Protecting critical infrastructure from a cyber pandemic

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Jeremy Kaye, Head, Executive Briefing Center, Check Point Software Technologies, Mitch Muro, IoT Security Product Marketing Manager, Check Point Software Technologies & Katerina Megas, Program Manager for Cyber Security for IoT, National Institute of Standards and Technology (NIST)


  • Cyber-attacks on infrastructure services are on the rise, most recently the Colonial Pipeline hack in the US and the public health service attack in Ireland.
  • Hackers are exploiting the use of Internet of Things (IoT) which creates millions of new vulnerability points in critical infrastructure.
  • We need the public and private sectors to build greater consensus on IoT security standards and build trust in security across critical infrastructure.

We are in the midst of a “cyber pandemic”. In 2020, COVID-19 accelerated a transition towards remote working and the software being used for these attacks has become easier to execute, ransomware attacks have risen rapidly and continue to accelerate in 2021:

  • Attacks in the US alone have increased 300% in the past nine months.
  • More than 60% of ransomware attacks target industries with critical infrastructure, led by healthcare, utilities, and manufacturing.
  • US utilities have been attacked 300 times every week with an increase of 50% in just two months.

A prime target for cybercriminals has been the Operational Technology (OT) networks which interconnect the Industrial Control Systems (ICS) that manage our critical infrastructure. As services like power grids, water treatment facilities, transport and healthcare systems increasingly integrate their operational technology systems with the internet of things – for example through remote sensors and monitoring – this creates a new frontier of risks where millions more vulnerability points and new vectors can be exploited by hackers.

These attacks have huge implications not only on businesses but also on communities, cities, states, and entire countries. The consequences can be dire. In April 2020, hackers targeted Israel’s water treatment facilities through their IoT system, which gave attackers the ability to change the water pressure, temperature, and chlorine levels of the water. If the attack had fully succeeded, this could have led to whole communities becoming sick from the water supply or triggering a failsafe which would have left thousands of people without water entirely.

How are hackers exploiting IoT systems?

IoT devices and connected systems can be a large security risk for critical infrastructure services when security best practices are not implemented, as they come with a few intrinsic flaws:

  • Lack of standardization in cybersecurity practices across the supply chain leads to greater exposure.
  • Vulnerable security protocols and designs, including weak passwords and patching practices.
  • Obsolete and unsupported architecture, firmware and software.
  • Attack surface that increases with the number of connected devices.

As a result, there are a number of ways for hackers to exploit these devices and either perpetrate attacks on bigger targets or move laterally to harm mission-critical systems and steal information of customers and employees, intellectual property, or other sensitive assets.

A new “botnet” attack called Mozi has been extremely active in the past 18 months, accounting for 90% of total IoT attacks in 2020 and controlling nearly 500,000 connected devices. Each compromised device is instructed to find more devices to infect, which enables cyber criminals to gain control over entire networks and its data and hold it for ransom. Cybersecurity

What is the Forum doing to avert a cyber pandemic?

Next-generation technologies such as AI, ubiquitous connectivity and quantum computing have the potential to generate new risks for the world, and at this stage, their full impact is not well understood.

There is an urgent need for collective action, policy intervention and improved accountability for government and business in order to avert a potential cyber pandemic.https://www.weforum.org/videos/a-cyber-attack-with-covid-like-characteristics

The Forum’s Centre for Cybersecurity launched the Future Series: Cybercrime 2025 initiative to identify what approaches are required to manage cyber risks in the face of the major technology trends taking place in the near future.

Find out more on how the Forum is leading over 150 global experts from business, government and research institutions, and how to get involved, in our impact story.

In March 2021, Silicon Valley start-up Verkada suffered a massive IoT cyber-attack. The hackers were able to obtain administrative privileges to a large number of security surveillance cameras, meaning they could execute their own malicious code on the devices.

Once a hacker can breach a networked device, they can then use the device as a launching point for attacks laterally, exposing systems that are critical to operations. As industries further integrate IT and OT networks to gain new insights, these devices pose an even greater danger for operations that rely on industrial control systems. Without a greater push for security that addresses these connected devices, we are likely to continue seeing more attacks that target critical infrastructure industries.

What is being done at a national and global scale?

Critical infrastructure remains largely private-owned and will require a coordinated effort between the public and private sectors to deter ransomware and IoT threats. To address gaps in security protocols and standards within critical industries, governments are taking it upon themselves to introduce and expand on existing cyber security policies for IoT devices.

The European Union Agency for Cybersecurity (ENISA) published guidelines on security IoT supply chains in 2020 and is now developing specific security measures for IoT operators and critical infrastructure industries. Meanwhile, the IoT Cyber Security Improvement Act was enacted in late 2020, which requires US public sector users of IoT, including those used in critical infrastructure, to extend robust cyber defenses to their IoT deployments.

The standard for this has been developed by the National Institute for Standards in Technology (NIST), who has been central in developing approaches for improving cyber security across the US for several years. NIST has developed a number of guidance documents in consultation with stakeholders in government, industry and the private sector, and in coordination with other nations’ international standardization efforts. Given the size of the US government as a customer, the NIST standards adopted for the public sector could also act as a broader de-facto industry standard for all types of IoT devices in the US and beyond. https://open.spotify.com/embed/episode/0uqF6UceaRIUZRaQkFnQd5

Looking beyond the IoT Cybersecurity Improvement Act which focuses on the US Federal Government market, Public Law 116-283 which passed at the end of 2020 called for an IoT Steering Committee made up of private sector stakeholders to advise a US Federal government-wide interagency group. The Steering Committee and Federal Working Group are tasked to identify the benefits of IoT, improve IoT regulation and remove barriers to adoption. In a parallel effort, the President’s May 2021 Executive Order on cybersecurity calls for the piloting of a labelling programme for consumer IoT products that identifies how they meet cybersecurity criteria, which will be operational by February 2022.

These efforts to establish security requirements for IoT devices goes beyond federal agencies and contractors to address the need for security in critical infrastructure. Industries that are most exposed to these attacks seek uniformity and efficiency, and thus look to these laws and policies as guidelines to adopt baseline security requirements.

What can the public and private sector do?

As cyberattacks rise in critical industries, governments and the private sectors have a shared responsibility to protect these systems. Adopters of IoT devices can work alongside policy-makers and cybersecurity suppliers to build greater consensus on IoT security standards while also developing trust in security across critical infrastructure.

1) Establish a consistent approach on IoT security globally by:

  • Agreeing on a common global baseline standard on IoT security (differentiating consumer and industrial devices).
  • Promoting shared security principles from industry alliances such as the Cyber Tech Accord, Charter of Trust or Paris Call for Trust and Security.
  • Aligning regulations and baseline device security certification mechanisms.
  • Developing common principles for digital security and international norms.
  • Focus not only on the suppliers but also the consumers of IoT technology.

2) Building trust through better transparency and international cooperation:

  • Clarifying the responsibility model across the supply and value chain.
  • Fostering cross-sector and international collaboration.
  • Promoting the use of international information-sharing frameworks and assurance best practices.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© WFP/Khadija Dia Food is distributed to displaced families sheltering in a school in Tariq Jdide, Beirut.

Middle East war risks pushing 45 million more people into acute hunger

This article is published in association with United Nations. The Middle East war could cause the worst disruption to lifesaving humanitarian work since COVID, the UN World Food Programme (WFP) warned on Tuesday, as the UN chief again demanded an end to the widening conflict. “The Secretary-General asserts once more that the war in the Middle […]
© World Vision Smoke rises in Beit Mery, close to the Lebanese capital, Beirut, following an airstrike.

Middle East war’s ‘spiral of conflict’ drives mounting civilian toll

This article is published in association with United Nations. The widening war in the Middle East and its growing impact on civilians came under scrutiny at the UN in Geneva on Monday, as independent experts briefing the Human Rights Council warned of escalating violence following the onset of Israeli and US strikes on Iran and counterstrikes […]
© Mousawat A mother and child displaced by the conflict in Lebanon receiving care at a clinic.

Middle East war: Women in Lebanon forced to give birth on roadside

This article is published in association with United Nations. As the UN Secretary-General touched down in Beirut on Friday in solidarity with the people of Lebanon, UN agencies highlighted the dangers for civilians and particularly pregnant women and migrant workers, amid ongoing airstrikes and rocket fire between Hezbollah fighters and Israel.  “There’s 11,600 pregnant women who […]
© WFP/Arete/Ali Yunes Some residents of Beirut who have been displaced by the conflict are now living on the streets of the Lebanese capital.

‘Perfect storm’: Lebanon crisis deepens as civilians bear the brunt

This article is published in association with United Nations. Lebanon is facing a “perfect storm of unpredictable challenges” as conflict, mass displacement and dwindling humanitarian resources converge, the UN’s Resident and Humanitarian Coordinator in Lebanon, Imran Riza, has warned. The current escalation began on 2 March, when outgoing fire by Hezbollah drew a strong retaliation from […]
© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]
© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

From Local Barriers to Global Lessons: Practical Paths Toward Inclusive Healthcare

This article was exclusively written for The European Sting by Ms. Zainatun Nawwariyah is a fifth-year medical student at the Faculty of Medicine, University of North Sumatera, who is passionate about advancing medicine through research, advocacy, and service. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com