Protecting the Cheddar

In the last decade, ransomware and other kinds of digital attacks have affected a whole host of critical infrastructure including hospitals in the UK, an electric grid in Ukraine, a nuclear plant in Iran, an oil pipeline in the US, and a meat processor in Brazil. Penetration testers have even found critical vulnerabilities in US nuclear weapons facilities. It’s not a question of if an attack will be launched against critical infrastructure, but rather, when an attack will be launched. When critical systems are digitized and connected to the Internet, the systems can be run more efficiently and effectively, however, digitization (and especially Internet connection) can lead to attacks that wholly take down critical systems. These systems are huge and essentially impossible to perfectly protect. In the case of the Iranian nuclear plant, the plant itself wasn’t even connected to the Internet (it was “air gapped”) – US and Israeli operatives breached the plant by leaving infected USBs around the plant with the hopes that somebody working there would pick up a USB and plug it into a critical system.

Organizations need to decide if the efficiency and effectiveness gained through digitization is worth the hit their brand (and the world) could take in the highly likely case of attack. For systems like power plants, hospitals, and oil pipelines, the consequences of attack are dire – people may die. That being said, without the efficiency and performance afforded by digitization, more people may be hurt without digitization efforts; businesses must make this calculation.

It is essential that businesses understand these tradeoffs as they make decisions. Had Sara not spoken up, Newhouse Cheese Company may not have had the correct mindset in making the decision about whether to de-digitize. The company would have lost the opportunity to consider the potentially catastrophic effects that their digitization efforts could have on the company’s brand and the health of their customers. Despite being a non-technical and non-executive woman in a room filled with executive (and some technical) men, Sara voiced her concerns regarding the company’s digitization efforts and allowed the company to fully understand the consequences of its actions.

For our own project, my group will need to think carefully about how the use of technologies like the blockchain may open our customers up to threats of theft, as transactions that occur on the blockchain are very difficult to reverse, and attackers have made off with billions of dollars worth of stolen blockchain-based assets. Additionally, we will need to think about how we would handle a ransomware attack. Our systems could be vulnerable to a denial of service attack which could put our (albeit non-critical) infrastructure at risk of shutting off. We may also handle sensitive financial data that could be a target for attackers, and we will need to consider how to protect that kind of information.

Avatar

About the author