global to conduct regular cyber engineering evaluations of industrial control systems for clients

    JOHNSTON, R.I., USA—As part of its continuing commitment to cyber risk assessment, prevention and control, FM Global, one of the world’s largest commercial property insurers, has become one of the first insurance carriers to offer industrial control systems (ICS) evaluations at client locations as part of its routine engineering site visits. The ICS evaluation will […]

  • Rockwell Automation to Acquire Avnet to Expand Cybersecurity Expertise

    Acquisition will enhance Rockwell Automation’s ability to deliver IT/OT cybersecurity services globally January 08, 2020 07:00 AM Eastern Standard Time MILWAUKEE–(BUSINESS WIRE)–Rockwell Automation, Inc. (NYSE: ROK) today announced that it has signed an agreement to acquire privately held Avnet Data Security, LTD, an Israeli-based cybersecurity provider with over 20 years of experience providing cybersecurity services. […]

  • The POWER Interview: NCC Group on Cybersecurity

    Reliability and resiliency are buzzwords in today’s world of power generation. The focus is often on valuing those attributes, be it through subsidizing baseload power to make it more economically viable, or through other means. Reliable delivery of electricity, of course, also depends on cyber-resilient systems, at power plants and across the grid. Cyberattacks against […]

  • Positive Technologies assists Siemens with eliminating dangerous vulnerabilities in utility control system

    Framingham, MA — Positive Technologies experts have discovered a total of 17 vulnerabilities in the SPPA-T3000. Vladimir Nazarov, Head of ICS Security at Positive Technologies, said: “By exploiting some of these vulnerabilities, an attacker could run arbitrary code on an application server, which is one of the key components of the SPPA-T3000 distributed control system. […]

  • How the DOE Plans to Modernize the Grid in the Near Term

    Twenty-three projects chosen by the Department of Energy (DOE) in response to its 2019 Grid Modernization Lab Call provide a broad look at the critical issues that are roiling the nation’s power sector, as well as the tools and technologies that it has determined will best bolster the grid of the future in the near […]

  • Air-Gapped Industrial Control Networks: What You Need to Know

    Many networks across a variety of verticals including government, military, financial services, power plants, and industrial manufacturing have been so-called “air-gapped.” This means they are physically and logically isolated from other networks where communication between these networks is not physically or logically possible. This can be a good thing or bad thing depending on your […]