<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>Federal Times - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 04:59:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>Federal Times - Federal Times</title>
	<link>https://one.sightlinemg.com/federaltimes/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/federaltimes/feed/?paged=2" />
	<item>
		<title>Russia warns of planned cyberattacks on its banks</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/12/02/russia-warns-of-planned-cyberattacks-on-its-banks/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/12/02/russia-warns-of-planned-cyberattacks-on-its-banks/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 02 Dec 2016 15:52:46 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/12/02/russia-warns-of-planned-cyberattacks-on-its-banks/</guid>

					<description><![CDATA[Russia's main domestic security agency says unspecified foreign special services are plotting a series of cyberattacks aimed at destabilizing the nation's financial system.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/12/02/russia-warns-of-planned-cyberattacks-on-its-banks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">23188</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/kremlin.jpg.jpg" width="1985" height="1418" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">MOSCOW — Russia&#8217;s main domestic security agency has said unspecified foreign special services are plotting a series of cyberattacks aimed at destabilizing the nation&#8217;s financial system.<br/><br/> The Federal Security Service, known under its Russian acronym FSB, said the computer servers involved in the planned attacks are located in the Netherlands and belong to Ukrainian company BlazingFast.<br/><br/></p>





<p class="wp-block-paragraph">The FSB said Friday that the attacks would be accompanied by a stream of text messages and posts on social networks containing claims of an imminent collapse of Russia&#8217;s major banks and the financial system&#8217;s breakdown. It said the action would target several dozen Russian cities.</p>



<p class="wp-block-paragraph">The Obama administration has accused Russia of conducting a series of hacks to interfere with the U.S. election, accusations Moscow has denied.</p>


]]></content:encoded>
	</item>
		<item>
		<title>Clapper: Non-state actor likely to blame for massive cyberattack</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/10/25/clapper-non-state-actor-likely-to-blame-for-massive-cyberattack/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/10/25/clapper-non-state-actor-likely-to-blame-for-massive-cyberattack/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 25 Oct 2016 18:26:33 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/10/25/clapper-non-state-actor-likely-to-blame-for-massive-cyberattack/</guid>

					<description><![CDATA[National Intelligence Director James Clapper says it appears that a "non-state actor" was behind a massive cyberattack last week that briefly blocked access to websites including Twitter and Netflix.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/10/25/clapper-non-state-actor-likely-to-blame-for-massive-cyberattack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">20147</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/clapper.jpg.jpg" width="2800" height="1867" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">National Intelligence Director James Clapper has said it appears a &#8220;non-state actor&#8221; was behind a massive cyberattack last week that briefly blocked access to websites including Twitter and Netflix.<br/><br/>At the Council on Foreign Relations in New York on Tuesday, Clapper said investigators are gathering a lot of data, and preliminary indications are that a non-state actor is to blame. But he said he wouldn&#8217;t want to completely rule out whether a nation-state might have been behind it.<br/><br/></p>





<p class="wp-block-paragraph">Last Friday, cyberattacks crippled a major internet firm, repeatedly disrupting the availability of popular websites across the United States. Members of a shadowy hacker group that calls itself New World Hackers claimed responsibility for the attack, but that claim could not be verified.</p>



<p class="wp-block-paragraph">Homeland Security Secretary Jeh Johnson confirmed Oct. 24 the Mirai botnet was used to perpetrate the large-scale distributed denial-of-service attack, leveraging a worldwide network of connected devices to send junk traffic at one of the companies that manages internet traffic.</p>



<p class="wp-block-paragraph">DHS is working with the intelligence community — through the National Cybersecurity and Communications Integration Center — and is developing &#8220;a set of strategic principles for securing the Internet of Things, which we plan to release in the coming weeks.&#8221;</p>


]]></content:encoded>
	</item>
		<item>
		<title>US, UK cybersecurity officials: Destructive hacks are coming</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/10/20/us-uk-cybersecurity-officials-destructive-hacks-are-coming/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/10/20/us-uk-cybersecurity-officials-destructive-hacks-are-coming/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 20 Oct 2016 15:48:52 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/10/20/us-uk-cybersecurity-officials-destructive-hacks-are-coming/</guid>

					<description><![CDATA[CYBERCOM's deputy commander says serious cyberattacks on critical infrastructure are happening right now.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/10/20/us-uk-cybersecurity-officials-destructive-hacks-are-coming/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">9825</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/mclaughlin.jpg.jpg" width="3024" height="1701" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The world should brace itself for more physically destructive hacks, two senior cybersecurity officials said Wednesday, warning that a more dangerous era of hacking was already upon us.<br/><br/> Paul Chichester, the director of operations at Britain&#8217;s new National Cybersecurity Center, told an event hosted by British defense think tank Royal United Services Institute that electronic intrusions were on their way to becoming more &#8220;destructive, disruptive and coercive.&#8221;<br/><br/></p>





<p class="wp-block-paragraph">&#8220;That will be our future,&#8221; he told a crowd of officers, academics and industry experts gathered for <a href="https://rusi.org/annual-conference/second-international-cyber-symposium-cyberspace-and-transformation-21st-century" target="_blank" title="Link: https://rusi.org/annual-conference/second-international-cyber-symposium-cyberspace-and-transformation-21st-century">a two-day symposium</a>in central London.</p>



<p class="wp-block-paragraph">Chichester was seconded by Air Force Lt. Gen. James K. McLaughlin, deputy commander at U.S. Cyber Command, who told attendees that infrastructure-wrecking attacks were being seen &#8220;right now in the environment.&#8221;</p>



<p class="wp-block-paragraph">Neither official went into specifics about what they&#8217;d seen or why they felt the threat was intensifying, although McLaughlin invoked a cyberattack in Ukraine that knocked out three separate power distribution companies last year. The Dec. 23 incident, believed to have been pulled off by a team of hackers using stolen passwords, left 225,000 people without electricity, according to <a href="https://ics-cert.us-cert.gov/alerts/IR-ALERT-H-16-056-01" target="_blank" title="Link: https://ics-cert.us-cert.gov/alerts/IR-ALERT-H-16-056-01">a U.S. Department of Homeland Security bulletin</a>published two months later.</p>



<iframe allowfullscreen="true" frameborder="0" src="/embed/player?filmId=00000155-ee7d-d761-a955-efff05350000&amp;autoplay=false"></iframe>



<p class="wp-block-paragraph">Cybersecurity experts long worried that hackers can hijack the vulnerable industrial control systems to wreak havoc in power plants, traffic systems, factories, dams or reservoirs. Still, publicly confirmed examples of real-world damage from hacking have — so far — been few and far between. The Ukrainian incident provided a rare and dramatic demonstration of the physical consequences of a well-organized cyberattack.</p>



<p class="wp-block-paragraph">McLaughlin said there was now no doubt such hacks were possible.</p>



<p class="wp-block-paragraph">&#8220;Three years ago these were just theoretical,&#8221; he said. &#8220;Now we see them. They&#8217;re practically here in front of us.&#8221;</p>



<iframe allowfullscreen="true" frameborder="0" src="/embed/player?filmId=00000155-e0c9-d412-a15d-e7ebc5010000&amp;autoplay=false"></iframe>
]]></content:encoded>
	</item>
		<item>
		<title>Regulators look to strengthen banks&#8217; cyber defenses</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/10/19/regulators-look-to-strengthen-banks-cyber-defenses/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/10/19/regulators-look-to-strengthen-banks-cyber-defenses/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 19 Oct 2016 16:57:15 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/10/19/regulators-look-to-strengthen-banks-cyber-defenses/</guid>

					<description><![CDATA[The rules proposed by the three agencies would pile on a second set of stricter standards for big banks' computer systems that are considered critical to the functioning of the financial industry.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/10/19/regulators-look-to-strengthen-banks-cyber-defenses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18712</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/yellen.jpg.jpg" width="3674" height="2504" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Federal regulators are looking to set up new standards for big banks&#8217; planning and testing for possible cyberattacks. The aim is to bolster the banking industry&#8217;s defenses amid concern over periodic security breaches at U.S. banks.<br/><br/> The move — announced Wednesday by the Federal Reserve, the Federal Deposit Insurance Corp. and a Treasury Department banking agency — is designed to get banks&#8217; senior executives and directors to pay closer attention to cybersecurity, agency officials said.<br/><br/></p>





<p class="wp-block-paragraph">Fed Chair Janet Yellen has said that cybercrime is a &#8220;very significant threat.&#8221;</p>



<p class="wp-block-paragraph">The proposal, open to public comment for three months, would apply to banks with $50 billion or more in assets. That would affect several dozen major banks and a few big insurance companies, all deemed to be so interconnected with the financial system that a cyberattack against one of them could shake the system&#8217;s stability.</p>



<p class="wp-block-paragraph">In a stunning incident early this year, hackers diverted $101 million from the Bangladesh central bank&#8217;s account at the New York Federal Reserve.</p>



<p class="wp-block-paragraph">The theft amplified worries about the security of the SWIFT global money-transfer system, which is overseen by the Fed and other central banks. Belgium-based SWIFT, formally the Society for Worldwide Interbank Financial Telecommunication, is a cooperative that manages the international transfer system among banks. The hackers in the Bangladesh bank case apparently got the money by stealing the central bank&#8217;s SWIFT access codes.</p>





<p class="wp-block-paragraph">The rules proposed by the three agencies would pile on a second set of stricter standards for big banks&#8217; computer systems that are considered critical to the functioning of the financial industry.</p>



<p class="wp-block-paragraph">The banks should establish goals for how long it would take them to recover from a cyberattack and should assess the potential for malware or corrupted data to spread through connected computer systems, the regulators said.</p>



<p class="wp-block-paragraph">The proposal doesn&#8217;t require the banks to submit their cybersecurity plans for approval or to notify the regulators if they suffer a data breach.</p>



<p class="wp-block-paragraph">Beyond their oversight of banks&#8217; efforts, the agencies themselves have suffered some serious security breaches. Computers at the Fed were penetrated dozens of times between 2011 and 2015, according to House lawmakers. The breaches raised concerns about the Fed&#8217;s ability to safeguard sensitive financial information in its computer systems, the lawmakers said.</p>





<p class="wp-block-paragraph">The Chinese government, meanwhile, is believed to have hacked into computers at the FDIC in 2010, 2011 and 2013, including the workstation of then-FDIC Chair Sheila Bair, according to a congressional report. It cites a May 2013 memo from the FDIC inspector general to agency Chairman Martin Gruenberg, describing an &#8220;advanced persistent threat&#8221; said to have come from the Chinese government — which compromised 12 computer workstations and 10 servers at the FDIC.</p>



<p class="wp-block-paragraph">The issue of suspected Chinese government hacking has been sensitive since the disclosure last year of a massive breach of the U.S. Office of Personnel Management&#8217;s databases, which the U.S. believed was carried out by Chinese cyber spies. In one of the worst data breaches in U.S. history, the personal files of 21 million Americans were stolen.</p>


]]></content:encoded>
	</item>
		<item>
		<title>Emerging focus on cyberthreats to energy infrastructure</title>
		<link>https://one.sightlinemg.com/federaltimes/management/2016/10/18/emerging-focus-on-cyberthreats-to-energy-infrastructure/</link>
					<comments>https://one.sightlinemg.com/federaltimes/management/2016/10/18/emerging-focus-on-cyberthreats-to-energy-infrastructure/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 18 Oct 2016 16:52:43 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/10/18/emerging-focus-on-cyberthreats-to-energy-infrastructure/</guid>

					<description><![CDATA[The expanding cybersecurity focus on energy infrastructure by both the public and private sectors is certainly a welcome development.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/management/2016/10/18/emerging-focus-on-cyberthreats-to-energy-infrastructure/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">10749</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/chuck-brooks.jpg.jpg" width="872" height="625" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Last week, the Kentucky Office of Homeland Security hosted an exercise simulating attacks on the power grid and government computer networks. Participants included law enforcement, first responders, and private sector representatives engaged in health and security. <br/><br/> The exercise centered on how the state would react if hackers were able to take down Kentucky&#8217;s energy grid while simultaneously engaged in the exfiltration of information from government computer networks. The goal was to provide a gap model and develop best practices that can be utilized by other states and by the federal Department of Homeland Security (DHS). <br/><br/> Also last week, InfraGard of the National Capital Region announced a partnership between the FBI and the private sector to protect critical infrastructure and provide a comprehensive effort to recognize and support National Critical Infrastructure Security and Resilience Month. The initiative supports the DHS&#8217; National Protection and Programs Directorate&#8217;s (NPPD) Office of Infrastructure Protection mission to raise awareness around critical infrastructure protection during the month of November. The energy sector has been a key area of attention for the NPPD.<br/><br/></p>





<p class="wp-block-paragraph">And perhaps the most concerning of news activity was the announcement by head of the United Nations nuclear watchdog, International Atomic Energy Agency Director Yukiya Amano, that a nuclear power plant in Germany was hit by a &#8220;disruptive&#8221; cyberattack within the past three years. Amano was quoted by Reuters as saying: &#8220;This issue of cyberattacks on nuclear-related facilities or activities should be taken very seriously. We never know if we know everything or if it’s the tip of the iceberg.&#8221; And he noted that this is &#8221; <a class="" href="http://www.federaltimes.com/articles/cyberattacks-on-nuclear-power-plants-not-an-imaginary-risk-says-iaea-chief" target="_blank" title="Link: null">not an imaginary risk</a>.&#8221;</p>



<p class="wp-block-paragraph">It should also be noted that in 2014, a computer in the control room at Monju Nuclear Power Plant in Tsuruga, Japan, was subjected to malware, but possibly by accident. And in 2015, South Korean hackers targeted Korea Hydro and Nuclear Power Company, but luckily to no avail. Most cyber experts believe that North Korea was behind the attempted cyberattack. These incursions are a wake-up call as there is a very real and growing fear that a future cyberattack on a nuclear plant could risk a core meltdown.</p>



<p class="wp-block-paragraph">Non-nuclear power plants have also been subjected to intrusions and breaches. A hack in Ukraine was held up as a prime example. In December 2015, hackers breached the IT systems of the electricity distribution company Kyivoblenergo in Ukraine, causing a three-hour power outage.</p>



<p class="wp-block-paragraph">Refineries, dams and data centers are all potential targets of cyber incursion. According to a report released last month titled &#8220;The Road to Resilience: Managing and Financing Cyber Risks,&#8221; oil and gas companies around the world could face costs of up to $1.87 billion in cybersecurity spending by 2018.</p>



<p class="wp-block-paragraph">There have been attempted cyberattacks on grids and utilities, many via phishing and ransomware, and some have been successful. Adm. Mike Rodgers, head of the National Security Agency and U.S. Cyber Command, has stated that only two or three countries have the ability to launch a cyberattack that could shut down the entire U.S. power grid and other critical infrastructure.</p>





<p class="wp-block-paragraph">Much of our grid still relies on antiquated technologies, and more investment in defenses are needed. As technology exponentially advances and as threat actors (including cyber mercenaries) gain tools via the dark web, that number of potential state-sponsored adversaries could expand in the near future.</p>



<p class="wp-block-paragraph">In 2013, President Barack Obama issued Executive Order 13636, &#8220;Improving Critical Infrastructure Cyber-security,&#8221; which called for the establishment of a voluntary risk-based cybersecurity framework between the private and public sectors.</p>



<p class="wp-block-paragraph"><a class="" href="http://data.rollcall.com/members/3717" target="_blank" title="Link: http://data.rollcall.com/members/3717">Rep. </a></p>



<p class="wp-block-paragraph"><a class="" href="http://data.rollcall.com/members/3717" target="_blank" title="Link: http://data.rollcall.com/members/3717">Trent Franks</a></p>



<p class="wp-block-paragraph">, R-Ariz., chairman of the congressional EMP Caucus, and considered the foremost expert in Congress on electromagnetic pulses,</p>



<p class="wp-block-paragraph">has introduced legislation ( <a href="http://beta.congress.gov/113/bills/hr3410/BILLS-113hr3410ih.pdf" target="_blank" title="Link: http://beta.congress.gov/113/bills/hr3410/BILLS-113hr3410ih.pdf">HR 3410</a>) called the Critical Infrastructure Protection Act. The law would enable DHS to implement practical steps to protect the electric grid by training and mobilizing first responders for possible EMP events.</p>



<p class="wp-block-paragraph">Along with Franks and Peter Prye, who heads the Task Force on National and Homeland Security (a congressional advisory board), several noted industry and policy experts, including former CIA Director Jim Woolsey; Frank Gaffney, former deputy secretary of defense and president and CEO of the Center for Security Policy; and Michael Del Rosso, former chairman of IEEE-USA Critical Infrastructure Protection Committee have been especially active in alerting the public to the critical need to find near-term solutions to protect the grid.</p>



<p class="wp-block-paragraph">Clearly the entire energy critical infrastructure is justified in garnering the attention of DHS, states, regulatory organizations and the many subject-matter experts on the topic of cybersecurity.</p>



<p class="wp-block-paragraph">While the threats are complex and the threat actors varied among hackers, state sponsors, organized criminal enterprises and terrorists, there are several themes to adhere to mitigate risk. These include:</p>



<ul class="wp-block-list"><li>Remain vigilant and continually analyze and game the energy cyberthreat landscape, as the methods, means and malware variants are constantly morphing.</li><li>Share and communicate cybersecurity information between the public and private sectors (a majority of the energy infrastructure is owned by the private sector). The government and industry are currently using pilot programs including Cybersecurity Risk Information Sharing Program and the Trusted Automated eXchange of Indicator Information to facilitate rapid sharing of security information. DHS NPPD has established an active and successful program in the area. DHS’ Cybersecurity Emergency Response Team responded to 295 cyber incidents in the energy sector in 2015.</li><li>Follow industry protocols, especially related to Supervisory Control and Data Acquisition (SCADA). Power companies use SCADA networks to control their industrial systems, and many of these networks need to be updated and hardened to meet growing cybersecurity threats.</li><li>Maintain robust access management control and cyber incident response programs. This includes following<span class="apple-converted-space"> </span><a href="https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwiGtPyUz9vPAhUC9R4KHWu6B6QQFggdMAA&amp;url=https%3A%2F%2Fwww.nist.gov%2F&amp;usg=AFQjCNFzujGqOiwAPrFHfamIzqr1-nTw9Q&amp;sig2=gY4luuucziICsIgXUbhQOg&amp;bvm=bv.135974163,d.dmo" target="_blank" title="Link: https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwiGtPyUz9vPAhUC9R4KHWu6B6QQFggdMAA&amp;url=https%3A%2F%2Fwww.nist.gov%2F&amp;usg=AFQjCNFzujGqOiwAPrFHfamIzqr1-nTw9Q&amp;sig2=gY4luuucziICsIgXUbhQOg&amp;bvm=bv.135974163,d.dmo">National Institute of Standards and Technology</a>,<span class="apple-converted-space"> </span><a href="http://www.nerc.com/Pages/default.aspx" target="_blank" title="North American Electric Reliability Corporation">North American Electric Reliability Corporation</a>,<span class="apple-converted-space"> </span><a href="https://www.ferc.gov/" target="_blank" title="Link: https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwiD-fK7z9vPAhVEGR4KHYDvB2sQFggdMAA&amp;url=https%3A%2F%2Fwww.ferc.gov%2F&amp;usg=AFQjCNF6ZC4paYVY3TeDDOrUEXcC07YEoA&amp;sig2=ajnYhPKQqVDQEYKd2I0ltA&amp;bvm=bv.135974163,d.dmo">Federal Energy Regulatory Commission</a> and <a class="" href="http://www.nrc.gov/" target="_blank">U.S. Nuclear Energy Regulatory Commission</a> cybersecurity protocols.</li><li>Invest in next-generation security controls and cybersecurity technologies.</li></ul>



<p class="wp-block-paragraph">The World Energy Council says countries must raise their game in combating cyberattacks on nuclear and other energy infrastructures. They note that the frequency, sophistication and costs of data breaches are increasing. The expanding cybersecurity focus on energy infrastructure by both the public and private sectors is certainly a welcome development.</p>



<p class="wp-block-paragraph"><em>Charles &#8220;Chuck&#8221; Brooks serves as the vice president for government relations and marketing for Sutherland Government Solutions. He served at the Department of Homeland Security as the first director of legislative affairs for the Science and Technology Directorate. Find him on Twitter at <a class="" href="https://twitter.com/ChuckDBrooks" target="_blank" title="Link: https://twitter.com/ChuckDBrooks">@ChuckDBrooks</a>.</em>  <br/></p>



<div class="fb-comments fb_iframe_widget fb_iframe_widget_fluid" data-href="http://www.federaltimes.com/articles/gen-touhill-brings-vision-strategy-as-nations-first-ciso" data-mobile="true" data-numposts="1" fb-xfbml-state="rendered"></div>
]]></content:encoded>
	</item>
		<item>
		<title>Cyberattacks on nuclear power plants ‘not an imaginary risk,’ says IAEA chief</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/10/12/cyberattacks-on-nuclear-power-plants-not-an-imaginary-risk-says-iaea-chief/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/10/12/cyberattacks-on-nuclear-power-plants-not-an-imaginary-risk-says-iaea-chief/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 12 Oct 2016 20:14:43 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/10/12/cyberattacks-on-nuclear-power-plants-not-an-imaginary-risk-says-iaea-chief/</guid>

					<description><![CDATA[International Atomic Energy Agency Director General Yukiya Amano told reporters about recent cyber disruptions of nuclear-related facilities and activities, and the need to increase precautionary measures.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/10/12/cyberattacks-on-nuclear-power-plants-not-an-imaginary-risk-says-iaea-chief/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13334</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/nuclear-plant.power_.plant_.Dukovany.jpg.jpg" width="800" height="600" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p><span class="inbox-inbox-s1">&#8220;Cyberattacks on nuclear-related facilities or activities should be taken very seriously,&#8221; International Atomic Energy Agency Director Yukiya Amano recently told Reuters while visiting Germany.</span><span class="inbox-inbox-apple-converted-space"> </span><br/><br/> <span class="inbox-inbox-s1">Without getting into specifics, Amano revealed that a nuclear plant had been the target of a &#8220;disruptive&#8221; — but not destructive — cyberattack two to three years ago, according to <a class="" href="http://www.reuters.com/article/us-nuclear-cyber-idUSKCN12A1OC" target="_blank" title="Link: null">an Oct. 10 story published by Andrea Shalal</a>. In addition, Amano recounted how there was an attempt to smuggle a small amount of highly enriched uranium about four years ago.<br/></span><br/>&#8220;This is not an imaginary risk,&#8221; he said.<br/><br/></p>





<p class="wp-block-paragraph">Though he had not previously discussed these events publicly, Amano did say he highlighted the issue of increasing precautionary measures for nuclear sites at an IAEA cybersecurity conference in June 2015 and increasing cyber and overall nuclear security would be a topic again at a summit in Vienna in December.</p>



<p class="wp-block-paragraph">While no hackers have impacted reactor operations at nuclear installations, there have been cases of data exfiltration and viruses infecting internal networks.</p>



<p class="wp-block-paragraph">Amano said IAEA continues to support global nuclear security training databases and the distribution of thousands of compact radiation detection devices.</p>


]]></content:encoded>
	</item>
		<item>
		<title>Cyberwar and popcorn: &#8216;Zero Days&#8217; movie stokes legitimate fears</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/09/08/cyberwar-and-popcorn-zero-days-movie-stokes-legitimate-fears/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/09/08/cyberwar-and-popcorn-zero-days-movie-stokes-legitimate-fears/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 08 Sep 2016 14:50:41 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/09/08/cyberwar-and-popcorn-zero-days-movie-stokes-legitimate-fears/</guid>

					<description><![CDATA[According to research scientist Kenneth Geers, none of the issues raised in "Zero Days" is hyperbole, and this film is worth your time.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/09/08/cyberwar-and-popcorn-zero-days-movie-stokes-legitimate-fears/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">17530</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/geers.jpg.jpg" width="4896" height="3264" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p>The new documentary about Stuxnet, &#8220;<a href="http://www.zerodaysfilm.com/" target="_blank" title="Link: http://www.zerodaysfilm.com/">Zero Days</a>,&#8221; begins with the real-world murder of nuclear scientists. This is a smart way to start a movie about cyberwar because skeptics often fail to see the connection between digital and traditional operations. In fact, nation-states have always understood that cyberattacks are merely one type of weapon in a very large military and intelligence arsenal.<br/><br/> At the strategic level, it is only logical that the world’s most advanced malicious code was written to address one of the White House’s most pressing concerns: how to prevent Iran from joining the most exclusive club in the world — the nuclear club.<br/><br/> <iframe allowfullscreen="" frameborder="0" height="315" src="https://www.youtube.com/embed/7VgIayOpjEc" width="560"></iframe> <br/><br/>The George W. Bush (and later the Obama) administration had another dilemma on its hands: how to avoid invading a third Muslim country. The answer was to employ a new, high-speed, long-range and low-signature weapon, aka malware. <br/><br/> President Bush had seen the combined arms power of <a href="http://www.thedailybeast.com/articles/2014/11/09/how-the-nsa-sorta-won-the-last-iraq-war.html" target="_blank" title="Link: http://www.thedailybeast.com/articles/2014/11/09/how-the-nsa-sorta-won-the-last-iraq-war.html">computer network operations</a> during his 2007 &#8220;surge&#8221; in Iraq, but the deal clincher may have come when White House aides tossed the shards of a <a href="http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html?_r=0" target="_blank" title="Link: http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html?_r=0">demolished centrifuge</a> onto the Situation Room table and explained that malware alone could now destroy critical infrastructure.<br/><br/> The technical wonders of Stuxnet are well-known, so I will just mention some of those highlighted in &#8220;Zero Days.&#8221; First, the primary attack vector was likely via Iranian IT contractors, who worked outside the nuclear establishment but were assumed to have access to it. Second, breaching an air-gapped network seems to have a shocking ramification: The lack of a traditional command-and-control (C2) channel means that the attacker should lose control of a now-autonomous weapon. Third, as with the <a href="https://www.wired.com/2016/03/inside-cunning-unprecedented-hack-ukraines-power-grid/" target="_blank" title="Link: https://www.wired.com/2016/03/inside-cunning-unprecedented-hack-ukraines-power-grid/">Christmas 2015 electricity grid attack</a> in Ukraine, the emergency mechanisms were also compromised, so even when system administrators became aware of the attack, there was no immediate digital solution. Fourth, Symantec researchers stated that the virtually bug-free Stuxnet code was something they had not seen before or since, which means either that this was an extremely rare event or an extremely rare lapse in tradecraft.<br/><br/></p>



<iframe allowfullscreen="true" frameborder="0" src="/embed/player?filmId=00000155-ee7d-d761-a955-efff05350000&amp;autoplay=false"></iframe>



<p class="wp-block-paragraph">On the side of cyber defense, one emerging dynamic that must worry intelligence agencies is the international, crowd-sourced nature of technical analysis. Because data packets do not wear uniforms, computer network operations are more like covert action than traditional military operations — they are supposed to remain secret.</p>



<p class="wp-block-paragraph">However, from the <a href="https://www.youtube.com/watch?v=EcKxaq1FTac" target="_blank" title="Link: https://www.youtube.com/watch?v=EcKxaq1FTac">Cuckoo’s Egg</a>to Stuxnet to the <a href="https://www.washingtonpost.com/world/europe/alleged-russian-involvement-in-dnc-hack-gives-us-a-taste-of-kremlin-meddling/2016/08/13/8075eb60-5f03-11e6-84c1-6d27287896b5_story.html" target="_blank" title="Link: https://www.washingtonpost.com/world/europe/alleged-russian-involvement-in-dnc-hack-gives-us-a-taste-of-kremlin-meddling/2016/08/13/8075eb60-5f03-11e6-84c1-6d27287896b5_story.html">DNC hack</a>, all cyberattacks share this mysterious quality: If they rise above a certain threshold of pain, curious scientists in disparate and previously disconnected laboratories will sacrifice a certain amount of sleep in order to find even one piece in a very large puzzle. And, as seen in &#8220;Zero Days,&#8221; even a three-letter agency like the NSA (National Security Agency) appears to want to offer some juicy details, including the assertion that it was Israel, and not Fort Meade, who blew the operation.</p>



<p class="wp-block-paragraph">The national security implications of Stuxnet are as controversial as ever. The technical nature of the topic, the &#8220;attribution problem&#8221; and over-classification give government hackers the space to do whatever they can get away with. But the laws of war dictate that militaries must operate within certain predefined parameters.</p>



<p class="wp-block-paragraph">As a technical expert to the <a href="http://www.securityweek.com/security-think-tank-analyzes-how-international-law-applies-cyber-war" target="_blank" title="Link: https://en.wikipedia.org/wiki/Tallinn_Manual">Tallinn Manual</a>process, I believe that our understanding of a national security threat must evolve with technology. This is happening, but slowly. For example, no one is quite sure where the line is between cyber espionage and cyberattack. Once a hacker is in position to read an adversary&#8217;s traffic, he or she can also manipulate it. Hence, the colocation of NSA and Cyber Command; the former has the technical capability to hack networks, while the latter has the authority to manipulate data.</p>





<p class="wp-block-paragraph">We have already seen hints of self-imposed restrictions: Instead of compromising as many machines as possible, Stuxnet wanted to hack as few as possible. Further, one of the &#8220;kill dates&#8221; found in the code, Jan. 11, 2009, was just a week before the presidential inauguration of Barack Obama. Apparently, a legal team had decided that a presidential reauthorization of the operation was necessary.</p>



<p class="wp-block-paragraph">&#8220;Zero Days&#8221; asks all of us to think harder about national security in the digital age, specifically from the standpoint of arms control and international norms. In the film, an alleged secret government source claims that Stuxnet was only a small part of &#8221; <a href="http://www.nytimes.com/2016/02/17/world/middleeast/us-had-cyberattack-planned-if-iran-nuclear-negotiations-failed.html" target="_blank" title="Link: http://www.nytimes.com/2016/02/17/world/middleeast/us-had-cyberattack-planned-if-iran-nuclear-negotiations-failed.html">Nitro Zeus</a>,&#8221; a larger operation that could theoretically knock Iran right out of cyberspace. The right question to ask, then, is whether Iran (or more likely, Russia or China) could do the same to the U.S., and whether crossing the digital Rubicon with Stuxnet was worth it.</p>



<p class="wp-block-paragraph">It is widely believed that Iran sent a message to the West in <a class="" href="http://www.ft.com/cms/s/0/15e1acf0-0a47-11e6-b0f1-61f222853ff3.html" target="_blank" title="Link: http://www.ft.com/cms/s/0/15e1acf0-0a47-11e6-b0f1-61f222853ff3.html">retaliatory cyberattacks</a>on Saudi Aramco and Wall Street, thereby signaling that the U.S. does not have a monopoly on cyber weapons.</p>



<p class="wp-block-paragraph">The U.S. has more strategic depth in cyberspace than all of the world’s dictators combined, but we still have a lot to lose. Our economies and democracies depend on critical infrastructure, which, in turn, depend on the proper functioning of the internet. This is why, for example, the Department of Homeland Security spent significant resources to protect the U.S. from &#8230; guess what? Stuxnet.</p>





<p class="wp-block-paragraph">And relative to international norms, a legitimate fear is that this operation set a bad precedent: The U.S. did it, so it must be OK.</p>



<p class="wp-block-paragraph">As the Internet of Things expands all around us, the line between &#8220;cyberspace&#8221; and &#8220;physical space&#8221; will disappear. In &#8220;Zero Days,&#8221; researchers demonstrated this in a laboratory by popping a balloon with a Stuxnet-infected computer. At NATO’s annual <a href="https://ccdcoe.org/exercise-locked-shields-2016-highlights-priorities-cyber-defence.html" target="_blank" title="Link: https://ccdcoe.org/exercise-locked-shields-2016-highlights-priorities-cyber-defence.html">Locked Shields</a>cyber defense exercise, we attached small fireworks to miniature factories.</p>



<p class="wp-block-paragraph">Of course, the public will never understand all the technical aspects of Stuxnet, and there is nothing simple about the idea of cyber arms control. But just like Bush in the Situation Room, the public can see when something is physically destroyed. And by comparison, it should be simple to begin an international discussion on cyberwarfare in order to examine how we might limit the size of the cyber battlefield.</p>



<p class="wp-block-paragraph">In my view, none of these issues raised in &#8220;Zero Days&#8221;</p>



<p class="wp-block-paragraph">is hyperbole, and this film is worth your time.</p>



<p class="wp-block-paragraph"><i>Kenneth Geers (PhD, CISSP) is a senior research scientist at <a href="http://www.enterprise.comodo.com/" target="_blank" title="Link: http://www.enterprise.comodo.com/">Comodo</a></i></p>



<p class="wp-block-paragraph"><i>, a global innovator and developer of cybersecurity solutions. He is also a NATO CCD COE (Cyber Centre) ambassador, a non-resident senior fellow at the Atlantic Council, an affiliate at the Digital Society Institute of Berlin, a visiting professor at Taras Shevchenko National University of Kyiv in Ukraine, and an accomplished author.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Known unknowns of cybersecurity talent shortfall, Part 2</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/2016/08/30/known-unknowns-of-cybersecurity-talent-shortfall-part-2/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/2016/08/30/known-unknowns-of-cybersecurity-talent-shortfall-part-2/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 30 Aug 2016 15:24:23 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/08/30/known-unknowns-of-cybersecurity-talent-shortfall-part-2/</guid>

					<description><![CDATA[Here's Part 2 of an in-depth dive into how the cyber workforce gap introduces a special set of threats.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/2016/08/30/known-unknowns-of-cybersecurity-talent-shortfall-part-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19622</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/636038457961949450-fed-carbon-plantjpg.jpg" width="5184" height="3456" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph"><i><a class="" href="http://www.federaltimes.com/articles/known-unknowns-of-cybersecurity-talent-shortfall-part-1" target="_blank" title="Link: http://www.federaltimes.com/articles/known-unknowns-of-cybersecurity-talent-shortfall-part-1">Part 1 of this article</a> described the cybersecurity labor shortage and the unknown unknowns that threaten public and private networks alike. Part 2 will discuss how our nation&#8217;s critical infrastructure is put at risk by this talent shortfall, as well as four essential skills that every cybersecurity employee should have.</i> <br/><br/> <b>Now hiring</b><br/><br/> We&#8217;ve heard a lot lately about attacks within the financial services and health care industries, and for good reason. These industries hold sensitive, personal data that attackers want access to. While these industries are bearing the brunt of current attacks, research shows this will soon change. Fortinet&#8217;s recent <a href="https://www.fortinet.com/content/dam/fortinet/assets/white-papers/WP-CTAP-Threat-Landscape-and-Manufacturing.pdf" target="_blank" title="Link: https://www.fortinet.com/content/dam/fortinet/assets/white-papers/WP-CTAP-Threat-Landscape-and-Manufacturing.pdf">Cyber Threat Assessment Program (CTAP)</a> report showed that manufacturing is likely to be the next industry specifically targeted by ransomware. Manufacturing&#8217;s quest is greater efficiency, often achieved through greater automation. Automation, however, brings greater exposure to cyber compromise. This same concern extends to the supply systems supporting these manufacturing developments, such as transportation.<br/><br/>For example, automation of the manufacturing floors substantially increases targets for attack because the manufacturing sector&#8217;s success is built upon hitting delivery timetables; it cannot afford the massive, negative effects of a disruptive attack. Transportation systems supporting manufacturing, commuting or leisure travel operate in a similar fashion. Most are controlled by computers with the assistance of humans. Successful attacks on any part of these systems have cascading, not isolated, consequences. System defenses must address the known attack methods but also anticipate the unknown, including the when and the how. <br/><br/> These concerns are not limited to the private sector. When we take a look at government agencies&#8217; needs, there is not a single agency that does not require a more robust cybersecurity workforce. Government agencies are responsible for various systems and infrastructures that support the critical infrastructures mentioned above. Homeland security therefore always incorporates the risks to our critical infrastructures — from roadways to transportation systems to manufacturing and beyond. Incapacitation or destruction of any of these homeland segments would have a debilitating effect on security, public safety and the economy. Technology alone can&#8217;t protect these systems because the threat is not just technical. In order to fully protect these critical infrastructures, we need skilled cybersecurity professionals in a wide array of competencies to protect against the known and the unknown.<br/><br/> <b>Knowing the known to uncover the unknown </b><br/><br/> While the workforce shortfall is one we cannot ignore, the question becomes: How do those entering the cybersecurity field know what tools and skill sets are needed to be successful? Here are four key areas that those entering the cybersecurity field should have in their knowledge toolbox:<br/><b><br/>&#8212; Understanding:</b> A basic level of understanding how IT messaging works is foundational in any cybersecurity position. Having the knowledge of how programs exchange messages and what data or information is included in those messages is paramount for cybersecurity professionals.<br/><b>&#8212; </b><b>Human nature: </b>The common misconception within IT is that you only need to know how technology works. This is contrary to the world in which we live. Sure, understanding how technology works is necessary, but what is more important is having an understanding of the people using the technology. Knowing human nature and the characteristics of those using the technology will provide a better understanding of how preventable breaches such as email phishing attacks infiltrate networks.<br/><b>&#8212; </b><b>Lock and key:</b> When you think of how much of our personal information resides in digital form, cyberthreats become more personal. From banking to health care to our tax returns, all are for the most part done online or in digital form. These are the known knowns. We know the type of data and we know it is at risk, but without groomed professionals prepared to fight the cybercrimes of tomorrow and keep this data protected, all of our online information can be compromised and held hostage. We must apply the key learnings from these knowns to future unknown threats so they can be anticipated and mitigated earlier, or blocked altogether.<br/><b>&#8212; </b><b>Education is power:</b> Through the National Initiative for Cybersecurity Education (NICE) program, the federal government is taking steps to establish an ecosystem of cybersecurity education, training and workforce development across the public and private sectors. Keeping up to date with NICE&#8217;s recommendations will give a leg up on the competition.<br/><br/></p>





<p class="wp-block-paragraph">Threats are increasing daily across every industry worldwide. If actions are not taken to bridge the cybersecurity workforce gap, particularly within government agencies, society will become paralyzed. Solving the known unknowns and the unknown unknowns of tomorrow requires educating, building and reinforcing our cybersecurity talent pool and workforce. This involves training the people using technology that transmits data to understand what information is held within the data, as well as creating more of the professionals working behind the scenes to protect it moving forward.</p>



<p class="wp-block-paragraph">Ensuring the secure future of our society and global economies depends on security technology innovation, but it also depends on the people who operate our global cyber businesses. While there are many unknowns on the horizon, what we do know is that cybersecurity will continue to remain a hot topic. We need an expanded, skilled cybersecurity workforce today to protect against the unknown threats of tomorrow.</p>



<p class="wp-block-paragraph"><i>Steve Kirk is a cybersecurity professional with 17 years of experience, 11 of them with Fortinet. Prior to Fortinet, he worked for network security company Secure Computing, 3Com and Foundry. Kirk has 26 years of experience supporting the U.S. federal sector. He is a graduate of Radford University.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Transportation: A Nation in Motion</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/transportation-a-nation-in-motion/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/transportation-a-nation-in-motion/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 18 Jul 2016 16:26:18 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/07/18/transportation-a-nation-in-motion/</guid>

					<description><![CDATA[Networks enable vehicles to be smarter and safer, but bring some risks.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/transportation-a-nation-in-motion/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">15799</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/636044415258846670-railways-2jpg.jpg" width="3000" height="1924" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">A year ago, security researcher Chris Roberts grabbed headlines for hacking an airplane.</p>



<p class="wp-block-paragraph">More specifically, he hacked the plane&#8217;s inflight entertainment system. Details did grow a little murky from there, with an FBI affidavit asserting that Roberts hacked a plane inflight, causing it to veer off course – a claim that plane manufacturer Boeing and aviation adamantly denied as humanly possible.</p>



<p class="wp-block-paragraph"><strong><em>Special Multimedia Report</em></strong></p>



<p class="wp-block-paragraph"><a href="http://www.federaltimes.com/critical-infrastructure/"><strong><em>Critical Risk: Assessing the cybersecurity of the nation&#8217;s infrastructure</em></strong></a></p>



<p class="wp-block-paragraph">But questions of what is or what may be possible are exactly what spur increasing fear among the traveling public – some legitimate, some not – and attention from leadership within the transportation sector, tasked with managing the risk.</p>



<p class="wp-block-paragraph">All modes of transportation are becoming more reliant on cyber-based functions, and as technology asserts itself, that will become more the case, said Mark Troutman, director at the Center for Infrastructure Protection and Homeland Security at George Mason University. He pointed to a proposal under development for a new system that can link trucks together under the control of one human driver.</p>



<p class="wp-block-paragraph">&#8220;You and I would see four or five trucks tailgating each other, hooked together virtually,&#8221; he said. &#8220;That&#8217;s great, because you can have five tractor trailers that are controlled by one person. If I&#8217;m a business owner, it&#8217;s perfect; immediate cost control. But think of the ability of an adversary to untether those.&#8221;</p>



<p class="wp-block-paragraph">&#8220;That&#8217;s just one example,&#8221; Troutman added. &#8220;There are others,&#8221; covering the gamut of planes, trains and automobiles.</p>



<p class="wp-block-paragraph">But in cybersecurity there is a fine line between rational threat analysis and fear mongering. Cybersecurity experts often say that criminals and enemy nation states have the ability to do cyber damage, but choose not to. For the former, the payoff is too uncertain and for the latter, the potential retaliation too staggering. As Troutman said, &#8220;I can spin a scenario of untethering a truck, but that would be complex to pull off and one would need to ask why anybody would bother to properly evaluation the nature of the threat.</p>



<p class="wp-block-paragraph">That is a struggle for the aviation industry, which has been evolving toward much more interconnected systems by necessity, where data is shared between government and industry, which the Federal Aviation Administration in turn must regulation – from airlines as well as the aircraft manufacturers.</p>



<p class="wp-block-paragraph">&#8220;As we are sharing information across technological systems, we&#8217;re opening certainly more gateways into those systems, and we need to be very, very vigilant and thoughtful about who we provide access,&#8221; said FAA Administrator Michael Huerta. He described a &#8220;very aggressive and multilayered approach to ensure that we do not have cyber disruptions in our national airspace system&#8221; – one which undergoing a technological upgrade as we speak, via the Next Generation Air Transportation System, or NextGen. That system transforms air traffic control from a radar-based system with radio communication to a satellite-based one. NextGen is far more efficient. But some have questioned whether it is more vulnerable.</p>



<p class="wp-block-paragraph">So then, can someone hack into an airplane? Huerta said that the FAA has seen no documented cases of an individual being able to hack into the core avionics systems.</p>



<p class="wp-block-paragraph">&#8220;It&#8217;s not just the companies and their operating systems. It&#8217;s also the avionics systems in the aircraft themselves. We want to make sure that we have a very clear understanding of how those systems operate,&#8221; he said. &#8220;It wasn&#8217;t that long ago that all objectives in cyber were to keep the bad guys out. And I think we across industry generally have evolved to a different framework of thinking: let&#8217;s assume they may get in. It&#8217;s really a question of how do we respond to that.&#8221;</p>
]]></content:encoded>
	</item>
		<item>
		<title>Health: Digital Progress = Digital Risk</title>
		<link>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/health-digital-progress-digital-risk/</link>
					<comments>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/health-digital-progress-digital-risk/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 18 Jul 2016 16:19:09 +0000</pubDate>
				<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Inside the Agencies]]></category>
		<category><![CDATA[Special Multimedia Reports]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2016/07/18/health-digital-progress-digital-risk/</guid>

					<description><![CDATA[Health care is, perhaps more than most any other sector, a treasure trove of valuable data.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/smr/critical-infrastructure/2016/07/18/health-digital-progress-digital-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11274</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/636044410762741849-medicaljpg.jpg" width="3600" height="2395" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Health care is, perhaps more than most any other sector, a treasure trove of valuable data. In the past, it was personal identifiable information that enables identity theft. But that&#8217;s evolved.</p>



<p class="wp-block-paragraph">&#8220;All sectors have a long history of dealing with the privacy and financial consequences of cyberattacks,&#8221; said Steve Curren, <a href="https://www.linkedin.com/title/director-%28acting%29%2C-division-of-resilience%2C-office-of-emergency-management?trk=mprofile_title">acting director of the Division of Resilience in the Department of Health and Human Services Office of Emergency Management</a>. &#8220;The emerging challenge for the health care and public health sector is the potential for cyberattacks that end up impacting patient care. As our dependence on technology increases and systems become more interconnected, we need to remain aware of the importance of good cybersecurity practices in keeping patients safe.</p>



<p class="wp-block-paragraph">Actual health consequences of past attacks have often been either indirect or difficult to prove. Even Hollywood Presbyterian Medical Center, which earlier this year paid a hacker $17,000 in bitcoin to restore crippled systems, saw no impact on patient care.</p>



<p class="wp-block-paragraph">But the potential is there: systems could be brought down in a similar ransomware attack, interfering with drug delivery and other vital systems. A hacker getting into drug development research could carry out competitive sabotage. Laboratory research in the wrong hands could squash a medical breakthrough or even arm terrorist for a biological attack.</p>



<p class="wp-block-paragraph">&#8220;As a general matter, I don&#8217;t like to start from worst case scenarios. I try to work from bad scenarios that have a reasonable likelihood,&#8221; said Darren Lacey, chief information security officer and director of IT compliance for the Johns Hopkins University and Johns Hopkins Medicine. &#8220;I think you have to keep in the back of your head that something much worse could happen, but if you build your entire security program around that, it distorts the security program from the stuff that actually does happen quite a bit.&#8221;</p>



<p class="wp-block-paragraph">The problem is one of complexity, as Curren describes it: The threats are as diverse as the number of organizations and systems they impact. And what Lacey has seen emerging in the last couple of years are directed attacks – where hackers come after an asset and then, after being blocked, come back again and again. It&#8217;s evidence that the health care industry, Hopkins specifically, has become a target.</p>



<p class="wp-block-paragraph">&#8220;Attackers are sophisticated enough to know with some degree of persuasion what exactly they&#8217;re going after and that seems to be characteristic of state actors,&#8221; he said. &#8220;They&#8217;ve done their homework much more than in the past. It doesn&#8217;t change that that much how you defend it, interestingly enough, because you&#8217;ve still got to do the same things.  But you keep it in the back of your mind, &#8216;if I was a foreign state actor or a sophisticated cyber criminal, what would I be interested in?&#8217; And you hope you guess right.&#8221;</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
