One of the most infamous cyberattacks on critical infrastructure, or CI, occurred in May 2021, when the Colonial Pipeline was hit with ransomware. The breach resulted in shutdown of pipeline operations, a gasoline shortage and a spike in fuel prices.
But the attack, which targeted billing systems, didnt cause the shutdown. Rather, the pipelines operators turned off pumping systems over concerns the attackers could gain control of operational technology, or OT, and place public safety at risk.
The incident illustrates the unique issues that are involved in cybersecurity for CI such as petroleum pipelines, power stations, electric utilities, water treatment plants, dams, ports, and mass transport systems. Exploits that target IT might result in exposed data or business disruption. Attacks involving OT could result in injury, illness, or worse across cities or regions.
Thats why operators of CI manage OT differently from how typical organizations handle IT. Most enterprises continually upgrade systems, with a focus on protecting data. CI operators deploy systems once and hope not to change them for years, with an emphasis on maintaining safety.
But OT-specific approaches are no longer adequate for safeguarding CI, for two reasons. First, OT and IT are becoming interconnected as OT becomes digitized. Second, quantum computing could soon render existing password and data encryption strategies obsolete.
In response, CI operators should borrow approaches from IT security protocols but apply them in OT-specific ways. In particular, they need to conduct thorough risk assessments, embrace zero trust security, and implement micro-segmentation to safeguard CI.
Where IT people talk about 5 nines of uptime, or 99.999% availability, OT pros think in terms of 11 nines. Both groups use the term reliability, but the difference in degree becomes a difference in kind.
Its part of why OT managers adhere to the Purdue Model, a framework for industrial control system security, developed at Purdue University in the 1990s. The Purdue Model emphasizes segmentation of operations, processes, controls, and sensors to protect OT from cyberattacks. OT is completely isolated from IT, with the equivalent of a demilitarized zone between them.
The Purdue Model remains a bedrock of OT security. But its no longer sufficient, because OT properties are no longer truly separated from IT. OT systems rely on expanding networks of IoT devices. Theyre increasingly monitored over remote connections. Some are disconnected from the internet but connected to corporate IT. Others are cut off from IT but exposed to the internet.
Today, CI needs a holistic approach to OT security that adapts traditional IT cyber practices to overcome the shortcomings of piecemeal OT protections.
Strengthening OT security for the quantum era starts with risk assessment. Many organizations lack a clear picture of how their OT systems are vulnerable and the potential consequences of those vulnerabilities.
CI organizations can leverage assessment tools designed for IT security by using these tools to identify all the resources on the network, down to the firmware level, and uncover security gaps. Keep in mind that if an assessment tool can find a resource on the network, so can an attacker.
An effective tool should provide the organization with a risk score. But remember that the tool is likely designed for IT, not OT. The organization needs to understand how the tool calculated the risk score and then factor in OT requirements to gain a true understanding of the vulnerabilities. Now the CI organization can prioritize remediations based on the likelihood of attack, the sensitivity of the data, and the criticality of the infrastructure.
The federal government has mandated a zero trust approach to cybersecurity, and organizations like NIST have issued zero trust frameworks. While zero trust covers multiple pillars of cybersecurity, from identities to data, the basic idea is never trust, always verify.
That means authentication of any user or system that requests access to a resource should be temporary. Every entity should re-authenticate for every resource, every time it wants access. That way, a malicious actor cant break into the network and gain de facto access to everything.
Zero trust replaces perimeter-focused, defense-in-depth security that hardens the edges but leaves the center vulnerable. It shifts the focus of security to users, which typically are the most vulnerable component of the infrastructure.
Zero trust dovetails with risk assessment, because its risk-based. It tailors access control to each entity that wants access. Its ideal for centralized, mission-critical OT systems supported by a growing number of IoT devices at the edge.
The third piece of the OT security puzzle is micro-segmentation. Traditional segmentation involved roadblocks like firewalls and virtual LANs. Micro-segmentation is more sophisticated, enabling organizations to isolate any user, application, or device, no matter where it appears in the infrastructure.
Micro-segmentation is based on identity, with the assumption of least-privilege access. For example, a developer might be granted access to a portion of the system that requires upgrade but be prevented from accessing any other part of the infrastructure.
In the past, segmentation required extensive planning and system upgrades that could take months to realize. In contrast, a micro-segmentation solution based on software-defined networks can be rolled out in one or two weeks. Agencies can deploy either on-prem or in the cloud, with no need to replace hardware.
The OT systems that control critical infrastructure involve unique security and safety requirements. But theyll increasingly intersect with IT systems and face new vulnerabilities in the quantum computing era. By leveraging risk assessment, zero trust, and micro-segmentation, OT operators can adapt to these challenges while maintaining their traditional focus on CI safety and continuity.
Darren Pulsipher is Chief Solutions Architect Public Sector at Intel Corp.
This article is an Op-Ed and the opinions expressed are those of the author. If you would like to respond, or have an editorial of your own you would like to submit, please email C4ISRNET and Federal Times Senior Managing Editor Cary OReilly.
Originally posted here:
How to protect critical infrastructure in the quantum-computing era - Federal Times
- Mathematician breaks down how to defend against quantum ... - Phys.Org [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Here Is Everything You Need to Know About Quantum Computers - Interesting Engineering [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Quantum Computing Market Forecast 2017-2022 | Market ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- What is Quantum Computing? Webopedia Definition [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Quantum computing is about to disrupt the government contracts market - Bloomberg Government (blog) [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Scientists: We Have Detected the Existence of a Fundamentally New State of Matter - Futurism [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- What Sorts Of Problems Are Quantum Computers Good For? - Forbes [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- quantum computing - WIRED UK [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Inside Microsoft's 'soup to nuts' quantum computing ramp-up - Computerworld Australia [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Molecular magnets closer to application in quantum computing - Next Big Future [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- The Bizarre Quantum Test That Could Keep Your Data Secure - WIRED [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- IBM boosts power of quantum computing processors as it lays ... - www.computing.co.uk [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- IBM makes leap in quantum computing power - ITworld [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Toward mass-producible quantum computers | MIT News - MIT News [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Purdue, Microsoft Partner On Quantum Computing Research | WBAA - WBAA [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Tektronix AWG Pulls Test into Era of Quantum Computing - Electronic Design [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Google to Achieve "Supremacy" in Quantum Computing by the End of 2017 - Big Think [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Quantum Computing Becomes More Accessible - Scientific American [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Qudits: The Real Future of Quantum Computing? - IEEE Spectrum - IEEE Spectrum [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Alkermes and IBM's quantum computing. Who'll be the big winner? Malcolm Berko - Durham Herald Sun [Last Updated On: July 6th, 2017] [Originally Added On: July 6th, 2017]
- Quantum Computers Made Even More Powerful with New microchip generating 'Qudits' - TrendinTech [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Quantum Computing Record Broken - Wall Street Pit [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Technique for measuring and controlling electron state is a ... - UCLA Newsroom [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Quantum cheques could be a forgery-free way to move money - New Scientist [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Quantum-computer node uses two different ion species - physicsworld.com [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Quantum Computers vs Bitcoin How Worried Should We Be? - The Merkle [Last Updated On: July 10th, 2017] [Originally Added On: July 10th, 2017]
- Why you might trust a quantum computer with secretseven over ... - Phys.Org [Last Updated On: July 12th, 2017] [Originally Added On: July 12th, 2017]
- Physicists Take Big Step Towards Quantum Computing and ... - Universe Today [Last Updated On: August 1st, 2017] [Originally Added On: August 1st, 2017]
- Quantum Computing Market Worth 495.3 Million USD by 2023 | 08 ... - Markets Insider [Last Updated On: August 10th, 2017] [Originally Added On: August 10th, 2017]
- China uses a quantum satellite to transmit potentially unhackable data - CNBC [Last Updated On: August 10th, 2017] [Originally Added On: August 10th, 2017]
- Blind quantum computing for everyone - Phys.org - Phys.Org [Last Updated On: August 12th, 2017] [Originally Added On: August 12th, 2017]
- Quantum Computing Is Real, and D-Wave Just Open ... - WIRED [Last Updated On: August 12th, 2017] [Originally Added On: August 12th, 2017]
- Machine learning tackles quantum error correction - Phys.Org [Last Updated On: August 15th, 2017] [Originally Added On: August 15th, 2017]
- Quantum Internet Is 13 Years Away. Wait, What's Quantum Internet? - WIRED [Last Updated On: August 15th, 2017] [Originally Added On: August 15th, 2017]
- Physicists Have Made Exotic Quantum States From Light - Futurism [Last Updated On: August 16th, 2017] [Originally Added On: August 16th, 2017]
- $495.3 Million Quantum Computing Market 2017 by Revenue Source, Application, Industry, and Geography - Global ... - PR Newswire (press release) [Last Updated On: August 18th, 2017] [Originally Added On: August 18th, 2017]
- How quantum mechanics can change computing - The Conversation US [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- Introducing Australia's first quantum computing hardware company - Computerworld Australia [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- IEEE Approves Standards Project for Quantum Computing ... - insideHPC [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- Commonwealth Bank investing in Australia's first quantum computer company - Which-50 (blog) [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- How quantum mechanics can change computing - San Francisco ... - San Francisco Chronicle [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Quantum Computing Is Coming at Us Fast, So Here's Everything You Need to Know - ScienceAlert [Last Updated On: August 27th, 2017] [Originally Added On: August 27th, 2017]
- Quantum computing event explores the implications for business - Cambridge Network [Last Updated On: August 30th, 2017] [Originally Added On: August 30th, 2017]
- Microsoft's Aussie quantum computing lab set to scale up next-gen ... - ARNnet [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- An Entirely New Type of Quantum Computing Has Just Been Invented - Futurism [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- Microsoft just upped its multi-million bet on quantum computing - ZDNet [Last Updated On: September 7th, 2017] [Originally Added On: September 7th, 2017]
- Here's what quantum computing is and why it matters [Last Updated On: October 6th, 2017] [Originally Added On: October 6th, 2017]
- What will you actually use quantum computing for? | ZDNet [Last Updated On: October 11th, 2017] [Originally Added On: October 11th, 2017]
- Quantum Computing | Intel Newsroom [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Intel Takes First Steps To Universal Quantum Computing [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Qudits: The Real Future of Quantum Computing? - IEEE Spectrum [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- quantum computing - engadget.com [Last Updated On: October 13th, 2017] [Originally Added On: October 13th, 2017]
- Quantum computing - news.microsoft.com [Last Updated On: November 1st, 2017] [Originally Added On: November 1st, 2017]
- IBM's processor pushes quantum computing ... - engadget.com [Last Updated On: November 16th, 2017] [Originally Added On: November 16th, 2017]
- Yale Professors Race Google and IBM to the First Quantum ... [Last Updated On: November 16th, 2017] [Originally Added On: November 16th, 2017]
- Quantum Computing Is the Next Big Security Risk | WIRED [Last Updated On: December 8th, 2017] [Originally Added On: December 8th, 2017]
- Microsoft offers developers a preview of its quantum ... [Last Updated On: December 12th, 2017] [Originally Added On: December 12th, 2017]
- New silicon structure opens the gate to quantum computers [Last Updated On: December 14th, 2017] [Originally Added On: December 14th, 2017]
- Quantum Computing Explained | What is Quantum Computing? [Last Updated On: December 21st, 2017] [Originally Added On: December 21st, 2017]
- What is Quantum Computing? | SAP News Center [Last Updated On: December 23rd, 2017] [Originally Added On: December 23rd, 2017]
- Is Quantum Computing an Existential Threat to Blockchain ... [Last Updated On: December 25th, 2017] [Originally Added On: December 25th, 2017]
- IBM puts its quantum computer to work in relaxing, nerdy ASMR ... [Last Updated On: January 8th, 2018] [Originally Added On: January 8th, 2018]
- Quantum computing is going to change the world. Here's what ... [Last Updated On: January 8th, 2018] [Originally Added On: January 8th, 2018]
- The Era of Quantum Computing Is Here. Outlook: Cloudy ... [Last Updated On: January 26th, 2018] [Originally Added On: January 26th, 2018]
- What is quantum computing? - Definition from WhatIs.com [Last Updated On: February 5th, 2018] [Originally Added On: February 5th, 2018]
- Senate bills would make quantum computing a priority [Last Updated On: June 10th, 2018] [Originally Added On: June 10th, 2018]
- Two Quantum Computing Bills Are Coming To Congress [Last Updated On: July 5th, 2018] [Originally Added On: July 5th, 2018]
- Quantum Computing Market Research Report- Forecast 2022 | MRFR [Last Updated On: August 1st, 2018] [Originally Added On: August 1st, 2018]
- What Is Quantum Computing? The Complete WIRED Guide | WIRED [Last Updated On: August 22nd, 2018] [Originally Added On: August 22nd, 2018]
- Quantum Computing | USRA [Last Updated On: August 30th, 2018] [Originally Added On: August 30th, 2018]
- The quantum computing race the US cant afford to lose [Last Updated On: September 3rd, 2018] [Originally Added On: September 3rd, 2018]
- The reality of quantum computing could be just three years ... [Last Updated On: September 12th, 2018] [Originally Added On: September 12th, 2018]
- US takes first step toward a quantum computing workforce ... [Last Updated On: September 17th, 2018] [Originally Added On: September 17th, 2018]
- China bet big on quantum computing. Now the ... - money.cnn.com [Last Updated On: September 17th, 2018] [Originally Added On: September 17th, 2018]
- China bet big on quantum computing. Now the US races to ... [Last Updated On: October 26th, 2018] [Originally Added On: October 26th, 2018]
- A new type of quantum computer has smashed every record ... [Last Updated On: December 21st, 2018] [Originally Added On: December 21st, 2018]
- IBM unveils its first commercial quantum computer [Last Updated On: January 9th, 2019] [Originally Added On: January 9th, 2019]
- IBM thinks outside of the lab, puts quantum computer in a box [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Quantum Computing | The MIT Press [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- CES 2019: IBM's Q System One Is the Rock Star Quantum ... [Last Updated On: January 13th, 2019] [Originally Added On: January 13th, 2019]