- Areport “In the Crossfire: Critical Infrastructure in the Age of Cyberwar,” commissioned by McAfee and authored by the Center for Strategic and International Studies (CSIS), has revealed the staggering cost and impact of cyberattacks on critical infrastructure such as electrical grids, telecommunications and transportation networks.
A survey of 600 IT security executives from critical infrastructure enterprises worldwide showed that 54 percent have already suffered large scale attacks or stealthy infiltrations from organized crime gangs, terrorists or nation-states. The average estimated cost of downtime associated with a major incident is $6.3 million per day. The report is available for free download at http://resources.mcafee.com/content/NACIPReport.
For the report, Vanson Bourne, a UK-based specialist research consultancy, surveyed more than 600 people responsible for IT or security in critical infrastructure enterprises across seven sectors in the US, UK, Japan, China, Germany, France, Italy, India, Russia, Spain, Brazil, Mexico, Australia and Saudi Arabia. Vanson Bourne has a database of contacts in the respective countries and they surveyed businesses above 1,000 users in the verticals of finance, government, energy, oil & gas, water, transportation and telcos. From Saudi Arabia, there were thirty respondents to the anonymous survey-based interviews done online. CSIS was responsible for analyzing the survey data. The survey found that the risk of cyberattacks is rising. Despite a growing body of legislation and regulation, 37 percent of IT executives said the vulnerability of their sector had increased over the past 12 months and two-fifths expect a major security incident in their sector within the next year. Only twenty percent think their sector is safe from serious cyberattack over the next five years.
Many of the world’s critical infrastructures were built for reliability and availability, not for security. Traditionally, these organizations have had little to no cyber protection, and have relied on guards, gates and guns. Today however, computer networks are interconnected with corporate IT networks and other infrastructure networks, which are accessible from anywhere in the world.
“From public transportation, to energy to telecommunications, these are the systems we depend on every day,” said Dave DeWalt, president and chief executive officer of McAfee. “An attack on any of these industries could cause widespread economic disruptions, environmental disasters, loss of property and even loss of life.” Other key report findings:
l Low confidence in preparedness: Over a third of those surveyed believe their sector is unprepared to deal with major attacks or stealthy infiltrations by high-level adversaries. Saudi Arabia, India and Mexico emerge as the least confident.
l Recession-driven cuts raising the risk: Two thirds of IT executives surveyed claimed that the current economic climate has caused cutbacks in the security resources available.
l Government involvement in cyberattacks: Sixty percent of those surveyed believe representatives of foreign governments have been involved in past infrastructure infiltrations. In terms of countries that posed the biggest threat to critical infrastructure security, the United States and China topped the list.
“Over 50 percent of those surveyed felt that current laws were inadequate to protect them against attack. Equally, over 40 percent felt that the current government regulations in their countries hadn’t actually had significant effect on improving security, in fact many felt that the laws distracted them from what they really needed to do,” said Greg Day, principal security analyst EMEA, McAfee.
Day advised that there are even problems in defining the meaning of “cyberwar” or “cyberterrorism.” The attacks themselves range from those created by just one individual, who for a political or religious motive is trying to attack a business or a government, or they can be state funded, structured, organized attacks.
“The absolute reality is the ease with which an individual can find the right tools to go and instigate the kind of attacks that can have significant impacts on either an organization or a country,” Day emphasized. “And just as important, the challenge of absolute proof — ‘Who was behind it?’ — are why we are only going to see more and more of this. It’s very hard to prove the origin of cyberattacks and then there isn’t consistency of legislation around the world. Awareness has got to be the first step in dealing with the problem, but then there has got to be international collaboration and cooperation.”

