By: Rick Grinnell, co-founder and managing partner of Glasswing Ventures.
In this modern connected age, there’s no shortage of risks to fret about. I hate to add one more, but cyberattacks against utilities and power plants have recently rocketed to the top of the list of major security concerns.
For instance, a June report from ESET released new research revealing that the Ukrainian power grid was taken down in late 2015 by the Win32/Industroyer malware. This malware has been considered the biggest threat to industrial control systems since Stuxnet. In addition, the fact that Iranian hackers were able to infiltrate the New York Dam in 2013 is further proof that taking down power plants, power grids and other key components of critical infrastructure, both within the United States and overseas is a big goal for hackers.
However, the news isn’t all dire. One reason for optimism is the fact that hackers have not yet been able to cause significant damage thus far. The other is these mounting threats are a huge opportunity for innovation, particularly for firms that are well-versed in artificial intelligence and machine learning applied to security defense and response.
Growing threats lead to growing market
Overall, cybercrime is not going away and is only getting worse, and businesses continue to increase investments in solutions to thwart cybercrime.
While some of that spending is going to the usual suspects like Symantec, Cisco, IBM, and Raytheon, there is a healthy market for cybersecurity-focused startups. Many of those firms employ AI/machine learning. For instance, Dragos a startup focused on protecting industrial control systems (ICS) and critical infrastructure from cyber threats, recently announced a $10 million funding round.
In addition, Microsoft bought Hexadite for $100 million and Amazon purchased Harvest AI for $20 million last year. Both firms employ AI to detect and fight cybercrime. Crowdstrike and Cylance have also zoomed to $1 billion-plus valuations for their AI-focused cybercrime solutions.
Why AI? As the level of threats keeps increasing, the ability to monitor and respond to those threats has surpassed human abilities. According to Caleb Barlow, vice president of threat intelligence for IBM Security in a recent FT article, large companies may face as many as 200,000 “security events” every day. AI can mimic what a human cybersecurity analyst would do but the effect is magnified and runs 24/7 without human error.
Will AI save our power grids?
Of course, hackers can use advanced techniques and technologies like AI for their purposes, too. Just as the AI-enabled offensive and defensive solutions are becoming more commonplace, hackers are doubling down on the energy sector as a key target. A September report from Symantec identified Dragonfly 2.0, an international syndicate that appears to be interested in gaining access to energy facilities. Dragonfly 2.0 uses multiple techniques, including malicious emails, watering hole attacks and Trojanized software to attempt to gain such access. Once inside CI networks, the group operates in data-gathering mode, learning how these systems work, in order to potentially take control at some point in the future. The recent hurricanes in the Caribbean, Florida and Texas have caused massive destruction and power disruption for millions of people. A successful CI cyberattack, while hard to comprehend, could be even more devastating, impacting even more people around the world. It is more imperative than ever to stay ahead of hackers by using increasingly sophisticated and intelligent defenses.
While more sophisticated endpoint defense can solve some of these more PC-centric and OS-specific exploits, an emerging set of vulnerabilities tied to IoT deployments in CI networks becomes a more menacing attack vector. Fortunately, there are a few innovative cybersecurity companies and tools already on the market that address many of the IoT security needs of critical infrastructure (CI) facilities, including Pwnie Express* and Armis, which provide visibility into all of the malicious devices and activities trying to connect to CI networks. New players like Aperio Systems have introduced products that plug into CI control systems and use machine learning algorithms to study and identify the unique fingerprints of a system. They then use that baseline to judge anomalies, which raise red flags.
So far, this is a wide-open market and an urgent opportunity. There is a great business case to be made for pursuing AI-based solutions to CI security threats. There’s a marketing case too: For much of the public, AI is still perceived through Hollywood’s lens. Helping defeat CI hacking is good PR for AI and will help the public better understand the reality-based benefits of AI.
About the Author: Rick Grinnell is co-founder and managing partner of Glasswing Ventures. As a venture capitalist and seasoned operator, Rick has invested in some of the most dynamic companies in security, enterprise infrastructure and storage. During his 15 years of venture capital experience, he has led investments and served on the board of directors for companies such as EqualLogic (acquired by Dell), Prelert (acquired by Elastic), Pwnie Express, Resilient Systems (acquired by IBM), Trackvia and VeloBit (acquired by Western Digital).
Critical Infrastructure Attacks Drive Startup & Innovation Opportunities
By: Rick Grinnell, co-founder and managing partner of Glasswing Ventures. In this modern connected age, there’s no shortage of risks to fret about. I hate to add one more, but cyberattacks against utilities and power plants have recently rocketed to the top of the list of major security concerns. For instance, a June report from ESET released new research revealing that the Ukrainian power grid was taken down in late 2015 by the Win32/Industroyer malware. This malware has been considered the biggest threat to
Mocana Integrates Embedded Security Software With Industrial Cloud Platforms
Mocana Integrates Embedded Security Software with AWS IoT, Microsoft Azure IoT, and VMware Liota to Protect Devices (SecurityWeek / Kevin Townsend) - Two constants in current cybersecurity are the growing threat from insecure IoT botnets (Mirai, WireX, etcetera), and the continuing security provided by strong encryption. It is part of the mission of one venture capital funded firm to solve the former by use of the latter. Mocana was formed in 2002 as an embedded security software company for military applications. With the help
Russia-linked Hackers Target Control Systems in U.S. Energy Firms: Symantec
(Eduard Kovacs, SecurityWeek) - A group of cyberspies believed to be operating out of Russia has been observed targeting energy facilities in the United States and other countries, and the attackers appear to be increasingly interested in gaining access to the control systems housed by these organizations. The group, known as Dragonfly, Crouching Yeti and Energetic Bear, has been active since at least 2010, but its activities were first detailed by security firms in 2014. Many of the threat actor’s attacks have focused on
Reminder: 2017 ICS Cyber Security Conference USA Call for Speakers Open Through August 15
The official Call for Papers (speakers) for SecurityWeek’s 2017 Industrial Control Systems (ICS) Cyber Security Conference, being held October 23 – 26, 2017 at the InterContinental Buckhead Atlanta, Georgia, USA is open through August 15, 2017. As the original ICS/SCADA cyber security conference, the event is the largest and longest-running cyber security-focused event series for the industrial control systems sector. The conference caters to the energy, water, utility, chemical, transportation, manufacturing, and other industrial and critical infrastructure organizations. With a 15-year history, the conference
GCHQ Warns of State-sponsored Hackers Targeting Critical Infrastructure
By Kevin Townsend (SecurityWeek) The U.K. Government Communications Headquarters (GCHQ), Britain's secret eavesdropping agency, warns that 'a number of [UK] Industrial Control System engineering and services organisations are likely to have been compromised' following the discovery of 'connections from multiple UK IP addresses to infrastructure associated with advanced state-sponsored hostile threat actors.' The warning comes from a National Cyber Security Centre (NCSC) memo obtained by Motherboard and confirmed by the BBC. NCSC is part of the UK's primary cyber intelligence agency, GCHQ. From the little information available, it
DHS Releases ICS-CERT 2016 Assessment Summary Report
By: Eduard Kovacs (SecurityWeek) - The assessments conducted by the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) in 2016 showed that inadequate boundary protection has remained the most prevalent weakness in critical infrastructure organizations. ICS-CERT conducted 130 assessments in the fiscal year 2016, which is more than in any previous year. Monitor newsletters published by ICS-CERT this year show that it has already conducted 74 assessments in the first half of 2017. Assessments are offered to both government organizations and private sector companies
What Modular, Network-based ICS Threats Mean to Your Systems
By Cameron Camp, Security Researcher, ESET Industroyer, the recent complex malware targeting industrial control systems, offers attackers a modular complex way to attack systems like the power grid. What are the implications of this? For years, adversaries have been quietly testing the defenses of bulk critical infrastructure like gas and oil systems, hydroelectric dams and the power grid. In recent years, starting with Stuxnet in 2010, more focused attempts at directly manipulating industrial systems have started to gain prominence, including Industroyer, which
How Vulnerable are Our Industrial Control Systems? What We Learned From ICS Attacks of 2016
Multiple cyberattacks on critical infrastructure facilities in 2016 resulted in mere inconvenience or embarrassment. How long can dumb luck keep us from harm? By Michael Shalyt, VP Product, APERIO Systems When the U.S. Energy Department released a nearly 500 page report this month warning of an “imminent” threat to the electrical grid, it was the latest reminder of just how dependent our day-to-day existence is on critical infrastructure networks — from power grids and water supplies to transportation networks and more. In 2016, attackers clearly
Bechtel Opens Industrial Cyber Security Lab
Global engineering and construction giant Bechtel has opened a new cyber security lab aimed at protecting industrial equipment and software that control facilities such as power plants, chemical plants, and other large-scale critical infrastructure operations. With the goal of protecting industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems from cyber threats, Bechtel says the lab will leverage its experience designing and implementing National Institute of Standards and Technology Risk Management Framework (NIST-RMF) solutions for its government
Rockwell Automation Partners With Claroty on Industrial Network Security
Rockwell Automation is teaming up with industrial cybersecurity startup Claroty to combine their security products and services into future, combined security offerings. Rockwell, an industrial automation giant with more than 22,000 employees, said that after a competitive review process it selected Claroty for its anomaly-detection software purpose built for industrial network security. Armed with $32 million in funding through Series A and a Series B rounds, Claroty exited stealth mode in September 2016 to announce a security platform designed to provide “extreme
