US Pipeline Operators Rush to Meet New Cyber Security Mandate

Following the devastating Colonial Pipeline ransomware attack, US regulators issue a swift directive requiring pipeline operators to assess and report their cyber security posture within 30 days.

A new US government directive requires pipeline operators to evaluate and report on their cyber security readiness within 30 days following the Colonial Pipeline ransomware attack. The May 2021 incident forced a six-day shutdown of the 8,900-kilometre pipeline that supplies 45 percent of the US East Coast's fuel, prompting the Transportation Security Administration to issue Security Directive Pipeline-2021-01.

The Colonial Pipeline operator pays a ransom to the DarkSide criminal gang to regain access to its locked IT systems and faces tens of millions of dollars in recovery costs. Although the attack impacts only IT systems and does not directly breach operational technology (OT) systems, it exposes critical vulnerabilities in the energy supply chain.

Industry research indicates that 60 percent of critical infrastructure companies remain in the earliest stages of OT cyber security maturity, meaning many pipeline operators struggle to implement robust protections. Existing frameworks like the DNV Recommended Practice DNVGL-RP-G108 help these companies apply relevant standards to meet the new compliance requirements and better secure their systems.

Read More at the original source →