cybersecurity of electrical grid

13
CYBERSECURITY OF ELECTRICAL GRID Marius Celskis Information security manager, Litgrid Industrial Cyber Security Professional (GICSP) Certified Incident Handler (ECIH) CompTIA Security+ Certified Professional

Upload: others

Post on 17-Jan-2022

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cybersecurity of Electrical Grid

CYBERSECURITY OF ELECTRICAL

GRID

Marius Celskis

Information security manager, Litgrid

Industrial Cyber Security Professional (GICSP)

Certified Incident Handler (ECIH)

CompTIA Security+ Certified Professional

Page 2: Cybersecurity of Electrical Grid

Power system

Power plant

generates

electricity

Transformer

steps up

voltage for

transmission

Transmission

lines carry

electricity long

distances

Distribution

lines carry

electricity to

houses

Transformer

steps down

voltage

Consumers

Page 3: Cybersecurity of Electrical Grid

700

MW

500

MW

Electricity transmission never stops

1945

Power system

1970

Infrastructuredevelopment

1990

Restoration of independence

2010

Closure of Ignalina NPP

2016

LitPol Link andNordBalt

Page 4: Cybersecurity of Electrical Grid

• > 7 000 km lines and

substations of 400,

330, 110 kV

transmission grid

• > 2 500 km optical

cable

The grid

Page 5: Cybersecurity of Electrical Grid

Management system

Page 6: Cybersecurity of Electrical Grid

Different actors

Operators Regulators Manufacturers

IntegratorsService

providersProducers

Consumers

Page 7: Cybersecurity of Electrical Grid

• 2013 California sniper attack on

substation

• 1996 IRA planned attack on London HV

electrical substations

• 1959–72 KGB plan to destroy two large

hydroelectric dams in Montana

Attacks on electrical grid

Page 8: Cybersecurity of Electrical Grid

• 1982 Siberian gas pipeline explosion

• 2010 Stuxnet

• 2013 "some disruption" at the nuclear

power plant by cyber attack

• 2015 Ukraine power distribution grid

attack

Cyber attacks on control

systems

Page 9: Cybersecurity of Electrical Grid

Cybersecurity requirements

Local laws Contractual obligations

Best practices

Page 10: Cybersecurity of Electrical Grid

• ENTSO-E security practices

• NIST 800-82 Guide to Industrial Control

Systems (ICS) Security

• NISTIR 7628 Guidelines for Smart Grid

Cybersecurity

• NERC Critical Infrastructure Protection

Best practices

Page 11: Cybersecurity of Electrical Grid

• BDEW Requirements for Secure Control

and Telecommunication Systems

• ISA/IEC-62443 Security for industrial

automation and control systems

• IEEE 1686 Standard for Intelligent

Electronic Devices Cyber Security

Capabilities

Best practices (cont.)

Page 12: Cybersecurity of Electrical Grid

• Penetration tests

• Social engineering tests

• Awareness program

• Continuity plans for blackout

• Recovery exercises

• Redundant high security operational and

data centers

• Participating in NATO ENSECCOE and

MoD trainings

Protection

Page 13: Cybersecurity of Electrical Grid

Litgrid mission:

Ensure reliable transmission of

electricity and enable

competition in the open

electricity market

Litgrid vision:

Full integration of the Lithuanian

power system into the European

power infrastructure and the

common electricity market