Ransoming Critical Infrastructure: Colonial Pipeline - Snippet from SANS Emergency Webcast
During the presentation, Tim Conway highlighted that over 30 similar outages on the Colonial Pipeline have occurred over the past 20 years due to storms, ruptures, or mechanical impacts. This snippet highlights the impacts of disruption events of the past consisted to the severity of the current ransomeware cyber attack. The current pipeline disruption is the first cyber-related shutdown that has occurred. Tim continued, “None of those 30 events bubbled up to a national level response at the scale we are currently seeing with the current cyber attack.”
“If you are an organization, don’t point to your IT incident response plan and assume it’s good… look towards OT specific IR plans.” - Tim Conway
SANS is the most trusted and by far the largest source for information security training and security certification in the world. It also develops, maintains, and makes available at no cost, the largest collection of research documents about various aspects of information security, and it operates the Internet's early warning system - the Internet Storm Center.