{"id":4078,"date":"2024-06-17T12:00:00","date_gmt":"2024-06-17T17:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/addressing-misinformation-in-critical-infrastructure-security"},"modified":"2024-06-17T12:00:00","modified_gmt":"2024-06-17T17:00:00","slug":"addressing-misinformation-in-critical-infrastructure-security","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/17\/addressing-misinformation-in-critical-infrastructure-security\/","title":{"rendered":"Addressing Misinformation in Critical Infrastructure Security"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt387fd01355a30e8e\/6670404e27143f1cee6b2560\/Infrastructure_Jochen_Tack_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Francis Scott Key Bridge collapse in Baltimore, Md., in late March sent shockwaves through the country. Almost immediately, there was widespread&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cnn.com\/2024\/03\/28\/politics\/baltimore-bridge-collapse-conspiracy-theories\/index.html\" rel=\"noopener\">speculation and conspiracy theories<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;regarding its cause, including fears of a cyberattack. Although investigations ruled out deliberate sabotage, the incident raised public concern about the vulnerability of physical infrastructure.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.secureworld.io\/industry-news\/congress-cyber-forensics-ship-bridge-strike?utm_campaign=Industry%20News&amp;utm_medium=email&amp;_hsenc=p2ANqtz-_CYHClZF0AakX-ln7ti-yIJjsCbUx-iMTzt8QwL-zl07_qjWNNR9TBlCNw49opXvdgxO8LmQjIYtO4E8rL3B8iKpn1MA&amp;_hsmi=308549589&amp;utm_content=308551905&amp;utm_source=hs_email\" rel=\"noopener\">Some members of Congress<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;even called for further investigation into the possibility of malicious code being involved.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The incident rightly drew attention to the potentially devastating impact of cyberattacks on US infrastructure and human safety. However, it also highlighted a broader issue: a general lack of awareness regarding the reality and scale of cyber-risks to critical infrastructure. Beyond this incident, whether it was the result of foul play or not, there is a ticking time bomb of risk to critical infrastructure that is very real and potentially imminent if not addressed. While this physical attack may have brought the possibility of cyberattacks to the public consciousness, there are many more threats that we cannot physically see lurking beneath the surface that are equally damaging.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While physical incidents capture headlines and public attention, silent, invisible attacks on critical infrastructure remain poorly understood.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/chinese-hackers-deployed-backdoor-quintet-to-down-mitre\" rel=\"noopener\">The MITRE breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, for example, was not an attack that caused visible physical damage, but a breach through Ivanti zero-day vulnerabilities.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/mitre-cyberattack-ivanti-exploits\/713860\/#:~:text=Exploits%20of%20Ivanti%20VPN%20products%20have%20hit%20roughly%201%2C700%20organizations.\" rel=\"noopener\">Despite affecting 1,700 entities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it flew under the radar of most Americans. While the breach did not result in visible damage, it led to unauthorized access to sensitive data. This can undermine national security, compromise intelligence operations, and expose confidential information, leading to long-term repercussions just as significant as any physical system attack.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The disconnect between public perception and cyber threats is real, and we cannot let fear paralyze us into inaction. Combating misinformation and raising awareness about cyber-risks facing critical infrastructure is crucial to enhancing our collective resilience against evolving cyber challenges.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Public Perception vs. Reality\">Public Perception vs. Reality<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Theorizing can distort public understanding of cyber threats, undermine trust in legitimate news sources, and complicate efforts to educate the public and stakeholders about the fundamental nature of cyber threats and the necessary precautions to mitigate them. The public&#8217;s reaction to the Francis Scott Key Bridge collapse demonstrates the collective anxiety about cyber threats to critical infrastructure. This fear was fueled by references to&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/fact-check\/fabricated-image-baltimore-bridge-collapse-not-2023-netflix-film-2024-04-08\/\" rel=\"noopener\">fictional scenarios like the Netflix movie&nbsp;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link ContentText-BodyTextChunk_italic\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/fact-check\/fabricated-image-baltimore-bridge-collapse-not-2023-netflix-film-2024-04-08\/\" rel=\"noopener\">Leave the World Behind<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, in which a cyberattack on the US disables power grids, the Internet, and telecommunications services, sending the country into an apocalyptic world. With parallels drawn with the recent collapse, this heightens public anxiety and shifts focus away from real-life cyber threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, this is an opportunity for public reckoning, prompting a much-needed focus on improving critical infrastructure security. Physical attacks resulting in immediate and visible damage, such as property destruction or loss of life, will always catch the eyes of US citizens and evoke strong emotional responses. It&#8217;s also clear that society tends to attribute physical events to deliberate human actions more readily than cyberattacks, which are commonly perceived as accidental or impartial. This bias can impact the severity and urgency of responding to cyber threats \u2014 one of our nation&#8217;s greatest challenges today.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As we approach the election season, this moment is a critical opportunity for voters to advocate for policies that enhance critical infrastructure security. By recognizing the connection between cyber and physical threats and understanding that cyber incidents can have real-world consequences, we can push for&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/white-house-releases-implementation-plan-for-cybersecurity-strategy\" rel=\"noopener\">greater investment and action to protect our nation&#8217;s infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Educational Gap\">Educational Gap<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to a recent poll,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mitre.org\/news-insights\/news-release\/mitre-harris-poll-finds-us-public-worried-about-security-our-critical\" rel=\"noopener\">81% of Americans are worried about how secure our critical infrastructure is<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. It&#8217;s promising that securing critical infrastructure is already top of mind for average citizens. However, this event revealed a need for more awareness surrounding what constitutes a cyber-risk to critical infrastructure. This lack of understanding can be attributed to several factors, including insufficient education and training and limited public discourse on the sophistication of cyber threats.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To best address the educational gaps, all citizens, policymakers, and infrastructure operators must work together to better understand the state of our threat landscape. Luckily, the government is taking steps to improve education through initiatives like the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/niccs.cisa.gov\/cybersecurity-career-resources\/cybersecurity-education-and-training-assistance-program\" rel=\"noopener\">Cybersecurity Education and Training Assistance Program (CETAP)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, enhancing the quality and accessibility of cybersecurity education at all levels. The Cybersecurity and Infrastructure Security Agency (CISA) also launched public awareness campaigns to inform citizens about best practices for cyber hygiene. While encouraging, additional steps need to be taken.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/mitre-advises-us-government-to-shape-up-for-critical-infrastructure\" rel=\"noopener\"> policy changes prioritizing cybersecurity must be implemented<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> across critical infrastructure industries. This is how we hold our nation accountable, increase education and attention, and keep our critical infrastructure secure. For instance,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/2-years-after-colonial-pipeline-attack-us-critical-infrastructure-remains-as-vulnerable-to-ransomware\" rel=\"noopener\">after the Colonial Pipeline attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the Transportation Security Administration (TSA) released new regulations, prompting the oil and gas industry to take security much more seriously. Advocating for similar regulations in other critical infrastructure sectors, such as energy, transportation, and healthcare, is crucial for enhancing the cyber posture of these essential services, especially as we approach an election year.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Securing Our Tomorrow\">Securing Our Tomorrow<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The root solution lies in leading with a proactive versus reactive approach to cybersecurity. Proactive measures, such as implementing a zero-trust strategy, continuous monitoring, rotating credentials, and regular updates, can prevent incidents before they occur. In contrast, reactive measures often only address the damage after it has been done. By fostering a culture of cyber literacy and proactive risk mitigation, we can empower stakeholders at all levels to recognize and effectively respond to cyber threats before they escalate into catastrophic events or misinformation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a world where the lines between the physical and digital realms blur, widespread understanding of cyber threats to critical infrastructure is paramount. If we don&#8217;t double down on it now, misinformation will continue exacerbating these national security threats by distorting public perception and undermining trust in reliable information sources. By bridging the gap between psychological perception and cyber reality, staying educated, and taking proactive steps, we can build the secure future we are all striving for.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/addressing-misinformation-in-critical-infrastructure-security\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The Francis Scott Key Bridge collapse in Baltimore, Md.,<\/p>\n","protected":false},"author":12,"featured_media":4079,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=1802%2C1029&ssl=1",1802,1029,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=300%2C171&ssl=1",300,171,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=640%2C366&ssl=1",640,366,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=640%2C366&ssl=1",640,366,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=1536%2C877&ssl=1",1536,877,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=1802%2C1029&ssl=1",1802,1029,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=1024%2C585&ssl=1",1024,585,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/addressing-misinformation-in-critical-infrastructure-security.jpg?fit=1802%2C1029&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4078"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4079"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}