Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

marmar

(77,091 posts)
Wed Jun 2, 2021, 10:50 AM Jun 2021

Big Oil lobby fought cybersecurity regulations for years, making pipeline attack easier


(Salon) The American Petroleum Institute, the top trade group for the oil and gas industry, spent years opposing federal cybersecurity regulations before the Colonial Pipeline ransomware attack. After the attack, watchdog groups say API is still opposing strong federal regulation and pushing for taxpayer "subsidies" instead.

Colonial Pipeline, one of the largest pipelines in the country, which carries 45% of the fuel from Texas to New York, was forced to shut down after a ransomware attack by the foreign cybercriminal group known as DarkSide. Cybersecurity experts believe that Colonial lacked advanced cybersecurity defenses that can monitor networks for irregularities and detect threats like DarkSide's infiltration tools. But Colonial is not the first pipeline affected by cyberattacks and many other pipelines in the U.S. may have similar vulnerabilities.

A ransomware attack hit an unidentified natural gas facility in 2020, forcing it to shut down for two days, according to the Department of Homeland Security. The Cybersecurity and Infrastructure Security Agency said after the attack that the owner of the facility "did not specifically consider the risk posed by cyberattacks" or prepare employees to deal with one.

Federal officials have been sounding the alarm on the lax cybersecurity measures for years. Federal Energy Regulatory Commissioners Neil Chatterjee and Richard Glick warned in a 2018 op-ed that a lack of federal cybersecurity standards left energy firms vulnerable to cyberattacks. The Government Accountability Office in 2019 found that federal cybersecurity guidelines were badly out of date and lacked preparation to respond to an attack on critical infrastructure. After the Colonial attack, the cybersecurity firm Byos estimated that "less than 25% of the U.S. oil and gas industry has adequate cybersecurity in place," according to Bloomberg News. ..............(more)

https://www.salon.com/2021/06/02/big-oil-lobby-fought-cybersecurity-regulations-for-years-making-pipeline-attack-easier/




Latest Discussions»General Discussion»Big Oil lobby fought cybe...