Protecting critical infrastructure from a cyber pandemic

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Jeremy Kaye, Head, Executive Briefing Center, Check Point Software Technologies, Mitch Muro, IoT Security Product Marketing Manager, Check Point Software Technologies & Katerina Megas, Program Manager for Cyber Security for IoT, National Institute of Standards and Technology (NIST)


  • Cyber-attacks on infrastructure services are on the rise, most recently the Colonial Pipeline hack in the US and the public health service attack in Ireland.
  • Hackers are exploiting the use of Internet of Things (IoT) which creates millions of new vulnerability points in critical infrastructure.
  • We need the public and private sectors to build greater consensus on IoT security standards and build trust in security across critical infrastructure.

We are in the midst of a “cyber pandemic”. In 2020, COVID-19 accelerated a transition towards remote working and the software being used for these attacks has become easier to execute, ransomware attacks have risen rapidly and continue to accelerate in 2021:

  • Attacks in the US alone have increased 300% in the past nine months.
  • More than 60% of ransomware attacks target industries with critical infrastructure, led by healthcare, utilities, and manufacturing.
  • US utilities have been attacked 300 times every week with an increase of 50% in just two months.

A prime target for cybercriminals has been the Operational Technology (OT) networks which interconnect the Industrial Control Systems (ICS) that manage our critical infrastructure. As services like power grids, water treatment facilities, transport and healthcare systems increasingly integrate their operational technology systems with the internet of things – for example through remote sensors and monitoring – this creates a new frontier of risks where millions more vulnerability points and new vectors can be exploited by hackers.

These attacks have huge implications not only on businesses but also on communities, cities, states, and entire countries. The consequences can be dire. In April 2020, hackers targeted Israel’s water treatment facilities through their IoT system, which gave attackers the ability to change the water pressure, temperature, and chlorine levels of the water. If the attack had fully succeeded, this could have led to whole communities becoming sick from the water supply or triggering a failsafe which would have left thousands of people without water entirely.

How are hackers exploiting IoT systems?

IoT devices and connected systems can be a large security risk for critical infrastructure services when security best practices are not implemented, as they come with a few intrinsic flaws:

  • Lack of standardization in cybersecurity practices across the supply chain leads to greater exposure.
  • Vulnerable security protocols and designs, including weak passwords and patching practices.
  • Obsolete and unsupported architecture, firmware and software.
  • Attack surface that increases with the number of connected devices.

As a result, there are a number of ways for hackers to exploit these devices and either perpetrate attacks on bigger targets or move laterally to harm mission-critical systems and steal information of customers and employees, intellectual property, or other sensitive assets.

A new “botnet” attack called Mozi has been extremely active in the past 18 months, accounting for 90% of total IoT attacks in 2020 and controlling nearly 500,000 connected devices. Each compromised device is instructed to find more devices to infect, which enables cyber criminals to gain control over entire networks and its data and hold it for ransom. Cybersecurity

What is the Forum doing to avert a cyber pandemic?

Next-generation technologies such as AI, ubiquitous connectivity and quantum computing have the potential to generate new risks for the world, and at this stage, their full impact is not well understood.

There is an urgent need for collective action, policy intervention and improved accountability for government and business in order to avert a potential cyber pandemic.https://www.weforum.org/videos/a-cyber-attack-with-covid-like-characteristics

The Forum’s Centre for Cybersecurity launched the Future Series: Cybercrime 2025 initiative to identify what approaches are required to manage cyber risks in the face of the major technology trends taking place in the near future.

Find out more on how the Forum is leading over 150 global experts from business, government and research institutions, and how to get involved, in our impact story.

In March 2021, Silicon Valley start-up Verkada suffered a massive IoT cyber-attack. The hackers were able to obtain administrative privileges to a large number of security surveillance cameras, meaning they could execute their own malicious code on the devices.

Once a hacker can breach a networked device, they can then use the device as a launching point for attacks laterally, exposing systems that are critical to operations. As industries further integrate IT and OT networks to gain new insights, these devices pose an even greater danger for operations that rely on industrial control systems. Without a greater push for security that addresses these connected devices, we are likely to continue seeing more attacks that target critical infrastructure industries.

What is being done at a national and global scale?

Critical infrastructure remains largely private-owned and will require a coordinated effort between the public and private sectors to deter ransomware and IoT threats. To address gaps in security protocols and standards within critical industries, governments are taking it upon themselves to introduce and expand on existing cyber security policies for IoT devices.

The European Union Agency for Cybersecurity (ENISA) published guidelines on security IoT supply chains in 2020 and is now developing specific security measures for IoT operators and critical infrastructure industries. Meanwhile, the IoT Cyber Security Improvement Act was enacted in late 2020, which requires US public sector users of IoT, including those used in critical infrastructure, to extend robust cyber defenses to their IoT deployments.

The standard for this has been developed by the National Institute for Standards in Technology (NIST), who has been central in developing approaches for improving cyber security across the US for several years. NIST has developed a number of guidance documents in consultation with stakeholders in government, industry and the private sector, and in coordination with other nations’ international standardization efforts. Given the size of the US government as a customer, the NIST standards adopted for the public sector could also act as a broader de-facto industry standard for all types of IoT devices in the US and beyond. https://open.spotify.com/embed/episode/0uqF6UceaRIUZRaQkFnQd5

Looking beyond the IoT Cybersecurity Improvement Act which focuses on the US Federal Government market, Public Law 116-283 which passed at the end of 2020 called for an IoT Steering Committee made up of private sector stakeholders to advise a US Federal government-wide interagency group. The Steering Committee and Federal Working Group are tasked to identify the benefits of IoT, improve IoT regulation and remove barriers to adoption. In a parallel effort, the President’s May 2021 Executive Order on cybersecurity calls for the piloting of a labelling programme for consumer IoT products that identifies how they meet cybersecurity criteria, which will be operational by February 2022.

These efforts to establish security requirements for IoT devices goes beyond federal agencies and contractors to address the need for security in critical infrastructure. Industries that are most exposed to these attacks seek uniformity and efficiency, and thus look to these laws and policies as guidelines to adopt baseline security requirements.

What can the public and private sector do?

As cyberattacks rise in critical industries, governments and the private sectors have a shared responsibility to protect these systems. Adopters of IoT devices can work alongside policy-makers and cybersecurity suppliers to build greater consensus on IoT security standards while also developing trust in security across critical infrastructure.

1) Establish a consistent approach on IoT security globally by:

  • Agreeing on a common global baseline standard on IoT security (differentiating consumer and industrial devices).
  • Promoting shared security principles from industry alliances such as the Cyber Tech Accord, Charter of Trust or Paris Call for Trust and Security.
  • Aligning regulations and baseline device security certification mechanisms.
  • Developing common principles for digital security and international norms.
  • Focus not only on the suppliers but also the consumers of IoT technology.

2) Building trust through better transparency and international cooperation:

  • Clarifying the responsibility model across the supply and value chain.
  • Fostering cross-sector and international collaboration.
  • Promoting the use of international information-sharing frameworks and assurance best practices.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]
© Unsplash/Angus Gray Ship transits through the Strait of Hormuz have dropped by over 90 per cent since the crisis escalated in late February 2026.

Hormuz crisis strangling global economy, Guterres warns, demanding solutions to end stalemate

This article is published in association with United Nations. The escalating crisis in the Strait of Hormuz could push tens of millions into poverty, trigger a surge in global hunger and even tip the world towards recession, the UN Secretary-General warned on Thursday. António Guterres decried the restrictions on free passage through the crucial chokepoint which […]
This article is published in association with United Nations.

AI in advertising risks fuelling information crisis, UN warns

This article is published in association with United Nations. With spending on advertising topping $1 trillion a year worldwide, the United Nations on Wednesday highlighted the untapped power of major brands to shape the future of Artificial Intelligence, warning that a failure to act could deepen a global information integrity crisis. In a new brief titled […]
This article is published in association with United Nations.

2015 nuclear deal ‘no basis’ for any new agreement with Iran

This article is published in association with United Nations. The 2015 nuclear accord with Iran cannot be the starting point for a new agreement with the country, the head of the International Atomic Energy Agency (IAEA) said on Wednesday in New York.  Rafael Mariano Grossi was speaking during a press conference at UN Headquarters held on […]
Credit:Unsplash)

From Hormuz to Lebanon, crisis reverberates through trade routes, upending humanitarian networks

© WHO/Hanan Balkhy In Gaza displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services. This article is published in association with United Nations. Disruptions in the Strait of Hormuz continue to send shockwaves through global food systems, the UN Food and Agriculture […]
© UNICEF/Mohamed Zakaria A displacement centre in El Fasher, North Darfur (file).

World News in Brief: Sudan drone attacks condemned, South Sudan violence, airstrikes in Ukraine, South Africa Freedom Day

This article is published in association with United Nations. The United Nations has condemned two recent drone attacks in Sudan, one of which left seven dead, Spokesperson Stéphane Dujarric said on Monday during his regular media briefing in New York. An aid truck from the UN refugee agency (UNHCR) that was carrying emergency shelter kits came under attack by […]
© IMO/Cihancan Tunay A ship makes its way across an ocean.

Chokepoints and conflict: How the Hormuz crisis is exposing global shipping vulnerabilities

This article is published in association with United Nations. The blockading of ships in the Strait of Hormuz as a result of the conflict between the United States and Iran has demonstrated how ships and seafarers have become “leverage in geopolitical disputes,” according to the head of the UN’s International Maritime Organization (IMO). Since conflict began […]
Middle East war: After oil and gas, concerns grow over minerals crunch

Middle East war: After oil and gas, concerns grow over minerals crunch

This article is published in association with United Nations. The shipping crisis in the Strait of Hormuz caused by war in the Middle East has exposed a new threat: a looming shortage of strategic minerals that drive economies all over the world – and a race by countries to obtain them. Until war erupted on 28 […]
This article is published in association with United Nations.

Ceasefire extension offers diplomatic opening, but tensions persist in Strait of Hormuz

This article is published in association with United Nations. The United States’ decision to extend a fragile ceasefire with Iran has kept a narrow window open for diplomacy, but fresh security incidents in the Strait of Hormuz on Wednesday underscore the volatility of the situation and the risks to global shipping and regional stability. The UN […]
UN News Moreira da Silva (right), Executive Director of UNOPS on a visit to the Gaza Strip.

Strait of Hormuz: With hunger looming, life-saving fertiliser shipments cannot wait, head of UN task force says

This article is published in association with United Nations. As the Persian Gulf crisis continues, time is ticking for farmers who rely on fertilizer shipped via the Strait of Hormuz – and millions worldwide who depend on their crops, particularly in vulnerable countries such as war-torn Sudan.  In normal times, one third of global fertiliser trade […]
UN News A popular market in Khan Younis, southern Gaza Strip.

Economic collapse pushes highly educated Gazans into the ‘survival economy’

This article is published in association with United Nations. Young Palestinians in Gaza with university-level educations are setting aside dreams of putting their hard-won skills into practice and doing whatever they can to survive.  Abdullah al-Khawaja, an electrical engineering graduate displaced from Rafah to Khan Younis, now stands behind a small spice stall, having lost the […]
MONUSCO/Didier Vignon Dossou-Gbakon MONUSCO peacekeepers protect civilians in Ituri, eastern DRC.

World News in Brief: AI diagnostics, humanitarian deal for DR Congo, rights abuse allegations in Belarus, Ukraine children bear heaviest burden

This article is published in association with United Nations. New data shows that nearly three in four countries in Europe now use Artificial Intelligence in their health services to make a diagnosis. According to the UN World Health Organization (WHO) joint report with the European Union, 74% of countries in the bloc use AI tools in medical […]
© WFP The conflict in the Middle East is impacting the cost of food in many parts of the world.

Time running out on development goals as finance dries up, UN warns

This article is published in association with United Nations. Rising conflicts, the climate crisis and shrinking development finance are putting growing pressure on the poorest and most vulnerable countries – pushing development goals further off track. The warning comes in the Financing for Sustainable Development Report 2026 (FSDR), a new UN report launched on Monday, which finds […]
Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

World News in Brief: Myanmar amnesty, rising needs in Afghanistan, another power loss at Ukraine nuclear plant

This article is published in association with United Nations. Authorities in Myanmar released the country’s ousted president from prison on Friday, along with some 4,000 other people, as part of an amnesty to mark the traditional New Year festival. President Win Myint had been in jail since February 2021 when the military overthrew Myanmar’s democratically elected […]
UN Photo/Eskinder Debebe Siobhán Mullally, Special Rapporteur on Trafficking in Persons, especially women and children, one of the UN independent human rights experts calling for more accountability for the alleged trafficking victims in the Epstein files.

The Epstein files: Rights experts demand accountability, call for probe into trafficking allegations

This article is published in association with United Nations. UN independent human rights experts called on Thursday for justice and accountability for young women and girls who were trafficked systematically as part of allegations contained in the so-called Epstein files. The Human Rights Council-appointed experts also issued a general warning over the “continuing violence of patriarchal power systems” revealed […]
© World Bank A ship offloads its cargo at the port in Nuku'alofa, Tonga.

Middle East conflict chokes end of supply chain as lights go out in the Pacific

This article is published in association with United Nations. For Pacific Island countries, the Middle East crisis is not a distant geopolitical event. It is already showing up in higher fuel prices, electricity uncertainty and fears that communities sitting at the far end of global supply chains could be pushed into deeper economic insecurity. “We are […]
© UNICEF/Fouad Choufany The Basta neighbourhood in Beirut, Lebanon, lies in ruins.

‘Time for diplomacy over escalation’ in Middle East war: Guterres

This article is published in association with United Nations. As the war in the Middle East continues, the United Nations Secretary-General issued a passionate call for “serious negotiations” between the US and Iran to resume, warning that respect for international law “is being trampled” underfoot.  Addressing journalists at UN Headquarters in New York outside the Security […]
© IFAD/GMB Akash Prolonged disruptions to fuel and natural gas supplies could affect the global availability of fertilizers and impact crop yields. (file photo)

‘Clock is ticking’: Hormuz disruption raises fears of global food crisis

This article is published in association with United Nations. The clock is ticking for global food systems as disruptions in the Strait of Hormuz threaten to choke off the flow of fuel and crucial fertilizers needed for the next planting season – also raising the risk of higher food prices and a new wave of inflation.  […]
This article is published in association with United Nations.

Lebanon airstrike casualties ‘still under the rubble’ as ambulances, hospitals face new threats

This article is published in association with United Nations. With Lebanon still reeling from Israel’s devastating airstrikes on 8 April, UN humanitarians reported new fears of attacks on ambulances and looming food shortages in the south of the country on Friday. Speaking from Beirut, where he witnessed Wednesday’s attacks first-hand, the World Health Organization (WHO)’s representative […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com