DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech examines the intersection of technology and defense from every angle and provides analysis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • ‘Canes
  • Af-Cam
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the “Buzz”
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Crazy Ivan
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT’s Dust
  • Extra! Extra!
  • Eye on China
  • F-35 Watch
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Bubble with Joe Buff
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar’s Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples’ Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward’z Wonderz
  • You can run…

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » Legal Risk of Cyber Outage

Legal Risk of Cyber Outage

gavel2.jpg

New analysis indicates that critical infrastructure operators are ill prepared to deal with cyber attacks. That reinforced the Government Accountability Office (GAO) report earlier this year that found Tennessee Valley Authority, the nation’s largest public power company serving over 8.7 million people, is vulnerable to cyber attacks. One just released study asked respondents to indicate the state of readiness to defend against IT threats in eight different industries. The results showed that 50 percent of respondents said that utilities, oil and gas, transportation, telecommunications, chemical, emergency services and postal/shipping industries were not prepared. The energy sector emerged as the most vulnerable target. So it is no wonder the Department of Homeland Security (DHS) is once again moving to address the threat to our nation’s critical infrastructure.

DHS is looking for public input as it prepares for next year’s release of a revised version of the National Infrastructure Protection Plan (NIPP), thus updating the 2006 version of the plan. The federal government has sought to actively engage the private sector in a number of industries to address the threat of cyber attacks. Originally, the federal government identified seventeen critical infrastructure areas and designated federal agencies to be in charge of creating plans as well as overseeing collaborative efforts to protect those areas. It should be noted that earlier this year DHS announced that it also had designated critical manufacturing as an additional sector.

One industry insider speaking to me on the promise of anonymity said: “Utility executives are not going to spend money on defending their systems against cyber attacks. When they do, they decrease the financial performance of the company and that subtracts from the executives bonuses.” So is this yet another group of businesses that are going to the Federal Government looking for a hand out?

Cyber attacks against utilities are just not theoretical, they are real. Earlier this year there were dozens of reports that stated CIA senior analyst Tom Donohue told a gathering of 300 US, UK, Swedish and Dutch government officials, engineers and security managers from electric, water, oil & gas and other critical industry asset owners that “Cyber Attack Caused Multi-City Power Outage.” Cyber attacks against utilities are now a foreseeable risk.

Foreseeable Risk and Threats — (a legal term) — A danger which a reasonable person should anticipate. Foreseeable risk is a common affirmative complaint put up in lawsuits for negligence (a tort).

We sought out a legal opinion and got one.

“The significant media attention being given to the threat of cyber attacks, as well as the fact that a number of high ranking government officials have warned about this threat, suggest that corporations have a duty to assess their exposure to this risk and create a cyber risk mitigation strategy. Failure to do so could constitute negligence due to the fact that in this day and age, cyber attacks are reasonably foreseeable,” said Attorney Fred Rice specializing in corporate legal issues.

FACT: Tort litigation costs have reach nearly $300 billion annually.

But how far could the legal action go? I posed the following scenario to Edward Maggio, professor of criminal justice at the New York Institute of Technology. Scenario: A cyber attack directed against an electrical utility causes a power spike and outage. The spike and outages damage a piece of life support equipment resulting in the death of a patient relying on the device.

Given the above scenario, if the electrical utility did not take appropriate action to protect against such attacks, could the utility be held accountable?

“While culpability for the impact resulting from cyber attacks is a somewhat uncharted area of law, legal action against a power utility will be based on negligence. It is likely that hackers who engage in successful cyber attack against a power utility have likely made previous attempts against a chosen target. Such previous attempts would serve as evidence that a power utility had a duty to mitigate and protect itself from cyber attacks,” Maggio said.

It is clear that any utility that fails to appropriately plan for or respond to the increased threat of cyber attacks are failing in their duty to protect the general public. Anyone harmed as a result of a cyber attack against a utility may have cause of action (lawsuit) when they were harmed due to the power utility’s failure to increase its cyber security he went on to explain.

Will it take a major cyber attack with litigation before the necessary steps are taken to protect our critical infrastructure? It sure looks that way.

– Kevin Coleman

Share |

November 17th, 2008 | Cyber-warfare | 41876 Comments »http://defensetech.org/2008/11/17/legal-risk-of-cyber-outage/Legal+Risk+of+Cyber+Outage2008-11-17+19%3A15%3A38Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « Monday — Fire for Effect | Paks Rumbling with Afghan Rebels? » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Ptsfp says:
    November 17, 2008 at 4:54 pm

    Yes, I truly believe it will take a major incident before companies, especially utilities, think seriously about cyber security.
    I have worked in the oil and gas industry and cyber terrorism is talked about as much as executives taking voluntary pay decreases…
    In the early 90’s many telecomm systems and even a dam were compromised by a hacker. He was known for his persistence, spending endless hours attacking again and again until he compromised a system, and then he moved on. He could have caused a lot of damage if he wanted to. The FBI finally caught up with him and found that he was a 20ish year old kid who had mental issues. I don’t even think they brought charges against him, due to his mental condition and the FBI’s fear of the public response.

    Reply
  2. Chaimss says:
    November 17, 2008 at 7:08 pm

    My biggest question is why the AFCoS just downgraded Cyber Command to an NAF when it obviously needs to be seen as a greater responsibility.

    Reply
  3. Kevin says:
    November 17, 2008 at 9:59 pm

    Chaimss
    The Airforce got ahead of themselves on establishing a cyber command. At one point we had four being established and Sec Gates said enough and gave the planning and overall control to U.S. Strategic Command.

    Reply
  4. ohwilleke says:
    November 18, 2008 at 11:05 am

    Wouldn’t this be a Homeland Security issues rather than a DOD issue?

    Reply
  5. Kevin says:
    November 18, 2008 at 7:27 pm

    ohwilleke
    It can be both a DoD and DHS issue!

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

NOTE: Comments are limited to 2500 characters and spaces.

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Recent Articles
    • JSF Price Tag Jumps to $135 Million
    • EADS Tanker, Not Dead Yet
    • JFCOM’s Mattis Pushes Light IW Aircraft
    • And, the Vertical Landing
    • NLOS-LS Missile Fail Could Impact Navy’s LCS
    • JFCOM’s JOE Whacks Defense Industry
    • New F-35B Hover Video
    • China’s Shipbuilding in a Regional Context
    • Debating the Pros and Cons of LCS
    • Bigger, Badder IEDs in Afghanistan
    Recent Comments
    • EADS Tanker, Not Dead Yet
      As an European living in Germany I would have love to see...
      fightingirish
    • JSF Price Tag Jumps to $135 Million
      Gees the price is on the roof already. Maybe we just...
      roland
    • Ft. Irwin, Where You At?
      I was the driver for BoB Gaygos, B Co 6/31st Commander....
      Ricky houltzhouser
    • Ft. Irwin, Where You At?
      Luis, I was Captain Gaydos, driver Sgt. Houltzhouser in...
      Ricky Houltzhouser
    • Bigger, Badder IEDs in Afghanistan
      If you really want to win the war permanently, it will...
      steven
    • Cover Your Computer Mics and WebCams
      Another question, how would I physically obstruct the...
      Curious
    • Cover Your Computer Mics and WebCams
      whats a good way to physically cover my laptop webcam?...
      Curious
    • EADS Tanker, Not Dead Yet
      But, the Eurotrash airplane ISN'T better… The Boeing...
      WillyPete
    • JSF Price Tag Jumps to $135 Million
      Gee, I wonder why? Oh! Maybe it's because the...
      WillyPete
    • JSF Price Tag Jumps to $135 Million
      It would also help, a LOT to 'limit' excess...
      WillyPete
  • Channels:Military.com | Military Benefits | Military News | Off Duty |Join the Military | Military Education | Veteran Jobs | Military Money |Military Deals | Military Family | Military Community
  • Military.com Network:Military.com | MilBlogging | Defense Tech | DoD Buzz |SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps |Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program |Monster Network | Help | Feedback | Privacy Policy |User Agreement| © 2010 Military Advantage