How to prevent hackers from taking down critical infrastructure
On December 23, 2015, hackers took down the power grid in a region of Western Ukraine, triggering the first blackout ever caused by a cyber attack. This attack was part of a broader trend, as hackers are increasingly exploring ways to target critical infrastructure like power grids, transportation systems, hydroelectric dams, and chemical plants.
Few cyber attacks against critical infrastructure have had the level of success and sophistication as the attack in Ukraine though. The attackers spent months laying groundwork before storming the power grid’s control systems on the day of the blackout. Experts say that other hackers could leverage some of the same tools and tactics used in the attack to target control systems for other critical infrastructure targets.
These control systems are increasingly being connected to the internet as part of the growing adoption of the Internet of Things among enterprises in utilities and other sectors. However, these systems have often been in place for decades, long before cybersecurity was a major concern. So these aging systems often lack even basic security protections to beat back hackers.