Table of Contents
- Executive Overview
- Smart Cities Have a Cybersecurity Problem
- Future of Cyber-attacks on Smart Cities and Critical Infrastructure
- Relevant Certifications and Standards
- Recommendations
Executive Overview
We talk about many things when it comes to smart cities. The Internet of Things, smart sensors, the cloud, and a host of other new technologies from artificial intelligence (AI) to advanced operator visualization techniques have opened huge new opportunities for cities to improve the lives of citizens, increase safety and energy efficiency, and reduce operational expenditures. The Smart City Cybersecurity Problem, however, is rarely discussed.
Major cybersecurity incidents continue to grab headlines. Many of these incidents affect the IT infrastructure of cities, such as the recent ransomware attack on the City of Atlanta. Many more, however, are affecting the operational technology layer of smart cities and their associated infrastructure, such as the 2015 cyber-attack on the Ukrainian power grid system. This does not mean that IT-related attacks don’t affect operational technologies. The ransomware attack on Atlanta crippled government desktop computers and resulted in the shutdown or at least disruption of essential city services from law enforcement to utilities.
Today’s smart cities are really patchworks of old and new systems, each with their own cybersecurity concerns. Older systems like ICS (industrial control systems) and SCADA (supervisory control and data acquisition) systems for things like power, gas, and water distribution systems exist alongside new, IoT-based systems for smart lighting, transportation management, access control, and more.
The number of vendors and products in the rapidly emerging smart cities space is staggering, and the relative levels of inherent cybersecurity in these products and systems vary widely. Most smart cities fail to adequately address the role of cybersecurity in these new products and systems. Relevant standards and product registrations/certifications for cybersecurity in the smart city sector are only now beginning to emerge.
From an organizational standpoint, many cities seem ill prepared to respond to major cyberattacks. City and municipal governments tend to focus on the information technology (IT) world and have less experience managing the increasingly digital world of operational-related technologies. The utilities, which have become major investors in smart cities in the past couple of years, are more adept at the operational technology (OT) side of the equation. Both groups have their own challenges when it comes to managing the convergence of the IT and OT realms.
Cybersecurity for smart cities is not an unsolvable problem. Many cities and municipalities can take incremental steps to improve their cybersecurity organization, bridge the gap between IT and OT domains, and implement selection criteria to ensure better cybersecurity. Vendors and service providers are also greatly expanding their offerings, making it possible for cities to outsource certain aspects of the cybersecurity plan that cannot be performed in-house.
There's a Smart City Cybersecurity Problem
Smart cities have a resource problem. The operational personnel do not have the time to become cybersecurity experts on their own, but they need to be sure that their organization has an appropriate plan for managing cyber threats. Many smart city projects get too caught up in the implementation of new technologies without a sufficient focus on cybersecurity. A city CIO may become a hero by implementing a big new deployment of smart city technology, but a single ransomware attack could bring all that new technology to a grinding halt. Building a good cybersecurity program is a necessary first step.
As a 2017 ARC survey on cybersecurity trends revealed, building a program requires the support and buy-in of management, as well as building awareness and appreciation of cyber risks across the organization. Gaining management support can often be difficult because of the difficulty showing the monetary benefits of implementing better cybersecurity. However, the cost of recent incidents should provide an indication of the impact that large scale cyber-attacks can have in terms of downtime and risk to human life and the environment.
Develop Standard Policies for Cybersecurity
Having a good cybersecurity strategy doesn’t have to involve huge investments in technology and training. A sound strategy and standard policies can provide significant benefits. In 2016, the International City/County Management Association (ICMA), in partnership with the University of Maryland, Baltimore County (UMBC), conducted a survey to better understand local government cybersecurity practices. Only 47.7 percent of all respondents indicated that they had any kind of formal written cybersecurity policy, standards, strategy, or plan.
Ransomware payment is a good example of the benefit of sound cybersecurity policy. Many owner/operators and city governments are completely caught off guard when they face a ransomware attack. The City of Atlanta has estimated its recovery cost of the recent ransomware attack to be $2.7 million. A large part of these funds went to a third-party incident response company. Recent disclosures from the Atlanta city government reveal that it may take another $9.5 million for the city’s systems to fully recover from the attack. Hindsight is 20/20 but having standard policies in place to address such situations leads to improved preparedness and may spur increased attention to existing layers of cybersecurity. You need to prepare a response for potential real-world scenarios.
A Risk-based Approach
For smart cities to ensure that their efforts are focused on real and relevant concerns, a risk-based approach is required that looks at the smart city and infrastructure holistically. This requires involvement of both the IT and OT domains. While it is true that most of the headlines making cybersecurity incidents in today’s cities involve IT-level attacks such as ransomware and spear phishing, OT-level threats are on the rise. The key difference between IT- and OT-focused attacks is that OT systems can act in the physical world.
The Rise of OT Cyber-attacks
In simple terms, OT is the domain of systems and sensors that control the things that act in the physical world. Power distribution networks, microgrids, gas pipelines, water distribution networks, security cameras, and so on. OT systems have the potential to provide extreme efficiency in the applications they control or to wreak extreme havoc. The new generation of cyber-attacks, many of which appear to be sponsored by nation states with almost unlimited resources, are sophisticated multistage attacks designed to gain control over OT systems and cause disruption, chaos, and potential loss of human life.
Smart City Cybersecurity Can Learn from the ICS Space
Many application sectors in smart cities and infrastructure, such as power transmission and distribution, water and wastewater, and gas transmission rely on industrial control systems (ICS) and SCADA systems, for which a wide set of standards and best practices have been established. Meanwhile, smart lighting systems, environmental monitoring, traffic control, and other systems are being shaped by trends in IoT and digitization and rely on a different set of hardware and software. Smart cities would do well to adopt or adapt many of the cybersecurity best practices, standards, and product certification and testing approaches employed in the industrial sector, particularly as attacks become more sophisticated and targeted at the critical infrastructure aspects of cities and municipalities.
US Director of National Intelligence, Dan Coats, recently announced that the “warning lights are blinking red” again for an attack on critical infrastructure. According to Coats, “Russia, China, Iran and North Korea are launching daily cyber strikes on the computer networks of federal, state, and local government agencies, US corporations, and academic institutions.” Smart cities need to be prepared.
Future of Cyber-attacks on Smart Cities and Critical Infrastructure
We can get a feeling for what infrastructure attacks might look like by examining several recent high-profile incidents. One of the most notable examples is the CRASHOVERRIDE (aka, Industroyer) malware that disabled the Ukrainian power grid in December 2016. CRASHOVERRIDE was the first malware framework targeted specifically at power transmission and distribution applications.
In a similar attack on the Ukrainian power grid the previous year, more than 230,000 people lost power for up to six hours in the evening in the dead of winter. While the 2016 attack was caught before it had the chance to do similar damage, the content of the malware itself was much more powerful and showed substantial advancements over the 2015 attack. A new, sophisticated and modular form of malware, CRASHOVERRIDE specifically exploited several communication protocols used in the power industry. Cybersecurity companies like Dragos believe that, rather than an active attack, CRASHOVERRIDE is likely a proof-of-concept exercise.
The fact that the architects of the malware took the time to reverse-engineer industry-specific protocols (that many had previously deemed too obscure to deal with) is significant. Knowing how to exploit those protocols to gain control of a power distribution network represents a leap forward in the industry- and application-specific knowledge required to execute these kinds of attacks successfully. Clearly, the “security by obscurity” argument is no longer valid. Even highly proprietary systems or networks are no longer immune from hacking when you have nation state resources at your disposal, particularly for those bad actors with a deep understanding of industry-specific applications and systems.
Other attacks aren’t so targeted, but their impact is still great. Unsecured IoT devices can be easily compromised and, unbeknownst to their owners, turned into “zombies” in a huge network of hijacked distributed computing resources. Known as “botnets,” these can be used to launch massive denial of service (DoS) attacks, steal data, send spam, or for any number of other nefarious purposes. Examples include the Mirai botnet, which was originally created by a group of computer savants in the US to gain an advantage in the Minecraft game. Smart city devices and networks are at risk, especially with the number of vendors and integrators involved in installing and maintaining these systems and the continued reliance on facility operations to maintain and practice robust cyber policies.
Different Cybersecurity Requirements for Different Domains
The smart cities and infrastructure segments each have their own unique attacker profiles and cybersecurity requirements; many are shared with the ICS domain. There are some key differences, however. While an attack on an industrial installation is typically designed to disrupt production or to steal valuable intellectual property (IP), such as a drug manufacturing process; an attack on critical infrastructure and cities is designed to disrupt services and even endanger the lives and safety of citizens. This often makes smart cities and infrastructure more appealing targets.
Attacks on infrastructure and smart cities can have a much wider range than industrial attacks, which tend to be limited to a single industrial facility. Smart city and infrastructure attacks can have wide-ranging regional and even national impact and an attack in a densely populated area could potentially cause great chaos. The recent power failure at the Atlanta Airport, while not an official cyber-attack, shows what happens when densely populated public spaces are thrown into darkness and everything shuts down.
Industrial facilities are not immune from potentially chaos-producing cyber warfare either. The primary purpose of the new generation of TRITON process safety system malware, for example, is to prevent the safety systems in large processing plants from shutting down the plant or process in a safe manner if there is an incident that could lead to an explosion or release of toxic materials.
Cyber-physical assets in cities and infrastructure also tend to be more distributed than industrial plants. Power, gas, and water transmission networks typically span many square miles. Smart lighting and other distributed smart city systems are stretched out over many blocks.
Today’s smart cities also feature many systems and interconnections, which increases likelihood that something will be attacked. Widespread use of city-wide, open-access networks also increases attacker access to IT and control systems. The growing use of IoT devices to improve city processes also increases attack surfaces and likelihood of an incident.
Moving from Layers of Protection to Secure-by-Design Principles
Like the industrial sector, the smart cities and infrastructure sector tends to take a “layered” and defensive approach to cybersecurity. Layers of protection are necessary, but perhaps even more important, is to incorporate secure-by-design principles into products and applications to ensure a certain level of security right “out of the box.” Ensuring that devices are secure by design is the goal of many cybersecurity efforts, such as UL 2900 and ISASecure. Secure-by-design principles apply to software, devices, and networks. Many of today’s commercially available products and applications were not developed using these principles. Secure-by-design principles are well-documented for software and networks. In the rapidly expanding world of IoT devices, however, secure-by-design principles are not so well documented or followed. The ICS space also has a device-level security problem.
Defense-in-Depth Principles
It is not possible to secure any system with a single countermeasure or technique. Cyber threats are too varied and dynamic to expect any one method to stop all attacks. Serious cyber criminals will find ways around any single roadblock.
Organizations need “defense-in-depth” cybersecurity strategies with multiple layers of security controls for all their IT and OT systems. This approach ensures that intruders must overcome multiple, independent barriers before they can do real damage. This discourages casual intruders and gives organizations more time to recognize and stop serious threats. The goal of defense-in-depth strategies is to stop intruders as early as possible in the attack sequence. A proper cybersecurity technology solution ensures that attacks are blocked as early as possible in the lifecycle of a cyber-attack. Standard industry models such as the Lockheed Martin Cyber Kill Chain framework outline this approach.
Relevant Certifications and Standards
Assessing the security of new system components and IoT devices (both industrial and otherwise) is an additional challenge. User organizations currently trust that manufacturers have development processes in place to help ensure security in all hardware and software. Independent third-party testing and/or auditing can help validate this trust. Purchasing products from companies that have certified compliance to recognized industrial cybersecurity standards is both prudent and a recommended best practice.
Many industry sectors have certifying or registering bodies that will evaluate products or applications for conformance to certain cybersecurity specifications. In a broad sense, the smart cities space lacks such a certifying body. However, some existing standards and certification/registration programs cover key aspects for smart cities and infrastructure. Most of these are on the infrastructure side for applications like power transmission and distribution, gas transmission and distribution, and water and wastewater. The overlap of these applications into the industrial sector provides access to a range of standards and certification programs such as ISA/IEC 62443 and ISASecure product certification.
Other applications like smart lighting, transportation management, access control, and building controls have no specific standards for cybersecurity in place. However, industrial standards such as IEC 62443 have been applied in these environments. In addition, emerging programs such as the UL (Underwriters’ Laboratory) 2900 Series of standards, could be considered appropriate for these sectors. Some relevant standards that certifying bodies and consortia follow should be considered when developing a cybersecurity program for smart cities and smart infrastructure.
NERC CIP
Distribution networks, the focus of much of today’s new energy sector technology developments like microgrids, have no cybersecurity regulations. For many of the alternative energy systems, regulation is limited to their grid participation. This may be a godsend to those opposed to regulation and people who are overwhelmed with compliance reporting, but the lack of clear guidance can also be a burden. As David Lawrence noted in his 2018 cybersecurity workshop presentation at the ARC Industry Forum in Orlando, companies like Duke Energy need industry-accepted standards to ensure the security of the new systems they are designing and implementing for customers and smart cities.
As the major cybersecurity regulation in the electrical industry, NERC CIP seems like a logical place to start. A comprehensive, compliance-focused cybersecurity standard, NERC CIP also recognizes the need to incorporate a risk-based approach. Today, NERC CIP compliance is only mandated for certain cyber assets within the US electrical grid and Bulk Electric Supply. For owner/operators in the smart cities space, NERC CIP can provide valuable guidance in both the physical cybersecurity of systems; and requirements for personnel training, incident reporting, and development of incident response plans.
ISA-62443 and IEC 62443
As mentioned previously, the ICS world can offer a lot of cybersecurity expertise to the smart cities and infrastructure segments. Some aspects of smart infrastructure, such as ICS and SCADA systems used in water and oil and gas applications, are already governed by well-developed cybersecurity standards that have been in existence for many years. The International Society for Automation (ISA) is a prominent ICS-related standards development organization (SDO). The International Electrotechnical Commission (IEC) is an acknowledged international ICS-related standards body. ISA and IEC standards are used around the world.
The ISA-62443 and IEC 62443 cybersecurity standards have been developed by the ISA99 standards committee, in collaboration with IEC TC65. In recent years, the ISA99 committee and IEC have developed and approved a robust series of identical international standards that provide normative requirements for securing industrial automation and control systems (IACS). ISA publishes these as ANSI/ISA-62443; IEC as IEC 62443.
Collectively, the 62443 standards provide requirements and guidance for all participants and stakeholders in the lifecycle of industrial automation and control systems (IACS), including component and system suppliers, system integrators, asset owners, and service providers. This lifecycle begins with the development of single components, such as an embedded controller, or a group of components working together as a system or subsystem. A system integrator assembles these products into an automation solution, which is then installed at a site and becomes part of the IACS.
ISASecure Certification
The ISA Security Compliance Institute (ISCI), a neutral, not-for-profit consortium manages the ISASecure certification process. ISASecure certifications assess conformance to a subset of the IEC 62443 series. ISASecure certifies commercial-off-the-shelf (COTS) products and product supplier development lifecycle practices, for conformance with applicable parts of the IEC 62443 series. ISASecure is already looking at certifying products for building control system (BCS) applications.
UL 2900 Series of Standards
UL has well-established expertise and advisory capabilities in safety science, standards development, testing, and certification. UL 2900, a series of standards for cybersecurity, addresses the testing and certification requirements for products and processes as well as specific industry systems.
According to UL, the organization’s subject matter experts developed the UL 2900 standard with input from major government, academic, and industry stakeholders.
Their goal was to create a standard with broad-based coverage of security issues and support for many different industrial sectors. A key challenge was to ensure that it reflected the requirements of many different industrial cybersecurity standards and guidance documents in use today. For example, UL 2900-2-2 applies some security criteria from IEC 62443 for product testing and process validation. UL 2900 sections were published as national standards in both the US and Canada (ANSI/SCC) in July 2017.
UL 2900 covers product security with general and industry-specific software cybersecurity requirements. Current coverage includes industrial control systems, healthcare systems, and building security controls. Work continues to expand the standard for building automation and energy management.
Manufacturers can use UL 2900 cybersecurity certifications to validate internal processes and products as well as manage the supply chain security of components they integrate into their products. Supply chain risks are a particularly daunting challenge for manufacturers today as they increasingly leverage third-party software components. These companies need a way to identify, assess, and correct vulnerabilities in all product components before they are integrated into systems. They also need a means to stay abreast of any new threats that emerge.
UL Cybersecurity Assurance Program
The UL Cybersecurity Assurance Program (UL CAP) was created to help industrial end users and product manufacturers minimize cybersecurity risks through standardized, testable criteria for assessing software vulnerabilities and weaknesses. UL CAP was launched in June 2015, when the company established a task group to evaluate the complexities and challenges associated with cyber risks. This group developed the specifications which have since become the testable technical criteria of the UL 2900 Series of Standards.
Programs such as the UL Cybersecurity Assurance Program minimize risk for manufacturers by helping ensure that software is secure and remains so throughout its use. By deploying consistent testable criteria, companies can begin to reduce exploitation, address known malware, enhance security controls and expand security awareness; all essential steps for conducting business in today’s connected world.
UL CAP includes a range of services to help manufacturers stay abreast of industrial cybersecurity developments and sustain the security of their products and systems. UL provides advisory, testing and certification services for UL 2900 as well as IEC 62443.
ISO/IEC 27000 Series Standards
The ISO/IEC 27000 family of standards helps organizations keep information assets secure. ISO/IEC 27000 describes the overview and the vocabulary of information security management systems (ISMS). It references the information security management system family of standards (including ISO/IEC 27003, ISO/IEC 27004 and ISO/IEC 27005), with related terms and definitions.
This international standard specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system within the context of the organization. It also includes requirements for assessing and treating information security risks tailored to the needs of the organization. The requirements are generic and intended to be applicable to all organizations, regardless of type, size or nature.
The series is deliberately broad in scope, covering more than just privacy, confidentiality and IT/technical/cybersecurity issues. It is applicable to organizations of all shapes and sizes. All organizations are encouraged to assess their information risks, then treat them (typically using information security controls) according to their needs, using the guidance and suggestions where relevant. Given the dynamic nature of information risk and security, the ISMS concept incorporates continuous feedback and improvement activities to respond to changes in the threats, vulnerabilities, or impacts of incidents.
NIST Cybersecurity Framework
The US Commerce Department’s National Institute of Standards and Technology (NIST) has received considerable recognition over the past few years for developing the Cybersecurity Framework (CSF), now widely used as the basis for establishing effective security management systems. NIST recently released version 1.1 of its Framework for Improving Critical Infrastructure Cybersecurity. US Secretary of Commerce, Wilbur Ross, has appealed to C-level management at all companies in the US to use the framework as the first line in their overall cyber-defense strategy. The framework was originally developed to address industries deemed vital to US national and economic security, including energy, banking, communications and the defense industrial base. It has since proven flexible enough to be adopted voluntarily by large and small companies and organizations across all industry sectors, as well as by federal, state, and local governments.
Version 1.1 of the NIST Framework includes updates on authentication and identity, self-assessing cybersecurity risk, managing cybersecurity within the supply chain, and vulnerability disclosure. NIST based the changes to the framework on feedback collected through public calls for comments, questions received by team members, and workshops held in 2016 and 2017. Two drafts of Version 1.1 were circulated for public comment to help NIST address stakeholder inputs comprehensively. A new section 4.0, called Self-Assessing Cybersecurity Risk, explains how organizations can use the framework to understand and assess their cybersecurity risk, including the use of measurements.
Supplier-sponsored Certification Programs
Many smart city and infrastructure suppliers offer their own testing and certification programs for partner products. These are typically system or platform suppliers under whose platform or software environment many third-party sensor or application providers might offer their products. Third-party vendors typically submit their devices to system or platform supplier’s lab where the supplier evaluates the product and performs penetration testing, white hat hacking, etc. Products are usually tested regularly. Newer versions of a product or newly issued supplier specifications may require additional testing.
Recommendations
Develop an Effective Cybersecurity Organization
Not surprisingly, most experts recommend that getting a top management sponsor is the most important step in launching a successful industrial cybersecurity program. Top management support is essential for any major program and cybersecurity is no exception. Funding is an obvious problem, particularly when people discount the likelihood of a cyber-attack. Having a top manager championing the need to address cyber risks will greatly ease the release of funds. Performing assessments and implementing defenses invariably impact operations and top management support is invaluable in overcoming delays caused by reluctant operations managers.
Building awareness of cyber risks is another critical issue in many companies. Despite the growing number of highly publicized incidents, many people still underestimate the potential impact of a serious cyber event. Many managers assume their investments in IT cybersecurity will also protect plants from cyber-attacks.
Even with top management support, cybersecurity program managers will generally find that they need their plans approved by IT and operations managers. Budget responsibility for industrial cybersecurity varies across industrial organizations. Frequently, IT departments will also have to justify and approve use of solutions and resources that may not be on their preferred solutions list.
ARC Cybersecurity Maturity Model
ARC’s cybersecurity maturity model reflects a layered approach for implementing an effective, defense-in-depth cybersecurity strategy. Security is developed outwardly, beginning with defense of individual assets and then moving outward to perimeter protection of facilities and monitoring of the external threat landscape. Focus also shifts from protecting devices and building a security culture, to managing sophisticated technology and anticipating attacks.
These steps encourage organizations to do the obvious and easy things first. This minimizes initial investments and resource requirements and enables industrial organizations and municipalities alike to achieve at least a minimal level of cyber protection. It also allows organizations to improve their security posture while they develop the necessary cybersecurity maturity to avoid wasteful investments on technology that they cannot manage or utilize effectively. For more information, please refer to the March 2016 ARC Strategy Report, A Maturity Model for Industrial Cybersecurity Planning.
ARC developed the Industrial Cybersecurity Maturity Model to help managers understand their cybersecurity challenges without having to become cybersecurity experts. It enables managers to balance cybersecurity investments with their willingness to accept cyber risks and the cost benefits of additional security layers. This model also provides a convenient way to explain the differences between passive and active cyber defense.
ARC’s model breaks cybersecurity into a set of steps that incrementally reduce cyber risks. Each step addresses a specific, easily understandable, security issue like securing individual devices, defending plants from external attacks, containing malware that may still get into a control system, monitoring systems for suspicious activity, and actively managing sophisticated threats and cyber incidents. Each step has an associated set of actions and technologies that can be used to accomplish its goals. The model also shows the human resources and tools required to sustain and utilize the technology investments effectively.
IT/OT Convergence and Your Cybersecurity Organization
IT and OT systems are notably different in function, technology, and operating environments. These differences have led to the bifurcation of cybersecurity responsibilities in most organizations. IT groups take care of IT cybersecurity; OT cybersecurity is the responsibility of engineering and operations.
Successful IT-OT convergence requires close cooperation between the previously separate IT and OT groups within an organization. IT and OT cybersecurity teams need to follow suit. Convergence of their efforts will close gaps in existing, siloed programs and help defend the organization against new challenges.
Many industrial and municipal organizations still view IT and OT cybersecurity as separate challenges. Different concerns and practices seem to justify siloed efforts and separation of responsibilities. However, attackers are already exploiting gaps between IT and OT defenses. For example, spam phishing is commonly used to gain privileges and entry into OT systems. And hackers are using HVAC and other poorly defended OT systems as entry points into data centers and corporate IT networks.
While necessary, IT-OT cybersecurity convergence will be challenging. The different priorities, practices, and technologies could be hard to reconcile. Cultural issues, such as overcoming the longstanding distrust between IT and OT groups can be an even larger hurdle. A convergence plan that anticipates these roadblocks is essential.
While there are significant potential benefits for doing so, converging IT and OT cybersecurity strategies will not be easy. IT and OT groups clearly have different cultures, concerns and perspectives. But some things that might ease the transition include:
- Joint training and cross-pollination of groups to break down the distrust that has developed over many years of siloed behavior.
- Participation in cybersecurity events and networking with peers to learn how they are dealing with cultural and logistic challenges.
- Facilitate workshops to reconcile IT and OT perspectives on people, practices and technologies. People without a vested interest can help drive consensus and develop joint ownership in group decisions that will be essential during program rollout.
Ask the Right Questions
Cybersecurity is a key concern for managers in every organization. While cybersecurity is an ever-moving target, requiring suppliers to certify the security of their products and development practices can help alleviate many concerns. Engaging with an experienced third-party for these evaluations can help manufacturers save time and resources.
Procurement security requirements based on balanced criteria, like UL 2900, can help organizations ease the burden on suppliers in meeting these demands and expand the purchasing pool. Finally, cybersecurity guidelines provided to vendors can help to streamline the process of establishing a reliable supply chain.
If you would like to buy this report or obtain information about how to become a client, please Contact Us