Sharing Cyber Information Drives Many Benefits

Category:
ARC Report Abstract

Overview

Today’s challenging cyber landscape demands an active defense that can respond rapidly to anomalies.  Sharing critical cyber information is an essential part of these efforts.   

Today’s cyber black markets, ransomware, and political tensions create more  challenges for critical infrastructure operators.  Conventional passive defenses aren’t enough to deal with these risks.  Every industrial organization needs active cybersecurity to detect and respond rapidly to anomalies in system and human behavior. 

Active defense requires investments in people, processes, technology, and information.  Companies need people who can quickly identify and manage sophisticated cyber-attacks and these people need processes and technologies that support their forensic and defensive efforts.  It’s essential to have information on threats occurring in related areas and industries.  Information gives defenders the guidance they need to anticipate attacks, direct surveillance efforts, focus forensic efforts, and accelerate implementation of effective responses.   

Mark Johnson-Barbier, Senior Principal Analyst at Salt River Project (SRP) discussed the importance of cyber information sharing at the 2020 ARC Industry Forum in Orlando, Florida.  His presentation highlighted how it empowers SRP’s cyber activities and the ways in which SRP is supporting information sharing across the electric power industry.  It also demonstrated the many benefits that companies gain from participating in such initiatives.     

Salt River Project Cybersecurity Challenge

SRP, a community-based, not-for-profit water and energy company, provides affordable water and power to more than two million people living in central Arizona.  Reliable delivery of these services is critical to their health and well-being. 

Sharing cyber information

Cybersecurity is a critical issue for SRP and its efforts go beyond compliance with NERC CIP requirements.   Currently, SRP’s security operations center (SOC) monitors cybersecurity activity at seven generation sites (three gas and four hydro), transmission & distribution network assets, and energy management system (EMS).  This includes port mirroring of networks and syslog information for controllers, DCS systems, Windows devices, and firewalls.  The company is actively instrumenting all OT systems to passively collect network activity, collect endpoint logs, and extend security visibility.   

Threat information plays a vital role in SRP’s security efforts.  Information is gathered from various sources and used to inform all cybersecurity activities.  The company is also proactive about security awareness training and information sharing with other critical infrastructure companies in the region.  This year, SRP plans to host its second cybersecurity conference with critical infrastructure organizations across Arizona and adjacent states like California, Colorado, and New Mexico.     

 

ARC Advisory Group clients can view the complete report at ARC Client Portal   

If you would like to buy this report or obtain information about how to become a client, please Contact Us     

 

Keywords: Cyber Information Sharing, Industrial Cyber Attacks, Active Cyber Defense, ARC Advisory Group.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients