Feeds

Electrical grid overlords take drubbing over cyber attack vulnerability

'Disorganized, ineffective'

High performance access to file storage

US lawmakers ripped into the organization that oversees North America's electrical grid, saying it isn't doing enough to prevent cyber attacks that could cripple the economy.

US Representative James Langevin, chair of the House Subcommittee on Emerging Threats, Cybersecurity and Science and Technology, said he had "little confidence" that the North American Electric Reliability Corporation (NERC) has fully addressed a vulnerability code-named Aurora, in which electric utilities generators and other equipment comes to a grinding halt.

"I still do not get the sense that we are addressing cybersecurity with the seriousness that it deserves," Langevin said, according to this report from IDG News Service. "I think we could search far and wide and not find a more disorganized, ineffective response to an issue of national security of this import. If NERC doesn't start getting serious about national security, it may be time to find a new electric reliability organization."

The public thrashing came after the release of a report (PDF) by the General Accountability Office (GAO) identifying numerous vulnerabilities at the Tennessee Valley Authority (TVA) that put the nation's biggest public power company at risk to cyber attacks.

Among other things, the TVA had firewalls that were improperly configured or bypassed, used poorly implemented passwords, and relied on logging practices that weren't up to snuff, according to the GAO report. TVA administrators had also neglected to install key software patches and ran intrusion-detection systems with "significant limitations." The GAO issued 92 recommendations for shoring up cyber security at the TVA, which supplies power to 8.7 million US residents in seven states.

The scrutiny comes as more and more electricity providers try to cut costs and boost efficiency by using so-called supervisory control and data acquisition (SCADA) systems, which allow workers to operate equipment remotely using the internet or telephone lines. The systems may save money, but they also potentially make the equipment vulnerable to cyber attack by extortionists, disgruntled employees and terrorists.

The TVA was already in the process of fixing the problems before investigators began their report, a TVA official said. And NERC, along with the Federal Energy Regulatory Commission, is in the process of implementing new rules for cybersecurity that go into effect in July. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.