cyber security awareness - gard security... · crew connectivity survey •only 15% of seafarers...

32
CYBER SECURITY AWARENESS Jarle Fosen, Senior Loss Prevention Executive January 2019 in the maritime industry

Upload: others

Post on 01-Aug-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

CYBER SECURITY AWARENESS

Jarle Fosen, Senior Loss Prevention Executive

January 2019

in the maritime industry

Page 2: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

Why do cyber

incidents happen?

2

Page 3: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

MODERN CRIMINALS USE KEYBOARDS, NOT GUNS

Cyber attack

Destruction of Data

Publication of sensitive data

Media Attention

Selling stolen data

Ransoming stolen data

Ransoming system operability

Arranging fraudulent cargo transportation

Financial Gains

Gaining knowledge

Espionage

OBJECTIVES

3

Page 4: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

INTRODUCTION

4

Page 5: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

AN INCREASINGLY DIGITISED SHIPIT & OT SYSTEMS ONBOARD

5

19502018

Page 6: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

BUSINESS BENEFITS FROM CONNECTINGOPERATIONAL TECHNOLOGY (OT)

6

Autonomy

Knowledge

Availability

Direct Running

Cost

Prediction & diagnostics

Optimal maintenence

Remote support

Efficiency in operations

Page 7: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

… so what may the

consequences be

from a cyber incident?

7

Page 8: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

CONSEQUENCES OF A CYBER ATTACK

• Business interruption –

including disruption to

the port’s activities

• Physical loss of or

damage to ship

• Loss of cargo

• Pollution

• Physical injury to crew

8

Page 9: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

MAERSK CYBER INCIDENT

June 2017 – worldwide malware meltdown

…EVEN THE BEST CAN BE HIT BY THE WORST

9

Petya (or NotPetya or Nyetya)

Page 10: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

BW GROUP CYBER INCIDENT

BW Group which commands

USD 2.0 bn LNG fleet & USD 2.1 bn LPG fleet

came under attack in July 2017

…EVEN THE BEST CAN BE HIT BY THE WORST

10

Internet and intranet systems were closed down temporarily

Page 11: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

COSCOJULY 2018 - US OPERATIONS DISRUPTED BY CYBER ATTACK

11

Page 12: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

CYBER TRENDINCIDENTS AND REGULATION

12

Page 13: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

RISK EVALUATION

Information technology• IT Networks

• Emails

• Administration, accounts, crew lists, …

• PMS

• Stores requisitions

• Electronic manuals

• Electronic certificates

• Permits to work

• Charter party, notice of readiness, bill of

lading..

Operation technology• PLC (Programmable Logic Controllers)

• SCADA (supervisory control and data

acquisition)

• On-board measurement and control

• ECDIS

• GPS

• Remote support for engines

• Data loggers

• Engine & Cargo control

• Dynamic positioning, …

IT vs. OT

13

Page 14: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

RISK TRENDCYBER ISSUES

Source: AV-TEST Institute, Germany & IBM Managed Security Services)

14

Operational technology (OT)Information technology (IT)

Page 15: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

WWW.SHODAN.IOGOOGLE SEARCH FOR IoT

15

Page 16: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

CREW CONNECTIVITY SURVEY

• Only 15% of seafarers had received any form of

cyber security training.

• Only 33% of seafarers said the company they last

worked for had a policy to regularly change

passwords on board.

• 71% of seafarers are willing to share personal data

to further their career prospects.

• 52% are willing to share personal data in return for

free Internet access.

• 50% of seafarers are willing to share their

employment reviews, whilst 44% are prepared to

share their medical history, with prospective

employers.

2018

According to Crew Connectivity 2018 Survey Report by Futurenautics group

16

Page 17: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

PEOPLE ARE THE KEYIT IS NOT ONLY ABOUT PROCESS AND TECHNOLOGY

17

▪ Training & awareness

▪ Professional skills

& qualifications

▪ Written procedures

▪ Authorizations

▪ Physical security

▪ Management Systems

▪ Governance Frameworks

▪ Policies & procedures

▪ Vendor/third party contracts-follow up

▪ Audit regimes

▪ System design, design review

▪ Software configurations

▪ Inspection/verification

▪ Testing

– Functional testing

– Vulnerability scanning

– Penetration test

PEOPLEPROCESS

TECHNOLOGY

Page 18: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

How can we in

loss prevention help?

18

Make the crew see the cyber risk to stop it

Page 19: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

WE HAVE IDENTIFIED SOME THREAT SCENARIOSFOR THE SHIP AND CREW TO BE AWARE AND LEARN FROM

19

Page 20: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

THREAT SCENARIO #1

20

Page 21: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

21

Do they know the cyber

risks?

Page 22: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

REMOVABLE MEDIA / EXTERNAL HARDWARE &

MIXING ISOLATED AND OPEN NETWORKS

22

Page 23: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

THREAT SCENARIO #2

23

Page 24: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

THREAT SCENARIO #3

24

Page 25: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

TAMPERING WITH NAVIGATION SYSTEMS &

RANSOMWARE

25

Page 26: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

THREAT SCENARIO #4

26

Page 27: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

THREAT SCENARIO #5

27

Page 28: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

BEST PRACTICES

28

Page 29: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

CASE STUDY

• Divide into groups

• Study the case background and incident text

• Perform an onboard risk assessment of the

incidents and identify the factors which lead to it

• Use the keywords provided for your discussion

CYBER SECURITY - SAFETY OF THE CREW

29

Page 30: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

MAIN LEARNING POINTS

1. Think and ask before you click!

2. Research the facts behind e-mails and their attachments!

3. Make sure external drives and USBs are clean!

4. Be aware when third parties enter your systems or data!

5. Protect your passwords!

6. Never connect personal items to the ship critical systems.

7. Never use external wi-fi for company emails or downloads unless

protected by VPN!

8. Learn how to install and use two step authentication.

9. Learn how backup and restore is done onboard your ship.

10.Always report errors and mistakes.

11.Educate yourself on cyber risks and how it affects your ship, your

colleagues and you personally!

CREW PREPAREDNESS

30

Page 32: CYBER SECURITY AWARENESS - Gard Security... · CREW CONNECTIVITY SURVEY •Only 15% of seafarers had received any form of cyber security training. •Only 33% of seafarers said the

32

Connect with Gard on: