‘Easier to target’: water, power firms face rising risk

Water, energy, banking and telecommunications providers in Australia will be asked to bolster their defenses following a series of online attacks designed to disrupt essential services.
The Australian Signals Directorate set out recommendations for utility providers in a 16-page guide signed on Tuesday by Five Eyes’ intelligence partners in Canada, New Zealand, the UK and the US.
The advice comes in the wake of sophisticated attacks on critical infrastructure by Chinese-sponsored hacking groups; one of which compromised nine US telecommunications companies.
It also comes weeks after a national telstra outage by Telstra that caused widespread disruption to retail stores, transport and emergency services.
The agency’s document, called CI Fortify, was developed with industry partners and is designed to help critical infrastructure providers isolate operational technology from the rest of their networks.
Operating technology may include switches, pumps, and other equipment that are vital in providing services such as water and electricity but are less complex than other parts of a network.
Australian Signals Directorate Cyber Amplification deputy director general Heidi Hutchison said the age, design and underlying connections of this equipment could leave it vulnerable to online attacks.
“It’s generally easier to target, especially because a lot of the connections that have been established over the last 10 years are not necessarily done with cybersecurity in mind,” he told AAP.
“This asks organizations to think more seriously about the architecture that needs to be in place.”
The security advice is designed to help essential service providers isolate parts of their networks for up to three months to give them time to respond to an online attack.
He said recent attacks on critical infrastructure by Chinese-backed hacking groups have changed the threat level for utility providers, including Salt Typhoon pre-located within water and energy firms and Volt Typhoon infiltrating telecommunications companies.
“There was no other reason for an actor to remain seated other than to cause disruption to services; it had no espionage value,” Ms Hutchison said.
“This was a real indication that we need to better prepare our critical infrastructure to be able to detect these actors in their environments.”
The Australian Signals Directorate’s recommendations include identifying vital systems, networks and customers, creating isolation points to contain attacks and testing isolation plans.


