Authlogics Authlogics
  • Solutions
    • Password Security Auditing
    • Password Policy Compliance
    • Password Breach Database
    • Passwordless Authentication
    • Deviceless OTP
    • Single Sign-On
    • Cloud Protection
      • Amazon Web Services
      • Azure and Office 365
    • Helpdesks
    • Retail Banking
    • Transaction Verification
  • Products
    • Password Security Management
    • Multi-Factor Authentication
      • Authenticator Mobile App
      • PINgrid
      • PINphrase
      • PINpass
      • Yubikey
    • System Agents
      • ADFS Agent
      • Domain Controller Agent
      • Exchange Agent
      • Remote Desktop Agent
      • Windows Desktop Agent
  • Resources
    • Demonstration
    • Whitepapers
    • Datasheets
    • Case Studies
    • Use Cases
    • Pricing
    • Blog
    • Accolades
    • UK Government: G-Cloud
  • Partners
    • Find a Reseller
    • Find a Distributor
    • Technology Partners
    • Become a partner
    • Password Security Portal
  • Company
    • Contact Us
    • Intellectual Property
    • About Us
  • Support
    • Downloads
    • Documentation
    • Knowledge Base
    • Community
    • Log a call
Authlogics Authlogics
  • Solutions
    • Password Security Auditing
    • Password Policy Compliance
    • Password Breach Database
    • Passwordless Authentication
    • Deviceless OTP
    • Single Sign-On
    • Cloud Protection
      • Amazon Web Services
      • Azure and Office 365
    • Helpdesks
    • Retail Banking
    • Transaction Verification
  • Products
    • Password Security Management
    • Multi-Factor Authentication
      • Authenticator Mobile App
      • PINgrid
      • PINphrase
      • PINpass
      • Yubikey
    • System Agents
      • ADFS Agent
      • Domain Controller Agent
      • Exchange Agent
      • Remote Desktop Agent
      • Windows Desktop Agent
  • Resources
    • Demonstration
    • Whitepapers
    • Datasheets
    • Case Studies
    • Use Cases
    • Pricing
    • Blog
    • Accolades
    • UK Government: G-Cloud
  • Partners
    • Find a Reseller
    • Find a Distributor
    • Technology Partners
    • Become a partner
    • Password Security Portal
  • Company
    • Contact Us
    • Intellectual Property
    • About Us
  • Support
    • Downloads
    • Documentation
    • Knowledge Base
    • Community
    • Log a call
E&T Article

ARTICLE: When cutting costs on defending your networks isn’t an option

Steven Hopeon 2nd February 2022

The gas and oil industry’s uniquely political roles mean that the repercussions of a security breach can be more than just financial.

Access management and authentication processes are a necessity in any modern enterprise in almost every industry on Earth. The information held within a corporate network is valuable enough that nefarious actors will continue to target it mercilessly.

The ability to properly protect these assets is the difference between a strong, compliant organisation and one that ends up hauled in front of a regulatory board to answer for its failings. For the gas and oil industries, secure authentication can be an even more serious consideration.

For as long as gas and oil have been important commodities on the global stage, they have been political footballs to be kicked around. An appropriate security posture is not just important for safety, security and prosperity, but is also an important way for businesses to avoid raising their heads above the parapet and risking incurring political hostility.

For an example of how authentication and political crisis can intersect, we need to look no further back than May 2021. Nobody could have missed the seismic impact of the Colonial Pipeline hack in the USA. Hackers – assumed to be Russian-based – managed to successfully compromise a Houston oil pipeline, causing knock-on effects to the US petrol supply chain that for weeks left vast swathes of the country unable to fill up the cars that form the backbone of the country’s transport network.

This was one of the most high-profile ransomware incidents in US history and led the company’s chief executive to a Senate hearing in which he was forced to defend the organisation’s actions. Further fallout included President Biden signing an executive order strengthening US cyber-security defences. Herein lies the problem for the gas and oil industries: the geopolitical nature of the commodities at stake means they are inherently political in a way other industries are not.

For this reason, the basics of authentication become even more important. After all, it was a compromised password for a dormant account that led the hackers into the Colonial pipeline in the first place. The price paid by the company was dire – financially, politically and reputationally – and could have been avoided simply by deploying a more robust set of authentication standards. The Senate hearing that investigated the incident was well aware of this. The Colonial Pipeline CEO was asked outright if the organisation had a system of multi-factor authentication in place, and could not answer that it did. That being said, the attack didn’t even need multi-factor authentication as a defence – basic user-account management and modern password controls in line with NIST SP 800-63B would have done the job.

The CEO also claimed that this single-factor authentication was being used on a legacy VPN where the breach occurred. This is also not a strong enough excuse. Hackers will attempt to enter every point of the network, from legacy VPNs to organisations in your supply chain that might represent an easy route into a network.

The security issues that this presented did not stop at the domestic problem of disrupted petrol supply chains. Worse still, Colonial ended up in the midst of geopolitical manouevering. The cybercrime group DarkSide, which took responsibility for the hack, claimed that its motivations were entirely financial, not political. However, when a hacking group is assumed to be based in Russia, this distinction becomes less relevant. While stating that the Putin administration did not have anything to do with the hack, Biden did use the opportunity to suggest it needs to take “responsibility” for groups operating within its jurisdiction.

The seismic repercussions of a single authentication issue speak to a wider truth; one that suggests that although the gas and oil industries are among the wealthiest on earth, in some corners there has been wholesale failure to secure cyber-security defences and policies. This has to change.

While the associated time and resources spent on appropriate authentication may seem unnecessary when the threat is not visible, these costs pale into insignificance when compared to the operational, financial and reputation issues that could befall a business in a worst-case scenario. Ensuring that appropriate authentication defences such as multi-factor authentication and proper password security policies are in place may seem unnecessary, but they are definitely preferable to a trip to the Senate with your tail between your legs.

Steven Hope is co-founder and CEO at Authlogics

Article published in E&T News on 25th January 2022.

in Authentication, Business, Customer Experience, Data Breach, Multi Factor Authentication, Password Security, Security
tags: Authentication, Authlogics, business, colonial pipeline, compromised credentials, cybersecurity, darkside, multi-factor authentication, password security

Leave a Reply Cancel reply

  • Previous

    The Rise of Ransomware, Cryptocurrency Corruption, and Vaccine Vulnerabilities.

  • Next

    The Road to Password Hell is Paved with Good Intentions

Recent Posts

  • If You Do One Thing on World Password Day, Find Out How Many of Your Passwords are Being Shared Around the World
  • The Road to Password Hell is Paved with Good Intentions
  • ARTICLE: When cutting costs on defending your networks isn’t an option
  • The Rise of Ransomware, Cryptocurrency Corruption, and Vaccine Vulnerabilities.
  • The biggest risk to retailers and consumers on Black Friday / Cyber Monday? Breached and insecure passwords

Recent Comments

  • The highway to password hell is paved with good intentions - Andre HOT on Have you been Pwned? Most likely
  • The street to password hell is paved with good intentions - Trend Directory on Have you been Pwned? Most likely
  • The highway to password hell is paved with good intentions - Theopenlab on Have you been Pwned? Most likely
  • The highway to password hell is paved with good intentions - Lecheyre.ch on Have you been Pwned? Most likely
  • The road to password hell is paved with good intentions - ilmi Wap on Have you been Pwned? Most likely

Archives

  • May 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • February 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • May 2020
  • April 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • January 2019
  • September 2018
  • January 2018
  • October 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015

Categories

  • Authentication
  • Awards
  • Business
  • Compliance
  • Customer Experience
  • Data Breach
  • Download
  • Implementation
  • Management
  • Marketing
  • Multi Factor Authentication
  • Password
  • Password Replacement
  • Password Security
  • Passwordless Authentication
  • PIN
  • Predictions
  • Remote Working
  • Security
  • Single Signon
  • Strategy
  • Uncategorised

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Contact us

UK: +44 1344 568 900
US: +1 408 706 2866

sales@authlogics.com
info@authlogics.com

Visit us

329 Doncastle Road, Bracknell,
Berkshire, RG12 8PE, UK

Map it »

1551 McCarthy Blvd, Suite 215,
Milpitas, CA, 95035, US

Map it »

Follow on

Legal information

Privacy Policy
© Authlogics Ltd. All Rights Reserved.