Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

21–30 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#22

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

That sort of scenario preparation takes a lot of time for planning and design to support work-arounds. If the business thinks this is low risk, they won't invest, no matter how significant the scenario could be.

Businesses train and prepare for scenarios that make money, not scenarios that may lose money. I used to do a lot of work related to safety across industries and I can assure you, every business I worked with was only interested in the bare minimum of legally required safety. It was rare to see a business interested in investing resources into things like safety or security vs something that might directly increase their revenue streams.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#26

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

IT/Security/Software is all secondary for a pipeline operator, who's main business is to move liquids from A to B over a set of fixed pipes put in place decades ago.

Without some forcing function to have cybersecurity threats taken seriously, industrials are unlikely to suddenly develop tier-1 security protocols.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#28

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

This is predicated on computer systems outside of the tech industry not being held together with zipties and prayers.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#30

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

With tons of companies paying insane software engineering salaries, I doubt that a pipeline operator that probably doesn't invest much in IT at all is attracting the best talent either.
Post reply on HN