Author Topic: Why is a Billion Dollar Pipeline Incapable of Defending Itself Against Ransomware?  (Read 476 times)

0 Members and 1 Guest are viewing this topic.

Online mystery-ak

  • Owner
  • Administrator
  • ******
  • Posts: 382,830
  • Gender: Female
  • Let's Go Brandon!
Why is a Billion Dollar Pipeline Incapable of Defending Itself Against Ransomware?

The person in charge has some serious explaining to do. This sort of risk didn't come from nowhere.

May 14, 2021|

12:01 am
Bill Blunden

    “This is why frontier life is so difficult.

    Not because of the Indians or the elements but because of the idiots”

    ─Samantha, from the movie Bone Tomahawk


As details emerge concerning the recent breach of Colonial Pipeline’s network the press has focused primarily on the fallout of the shutdown. In a manner similar to the coverage of events surrounding the financial collapse of 2008, the media’s collective spotlight is emphasizing the spectacle of the ensuing calamity and its scale rather than the underlying failures that enabled it. This indicates that an agenda is likely at work. Or maybe it’s just a twist of fate that all those bankers skipped off into the sunset with their annual bonuses?

Ransomware is a pervasive threat. Any chief information officer worth his salt will have the foresight to deploy the controls necessary to sufficiently raise the cost of attacks as well as limit the damage that they incur—particularly when it comes to protecting the American infrastructure. Entire frameworks have been designed for managing cybersecurity. They’ve been around for years. There is even guidance aimed squarely at the energy sector describing how to implement them. The security programs produced by these frameworks almost always involve essential activities like threat modeling and risk assessment, as well as performing table top exercises, penetration testing, and disaster recovery dry runs. It’s all about managing risk and forging a solid incident response playbook.

When leaders don’t cut corners frameworks yield results. For example, in 1991 the Federal Reserve of Minnesota successfully executed its disaster recovery plan after a water main burst above its data center. With the alacrity that comes from careful, deliberate, preparation the Federal Reserve’s emergency response team sprang into motion. In a matter of hours a backup data center in another city was brought online and began handling daily transactions thanks to the dedication of 50 employees. Based on statements from officials who understand its procedures, the Fed’s digital platform includes multiple layers of redundancy to the extent that it would probably take a nuclear first strike to knock America’s central banking system out of commission. And if the precautions taken during the Cold War are any indication, even that might not be sufficient.

more
https://www.theamericanconservative.com/articles/why-is-a-billion-dollar-pipeline-incapable-of-defending-itself-against-ransomware/
Proud Supporter of Tunnel to Towers
Support the USO
Democrat Party...the Party of Infanticide

“Therefore do not worry about tomorrow, for tomorrow will worry about itself. Each day has enough trouble of its own.”
-Matthew 6:34

Offline catfish1957

  • Laken Riley.... Say her Name. And to every past and future democrat voter- Her blood is on your hands too!!!
  • Political Researcher
  • *****
  • Posts: 31,432
  • Gender: Male
Truly anecdotal, but way back when I working as a Plant Environmental Manager, we had an regulatory agency inquiry around custody (monitoring)  issues on a section of valves around a pipeline station next to our plant. To resolve, and get details of ownership/operation(ship), I contacted their head enviromental contact in their company. 

I'll be nice, and just say that that person was less knowledgeable, and competent than my most junior engineer.
I display the Confederate Battle Flag in honor of my great great great grandfathers who spilled blood at Wilson's Creek and Shiloh.  5 others served in the WBTS with honor too.

Offline Bigun

  • Hero Member
  • *****
  • Posts: 51,489
  • Gender: Male
  • Resistance to Tyrants is Obedience to God
    • The FairTax Plan
“This is why frontier life is so difficult.

    Not because of the Indians or the elements but because of the idiots”


    ─Samantha, from the movie Bone Tomahawk

Yep! Entirely correct!  Anyone who thought it would be ok to use the internet for aiding control systems like these fits into the category of idiot!
"I wish it need not have happened in my time," said Frodo.

"So do I," said Gandalf, "and so do all who live to see such times. But that is not for them to decide. All we have to decide is what to do with the time that is given us."
- J. R. R. Tolkien

Offline Bigun

  • Hero Member
  • *****
  • Posts: 51,489
  • Gender: Male
  • Resistance to Tyrants is Obedience to God
    • The FairTax Plan
Truly anecdotal, but way back when I working as a Plant Environmental Manager, we had an regulatory agency inquiry around custody (monitoring)  issues on a section of valves around a pipeline station next to our plant. To resolve, and get details of ownership/operation(ship), I contacted their head enviromental contact in their company. 

I'll be nice, and just say that that person was less knowledgeable, and competent than my most junior engineer.

Have you ever been called on to interact with OSHA people @catfish1957?  THAT is an eye-opening experience I'll assure you!
"I wish it need not have happened in my time," said Frodo.

"So do I," said Gandalf, "and so do all who live to see such times. But that is not for them to decide. All we have to decide is what to do with the time that is given us."
- J. R. R. Tolkien

Offline Cyber Liberty

  • Coffee! Donuts! Kittens!
  • Administrator
  • ******
  • Posts: 80,061
  • Gender: Male
  • 🌵🌵🌵
The pipeline company didn't want to do what it took, and chose to either cut corners or hire cheap IT people.  It's not complicated.  The large company I worked for was extremely concerned about the Goodnight virus, back in the day.  Colonial clearly did not think it was a serious threat.
For unvaccinated, we are looking at a winter of severe illness and death — if you’re unvaccinated — for themselves, their families, and the hospitals they’ll soon overwhelm. Sloe Joe Biteme 12/16
I will NOT comply.
 
Castillo del Cyber Autonomous Zone ~~~~~>                          :dontfeed:

Offline catfish1957

  • Laken Riley.... Say her Name. And to every past and future democrat voter- Her blood is on your hands too!!!
  • Political Researcher
  • *****
  • Posts: 31,432
  • Gender: Male
Have you ever been called on to interact with OSHA people @catfish1957?  THAT is an eye-opening experience I'll assure you!

Over 30 years of dealing with OSHA, EPA, DOT, etc. and their state, (and local for Houston) counterparts.

Hands down the EPA pencil d__k's were the worst. Some of those bufoons were downright scary crazy with need for power and intimindation.
I display the Confederate Battle Flag in honor of my great great great grandfathers who spilled blood at Wilson's Creek and Shiloh.  5 others served in the WBTS with honor too.

Offline Bigun

  • Hero Member
  • *****
  • Posts: 51,489
  • Gender: Male
  • Resistance to Tyrants is Obedience to God
    • The FairTax Plan
Over 30 years of dealing with OSHA, EPA, DOT, etc. and their state, (and local for Houston) counterparts.

Hands down the EPA pencil d__k's were the worst. Some of those bufoons were downright scary crazy with need for power and intimindation.

I was involved in the aftermath of an industrial accident that took the lives 17 people years ago and can tell you that I have NEVER before encountered gross incompetence like I saw from the OSHA people involved in that. It was truly horrifying, and I mean that sincerely.
"I wish it need not have happened in my time," said Frodo.

"So do I," said Gandalf, "and so do all who live to see such times. But that is not for them to decide. All we have to decide is what to do with the time that is given us."
- J. R. R. Tolkien

Offline DefiantMassRINO

  • Hero Member
  • *****
  • Posts: 10,106
  • Gender: Male
Because no executive gets a bonus for preventing a cyberattack that never happens.
Self-Anointed Deplorable Expert Chowderhead Pundit

I reserve my God-given rights to be wrong and to be stupid at all times.
"If at first you don’t succeed, destroy all evidence that you tried." - Steven Wright

Offline Cyber Liberty

  • Coffee! Donuts! Kittens!
  • Administrator
  • ******
  • Posts: 80,061
  • Gender: Male
  • 🌵🌵🌵
Because no executive gets a bonus for preventing a cyberattack that never happens.

And this is why Business Administration majors must never be allowed to be CEOs.  They only listen to the bean counters and never to the real people working productive jobs.  The corporation I worked for paid me a $2K bonus for making sure my lab was ready for Y2K. 
For unvaccinated, we are looking at a winter of severe illness and death — if you’re unvaccinated — for themselves, their families, and the hospitals they’ll soon overwhelm. Sloe Joe Biteme 12/16
I will NOT comply.
 
Castillo del Cyber Autonomous Zone ~~~~~>                          :dontfeed:

Offline Absalom

  • Hero Member
  • *****
  • Posts: 4,375
Because modern Corporatism is synonymous w/bureaucracy and fat wallets;
having little, if anything to do w/creativity and innovation.
Doubt it? Reflect on the J & J embarrassment a moment.

Offline Restored

  • TBR Advisory Committee
  • ***
  • Posts: 3,659
Because no executive gets a bonus for preventing a cyberattack that never happens.

Pretty much it. Making it secure makes it difficult and difficult frustrates idiots. I know people who leave CPA's over secure document sharing to go to a CPA who emails their tax documents in the clear.
The reason the systems were open was it was just easier.
Countdown to Resignation

Offline corbe

  • Hero Member
  • *****
  • Posts: 38,267
  Later it will be revealed that the head of their IT department is in transition.

No government in the 12,000 years of modern mankind history has led its people into anything but the history books with a simple lesson, don't let this happen to you.

Offline Sled Dog

  • The Ultimate Weapon: Freedom - I Won't
  • Hero Member
  • *****
  • Posts: 3,138
Over 30 years of dealing with OSHA, EPA, DOT, etc. and their state, (and local for Houston) counterparts.

Hands down the EPA pencil d__k's were the worst. Some of those bufoons were downright scary crazy with need for power and intimindation.

Certain parts of Ghost Busters were real....
The GOP is not the party leadership.  The GOP is the party MEMBERSHIP.   The members need to kick the leaders out if they leaders are going the wrong way.  No coddling allowed.

Offline Cyber Liberty

  • Coffee! Donuts! Kittens!
  • Administrator
  • ******
  • Posts: 80,061
  • Gender: Male
  • 🌵🌵🌵
Certain parts of Ghost Busters were real....

You betcha.  Walter Peck was a really believable character.
For unvaccinated, we are looking at a winter of severe illness and death — if you’re unvaccinated — for themselves, their families, and the hospitals they’ll soon overwhelm. Sloe Joe Biteme 12/16
I will NOT comply.
 
Castillo del Cyber Autonomous Zone ~~~~~>                          :dontfeed:

Online roamer_1

  • Hero Member
  • *****
  • Posts: 43,677
Heard tell this was tied to an unpatched MSExchange exploit.

If anybody hears more along those lines, please ping me.