Protecting Against the Typhoon: A Warning for Critical Infrastructure

Published March 26, 2024

The Volt Typhoon saga continues. Volt Typhoon is a China-based hacking group accused of targeting critical infrastructure, and federal agencies have been tracking its activity for some time. The concern around its ability to establish base camps in IT networks in order to gain eventual access to OT networks has only grown. Here’s the latest.

What the First Advisory Found

An advisory from CISA, the NSA and the FBI reported that hackers suspected of ties to China’s government had taken action affecting critical infrastructure systems. Cybersecurity representatives in Australia, New Zealand and the United Kingdom joined it, and the systems named included both IT and OT. As reported by The Record, the group took zipped files holding “diagrams and documentation related to OT equipment.” The files covered supervisory control and data acquisition systems, relays and switchgear.

Authorities had already tracked attacks by the group in the United States and in territories including Guam. One was carried out against a water utility. In February the Biden administration released an executive order calling for improved security in the water and wastewater sector. Operators of water and wastewater systems can check which OT drawings and asset records sit on reachable IT networks.

The same order set out cybersecurity requirements for United States ports. As Security Week explained, it focuses specifically on the risk that cranes made in China pose to US ports and their OT networks. It also gives the Coast Guard authority to put forward rules enforcing cybersecurity and reporting standards for waterfront facilities and vessels. Facility operators can confirm whether their site falls within the scope of those rules.

A New Warning is Issued

The CISA, NSA, FBI, and several other agencies in the U.S. have joined cybersecurity agencies from Australia, Canada, the United Kingdom, and New Zealand to alert critical infrastructure leaders of the threat that Volt Typhoon poses, particularly to OT systems. This doubles down on the warning that they issued last month in which they emphasized the Chinese hackers’ successful breach of critical infrastructure in the U.S., which lasted years in some cases. Worried that Volt Typhoon may be interested in taking advantage of vulnerabilities, especially during times of geopolitical tensions, the agencies have urged operators to “empower their cybersecurity teams to make informed resourcing decisions, secure their supply chain, and ensure that performance management outcomes align with their organization’s cyber goals,” according to Sergiu Gatlan at Bleeping Computer.

While a warning for all critical infrastructure, a particular spotlight has been put on water and wastewater systems, which already suffer from resource shortages. The Biden administration is continuing to advise states to be vigilant for cyberattacks against these systems, specifically with the threat of Volt Typhoon rising. In a recent letter, Environmental Protection Agency Administrator Michael Regan and National Security Advisor Jake Sullivan noted that Volt Typhoon has already compromised information technology connected to drinking water facilities.

Cybersecurity Concern Rises

In addition to causing major disruption to essential networks, experts are increasingly concerned that China will be able to steal intellectual property through such cyberattacks. During the Billington State and Local Cybersecurity Summit in Washington, D.C., industry speakers discussed China’s use of AI in espionage efforts. To protect from this risk, the CISA has promoted the benefits of “tabletop exercise,” or the process of simulating such attacks in order to develop proper response strategies and techniques.

Despite the push for such preventative measures, the cybersecurity concerns are obviously at an all-time high. Those concerns reach well beyond people who work in the field. A new study shows that the general public is also as worried about the impacts of cyberattacks. MITRE and The Harris Poll found that, “81% of US residents are worried about how secure critical infrastructure may be.” While 78% of respondents believe the responsibility for addressing this problem lies on the federal government, 49% said the responsibility falls on both public and private organizations. Regardless of where the responsibility should be placed, the fact remains that cybersecurity will continue to be a priority, with OT taking a more prominent position, an area that DYNICS knows well. It is essential that facilities downsize the attack surface of their OT networks by denying by default and limiting traffic only to what is required for the operation of the plant. Be sure to explore our products designed specifically to shield OT systems.

Sources

Author: <a href="https://dynics.com/author/dynics-team/" target="_self">Dynics Team</a>

Author: Dynics Team

The Dynics engineering group designs and builds industrial computing hardware and OT cybersecurity systems for the plant floor. Its engineers hold more than 75 years of combined experience, and its plant-floor deployments go back more than 30 years. More than 75% of staff work in product development, design, assembly, and service. Dynics designs, fabricates, and assembles its panel PCs, monitors, rackmount chassis, and security appliances at a 37,500 square foot facility in Ann Arbor, Michigan.

Related Posts

You Might Also Like...

Case Studies
A factory assembly line with robotic arms constructing car frames in a large industrial facility.
Securing Multi-Supplier OT Access While Enabling Real-Time Operational Visibility

Securing Multi-Supplier OT Access While Enabling Real-Time Operational Visibility

Managing multiple third-party suppliers within a manufacturing environment presents unique cybersecurity and operational challenges. In this case study, discover how a leading automotive manufacturer leveraged DYNICS ICS360.Defender and ICS360.Fusion to securely isolate eight independent supplier networks while maintaining centralized operational visibility.