Abstract
With the discovery of the Stuxnet worm in June 2010 came the first documented cyber-attack on critical infrastructure that resulted in mass physical damage. This attack spurred governments and private industry owners of Critical Infrastructure to inspect their cybersecurity practices with the hopes of improving their protection methodologies. While this introspective approach has helped owners and operators of critical infrastructure realize the startling deficiency of security in this area, it has also spawned many attempts to remediate these problems that do not solve the underlying causes of the existing gaps in protection. In this chapter, three “post-Stuxnet” cyber-attacks against critical infrastructure sectors in three different countries are investigated-the USA, Germany, and Turkey. This analysis details the vectors of attack in each incident, the resulting impact, and measures that have been taken by both the public and private sectors in each country to bolster the security posture of their infrastructure after the incident. The result indicates common issues among all three incidents, namely faults in the design of the underlying control systems used and a dichotomy between the actions taken by corresponding governments and private industry. In order to address these faults, there needs to be scalable and risk-based processes to improve supporting processes of cybersecurity in critical infrastructure-namely information sharing, accountability, and risk assessment. This research provides insights into the effects of recent destructive cyber-attacks and the divide between governments and private industry, as well as lapses in security programs that prevents the effective defense of critical infrastructure.
| Original language | English |
|---|---|
| Title of host publication | The Palgrave Handbook of Managing Continuous Business Transformation |
| Publisher | Palgrave Macmillan |
| Pages | 335-352 |
| Number of pages | 18 |
| ISBN (Electronic) | 9781137602282 |
| ISBN (Print) | 9781137602275 |
| DOIs | |
| State | Published - Jan 1 2016 |
Keywords
- Critical infrastructure
- Cybersecurity
- Information sharing
- Risk assessment
- Security policy
Fingerprint
Dive into the research topics of 'Toward a safer tomorrow: Cybersecurity and critical infrastructure'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver