The Global Leader in Software M&A
Search Blogs
 

Recent Posts

European M&A is Hot »
The 10 worst things you can do when selling your software company (Part 8 of 10) »
Don’t Miss WFS NYC on June 5 »
The 10 worst things you can do when selling your software company (Part 7 of 10) »
The 10 worst things you can do when selling your software company (Part 6 of 10) »
Focus on: Cisco »
London WFS Recap »
Guerilla Marketing – Card Decks »
Q1 Global Tech M&A Report »
Cisco Continues its 2013 Acquisition Pace »
How Big is Big Data? »
The 10 worst things you can do when selling your software company (Part 5 of 10) »
SAP's Big Data Move »
Smart Phones - To The End Of The Earth! »
Mobile Spotlight Report »
Private Equity Panel Recap »
KC Revisited »
Gartner Analyst Day - Big Data Analytics »
Dow’s Record Close – M&A Market Soaring »
Field Report Overview »
Mobile Spotlight Report »
Social Spotlight Report »
Electric Reliability - Building a Smarter Network »
SaaS Spotlight Report »
Gaming Spotlight Report »
7 Habits of High Effective Sellers, Habit #2: Begin with the End in Mind »
Growth & Exits in Geekwire »
Living with the Jetsons »
The Trends that Define M&A »
Google Fiber Report »
Top Six Interviews of 2012 - Part Two »
Top Six Interviews of 2012 - Part One »
The Langara Experience »
Forecast 2013: Global Tech M&A Review & Predictions, January 17 »
Guerilla Marketing – Open house at a new installation »
Healthcare Market Spotlight »
The 10 worst things you can do when selling your software company (Part 4 of 10) »
The 10 worst things you can do when selling your software company (Part 3 of 10) »
Growing pains in e-commerce »
7 Habits of Highly Effective Sellers »
2013 Will Be a Banner Year For Tech M&A »
US Energy Policy and M&A »
Energy & Cleantech Market Spotlight Webcast »
Gifting before the Cliff! »
Very cool interactive graphic re: Euro-debt Crisis »
Interview with Corum VP Jeff Brown by CED »
Apple's bruises »
Election Politics and Tech M&A Special Coverage »
Guerilla Marketing – Pre-announce dramatic “vaporware” »
Software Defined Networking: New frontiers in virtualization of the datacenter »

Cyber Attacks, Energy Security and Spearfishing

It been reported that sometime in March, the U.S. Department of Homeland Security began issuing "amber" alerts that warned of a cyber-intrusion campaign aimed at the natural gas pipeline companies. The alerts were reinforced in a report from an arm of DHS, the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) to pipeline companies and power companies. ICS-CERT is charged with helping secure the nation's industrial control systems – IT systems that manage the valves, switches and automation processes critical to the chemical, industrial, and power industries. A number of natural gas pipelines have reported either attempts or intrusions related to a campaign which appears to have started in late December, 2011, and is still active.

It not hard to guess why pipeline safety is a major concern. Approximately 200,000 miles of the interstate natural gas transmission pipelines in the US supply 25% of our energy. Safeguarding the control systems from cyber-attack is a major issue in Congress, wrestling with whether to give authority to the feds to make sure the electric utility, oil and gas, and chemical industries meet certain levels of cyber security.

The threat of cyber-weapons and cyber-war could still seem abstract, even for technology CEOs. It became quite real at a classified security briefing in Spring 2010. The briefing on cyber-threats came at a secret session hosted by the Director of National Intelligence, the departments of Defense and Homeland Security and the head of the U.S. military's Cyber Command. Officials warned that due to a design flaw, "we can turn your computer into a brick." The meeting was part of the "Enduring Security Framework," a public-private partnership that brings CEOs from top technology and defense companies to Washington for classified briefings. The purpose is to share information about developments in cyber-warfare, highlighting the cyber-weapons that could be used against the CEOs' own companies.

So how does an attack get started? The ICS-CERT report described a pretty sophisticated "spear phishing" campaign, where attackers work to establish digital footholds inside corporate networks. Spear phishing has become an attack of choice for infiltrating corporate networks. In an attack, a specific person in the organization is researched, often using social networking sites like Facebook or LinkedIn to craft innocent looking e-mails that appear to be from a close associate.

It’s awfully serious and pretty scary. This got me thinking about my own use of social media, specifically LinkedIn for my business connections. Like many, I use social media to research my way to new business relationships. It’s a very real example of social media’s conflicted relationship - not just with personal privacy but with cyber security, too. However, for the record, I am not now nor have I ever knowingly been a cyber-threat!

Posted by JeffBrown, Vice President on 04 June 2012

Comments (0)    

Featured Contributors

DanielHolland
Sr. Marketing Coordinator

GeoffreySechter
Data Analyst

JasonSteblay
Research Analyst

JimPerkins
Regional Director, Digital Media Specialist

JonScott
Vice President

MarkJohnson
Director