In the latest episode of the 'OT Security Made Simple podcast' , Klaus Mochalski, founder and CEO of Rhebo, sits down with Todd Wiedman, Chief Security Officer of Landis+Gyr, to cover a range of topics, shedding light on the evolving challenges and solutions within the realm of AMI security.
The IEC 62443 family of standards is an old acquaintance to most security managers for industrial systems. For more than ten years, it has been considered THE standard for industrial cybersecurity. It also serves as a "horizontal standard" offering a sector-agnostic baseline for industrial cybersecurity, upon which sector-specific requirements, e.g. for the energy sector, could be added by industry experts. In this blog we explore its implications for the energy sector.
The utility industry is facing new and evolving security threats in the modern era of operational technology (OT) and information technology (IT) convergence. Geopolitical turmoil and changes in the workforce have further complicated the security landscape for utilities. As a result, it is becoming increasingly important to secure advanced metering infrastructure (AMI) systems.
Ransomware attacks are the number one cyber risk for utilities and critical infrastructure worldwide. Detecting malicious activities during the preparation phase of an attack to prevent disruption and spreading is at the heart of any cybersecurity strategy.
In its working paper "Critical Vulnerability in Log4j - Detection and Response", the German Federal Office for Information Security (BSI) underlines the persistent and complex danger of the Log4Shell vulnerability in industrial networks as well. Patching the vulnerability in the short to medium term is considered unrealistic for many companies. For this reason, the BSI recommends continuous monitoring and analysis of network communication via anomaly detection in addition to rule-based query analysis. Industrial anomaly detection solutions, as offered by Rhebo, a Landis+Gyr Company, enable companies to detect on compromises that have already occurred, active exploits and other malicious activities in the operational technology (OT) and industrial control systems (ICS) at an early stage. The vulnerability, documented as CVE-2021-44228, allows attackers to execute arbitrary code on systems using the widespread Log4j library without authentication.
The digitalization of the energy industry has led to a convergence of operational and informational technologies across metering infrastructures worldwide. This OT/IT convergence brings with it all the benefits of the connected, IoT era such as personal energy management insights, automated energy management and grid transparency. However it has also resulted in increasingly complex OT/IT ecosystems creating with new areas of vulnerability and increasing exposure to attacks.
Posts by Topic
- Smart Metering (72)
- Smart Grid (52)
- Landis+Gyr Product (29)
- Customer Focus (22)
- Grid Edge Intelligence (22)
- Gridstream Solution (21)
- G3 PLC (19)
- IoT Technologies (19)
- Grid Resiliency (16)
- Managed Services (16)
- Grid Digitization (13)
- Software Services (13)
- Electric Vehicles (12)
- Renewable Energy (12)
- AMI Services (11)
- Utility (11)
- Smart Charging (10)
- Smart Meter (10)
- Smart Meter Market (10)
- Consumer Engagement (9)
- Monitoring & Control Solution (9)
- Power Line Communication (PLC) (9)
- Smart Metering Solutions (9)
- Communication Technologies (8)
- Distribution System Operator (DSO) (8)
- Heat & Cold Metering (8)
- Internet of Things (8)
- Regulation (8)
- Automated Network Management (7)
- Distribution Intelligence (7)
- Interoperability (7)
- Smart Meter Focus (7)
- Cybersecurity (6)
- Demand Side Management (6)
- Services (6)
- Water Metering (6)
- e360 (6)
- Data Analytics (5)
- Distribution Automation (5)
- E360 Smart Meter (5)
- Energy Storage (5)
- Energy and Capacity Optimization (5)
- Gridstream Converge (5)
- Special News (5)
- pathway 06 (5)
- European Utility Week (4)
- Industrial Metering (4)
- Power Quality (4)
- Renewable Integration (4)
- Smart (4)
- About Landis+Gyr (3)
- Advanced Grid Analytics (3)
- Analytics (3)
- Artificial Intelligence (3)
- Communication Devices (3)
- Dynamic Load Management (3)
- Smart City (3)
- Smart Grid Terminal (3)
- Smart Infrastructure (3)
- AGA (2)
- Big Data (2)
- Cellular (2)
- Distributed Energy Resource (2)
- Events (2)
- ICG (2)
- P2P (2)
- Quality (2)
- Smart Metering Service (2)
- Smart Projects (2)
- Social Responsibility (2)
- Sustainability Report (2)
- sustainability (2)
- Advanced Metering Management (AMM) (1)
- Careers (1)
- Caruna (1)
- Connected Platform (1)
- Customer Interface (1)
- DC250 (1)
- Data Privacy (1)
- E450 (1)
- EUW (1)
- Enlit Europe (1)
- Gridstream GWA (1)
- Gridstream MDMS (1)
- Meter Data Management System (MDMS) (1)
- Micro Grid (1)
- Prepayment Metering (1)
- Resource Management (1)
- SMERTS2 (1)
- Smart Community (1)
- Smart Cooling Solutions (1)
- Standards (1)
- Street Lighting (1)
- Virtual Power Plant (1)
- netzero (1)
Popular Articles
- The E360 is a smart residential meter for the IoT world of today and tomorrow
- E570: Our New Smart Commercial Electricity Meter Explained in Two Minutes
- Get smart: Water meters and communication protocols
- Landis+Gyr Corinth - A 50 year legacy in smart meter manufacturing
- CU-L52: Stay Connected in a Changing World