Ukrainian CNI Cyber Attack
In the final few weeks of 2015, Ukraine's energy generation and distribution system came under a sophisticated cyber attack. The attackers displayed worrying levels of technical sophistication (modified BlackEnergy2 and BlackEnergy3 implants) and operational tradecraft (spear phishing, lateral network exploitation, system administrator/operator machine targeting) to achieve the outcome they wanted, even going so far as to TDoS the call centres of the energy companies in question. Cyber attacks like this are becoming the new normal in cyberspace, and other Western critical national infrastructure companies should stand up and take notice; we are not immune.
Luckily, there are some products and services emerging that can help to harden CNI systems to cyber threats. There is no single solution to this problem; hardening your systems and networks to this type of threat can only be achieved by a concerted and holistic campaign of cyber security systems, policies and procedures. The upside is that you don't need to be perfect; you just need to be tough enough that the bad guys move off to an easier fish to fry...