Federal incentives could help utilities overcome major cybersecurity hurdle: money

A new rule that would give electric utilities incentives for investing in cybersecurity is set to go into effect next month.

The post Federal incentives could help utilities overcome major cybersecurity hurdle: money appeared first on CyberScoop.

Continue reading Federal incentives could help utilities overcome major cybersecurity hurdle: money

Nuclear Weapons Agency Hacked in Widening Cyberattack – Report

Sources said the DoE suffered “damage” in the attack, which also likely extends beyond the initially known SolarWinds Orion attack vector. Continue reading Nuclear Weapons Agency Hacked in Widening Cyberattack – Report

FERC Releases Staff Report on Lessons Learned from CIP Audits

In October, the Federal Energy Regulatory Commission (FERC) released its “2020 Staff Report Lessons Learned from Commission-Led CIP Reliability Audits.” The report summarizes the Commission’s observations from Critical Infrastructure Protection (CIP) a… Continue reading FERC Releases Staff Report on Lessons Learned from CIP Audits

Joint “CYPRES” Report on Incident Response Released by FERC

Earlier this month, the Federal Energy Regulatory Commission (FERC) published a joint report entitled “Cyber Planning Response and Recovery Study” (CYPRES) in partnership with the North American Electric Reliability Corporation (NERC) and eight of its … Continue reading Joint “CYPRES” Report on Incident Response Released by FERC

5 Challenges Utilities Will Face in Preparing for New FERC Security Standards

Since the attack on the power grid in Ukraine, defending critical infrastructure against the threat of cyberattack has become a top priority. In an effort to strengthen supply chain risk management within the energy sector, the Federal Energy Regulato… Continue reading 5 Challenges Utilities Will Face in Preparing for New FERC Security Standards

Use This NERC CIP v6 Standards Summary to Stay Compliant

Thanks to FERC’s Order 822, the North American Electric Reliability Corporation’s critical infrastructure protection standards, known as NERC CIP, are continually updated. Seven updated standards proposed by NERC for inclusion have now been… Continue reading Use This NERC CIP v6 Standards Summary to Stay Compliant

Utilities will have stricter cybersecurity reporting requirements under new ruling

U.S. regulators are laying down stricter reporting requirements for electrical utilities that experience cybersecurity lapses. The Federal Energy Regulatory Commission (FERC) said Thursday that utilities will have to report attempts by attackers, even if they don’t have an immediate effect, that ultimately make it easier to “harm reliable operation of the nation’s bulk electric system.” Current requirements only make utilities report incidents that result in an actual compromise or disruption. “Cyber threats to the bulk power system are ever changing, and they are a matter that commands constant vigilance,” FERC Chairman Kevin McIntyre said in a statement. “Industry must be alert to developing and emerging threats, and a modified standard will improve awareness of existing and future cyber security threats.” The new standards will come by way of the North American Electric Reliability Corporation (NERC), a quasi-governmental body that implements FERC’s rulings for electrical utilities. NERC will have to develop standards […]

The post Utilities will have stricter cybersecurity reporting requirements under new ruling appeared first on Cyberscoop.

Continue reading Utilities will have stricter cybersecurity reporting requirements under new ruling

Regulators tightening controls on devices connecting to utility company networks

U.S. regulators are cracking down on the cybersecurity risks to the electric grid posed by everyday electronics like laptops and flash drives. A ruling issued last week by the Federal Energy Regulatory Commission requires utilities to implement security controls on portable devices that interact with “low-impact” systems, or ones that utilities deem less critical. FERC also ordered the revision of power reliability standards “to mitigate the risk of malicious code” stemming from the devices. The move comes as the Department of Homeland Security has warned that Russian government hackers have their sights on U.S. energy firms, and as Congress readies legislation to secure the grid. Observers say FERC’s tightening of security controls further down the grid could shake up how large portions of the sector approach cybersecurity. Daniel Skees, a lawyer who represents utilities before FERC, said the new ruling amounts to a “sea change” for utilities because it will […]

The post Regulators tightening controls on devices connecting to utility company networks appeared first on Cyberscoop.

Continue reading Regulators tightening controls on devices connecting to utility company networks

FERC, Fake WhatsApp, and Google Play Bug Bounty – Hack Naked News #148

Doug White and Jason Wood discuss improvements to IoT, fooling millions of Android users, Google Play bug bounties, school boards being hacked by pro-ISIS groups, and more with Jason Wood on this episode of Hack Naked News! News Despite the benefits, new devices will lead to new security risks. And the presence of malicious code […]

The post FERC, Fake WhatsApp, and Google Play Bug Bounty – Hack Naked News #148 appeared first on Security Weekly.

Continue reading FERC, Fake WhatsApp, and Google Play Bug Bounty – Hack Naked News #148

Report: Electrical grid cybersecurity efforts across U.S. government are ‘fragmented’

Though federal efforts remain “fragmented,” the U.S. government has made significant progress in developing policies, programs and technologies that help protect America’s electrical grid, according to a Government Accountability Office report released Friday. Since 2013, the Department of Energy, the Department of Homeland Security and the Federal Energy Regulatory Commission have worked together to implement […]

The post Report: Electrical grid cybersecurity efforts across U.S. government are ‘fragmented’ appeared first on Cyberscoop.

Continue reading Report: Electrical grid cybersecurity efforts across U.S. government are ‘fragmented’