Saturday, November 11, 2017

Report from SecureWorld Seattle - Being an Effective CISO Speech

This past week I attended the Seattle edition of SecureWorld.  The first keynote speaker was Mr. Demetrios Lazarikos (aka Laz) (laz@blue-lava.net) and his talk really hit home to me as a security practitioner and former CISO.  He offered some excellent advice regarding the characteristics of a cybersecurity leader, where they should report in the organizational structure, and offered some succinct recommendations to be considered.

So, this is a trip report of sorts but I also thought his comments were "dead on" and I heartily endorse his opinions.

Characteristics of Today's Cyber Leader

His key points about today's successful cybersecurity leader included:

  • Curious and a life-learner
  • Critical thinker
  • Patient and able to influence
  • Understand the value of the cybersecurity  program
  • Understand and can articulate the risks to revenue and sales enablement (It's the Money!)
  • Works closely with IT audit and regulators
  • Is in it for the PASSION
  • Never lets a cybersecurity opportunity go to waste -- EVER!
  • Tries to remain vendor agnostic

Organizational Reporting

Laz explicitly said the "CISO NEEDS TO REPORT TO THE CEO!"

I heartily agree!  The CISO is a very, very key cog in the gears of the organization and without an unencumbered communication to the chief decision-maker, the CISO's hands are tied (which I know from experience).

Talking to the Board of Directors

Laz again offered some terrific advice on ways to report and communicate to the Board of Directors.  Because you usually only have 10-15 minutes for your discussion, his suggestions included:

  • Ensure the reports are in terms THEY understand.  Not technical gobbly-gook.
  • Be streamlined
  • Quantify risk and loss exposure in dollars - not bits/bytes
  • Provide specific recommendations for moving ahead and protecting the enterprise
  • Emphasize the risk to revenue and risk to the brand -- not what the best firewall is

Recommendations

In closing, Laz offered some terrific recommendations for consideration by current and future CISOs:

  • Incorporate cybersecurity in all areas of your business -- from the individual employee to the CEO; from the mundane janitorial services to the strategic planning
  • Be an enabler -- always consider risk to revenue and sales enablement
  • Meet and know the CEO --- don't meet them for the first time during a data breach
  • Understand and report to the business in "business terminology"
  • Collaborate, Collaborate, Collaborate!
Overall, Laz's speech was one I could understand and equate to due to my time in the trenches and my own experience.  Thanks to SecureWorld for inviting Laz to speak! 

### ###

Tuesday, November 7, 2017

Resources to Learn About ICS Security

I had an interesting conversation with a colleague yesterday.  He called to ask for some advice on ways to advance his career in the industrial controls security space.  He held a Certified Information Systems Security Professional (CISSP) certificate and a Masters in Information Security.  However, he was frustrated on determining ways to move ahead in ICS security.

As I considered his questions I realized that a person who can advance in the areas of industrial controls security is someone with factory or process plant experience, and understanding of basic controls theory, and a solid understanding of factory/process plant operations and maintenance.  These are very fundamental to one understanding the causes and effects of ICS security.

CLASSROOM / ONLINE TRAINING

Besides the “floor” experience, an individual interested in ICS security probably needs some formal training on the key aspects of ICS security you don’t learn when studying for your CISSP.  My recommendations include:

ICS-CERT Cyber Security Industrial Control Systems (210W):  This is a free course available on the ICS-CERT Virtual Learning Portal.  The training is all self-paced and requires between 10 to 15 hours to complete.  It is a great way to begin your ICS security knowledge journey.

·         ICS-CERT Cyber Security Industrial Control Systems (210W):  This is a free course available on the ICS-CERT Virtual Learning Portal.  The training is all self-paced and requires between 10 to 15 hours to complete.  It is a great way to begin your ICS security knowledge journey.




·    SANS ICS 410: ICS/SCADA Security Essentials: If you take the course, you’ll essentially have the necessary training to pass the SANS GICSP – Global Industrial Cyber Security Professional certification.  The details on the 5-day class are located here.  Of note, you don’t need to take the course but can instead pay to take the test.

·    ISA Cybersecurity TrainingThe International Society for Automation (ISA) offers a series of four different classes covering ICS security.  These class titles include:
o    Industrial Networking and Security (TS12)
o    Introduction to Industrial Automation Security and the ANSI/ISA99 Standards (IC32C)
o    Using the ANSI/ISA99 Standard to Secure Your Control System (IC32)
o    Assessing the Cybersecurity of New or Existing IACS Systems (IC33)
o    IACS Cybersecurity Design & Implementation (IC34), and
o    IACS Cybersecurity Operations & Maintenance (IC37)
As I understand, each course has an associated certificate (not certification) with each class which you can receive after you satisfactorily pass a written test.
Overall, the ISA training has come a long way and should help with understanding practical ICS security.
You can find out more information regarding the ISA classes here.

READING RECOMMENDATIONS

In regards to reading, I’d highly recommend the following documents to read and establish your baseline knowledge of ICS security. 
  • Guide to Industrial Control Systems (ICS) Security, NIST SP 800-82 R2:  Even though this is issued by the National Institute of Standards and Technology (NIST) it is a decent “textbook” prepared to give the reader a comprehensive view of ICS and the security issues associated with “operational technology (OT).”  I’d recommend the student read this document before moving ahead to any of the training above.  By the way, this is free.
  • An Abbreviated History of Automation & Industrial Controls Systems and Cybersecurity, SANS:  This document is a high-level introduction to industrial controls, control theory, the history of industrial controls and a history of the security issues affecting ICS – including the infamous Stuxnet.  This information will be very helpful to the reader as they progress through the courses above and in their work.  Again, another resource available at no charge.
  • Industrial Network Security, by Eric D. Knapp and Joel Thomas Langill, Syngress Press:  Although a $40 investment, this book offers excellent information on ICS and ICS security you will not normally see in the resources above or in other books written on SCADA security.  Messrs. Knapp and Langill provide excellent, real-world perspective on ICS security.  So, if you’re serious about your ICS security training, I strongly recommend you get this book and read/study it.


I’ve been lucky in my past 45+ years of work where I’ve operated power plants, evaluated various factories, and had a chance to practice “practical ICS security.”  Fortunately, my background has given me the tools to advance in this area but I’ve also taken advantage of the resources above.

### END ###

Monday, October 23, 2017

REPORT FROM NERC GRIDSECCON

Last week I attended and spoke at the North American Electric Reliability Corporation (NERC) GRIDSECCON – electric grid security conference in St. Paul, Minnesota.  The meeting was very well attended with around 500 attendees from around the US, Canada, and even Japan.  My compliments to the organizers!  It was a terrific meeting and worth everyone’s time.

I’d like to raise three key points that surfaced during the meeting and go into more detail on one of them.

  1. There were several presentations regarding the risks to critical infrastructure by commercially available drones.  This was a bit of a surprise to many attendees since the drone threat has not really be recognized as one.
  2.   A major threat to electric utilities is the challenges of INSIDER THREAT.  This is an issue that makes one wonder “why would anyone want to attack my company from the inside?”  Well, the NERC Electricity-Information Sharing and Analysis Center (E-ISAC) team mentioned this risk repeatedly.  So, take some time to be sure you are paying attention to the inside of your company for both physical and cyber-attacks and disruptions.
  3.   The third threat of mention is of the “bad guys” trying to harvest credentials that can be used against the company.  This is where I’d like to spend a few extra lines of text.
CREDENTIAL HARVESTING

Right now, the current and potential attackers are trying to harvest and collect credentials used for cyber access into a utility/energy company.  These credentials can make the attacker’s life much easier and using ill-gotten credentials has been demonstrated in such notorious attacks as in the Ukraine. 

The attackers try to harvest credentials via the “normal” means such as using PHISHING attacks on email.  But the attackers are also surveying and monitoring social media for a user’s credentials and password access answers. 

For example, if I know a person works at Utility X, then I can monitor their social networking – including non-work-related posts – for such things as the names of their kids, pets, mother’s maiden name, etc.  All good information to use when you are trying to reset a password.  Also, by monitoring their social networking I may be able to glean information about upcoming utility operations such as a planned outage that keeps Dad or Mom away from their kid’s soccer game. 

Useful information for the attacker.

One particular issue that is really disconcerting is how individuals use the same username and password for their social networks and personal email as they use for work.  THIS IS REALLY DANGEROUS AND SHOULD NOT BE DONE!  If I can hack into your social network and determine your username and password, that allows me to “pivot” to the utility username and log in and enter the utility network.

Such a practice should not be condoned by any organization and, in fact, should be an Employee Awareness posting at least every six months.

CONCLUSION

NERC GRIDSECCON was a useful meeting and I look forward to next year’s event – somewhere in the Western Electric Coordinating Council (WECC) territory.  This meeting raised some very key points of concern and as you’ve seen above the utility and critical infrastructure management needs to pay attention to Drones, the Insider Threat, and Credential Harvesting.


Thanks for reading!

Friday, June 9, 2017

WannaCry Ransomware and Industrial Control Systems

The following article was posted on my LinkedIn account and was prepared by me with assistance from several of my colleagues at my employer, BBA (www.bba.ca).  
The actual article can be located at this LINK.
###
There’s been substantial discussion in the media and on the interwebs about the ransomware called “WannaCry”. This malicious software (malware), which blocks access to data until a ransom is paid, has been destructive. It’s caused financial consequences as well as extreme inconveniences for critical businesses across the globe, such as the National Healthcare Service in the United Kingdom, which was one of the first and most significant victims of the attack (a total of 300,000 computers in 150 countries had been locked by WannaCry as of the end of May 2017).

WHAT IS A RANSOMWARE?

Ransomware is a type of malicious software that carries out the cryptoviral extortion attack from a cyber program that blocks access to data until a ransom is paid. It displays a message requesting payment to unlock the data.
Where did ransomware originate? The first documented case appeared in 2005 in the United States, but quickly spread around the world.
How does it affect a computer? The software is normally contained within an attachment to an email that masquerades as something innocent.
How much are victims expected to pay? The ransom demanded varies. Victims of a 2014 attack in the UK were charged $864. However, there’s no guarantee that paying will get your data back.
How did WannaCry operate? It appears to have used a flaw in Microsoft's software, discovered by the National Security Agency and leaked by hackers, to spread rapidly across networks locking away files.

IT VS. OT SYSTEMS

However, it appears that the ransomware was focused on the Enterprise IT systems and not the Operations Technology (OT), also known as Industrial Controls Systems (ICS), although a small number of U.S. critical infrastructure operators were reportedly affected. In any case, understanding the difference between these two types of systems is crucial to ensure the cybersecurity of your plant or facility… and whether or not ransomware like WannaCry can affect them.
The above figure illustrates the typical separation between Enterprise Information Technology (IT) and Operational Technology (OT), also known as ICS. Enterprise IT is composed of systems used to run a business: emails, time sheet reporting, finance, expense reporting, purchasing, etc. These systems are normally Windows-based, including Windows Servers and Windows operating systems.
On the OT side of the business, most of the “computers” are small and specialized machines, such as programmable logic computers (PLCs), distributed control systems (DCSs), engineering work stations, historians (basically focused, real-time databases), etc. Some Windows operating systems are used on the OT side, but there are also many other types of industrial communications protocols for data exchanges beyond normal TCP/IP.
Most importantly, Enterprise IT networks are usually connected to the Internet, while OT networks tend to be separated from the world wide web. There’s normally no direct communication links between IT and OT networks. That’s why WannaCry ransomware is affecting applications and data on Enterprise IT systems more than on the OT systems.
To date, a handful of cases where ICS were infected were reported. Nonetheless, “the news should put all companies that rely on industrial control systems (ICS) on high alert because the choices available to protect the systems within an industrial process facility are much more limited than those in corporate IT”, explained PAS Global CEO this week. Indeed, there are opportunities for WannaCry to locate and encrypt an unpatched Windows system in any ICS.
As of this time, there are no verified examples where WannaCry attacked and “bricked” a human machine interface (HMI) on a factory floor or caused an industrial system to fail quietly or catastrophically. But the opportunities are present wherever Windows operating systems are installed in the ICS in such places as HMIs, ICS engineering workstations, etc. ICS components of a plant are not patched or updated as often as IT systems components for a simple reason: reboot activities and software uploads require a production shutdown or the production lines must be in “safe mode” to avoid undesirable consequences on the production systems.

RECOMMENDATIONS TO CONSIDER

Here are four basic recommendations to ensure that ransomware, such as WannaCry, doesn’t endanger your production line and operations:
  1. Make sure the ICS is separated from the Enterprise Information Technology (IT) network and from the Internet where the WannaCry malware could migrate.
  2.  ICS operators/engineers/security personnel should make it a high priority to patch the Windows systems as soon as practical to reduce the risk and impact of the WannaCry malware.
  3. ICS operators should ensure that any portable media (e.g., USB drives) and/or laptops/test equipment capable of “carrying” the WannaCry malware (or any malware in all cases) is checked for known malware before the portable media even comes into contact with the ICS and its components.
  4. ICS operators, engineers and security personnel should make it a point to closely monitor the US ICS-CERT alerts and advisories or subscribe to their mail alert.

SUMMARY

Simply stated, WannaCry can impact ICSs and susceptible components; it takes hard work and constant, 24/7 due-diligence to stay on top of the security of your ICS. Assuming the risks of a breach or successful attack should be a mantra and should always be at the top of everyone’s minds.
###

Monday, January 9, 2017

DHS Designates Election Infrastructure as a Critical Infrastructure Subsector

On Friday, January 6, 2017, Secretary of the US Department of Homeland Security announced that DHS has designated the US Election System as "CRITICAL INFRASTRUCTURE."

In the press release, Johnson noted that "Given the vital role elections play in our country, it is clear that certain systems and assets of election infrastructure meet the definition of critical infrastructure."

According to the press release, "Election Infrastructure" is defined as:


  • Storage facilities
  • Polling places
  • Centralized vote tabulation locations
  • Information and communications technology to include:
    • Voter registration databases
    • Voting machines
    • Other systems to manage the election process and report and display results on behalf of state and local governments

Johnson reiterated that this designation does not mean a federal takeover, regulation or oversight or intrusion concerning elections in the US.  The designation does not change the roles state and local governments have in administering and running elections.

However, the designation as Critical Infrastructure does mean that election infrastructure does become a priority within the National Infrastructure Protection Plan (NIPP).

###

Saturday, October 22, 2016

US Elections System as Critical Infrastructure?

What is "Critical Infrastructure?"

According to the US Department of Homeland Security "Critical Infrastructure" includes those assets, systems, and networks whether physical or virtual, that are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.

Presidential Policy Directive-21 (PPD-21), "Critical Infrastructure Security and Resilience," identifies 16 critical infrastructure sectors.  These sectors include:

  • Chemical Sector
  • Commercial Facilities Sector
  • Communications Sector
  • Critical Manufacturing Sector
  • Dams Sector
  • Defense Industrial Base
  • Emergency Services Sector
  • Energy Sector
  • Financial Services Sector
  • Food and Agriculture Sector
  • Government Facilities Sector
  • Healthcare and Public Health Sector
  • Information Technology Sector
  • Nuclear Reactors, Materials, and Waste Sector
  • Transportation Sector, and 
  • Water and Wastewater Sector

What About the US Elections System/Sector?

In the news these past six weeks there has been an elevated discussion regarding the US election system and whether or not it should be identified as "Critical Infrastructure" and thus protected in the same way and means as the other 16 identified infrastructures.  This is aggravated by Mr. Trump questioning the integrity of the US election system and elevated concerns raised by the media that our country's enemies may take action to negatively impact the results of the voting on Tuesday, November 8th.

In early August, Secretary of the Department of Homeland Security, Jeh Johnson, observed:


"There's a vital national interest in our election process, so I do think we need to consider whether it should be considered by my department and others as critical infrastructure."  However ... 
 "There's no one federal election system. There are some 9,000 jurisdictions involved in the election process," Johnson said. (Link)

So, Johnson's perception is that there is no single "Election Infrastructure Sector" per se and it may be challenging to quickly and effectively identify it as "Critical Infrastructure."

I even heard of this issue at a recent conference held by the North American Electric Reliability Corporation (NERC) where a "new" critical infrastructure sector could be the US election system.

With some investigation by this writer, an article published on September 13, 2016, in Fedscoop, was located noting DHS Assistant Secretary for Cybersecurity, Andy Ozment, said that DHS will not classify election systems as critical infrastructure before the November 2016 presidential election.

Ozment's quote continued:

"This is not something we're looking to in the near future.  This is a conversation we're having in the long term with state and local government, who are responsible for voting infrastructure.  We're focused right now on what we can usefully offer that local and state government will find valuable.

"From our perspective, it gives us more ability to help.  It does not put DHS in charge."

It will be fascinating to see how this conversation progresses -- especially if Mr. Trump's noisy questioning of the integrity of the voting process continues through and after the presidential election.

At a minimum, perhaps the "Election System Sector" could be included under the auspices of the "Government Sector" Critical Infrastructure designation rather than adding "Number 17."

###





Tuesday, October 18, 2016

Review - WEF Global Competitiveness Report

This September 2016 the World Economic Forum (WEF) published its annual Global Competitiveness Report 2016-17.  This report is almost 400 pages of a fairly comprehensive analysis of each country in the world and its relative competitiveness based on 12 separate factors (shown below):




And based on these 12 factors, the factors themselves are broken down into key elements for:

  • Factor-Driven Economies
  • Efficiency-Driven Economies, and
  • Innovation-Driven Economies
For instance Institutions and Infrastructure are key "Basic" requirements necessary for an economy to thrive and compete.

The WEF analysis then used these factors to ascertain the competitiveness of a country relative to the rest of the world as well as to its geographic region in many cases.  For instance, the top 10 most competitive countries using this methodology are:

And the bottom 10 are:

Infrastructure Factor

The elements reviewed to calculate each factor are listed in the "Technical Notes and Sources" section at the end of the report.  Since this blog is focused on infrastructure there is interest on the elements included in this calculation.  These include the following:

  • Quality of overall infrastructure
  • Quality of roads
  • Quality of railroad infrastructure
  • Quality of port infrastructure
  • Quality of air transport infrastructure
  • Available airline seat kilometers
  • Quality of electricity supply
  • Mobile-cellular telephone subscriptions
  • Fixed telephone lines
At first glance, this list is missing such elements as fresh/potable water supply, food availability and distribution, etc.  However, the "Technological Readiness" factors include the following that could be considered part of the strength of a country's infrastructure:

  • Availability of latest technologies
  • Firm-level technology absorption
  • Foreign Direct Investment and technology transfer
  • Internet users
  • Fixed broadband Internet users
  • Internet bandwidth
  • Mobile broadband subscriptions

Conclusion

As usual, the quality and content of this report are very good.  It is compelling and interesting and a useful reference for country policy development.

###



Friday, July 29, 2016

IMPACT OF POPULATION SHIFTS ON CRITICAL INFRASTRUCTURE -- Summary of OCIA Report

In early July the U.S. Department of Homeland Security (DHS)/Office of Cyber and Infrastructure Analysis (OCIA) published an analysis entitled Impact of Population Shifts on Critical Infrastructure.  The report is a very compelling and interesting read and gives you a sense of how hard it is to augment infrastructure when the population is increasing (such as in the areas where fracking is in progress) and, how difficult it is to maintain current infrastructure when your tax base -- i.e., population -- is leaving as in the Rust Belt of the US.

To give the reader a sense of those areas in the continental US where population increase and decline may contribute to stresses on installation and maintenance of critical infrastructure is shown in a map shown below:


The map does reflect population shifts from the Northeast and Midwest to the South and West -- especially Texas, Georgia and Arizona/Nevada. According to the report, the new growth is in part because of high-technology magnet areas in the West and South, energy development of shale gas and shale oil in rural areas throughout the country, and regrowth in cities in the South and West with housing-led reversals. This growth is also partially because of lower costs of living, potentially including lower tax rates.

Rapidly increasing populations result in:

  • Increased demand for services
  • Increased infrastructure use
  • Increased rural roadway use requiring expensive reconstruction and repair
  • Reduced available downtime for infrastructure maintenance and repairs
  • Challenges in funding immediately needed infrastructure upgrades since available money may be delayed due to tax and revenue stream deferrals to later years.
  • Increased frequency and severity of disruptions to water and wastewater systems
Reduced populations result in:
  • Reduced tax base resulting in funding shortfalls for infrastructure maintenance and repairs
  • Uneven population densities within metro areas

Conclusions

The report does offer some approaches to address bot increasing and declining populations and the impacts on critical infrastructure.  The key recommendations for both cases are:
  1. Strategic Planning -- For rapidly increasing population growth, strategic planning is critical for meeting increases in demand -- especially because of the lead-time needed for financing; designing and planning projects; obtaining regulatory approvals; siting and constructing the infrastructure.
  2. Public-Private Partnerships -- These partnerships and their collective approach can be useful for infrastructure planning/development/maintenance during times of population growth or decline.  Don't forget, most of the critical infrastructure in the US is privately owned.  And because these private entities rely on state/local government approval to deploy large infrastructure projects their partnership and cooperation is critical.
###










Thursday, June 23, 2016

HOW TO "READ" THE ECONOMIST MAGAZINE





My full-time job is that of a security consultant, but I am also a hobbyist student of geopolitics.  My favorite (or is that favourite) publication in this regard is The Economist published weekly.  Unfortunately due to my consulting work along with other personal and professional obligations I often don't have the opportunity to really "read" the magazine from cover-to-cover.  But, rather than place the magazine on my notorious "to be read" stack, I have established a technique I'd like to share on how I can take some quality time to glean the contents of the magazine and at least add quickly to my geopolitical knowledge.
PHASE I:  THE CONTENTS (~ Page 5)
When I receive the magazine the first section I turn to is Contents.  Here I read the different titles of the articles but I'm especially sure to read the side-boxes (see below) since they offer a good sense of the themes covered in this week's issue.
Figure 1 - Read the Boxes
PHASE II:  THE WORLD THIS WEEK (~ Pages 8-10)
This is the most interesting and most effective part of my time with The Economist.  On these three pages, I get to view and digest the weekly cartoon and then get a good flavor of the world's news that I certainly don't obtain from the US television or newspapers.  For instance, in this week's issue, there is news from Nigeria, Kenya, Ethiopia, Bahrain, Indonesia, Bangladesh besides the "normal" news sources of the US political scene, China, Paris and of course the UK.
PHASE III: LEADERS (~ Pages 13-17)
This part of the magazine is my favorite.  Here you can gain a sense of the pros/cons, plusses/minuses of the issues raised by the editors of the magazine.  I especially like the coverage of these editorial comments since they cover most of the world and, again, are not focused on the US.  Yes, there are comments on US politics (e.g., the 2016 election, Orlando, etc.) but the other editorial coverage is in areas that I am not familiar or often exposed.  
PHASE IV:  SKIMMING THE PAGES 
Finally, during my 15 minutes of quality time with the magazine, I'll skim through the different sections usually pausing on some of the editorials, reviewing any graphics/maps, and speeding through the different text boxes.
Of course, if I'm ready to get on a plane or have some added time then I'll be sure to read the magazine in more depth but my focal points will generally begin with my four phases above.
CONCLUSION
If you don't already subscribe to The EconomistI'd highly recommend you do.  You'll find that the view offered is so much more superior than US television and is more portable than my other favorite reads The New York Times or Washington Post.


Monday, May 23, 2016

Earthquake Risk and US Highway Infrastructure

Thanks to our friends at the Federation of American Scientists (FAS) a recent Congressional Research Service report entitled Earthquake Risk and U.S. Highway Infrastructure: Frequently Asked Questions was posted.  This 11-page report is an excellent overview of the current state of natural and man-made (read - "Fracking") earthquake impact on the US highway system.



Two figures in the report are very telling as to the concentration of earthquakes and implications on "Shaking expected for Tall Structures Like Bridges" (below)...


as well as a graphic showing the chance of human-induced and natural earthquakes.  (Look at the concentration around Oklahoma presumably due to Fracking.)


Key Comments in the Report

The report approaches these issues in a FAQ approach...so, here are some quick highlights:

Q:  What Are the Components of Seismic Risk?

A:  Seismic risk to a highway system is determined by three factors:

  • Likelihood of seismic events of varying magnitudes, and related physical events, often referred to as the hazard;
  • Vulnerability of highway structures to damage from such events; and
  • Potential consequences of that vulnerability (e.g., lives lost, economic disruption, etc.)
Q: How Vulnerable Is the U.S. Highway System?

A:  "No national database exists on the seismic design and retrofit status of highway system components; thus, a perspective on vulnerability at the national level is unavailable.  However, many states with large seismic hazards have compiled data on the vulnerability of highway components within their borders..."

Q:  How Vulnerable are Highway Bridges?

A: Basically many of the most vulnerable older bridges -- particularly in the West Coast States -- have been retrofitted to improve seismic resilience; however, many older bridges (around 13,000) in the New Madrid seismic zone (AR, IL, IN, KY, MO, MS, TN) have not been retrofitted.

Q: How Costly is Retrofitting Highway Infrastructure?

A:  Because no national data exist on the status of retrofitting existing highway bridges or other infrastructure (e.g.,tunnels, highway systems), no national estimates exist.  


Conclusion

If you are involved in transportation policy or a student of infrastructure, this is a useful starting point to give you a sense of the daunting task of improving the resilience of highway structures against earthquakes.


Thursday, May 19, 2016

"The Business of Hacking" -- Recommended Reading for CEOs, Boards of Directors, Governance Leadership

What is your view of the "hacking community?"  Is it one of masked computer operators working in a darkened room or that of a white-coated laboratory technician?  Well, your views of the hackers working on new products and "services" to steal your information may be substantially changed after your read the most recent document from Hewlett Packard Enterprise entitled The Business of Hacking:  Business Innovation Meets the Business of Hacking.

http://www8.hp.com/us/en/software-solutions/hacking-report/index.html?jumpid=va_gpnq3t2xdw  
This document is an easy and compelling read for Chief Executive Officers, Chief Information Officers, Boards of Directors, Risk Analysts and cyber security students.  The article does an excellent job giving a straight-forward discussion regarding the "reality" of the cybercrime community and their "business models."

The HP whitepaper does a nice job clearly identifying "who" the "Bad Guys" are with a simple chart (shown below):


This is extremely helpful to those trying to understand cybercrime and cyber "hacking" because it shows there are different types of hackers with different motivations and capabilities.

The article almost reads like a Gartner report with a "Magic Quadrant" depiction of where the attackers are working relative to Payout and Effort/Risk to their "business."  The quadrant analysis is shown below:


Although the report doesn't go into details on how organized cyber crime is used by Nation-States, analysis has shown that some countries may be using organized cyber crime to do their cyber attacks thus giving the Nation-State the ability to offer "plausible deniability."

Finally, this report will reinforce to the CEO's, et al that the cyber crime business is just that...a business...where the hackers want to maximize profit and minimize risk...where the hackers need to do research and development and they need to have a finance minister to run their economic shop.

On a parenthetical note, in 2006 I wrote Chapter 1A, "Cybercrime's Impact on Information Security,"  in Cybercrime & Security edited by Pauline C. Reich.  In my article I discussed cybercrime as a business -- albeit nefarious - but with a CEO, COO, HR manager, VP of R&D, CFO, etc. and that their motives are focused on "....profit maximization and risk management..."

Key Take-Aways

This white paper from HP is a great educational piece to get to your Board of Directors, CEO, COO, CFO, CIO and cyber security students who need to realize that one way to hamper cyber crime is to alter the criminal's business operations .... raise their expenses and increase their risk.

###







Thursday, April 14, 2016

WEBINAR: Climate-Resilient Infrastructure -- 28 April 2016

Greetings!

I've been rather swamped with a major project for the past few months so my Blog has been pretty quiet.  Anyway, I want to pass along this one Webinar my fellow infrastructure colleagues may be interested.

WEBINAR:  NEW APPROACHES TO CLIMATE-RESILIENT INFRASTRUCTURE

LINK:  http://uweoconnect.extn.washington.edu/public_mipm/ 

WHEN:  THURSDAY, APRIL 28, 2016, 11:00 AM TO NOON PACIFIC DAYLIGHT TIME (GMT-7)

This FREE webinar will feature a panel of experts on infrastructure planning and climate change discussing new approaches to planning climate-resilient infrastructure.  The topics to be covered include:

  • How climate change affects infrastructure
  • How planners can respond to climate change by planning integrated and resilient infrastructure
  • Principles for re-thinking how we invest in infrastructure
  • How US Federal Agencies are adapting this approach to their grants and disaster relief programs, including information on the Federal Emergency Management Agency (FEMA) National Resilience Challenge and the US Housing and Urban Development (HUD) Disaster Resilience Competition
Hosts:
Ms. Jill Sterrett, FAICP, Affiliate Instructor,  Department of Urban Design and Planning, University of Washington, Seattle, WA  USA

Mr. Rhys Roth, Faculty and Director of the Center for Sustainable Infrastructure, Evergreen State College, Olympia, WA USA

Mr. Steve Moddemeyer, Principal, CollinsWoerman Architects, Seattle, WA USA

Thursday, February 11, 2016

A View of the World's Infrastructure -- PBS Video "Humanity from Space"

I have been a student of global infrastructure for many years and even completed my Masters in Infrastructure Planning and Management from the University of Washington, Seattle, USA this past year.  This week I happened to view an absolutely fascinating video on the US Public Broadcasting System (PBS) called Humanity from Space.

http://www.pbs.org/program/humanity-from-space/ 
This video offers a terrific view of global infrastructure expansion and development from the early days of mankind up to the future views of expanded renewable energy, communications networks, highways, transportation, etc.

From the PBS page, here is a broader description of the video:



You can view the entire video at:  http://www.pbs.org/video/2365530573/

You may also be able to locate it on other alternative options such as Roku, Netflix, Amazon Prime.

Anyway, take time to view this phenomenal film....the graphics are thought provoking and the music is from one of my favorite composers, Thomas Bergersen/Two Steps from Hell.

Cheers!

###


Monday, February 8, 2016

ONE OF FEW IN THE WORLD – MASTERS IN INFRASTRUCTURE PLANNING AND MANAGEMENT


As I began writing this blog post the World Economic Forum (WEF) annual meeting in Davos, Switzerland is in progress.  In conjunction with this major meeting the WEF also produces its Global Risks Report.  One section of the report – shown below – is entitled “Global Risks of Highest Concern for Doing Business.”





As you look at this list, the eighth most important risk of concern is “Failure of Critical Infrastructure.” 

Wow, that is very disconcerting and it is important that critical infrastructure issues be addressed to help mitigate and alleviate these risks.  But even as you think about it, global infrastructure is strained even with issues #1 through #7 (and #9, of course).

But how?

Masters of Infrastructure Planning and Management


In August 2015 I successfully completed the Master’s Degree in Infrastructure Planning and Management at the University of Washington, Seattle, Washington USA.  This program – entirely online, so you can take classes literally around the globe in various time zones – provided fantastic exposure to me as an infrastructure security professional on ways to manage and protect vital infrastructure systems from natural and man made threats.  The program curriculum is included below.



Figure 2 http://www.infrastructure-management.uw.edu/overview/courses/

And as you can observe, the courses train the students on such fundamental topics as risk management, geographic information systems (GIS), and strategic planning.  The core courses include “soup to nuts” reviews of different infrastructure sectors such as energy, water, food, transportation, emergency management and public health.

At the end of the two-year program I believe you can be an adept contributor to critical infrastructure planning and management at the local, regional, national or international level.

By the way, the instructors are also accomplished, practical professionals in their areas.  For instance the infrastructure finance professor studied under Nobel Laureates at the University of California.  The instructors teaching the energy courses work for the regional utility in Seattle, and the public health professor is a physician with almost 40 year’s experience in international public health management.

Overall, the instructors “…really know their stuff…” from a practical, hand-on perspective and after a quarter with each one of them you have not only learned the details of the sector but you also know where to look for more information – a key value to me as a critical infrastructure protection professional.

Graduates and their Stories


Some of my fellow classmates have done very well with their MIPM credentials.  One grad continued in the Business Continuity/Planning space for a major health insurance provider and is now the Global Emergency Preparedness manager for a major, US West Coast university.  Another classmate continues as a Lieutenant Colonel in the Army with expanded awareness of global infrastructure issues.  A third classmate is in a local city public utility doing planning work.

How Can I Get More Information?  Where Do I Sign Up?

If you want more details I’d first suggest you visit the University of Washington Master in Infrastructure Planning and Management web page.

Be sure to review the Admissions requirements and the Costs/Financial Aid page.  Overall, you’ll see that the entrance requirements are certainly those of a Top Tier University but within reason for the working professional.  Some of my classmates had their tuition covered by the GI Bill and my company reimbursed me for my courses.

Of note, each cohort starts at the end of September each year and the Application Deadline is June 1st.

Unique Training – Unique Opportunity


As the faculty and students can attest, this is one of the very few programs in the world offering Masters-level training on infrastructure planning and management.  And, it is ONLINE so you don’t need to attend classes and – as a working professional – I can tell you that class assignments can be completed even if you are on the road multiple time zones away from Seattle.

So, here are the key Links…..and remember, the Application Deadline is June 1st.

·         PROGRAM OVERVIEW: http://www.infrastructure-management.uw.edu/

·         CURRICULUM:                  http://www.infrastructure-management.uw.edu/overview/courses/

·         FACULTY:                            http://www.infrastructure-management.uw.edu/overview/faculty/

·         ADMISSIONS:                    http://www.infrastructure-management.uw.edu/admissions/

·         FINANCES:                          http://www.infrastructure-management.uw.edu/costs/

·         ONLINE LEARNING:         http://www.infrastructure-management.uw.edu/overview/onlinelearning/

###