Tech audit of Colonial Pipeline found ‘glaring’ problems
apnews.com
apnews.com
So they hired a consultant to produce a report. Then they purchased enterprise software. In my experience, this will not lead to a good outcome.
Ideally, it shouldn't be the case that Colonial needs to have information security expertise on staff, just like ideally, they shouldn't need to have physical security expertise on staff.
But in the real world, that obviously isn't the case. In 2021, every company is a tech company, and information security isn't something you can outsource. I wish that weren't the case and that we did a better job building software and designing systems to be secure by default. But we're nowhere close to that world.
1/ Digital security insurance
2/ Digital Security Jump Starting… like when your battery is dead you connect it to a functioning battery with jumper cables. There needs to be a service industry for bringing in fresh IT security systems and (re)establishing baseline IT security that meets the standard of the digital insurance industry.
Step 2. Tell the new CEO candidates why the last guy got fired.
That’s all the board has to do. You can be damn sure the next CIO and CSO will be empowered to build and run a security-first organization.
On the other hand, if the current CEO is let off the hook, nothing material will change as hacking will be treated as a PR problem to be solved again in the future by PR people.
Yeah, in an ideal world.
No, in the real world he's doing exactly what the owners want. They are typical of the private equity crowd.
This pipeline was built 60 years ago. It's been paid for many times over. Now it's being managed for maximum cash extraction.
The Colonial board is motivated only by money. My alternative solution would be:
Step 1: Fine the pipeline company $1,000,000,000 because they're deliberately being a bunch of incompetent asswipes.
That's the way you get the attention of those people. That's the only way.
Sadly, the US Supreme Court has taken a rather dim view of "excessive fines". Still, I'm sure that smarter people than I can think of some way to hit the company's board of directors with a financial clue-by-four.
https://www.wcnc.com/article/news/local/ncdeq-colonial-pipel...
* https://www.daybook.com/jobs/jDuPoWB4gbFMpS8x5
* https://www.indeed.com/jobs?q=Scada%20Cyber%20Security%20Man...
These types of attacks don't just "happen", they're caused by chronically underfunding/ignoring security staff. Generally that means being security staff at one of these companies is probably going to be a crap job.
In many cases, the client might not even have their own records of volumes - they just run the pumps till the tanks are full, and then wait for the bill from Colonial.
If Colonial can't produce said bill, they have made a massive loss.
If we've automated ourselves out of the capability to operate for a few days with paper and pen, when the alternative is a nationwide crisis where untold million humans were impacted by resource shortfalls...
How many pennies did we save by shutting down the pipeline, and did we successfully externalize the costs of the worst of the effects of the hack... if so then job well done! LOL
Never change, Colonial Pipeline! Never change a thing.
I was looking at Google satellite photos of their Roanoke, VA site, and you can see there is a regular gas station nearby, but is connected and has a giant loop for tanker trucks to fuel up.
In past jobs where I had driven a company vehicle, there was always a special gas card with a PIN, and when you would swipe at the pump, it would ask you to enter the current mileage of the vehicle.
If you cannot verify or authorize transactions, there is no point in giving away free product.
Nope, that’s nothing like what this is. Oil pipelines are heavily regulated, with ZERO competition. As government protected monopolies, they’re the exact opposite of a free market.
Making new regulations is not helpful when the problem is the existing regulations are not enforced.
"We've got to protect our phoney baloney jobs!"
I will add to this comment that I am very, very concerned that incidents like this lead to changing the rules on communications for hundreds of millions of people. Why do others pay for your mistakes in guarding your wealth for yourself?
https://www.bbc.com/news/world-europe-57111615
https://www.sungardas.com/en-us/blog/ransomware-attacks-on-u...
So yeah blame capitalism and not inherent human nature that applies to every large scale system built by humans.
Sounds a bit cheap to fix such a thing.
Aging private infrastructure built by tycoons.
Once the sizable venture capital is paid back the original shareholders rake in the bucks and money is no object when it comes to protecting their cash cow.
But future generations of shareholders pay a premium market price based on the cash from the cow at the time, which can be quite a favorable investment, but nothing like the VC bonanza.
Public, or private shareholders as in this case.
The maintenance, modernization and dedication to integrity that the original shareholders could easily afford might still end up out-of-reach to future generations.
But the business started out so good and "nothing changed" so it can be ignored.
Where grandpa took great pride in spending millions per year maintaining the assets which is so much less than they were spending building the company, Thurston Howell III just has financial people looking at his numbers and couldn't build anything his own self anyway. Plus if it all does go "down the tubes" he'll still be fine regardless.
Wear & tear plus obsolescence creeps in undetected until it rears its ugly head and they say "who knew?"
It doesn't really matter how much money the company throws at a problem if they don't fix it.