What the latest Iranian power plant attack means for the wider industry

151 Views

At this time, we don’t know much about the attack beyond that the power plant experienced downtime, which could have been a direct effect of the attack, part of the defensive response, or a combination of both. What it does demonstrate is that state-linked actors have both the intent and capability to target relatively ordinary industrial technology and are establishing access within the technology underpinning CNI that could potentially be used to cause disruption in future conflicts.

The conclusion, however, should not be that Iranian hackers have demonstrated an ability to switch off Britain’s whole electrical grid, but it does highlight the challenges the industry is facing. The electricity system is becoming increasingly distributed and, while one asset is of little consequence, a weakness that is repeated across hundreds of similar assets could compound to a significant problem due to the technology and suppliers the grid relies on.

How they got into the powerplant isn’t currently clear, but it doesn’t necessarily have to have been a sophisticated attack. CNI is vulnerable to all sorts of basic security challenges: exposed internet-facing devices, compromised remote access credentials, vulnerable gateways, or compromised third-party accounts. The challenge with securing operational technology (OT) is that it runs on legacy software that can’t be easily patched remotely, and operators always have to weigh up the operational and safety consequences of intervening as an outage or downtime could threaten safety. Replacing legacy systems takes time and has to be done with a lot of thought and care, but operators can’t accept exposure in the meantime. They must balance moving carefully when changing the plant, but quickly when reducing the risk around it. Immediate steps can be as simple as quickly identifying what is internet-facing, removing unnecessary remote-access paths, disabling dormant supplier accounts, rotating weak or compromised credentials, and restricting who can reach operational systems.

The question I would take from this incident is not how we protect one small generator but whether the same route into that generator exists across fifty others, and while we work carefully on the permanent fix, are we moving fast enough to stop somebody using it first?