Breaking News
0
Ad-Free Version. Upgrade your Investing.com experience. Save up to 40% More details

Analysis - Cyberattack exposes lack of required defenses on U.S. pipelines

Stock MarketsMay 12, 2021 03:15PM ET
Saved. See Saved Items.
This article has already been saved in your Saved Items
 
© Reuters. FILE PHOTO: Holding tanks are seen in an aerial photograph at Colonial Pipeline's Dorsey Junction Station in Woodbine, Maryland, U.S. May 10, 2021. REUTERS/Drone Base

By Timothy Gardner

WASHINGTON (Reuters) - The shutdown of the biggest U.S. fuel pipeline by a ransomware attack highlights a systemic vulnerability: Pipeline operators have no requirement to implement cyber defenses.

The U.S. government has had robust, compulsory cybersecurity protocols for most of the power grid for about 10 years to prevent debilitating hacks by criminals or state actors.

But the country's 2.7 million miles (4.3 million km) of oil, natural gas and hazardous liquid pipelines have only voluntary measures, which leaves security up to the individual operators, experts said.

"Simply encouraging pipelines to voluntarily adopt best practices is an inadequate response to the ever-increasing number and sophistication of malevolent cyber actors," Richard Glick, the chairman of the Federal Energy Regulatory Commission (FERC), said.

Protections could include requirements for encryption, multifactor authentication, backup systems, personnel training and segmenting networks so access to the most sensitive elements can be restricted.

FERC's authority to impose cyber standards on the electric grid came from a 2005 law but it does not extend to pipelines.

Colonial Pipeline, the largest U.S. oil products pipeline and source of nearly half the supply on the East Coast, has been shut since Friday after a ransomware attack the FBI attributed to DarkSide, a group cyber experts believe is based in Russia or Eastern Europe.

The outage has led to higher gasoline prices in the U.S. South and worries about wider shortages and potential price gouging ahead of the Memorial Day holiday.

Colonial did not immediately respond to a query about whether cybersecurity standards should be mandatory.

The American Petroleum Institute lobbying group said it was talking with the Transportation Security Administration (TSA), the Energy Department and others to understand the threat and mitigate risk.

THIN STAFFING

Cyber oversight of pipelines falls to the TSA, an office of the Department of Homeland Security (DHS), which has provided voluntary security guidelines to pipeline companies.

The General Accountability Office, the congressional watchdog, said in a 2019 report that the TSA only had six full-time employees in its pipeline security branch through 2018, which limited the office's reviews of cybersecurity practices.

The TSA said it has since expanded staff to 34 positions on pipeline and cybersecurity. It did not immediately respond to a request for comment on whether it supports mandatory protections.

When asked by reporters whether the Biden administration would put in place rules, DHS Secretary Alejandro Mayorkas said it was discussing administrative and legislative options to "raise the cyber hygiene across the country."

President Joe Biden is hoping Congress will pass a $2.3 billion infrastructure package, and pipeline requirements could be put into that legislation. But experts said there was no quick fix.

"The hard part is who do you tell what to do and what do you tell them to do," Christi Tezak, an analyst at ClearView Energy Partners, said.

U.S. Representatives Fred Upton, a Republican, and Bobby Rush, a Democrat, said on Wednesday they have reintroduced legislation requiring the Department of Energy to ensure the security of natural gas and hazardous liquid pipelines. Such legislation could get folded into a wider bill.

The power grid is regulated by FERC, and mostly organized into nonprofit regional organizations. That made it relatively easy for legislators to put forward the 2005 law that allows FERC to approve mandatory cyber measures.

A range of public and private companies own pipelines. They mostly operate independently and lack a robust federal regulator.

Their oversight falls under different laws depending on what they carry. Products include crude oil, fuels, water, hazardous liquids and - potentially - carbon dioxide for burial underground to control climate change. This diversity could make it harder for legislators to impose a unified requirement.

Tristan Abbey, a former aide to Republican Senator Lisa Murkowski who worked at the White House national security council under former President Donald Trump, said Congress is both the best and worst way to tackle the problem.

"Legislation may be necessary when jurisdiction is ambiguous and agencies lack resources," said Abbey, now president of Comarus Analytics LLC.

But a bill should not be seen as a magic wand, he said.

"Standards may be part of the answer, but federal regulations need to mesh with state requirements without stifling innovation."

Analysis - Cyberattack exposes lack of required defenses on U.S. pipelines
 

Related Articles

Australia takes wine dispute with China to WTO
Australia takes wine dispute with China to WTO By Reuters - Jun 18, 2021 24

By Lidia Kelly MELBOURNE (Reuters) -The Australian government said on Saturday it was lodging a formal complaint with the World Trade Organization over China's imposition of...

Add a Comment

Comment Guidelines

We encourage you to use comments to engage with users, share your perspective and ask questions of authors and each other. However, in order to maintain the high level of discourse we’ve all come to value and expect, please keep the following criteria in mind: 

  • Enrich the conversation
  • Stay focused and on track. Only post material that’s relevant to the topic being discussed.
  • Be respectful. Even negative opinions can be framed positively and diplomatically.
  •  Use standard writing style. Include punctuation and upper and lower cases.
  • NOTE: Spam and/or promotional messages and links within a comment will be removed
  • Avoid profanity, slander or personal attacks directed at an author or another user.
  • Don’t Monopolize the Conversation. We appreciate passion and conviction, but we also believe strongly in giving everyone a chance to air their thoughts. Therefore, in addition to civil interaction, we expect commenters to offer their opinions succinctly and thoughtfully, but not so repeatedly that others are annoyed or offended. If we receive complaints about individuals who take over a thread or forum, we reserve the right to ban them from the site, without recourse.
  • Only English comments will be allowed.

Perpetrators of spam or abuse will be deleted from the site and prohibited from future registration at Investing.com’s discretion.

Write your thoughts here
 
Are you sure you want to delete this chart?
 
Post
Post also to:
 
Replace the attached chart with a new chart ?
1000
Your ability to comment is currently suspended due to negative user reports. Your status will be reviewed by our moderators.
Please wait a minute before you try to comment again.
Thanks for your comment. Please note that all comments are pending until approved by our moderators. It may therefore take some time before it appears on our website.
Comments (1)
Gene Kret
Gene Kret May 12, 2021 7:57AM ET
Saved. See Saved Items.
This comment has already been saved in your Saved Items
Hey Sleepy Joe are you going to blame this on Trump too? Dems are slowly going to erode the US as China sits back and laughs... sad very sad.
Joel Hauser
Joel Hauser May 12, 2021 7:57AM ET
Saved. See Saved Items.
This comment has already been saved in your Saved Items
Omg it's chyna guys.
 
Are you sure you want to delete this chart?
 
Post
 
Replace the attached chart with a new chart ?
1000
Your ability to comment is currently suspended due to negative user reports. Your status will be reviewed by our moderators.
Please wait a minute before you try to comment again.
Add Chart to Comment
Confirm Block

Are you sure you want to block %USER_NAME%?

By doing so, you and %USER_NAME% will not be able to see any of each other's Investing.com's posts.

%USER_NAME% was successfully added to your Block List

Since you’ve just unblocked this person, you must wait 48 hours before renewing the block.

Report this comment

I feel that this comment is:

Comment flagged

Thank You!

Your report has been sent to our moderators for review
Disclaimer: Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. All CFDs (stocks, indexes, futures) and Forex prices are not provided by exchanges but rather by market makers, and so prices may not be accurate and may differ from the actual market price, meaning prices are indicative and not appropriate for trading purposes. Therefore Fusion Media doesn`t bear any responsibility for any trading losses you might incur as a result of using this data.

Fusion Media or anyone involved with Fusion Media will not accept any liability for loss or damage as a result of reliance on the information including data, quotes, charts and buy/sell signals contained within this website. Please be fully informed regarding the risks and costs associated with trading the financial markets, it is one of the riskiest investment forms possible.
Continue with Google
or
Sign up with Email