Learning from Ukraine’s power grid malware
What lessons can we learn from the recent malware attack on Ukraine’s power grid? And what impact will governments, banks and insurers’ increasing focus on cyber risk have on organisations operating critical national infrastructure control systems? On 23 December 2015, Ukrainian media reported a cyber-attack had left half the homes and 1.4 million people in the Ivano-Frankivsk region without electricity. Although services were restored within a few hours, this was largely due to manual intervention rather than by recovering compromised automation systems. Slovakian security firm ESET later reported that the initial incident was not isolated, and that multiple electricity companies had been affected simultaneously. Reuters also reported similar malware was found in Kiev's Boryspil airport, on…