Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

cthulu2016

(10,960 posts)
Mon Jul 23, 2012, 01:00 PM Jul 2012

Can Utility corporations be Trusted with their own Security?

If you're gonna regulate anyone, utilities kind of come to mind.

Cybersecurity Bill Backed By Obama Won’t Protect U.S., Experts Agree

...

There’s another point where security experts seem to have broad agreement, and it doesn’t bode well for U.S. cybersecurity preparedness: That the new bill that Obama advocates on behalf of in his op-ed, the Cybersecurity Act of 2012, has been neutered to the point of ineffectuality.

Lieberman originally introduced the bill in February but the Senate has been slow to act on it, with Republicans critical of provisions that would give the Department of Homeland Security the power to require that so-called critical infrastructure operators — namely utilities companies — to put certain cybersecurity measures in place.

Now that power has been stripped from a new version of the bill introduced by Lieberman and his cosponors on Thursday.

“Even if Congress passes cyber security legislation, it won’t stop this threat,” Carr said. “That’s the real story. No one including the President has the political will to force privately owned companies to spend what’s needed to protect our critical infrastructure, even if that spending drives down profits for a short time. The current legislation is entirely on a voluntary basis, which is utterly useless.”

...

http://idealab.talkingpointsmemo.com/2012/07/president-obamas-warning-on-cyber-attacks-divides-experts.php?ref=fpnewsfeed

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Can Utility corporations be Trusted with their own Security? (Original Post) cthulu2016 Jul 2012 OP
I used to work for the IT Department of a large utility in Oregon dballance Jul 2012 #1
Fuck no they refuse to spend money for it DainBramaged Jul 2012 #2
 

dballance

(5,756 posts)
1. I used to work for the IT Department of a large utility in Oregon
Mon Jul 23, 2012, 01:24 PM
Jul 2012

I think many people would be pleasantly surprised at the lengths our Cybersecurity team went to to protect our computer networks. It was always a constant pain in the ass to comply with all their rules but they could dead-stop any new system or code from going into production if it didn't meet the standards. All this was done because the people at the top, our CIO, CEO, and board realized it was actually necessary so they authorized the expenditures.

I think they actually realized allowing some nefarious group to take over our network and possibly shut down power that might be supplying power to hospitals, police and fire stations would not only be bad for customers but really bad for the bottom line.

It is also important to note that there were at least two networks there. The one called Energy Management System or EMS that actually controlled the Grid was physically separate from the network that supported more typical corporate functions like customer service, and accounting. There was yet another physically separate network that provided our web presence and all the functions customers could get to.

I'm not going to say no one will ever figure out a way to get into the EMS system and maybe create havoc but I know we did everything we could to prevent it with the full support and encouragement of Senior management.

Latest Discussions»General Discussion»Can Utility corporations ...