The risk posed by increasingly connected critical national infrastructure (CNI) assets, increasingly capable artificial intelligence (AI)-enabled hackers and improved legislation all mean the “battlefield is rising” in cybersecurity, according to an expert.
NCE spoke to Cyro Cyber chief executive officer Shannon Simpson to hear his perspectives on the increasingly demanding cybersecurity needs of the CNI sector.
Cyro is part of M Group and provides cybersecurity services to a range of CNI sectors including water and energy.
Simpson reflected on the recent news that AI agents from OpenAI, Anthropic and Meta had left controlled environments and hacked third parties.
“I think they are controllable if you teach them to be controllable,” he said.
“For me, a lot of what goes unnoticed is that these tools, these agents, which are clearly capable, are actually breaking the law.
“They’re breaking the Computer Misuse Act. Therefore, their owners should be culpable for that.”
Concerns have already been raised about the threat posed by cyber-attacks now being enabled by AI, meaning small numbers of people trying to attack targets like CNI can multiply their capabilities.
“The tools, without doubt, expedite the capability to be able to find vulnerabilities,” Simpson said.
“We have an offensive security testing team ourselves, and this is one area where we are starting to use these tools. The speed at which you can identify vulnerabilities [using AI] is undoubtable.
“That means that the inherent weaknesses within those systems are going to be found more quickly.”
The cyber security and CNI sectors have to work together while maintaining certain levels of secrecy. If too much information about their cyber defence activities is shared, it could help an adversary.
However, this can create a challenge for constructive collaboration between the sectors.
Simpson said collaboration between public and private cyber security experts is “improving certainly, but it can improve a lot more”.
“For example, you take the recent attack against the UK power station,” he said.
“A lot of people have been able to join some dots between the attacks that were going on [against] the US water companies [via] certain operational technology (OT) systems like Schneider, Siemens, and Rockwell, and therefore that raises suspicion that that UK power station, which is yet to be named, would have been running that sort of technology and would have been hit by the APT (advanced persistent threat) Iranian attacks there.”
An ‘advanced persistent threat’ is a designation given by the cybersecurity sector to known attackers.
Simpson adds: “That information could have been disclosed. That information could be helping other UK power stations and other users of those sorts of technologies to discern exactly where those issues were.”
Something cybersecurity professionals think about in relation to CNI is expanding ‘attack surfaces’, the area within a computer system that attackers could gain improper access to.
A significant proportion of CNI physical assets have OT built into them, which does things like remote monitoring or has the ability to control the flow of electricity or water.
Simpson said: “The biggest weakness is where IT has been introduced into OT environments, and by that I mean metering systems, monitoring systems, where you’ve got an OT system which is now being controlled or operated by an element of IT.”
This is one part of the increasing digitalisation of CNI, which is raising cybersecurity vulnerability concerns.
Another cyber risk that comes up from time to time is supply chain risks.
This means that, while you may have very well-protected large and high-profile organisations and assets, the wider network of small or medium-sized organisations within the supply chain may be less well protected and form a potential vulnerability for the CNI assets they support.
Regarding giving those smaller supply chain companies access to OT and IT technology, Simpson said: “They have to have systems in that, if you’re providing access to a third party across that system, you have to be able to monitor the traffic and ensure that’s okay, or restrict the access on a zero-trust basis, just to make sure that the identity of the activity that is going on there is absolutely trusted.”
He adds that the Cyber Security and Resilience (Network and Information Systems) Bill, which is currently being discussed in the House of Lords, will have a role to play in helping CNI organisations to enforce standards around trust and verification of who is accessing those systems.
“I think that’s one of the biggest challenges. And I think that’ll take the longest time for people to really get their to get their heads around because you’ve got to solve the problem of identity not only internally but you’ve got to solve the identity challenge, by that I mean identity classification, privileged access management,” he said.
“You’ve got to know exactly who is authenticated and to what levels of data they can get to, and that is going to take cultural and behavioural change that would ordinarily take two to three years to solve.”
Simpson said that the escalating cyber defence environment has led to an increase in the need for more security-vetted personnel. He said, “all of a sudden” there has been a proliferation of people appointed as “secure by design leads” and the creation of secure by design departments.
“These are organisations realising that they’ve got to get around the entire organisation, embed the secure by design culture into everything that they do,” he said.
That means that there is “pressure” to employ more security-vetted people, and he warned, “it’s not like there’s a lot of them running around already”.
“It can be difficult to determine whether the fever pitch reporting about the risks posed by emerging AI tools to organisations in general – and to CNI specifically – is worth taking seriously.”
He concluded: “I think what gets missed a lot in the narrative that’s coming out at the moment [is that] whilst the frontier capabilities are developing very quickly, as are the defensive capabilities.
“You look at the big players in those spaces. The Palo Altos, the Ciscos, the Microsofts, their investment in defensive capability almost outstrips that of the frontier.
“The battlefield is rising, but the defensive capabilities are rising just as quickly as the offensive ones as well.”