Showing posts with label Incident Response. Show all posts
Showing posts with label Incident Response. Show all posts

Tuesday, July 29, 2014

Mr. Gisli Olafsson -- A True and Proven Crisis Leader

I am currently a student in the University of Washington Masters of Infrastructure Planning and Management (IPM) program.  This quarter I am taking IPM501, Comprehensive Emergency Management.  As part of this course one of our required readings is an excellent crisis leadership book by Mr. Gisli Olafsson entitled The Crisis Leader.



We were very fortunate to "virtually meet" Mr. Olafsson on an Adobe Connect lecture on July 29th where Mr. Olafsson took 90 minutes to highlight his experiences as an urban search and rescue leader including his experience as a team leader for Iceland's International Urban Search and Rescue team (ICE-SAR) immediately after the tragic earthquake hit Haiti in 2010.

Overall, Mr. Olafsson is a very compelling and experienced emergency response manager and leader with some excellent -- albeit tragic -- stories from his experiences responding to disasters around the world.  In his lecture he raised some excellent comments and ideas about the role of leadership during a crisis.  Some of the key ideas and comments he raised are captured below:

CL = Y + T + R


The equation above is one way Mr. Olafsson tried to explain what crisis leadership includes and entails.  The terms are first interpreted as:

CL = Crisis Leadership
Y = You
T = Team
R = Response

In summary he used this equation as a way to help capture some key aspects of personal leadership.

Y = You

You need to know yourself -- you need to know how you react under times of stress and crisis and how you deal with events -- including those events with substantial amounts of death and destruction.  You need to understand your emotions, fears and how to deal with these psychological arrows so you can be an effective leader.

Mr. Olafsson pointed out that key to the "You" aspect is to realize that you need to trust your team and their capabilities in order to control and even block your fear.  You need to be prepared for the task at hand by knowing your own strengths and weaknesses.  You also need to be physically and psychologically fit to endure the long hours and stressful conditions.

T = Team

Paramount elements for leadership success includes being resilient (also referred to as "Semper Gumby" as a reference to the very flexible cartoon character).  Secondly, you need to always be preparing through planning and exercising.. 

Mr. Olafsson noted that as a rule of thumb from a World Bank document on Natural Hazards Unnatural Disasters that for every hour or preparation spent you can expect to save six hours of effort; similarly for every dollar spent you can expect to save six dollars.

You want to build your team so that you are a "...leader of leaders..." where the team members are empowered to not only do their job but also to fill the role as a leader as required for the situation and based on their technical specialties/expertise.  Don't be a micromanager but lead your "leaders" so they are effective and the job gets done.

R = Respond

Response to a crisis is a key reason why you are at the disaster.  But, you are surrounded by many challenges ranging from the disaster itself to the weather to the debris field to the emotional survivors and even to the smell.  First you need to focus -- block the external stimuli and do your task at hand.  Secondly, take advantage of the intelligence and help that can be provided by the local population affected by the disaster.  Apparently FEMA in the U.S. refers to this concept as "Survivor-centric Response."

Responding requires a team with solid morale.  As noted in Chapter 25, "Team Morale," Mr. Olafsson states, "No matter which way it starts out , one of your crucial roles as a leader is to ensure that you keep morale high, even during the most difficult times.  Your ability to do that depends on a number of things including:
  • Your rapport with team members...
  • Your ability to read others...
  • Your ability to understand how the situation is affecting people..."

Conclusion

If you are a leader of any sort -- but especially one placed -- or potentially placed -- into an emergency situation or worse yet a disaster, I would highly recommend you take time to read, digest and contemplate the excellent and field-proven advice offered in this book by Mr. Olafsson.  As a 40+ year leader myself, I found his advice to be "...right on..." and useful for my professional and personal leadership roles.

Mr. Olafsson's website is:  www.thecrisisleader.com and he can be followed on Twitter @gislio

###







Thursday, April 17, 2014

Two Views of Today's Cyber Risks

This week I've had the chance to view two reports that gave me -- and I expect others -- a powerful view of the cyber challenges we face.  One report was a global view our reliance on the Web and the "...increasing danger of global shocks initiated and amplified by the interconnected nature of the internet."

The second article was a survey done by Control Engineering magazine on the global views of cyber security of the industrial controls domain.  The survey revealed that almost 50% of the respondents perceive the control system threat in their organizations to be at a moderate level, but 25% cite a "high" or "severe" threat level in their systems.

So, rather than provide detailed reviews of each document, let me help aim you to the appropriate links with some summary notes added:

Risk Nexus - Beyond Data Breaches: Global Interconnections of Cyber Risk -- Zurich and Atlantic Council

(LINK) 
This well-written report (30 pages) consistently raises the bar of the global risk relative to our reliance on the Internet and ecommerce in a manner similar to the annual World Economic Forum's Risk Reports.  Perhaps we are so closely connected to the Internet that we put our selves in harm's way relative to our economic -- and maybe even mental well being (?).

One quote that I find especially telling is:

"The internet of tomorrow will both initiate and amplify global shocks in ways for which risk managers, corporate executives, board directors, and government officials may not be adequately prepared."

Finally, take a look at Page 8 of the report...they include 7 aggregations of cyber risk that certainly made me think:


  1. Internal IT enterprise (hardware, software, servers, and related people and processes)
  2. Counterparties and partners (relationship between competing/cooperating entities, etc.)
  3. Outsourced and contract (IT and cloud providers, contract manufacturing)
  4. Supply chain (Exposure to a single country, counterfeit or tampered products, risks of disrupted supply chain)
  5. Disruptive technologies (internet of things, smart grid, embedded medical devices, driverless cars...)
  6. Upstream infrastructure (submarine cables, internet governance and operation)
  7. External shocks (major international conflicts, malware pandemics)

At a minimum I'd suggest you pass this report to your Board of Directors and Executive Management so they get a sense of another view of risks that need to be addressed and mitigated.


Control Engineering Cyber Security Study - April 2014 (Registration Required)

(LINK)
Compliments to the Director of Research for Control Engineering, Ms. Amanda McLeman and her colleague Mark Hoske for this summary report.  The report is based on a survey of about 190 respondents from February 7 to March 2, 2014.  So the data is fairly contemporary.

This summary report is a collection of graphs showing the demographics of the respondents as well as the summary results of the questions.

A good summary graph of the Threats considered by the respondents is below:


If you cannot adequately read the graphic above the top three system components the respondents are most concerned about are:

  1. Computer assets that are running commercial operating systems
  2. Connections to other internal systems
  3. Network devices
Finally a summary of key "bullets" from the report include:
  • 24% of respondents said they had NEVER performed a systems security vulnerability test
  • 25% of those surveyed indicated their computer emergency response team appears well trained and capable
  • 41% agreed having industry-required standards without government involvement would improve or enable their efforts to implement proper control system cybersecurity.  (So, maybe the NIST Cyber Security Framework has some hope?)
Thanks for taking the time to read my comments and have a good week!

###








Thursday, March 6, 2014

New Policy Approaches to Address Cyber Threats Impacting the Electric Grid

In February the Bipartisan Policy Center released a report focused on cybersecurity and the North American Electric grid.  At first I was worried that this report would be another collection of the same ol' ideas of leaning on the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards as the panacea -- fortunately, this report is very good and really has some excellent ideas to help protect the electric grid from and during a cyber attack.


In a simple way I'd strongly suggest you skim this report if you are in any way/shape/form involved with electric grid cybersecurity defense, policy, funding or response.

The key areas of discussion in the report include:

  • The Existing Landscape for Electric Grid Cybersecurity Governance
  • Standards and Best Practices for Cybersecurity
  • Information Sharing
  • Responding to a Cyber Attack on the North American Electric Grid
  • Paying for Electric Grid Cybersecurity
The report is very refreshing and offers some new ideas on ways to defend the grid and respond to cyberattacks.  

One idea that has some merit is the concept of implementing an "Institute" similar to the Institute of Nuclear Power Operations (INPO) that would focus in continuous improvement of cybersecurity of the electric grid.  I sent the following email to one of the Advisory Board members supporting this idea.  In my email I observed:


The Institute of Nuclear Power Operations (INPO) was used as a model agency for oversight of the security of the grid.  I worked at INPO from 1986 to 1992 and when I left I was the Secretary of the Corporation and an evaluation Team Manager.  

Of note, the recently published Cybersecurity Framework (CSF) has an approach very similar to INPO's.  That is the CSF is "performance-based" rather than "compliance-based" which is an approach that INPO pursued.  INPO published a document entitled Performance Objectives and Criteria for Operating and Near-Term Operating Nuclear Plants that really focused on what would be viewed as optimal performance in particular areas (e.g., management, administration, operations, maintenance, etc.) with a collection of criteria that supported the performance objectives (similar to the CSF).  However, the process was not focused on compliance to the performance objectives but instead to how the plant truly performed.

An example to demonstrate this approach would be relative to CIP-008, incident response.  The NERC approach to reviewing CIP-008 is to actually sight the utility's incident response procedure; however, they do not check to see that it actually is a workable, accurate document (i.e., are the phone numbers/email addresses accurate, can it truly be used as written, is it practiced, etc.).  On the other hand the INPO approach would be to view the document but with emphasis on watching the utility perform the incident response process and observe strengths, weaknesses, etc. and highlight areas needing improvement.

In other words the assessment was based on the true performance of the utility; not a simple view of its paperwork -- a serious flaw with the NERC approach (in my opinion).

I am very pleased with the tone, content and ideas put forth in this report and I look forward to the "new" dialogue that surfaces in this domain different from the old, stale ideas that really don't solve the problem for the entire electric grid from generator to transmission line to distribution system to the toaster in your home.

Again, compliments to the authors and advisory group on this report!

###

Wednesday, October 9, 2013

Hot Off the Press! New White Paper from ENISA on Learning from ICS Incidents

Today our friends at the European Network and Information Security Agency (ENISA) published a white paper entitled Can We Learn from SCADA Security Incidents?



The paper is about 10-pages long and offers some ideas on how to organize and perform a systematic approach to evaluating Industrial Control System/SCADA incidents.  One helpful element of the white paper is Table 1 that shows a roles matrix for incident response and analysis in control systems which was extracted from the US Department of Homeland Security (DHS)/Idaho National Labs document Recommended Practice: Creating Cyber Forensics Plans for Control Systems. (Table 5)

Overall I'd suggest you at least skim through the document and use it when developing ICS/SCADA incident response plans.  It will offer some useful guidance for programmatic and organizational approaches to ICS incident analysis.  The US DHS document referenced above will give you a more thorough technical perspective for ICS post-event forensics.

Thanks again ENISA!  Keep up the good work!