{"id":2926,"date":"2021-09-09T19:00:00","date_gmt":"2021-09-10T00:00:00","guid":{"rendered":"https:\/\/www.aapaseaports.com\/?p=2926"},"modified":"2021-09-22T10:57:59","modified_gmt":"2021-09-22T15:57:59","slug":"staying-one-step-ahead-of-cyberattacks","status":"publish","type":"post","link":"https:\/\/www.aapaseaports.com\/index.php\/2021\/09\/09\/staying-one-step-ahead-of-cyberattacks\/","title":{"rendered":"Staying One Step Ahead of Cyberattacks"},"content":{"rendered":"<div class=\"htmlBody article_div\">\n<div class=\"roofHeader\"><span style=\"color: #ff0000\">To read the article in the full digital version of Seaports,<\/span> <a href=\"https:\/\/www.seaportsmag-digital.com\/aapq\/0321_third_quarter_2021\/MobilePagedReplica.action?pm=2&amp;folio=14#pg14\"><span style=\"color: #3366ff\">click here<\/span><\/a>.<\/div>\n<div class=\"byline\">By <span class=\"author-name\">Nick Fortuna<\/span><\/div>\n<figure class=\"picture\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/014.jpg\" alt=\"staying one step ahead of cyberattacks\" \/><figcaption><span class=\"attribution\"><a href=\"http:\/\/ISTOCK.COM\/KRULUA\">ISTOCK.COM\/KRULUA<\/a><\/span><\/figcaption><\/figure>\n<p><span class=\"dropCap\">N<\/span>owadays, just about everyone lives tethered to their cellphones, but that wasn\u2019t an option for Tracey Sandberg on that random Tuesday in September 2018 when the Port of San Diego was struck by a ransomware attack.<\/p>\n<p>Sandberg, who had joined the port as director of information technology earlier that year, was cut off from the outside world, sequestered in a jury room at the county courthouse, when Iranian hackers used malware to freeze the port\u2019s computer systems. After the attack, the port had limited access to permits and public documents for several days, and the administrative functions of the Harbor Police were impacted.<\/p>\n<p>When Sandberg arrived at work the next day, she knew she\u2019d have her hands full.<\/p>\n<p>&#8220;On Day 2, I walked back into the building, and the team said, \u2018Thank God you\u2019re here,\u2019&#8221; said Sandberg, now the port\u2019s chief technology officer. &#8220;Imagine that every laptop, every desktop and every server in your organization doesn\u2019t work. What do you do? How do you even begin to organize that recovery?&#8221;<\/p>\n<p>At the time, the port was working to upgrade its IT infrastructure, and though that process wasn\u2019t complete, the port\u2019s focus on cybersecurity paid off. The port had a disaster-recovery plan in place and was able to recover its data through backups, so it chose not to pay ransom to the two hackers, who eventually were indicted but never arrested.<\/p>\n<p>Sandberg said the port\u2019s leadership team lined up color-coded Post-it Notes in a long hallway Kanban to map out the recovery process. The first step was to clean about a dozen laptops and some servers so the IT department could establish a computer lab in a conference room. With few trusted workstations available, the port\u2019s top executives lined up alongside line-level employees for their turn at a laptop, and the IT team worked feverishly to clean and reconnect more critical components.<\/p>\n<p>&#8220;Technical staff would pick up a Post-it Note from the hallway and work that Post-it Note, and that\u2019s really how we got through the first few weeks of work,&#8221; Sandberg said. &#8220;It was a bonding time for the company as we made our way through this experience.&#8221;<\/p>\n<p>For every headline-making cyberattack \u2013 such as those on the Port of San Diego, the Colonial Pipeline and the JBS meat-processing company \u2013 there are countless similar attacks noticed only by businesses and their customers. Last year alone, the FBI\u2019s Internet Crime Complaint Center received 2,474 complaints identified as ransomware, with adjusted losses exceeding $29.1 million, an increase of 225% over the prior year, according to the agency.<\/p>\n<p>Ransomware attacks on businesses happen every 11 seconds on average, with global damages projected to reach $20 billion this year, according to the Boston-based cybersecurity firm Cybereason.<\/p>\n<p>The increasing frequency and sophistication of ransomware attacks represent a top security concern for port administrators, along with physical threats such as terrorism and natural disasters. In response, many ports have been upgrading their IT hardware and software over the past few years, often with help from the Department of Homeland Security\u2019s Port Security Grant Program, which provides up to $100 million in annual funding to protect the nation\u2019s critical port infrastructure.<\/p>\n<p>Sandberg said the ransomware attack accelerated the Port of San Diego\u2019s planned cybersecurity upgrades, which included investments in IT hardware, software and manpower. It also underscored the importance of following best practices, such as patching servers and laptops every month, using two-factor authentication to access computers and having a standardized process for making changes to IT infrastructure.<\/p>\n<p>Port employees also are trained to recognize spear-phishing attempts, in which hackers send suspicious emails to workers, encouraging them to click on a link or enter sensitive information. Employees are taught to flag spear-phishing attempts in the port\u2019s email system to help prevent them from spreading, and when they are detected, the IT team sends out a bulletin to workers showing them what those attempts look like.<\/p>\n<p>This fall, the Port of San Diego is planning to hold a tabletop exercise simulating another ransomware attack that brings operations to a halt. IT staff will be told to pretend that their laptops, desktops and other devices no longer work, and they\u2019ll begin the recovery process anew. With the threat from cyberattacks constantly evolving, the defensive preparation never ends.<\/p>\n<p>&#8220;We\u2019ll be testing ourselves and gauging our own preparedness,&#8221; Sandberg said.<\/p>\n<p>Here\u2019s a snapshot of other ports\u2019 cybersecurity initiatives:<\/p>\n<h2>Port of Los Angeles<\/h2>\n<p>The busiest port in the United States made big news in December, announcing a partnership with IBM to create a Port Cyber Resilience Center.<\/p>\n<p>Focused on detecting and defending against cyberattacks that could disrupt the supply chain, this first-of-its-kind system is expected to greatly improve the quality, quantity and speed of cyber-threat information sharing within the port community, according to Thomas E. Gazsi, the port\u2019s chief of public safety and emergency management.<\/p>\n<p>The three-year, $6.8 million agreement calls for IBM to provide the port with hardware, software and services to design, install, operate and maintain the Cyber Resilience Center.<\/p>\n<figure class=\"graphic\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/015.png\" alt=\"thomas e. gazsi\" \/><figcaption><em>Thomas E. Gazsi, Port of Los Angeles<\/em><\/figcaption><\/figure>\n<figure class=\"graphic\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/015-01.png\" alt=\"lance kaneshiro\" \/><figcaption><em>Lance Kaneshiro, Port of Los Angeles<\/em><\/figcaption><\/figure>\n<p>In 2014, the port established its Cyber Security Operations Center to monitor threats to the port\u2019s internal systems, and Los Angeles remains the only port to hold the prestigious ISO 27001 cybersecurity certification from the International Organization for Standardization. The new Cyber Resilience Center will bring the port\u2019s other stakeholders into the fold, creating a &#8220;system of systems&#8221; accessible to terminal-operating shipping lines, rail companies, trucking companies, labor groups and others, Gazsi said.<\/p>\n<p>&#8220;We take very seriously the fact that we are the busiest container port in the United States, and with that comes the responsibility to fortify and secure the supply chain in a responsible, digitized fashion,&#8221; Gazsi said. &#8220;You constantly have to prepare for a cyberattack and be ready to respond effectively, not only for yourself but for your stakeholders.&#8221;<\/p>\n<h2>Port of Beaumont<\/h2>\n<p>It\u2019s out with the old and in with the new at this port in southeastern Texas, which hired a third party to perform a cybersecurity audit of its IT network in 2019. The goal was to bring the port into compliance with the Cybersecurity Framework for Improving Critical Infrastructure established by the National Institute of Standards and Technology (<a href=\"https:\/\/www.nist.gov\/cyberframework\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"color: #3366ff\">https:\/\/www.nist.gov\/cyberframework<\/span><\/a>).<\/p>\n<p>The port has hired a third-party integrator to install new equipment and software that will address the priorities outlined in the cybersecurity audit, according to Randal Ogrydziak, the port\u2019s director of security, facilities, regulatory compliance, safety and emergency management.<\/p>\n<p>&#8220;Our administrative network was last upgraded many years ago, and back then, people didn\u2019t even know how to spell cybersecurity,&#8221; Ogrydziak said. &#8220;This will reduce our risk to cybercrime, but it won\u2019t eliminate it. You don\u2019t know what you don\u2019t know unless you have a trusted third party come in and assess your network. There\u2019s a cost associated with that, but you get what you pay for.&#8221;<\/p>\n<figure class=\"graphic\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/019.png\" alt=\"randal ogrydziak\" \/><figcaption><em>Randal Ogrydziak, Port of Beaumont<\/em><\/figcaption><\/figure>\n<p>Ogrydziak said the port focuses on cybersecurity training since the &#8220;insider threat&#8221; from employees is always present. A disgruntled worker might click on the wrong link intentionally, but most of the time, the offender makes an honest mistake and forgets what he\u2019s been taught about spear-phishing schemes, he said.<\/p>\n<p>Ogrydziak pointed to a cybersecurity presentation offered by a DHS official that he attended several years ago. The official said that the very next day after DHS employees were instructed on how to handle suspicious emails, he sent a fake email offering free NFL tickets to those who clicked on a link and provided some personal information.<\/p>\n<p>&#8220;They had to redo training for everybody,&#8221; he said.<\/p>\n<p>A good cybersecurity training program covers not only the basic threats but also the creative ways hackers can gain entry into a computer network. Simply connecting a smartphone to a computer for charging can give cybercriminals a way in. Alternatively, they might even label a flash drive &#8220;port employees\u2019 salaries for 2021&#8221; and leave it in the parking lot, hoping an employee plugs it into a computer.<\/p>\n<p>&#8220;You can have the latest hardware, software, firewalls and everything else, but it comes down to that insider threat, which is usually someone not thinking about what they\u2019re doing,&#8221; Ogrydziak said.<\/p>\n<h2>Port of Redwood City<\/h2>\n<p>This Northern California port has used federal grants to fund a variety of security improvements, including construction of an Interagency Operations Center; equipment such as cameras, lights and fencing; a new jet dock; and CBRNE (chemical, biological, radiological, nuclear, explosive) detection equipment for the Redwood City fire and police departments.<\/p>\n<p>The Interagency Operations Center (IOC) will be a place where local, state and federal first responders can collaborate with the port and its stakeholders to manage emergencies. The Port of Redwood City is a FEMA-designated Federal Staging Area in the event of an earthquake or other disaster.<\/p>\n<figure class=\"graphic\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/020.png\" alt=\"kristine a. zortman\" \/><figcaption><em>Kristine A. Zortman, Port of Redwood City<\/em><\/figcaption><\/figure>\n<p>Kristine A. Zortman, the port\u2019s executive director, said building the IOC involves replacing the port\u2019s existing IT hardware and software systems with newer versions, helping the port to stay one step ahead of hackers. She said IT infrastructure is similar to consumer electronics such as televisions and cellphones in that the latest products seem antiquated in just a few years.<\/p>\n<p>&#8220;It\u2019s about making sure that you have the most up-to-date technology, assessing whether that technology is giving you what you need, and identifying how that technology may leave you vulnerable to a breach,&#8221; Zortman said. &#8220;You don\u2019t ever want to be static because once you stop reassessing and looking to upgrade, that\u2019s when people start being able to find inroads into your system.&#8221;<\/p>\n<aside class=\"sidebar shortSidebar\">\n<h2>Cybersecurity Insight<\/h2>\n<p>To see the recorded AAPA webinar, How to Navigate Operational Technology (OT) Cybersecurity in Port Environments, held in June, visit: <a href=\"https:\/\/bit.ly\/PortCybersecurity\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"color: #3366ff\">https:\/\/bit.ly\/PortCybersecurity<\/span><\/a>.<\/p>\n<\/aside>\n<aside class=\"sidebar longSidebar\">\n<figure class=\"picture\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/017.jpg\" alt=\"best practices for combating cyber threats\" \/><figcaption><span class=\"attribution\">VS148\/<a href=\"http:\/\/SHUTTERSTOCK.COM\">SHUTTERSTOCK.COM<\/a><\/span><\/figcaption><\/figure>\n<h2>9 BEST PRACTICES FOR COMBATING CYBER THREATS<\/h2>\n<p>A cyberattack can come from just about anywhere, but Jason Atwell, senior manager of Mandiant Threat Intelligence, part of the cybersecurity firm FireEye, said threats typically come from the big four: Russia, China, North Korea and Iran.<\/p>\n<p>Those nations have a variety of geopolitical and monetary motivations for striking out at the United States and its allies, and ports are attractive targets because of the vital role they play in the nation\u2019s security and economy, Atwell said.<\/p>\n<figure class=\"graphic\"><img decoding=\"async\" src=\"https:\/\/aapw01.wpengine.com\/wp-content\/uploads\/sites\/8\/2021\/09\/017-01.png\" alt=\"jason atwell\" \/><figcaption><em>Jason Atwell, FireEye<\/em><\/figcaption><\/figure>\n<p>&#8220;If I\u2019m a bad actor who wants to cause chaos and inflict pain on one of my economic or geopolitical competitors, ports are an obvious choice for malicious activity,&#8221; he said. &#8220;A cyberattack on a port is something that\u2019s easily within the grasp of these major threat actors.&#8221;<\/p>\n<p>At the AAPA Port Security Seminar and Expo in New York City this past July, Atwell outlined nine best practices for bolstering ports\u2019 cybersecurity:<\/p>\n<ol>\n<li>Perform vessel and port security audits, identifying asset and patch management practices, main attack vectors and security controls for handling vulnerable legacy equipment.<\/li>\n<li>Implement strict segmentation where possible, aiming to keep information-technology systems separated from operational-technology systems, to protect critical systems from remote threats.<\/li>\n<li>Protect satellite communication systems by changing default passwords, implementing regular updates and limiting exposure to the Internet.<\/li>\n<li>Implement mechanisms for redundancy of navigational systems in case of disruption. Train employees to analyze anomalies without relying entirely on single human-machine interfaces, or HMIs.<\/li>\n<li>Implement strict policies for restricting the use of removable media, lock ports and have dedicated USB keys if required for updates.<\/li>\n<li>Monitor and log communications where manual updates of systems are performed; at a minimum, use an alternative antivirus software program to scan an update prior to implementation.<\/li>\n<li>Strengthen Wi-Fi networks with encryption and strong authentication, ensure personal Wi-Fi is appropriately segmented.<\/li>\n<li>Provide regular role-based security-awareness training for all employees.<\/li>\n<li>Work with third-party providers to receive updates about vulnerabilities in their products and to comply with security requirements.<\/li>\n<\/ol>\n<p>&#8220;If we\u2019re going to defend against, or at least mitigate, the impacts of future cyberattacks against ports and their corollary critical infrastructure, our adversaries have provided us with a preview we can use to prioritize our efforts,&#8221; Atwell said. &#8220;Recent threats like ransomware have had a silver lining in that they have shown us where our vulnerabilities are and what malicious actors are capable of, so we can now act accordingly to address these issues in a proactive way.&#8221;<\/p>\n<\/aside>\n<p>The Cyber Resilience Center will automate the process of sharing cyber-threat information throughout the port community, giving stakeholders that choose to participate more-detailed, accurate and timely information, according to Lance Kaneshiro, the port\u2019s chief information officer.<\/p>\n<p>&#8220;The Cyber Resilience Center will reduce the risk of a disruption to the flow of cargo by allowing us to work with our stakeholders to share cyber-threat information and to be available as a resource to help to restore individual operations if appropriate,&#8221; Kaneshiro said. &#8220;We needed to look beyond our individual systems for cybersecurity and look at it more from the ecosystem and supply-chain perspective by collaborating with our stakeholders.&#8221;<\/p>\n<aside class=\"sidebar shortSidebar\"><\/aside>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ports are shoring up against ransomware and cyberattacks, as the increasing frequency and sophistication of attacks represent a top security concern and the threats are constantly evolving.<\/p>\n","protected":false},"author":30,"featured_media":2928,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[435,4,446],"tags":[89,904,616,629,117,898,86,902,894,900,901,791,477,896,903,905,170,38,268,53,87,899,158,895,897,873,711],"class_list":["post-2926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-current-features","category-features","category-technology","tag-aapa","tag-aapa-port-security-seminar","tag-aapa-seaports","tag-accelerate-apprenticeship","tag-barbara-murray","tag-cyber-security-operations-center","tag-cybersecurity","tag-fireeye","tag-harbor-police","tag-interagency-operations-center","tag-jason-atwell","tag-kristine-a-zortman","tag-kristine-zortman","tag-lance-kaneshiro","tag-mandiant-threat-intelligence","tag-port-cybersecurity","tag-port-of-beaumont","tag-port-of-los-angeles","tag-port-of-redwood-city","tag-port-of-san-diego","tag-ports","tag-randal-ogrydziak","tag-seaports","tag-thomas-e-gazsi","tag-thomas-gazsi","tag-tracey-sandberg","tag-western-hemisphere-ports"],"_links":{"self":[{"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/posts\/2926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/comments?post=2926"}],"version-history":[{"count":0,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/posts\/2926\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/media\/2928"}],"wp:attachment":[{"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/media?parent=2926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/categories?post=2926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aapaseaports.com\/index.php\/wp-json\/wp\/v2\/tags?post=2926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}