A Colonial Pipeline facility in Baltimore, Maryland. A cyberattack forced the shutdown of 5,500 miles of Colonial Pipeline's sprawling interstate system, which carries gasoline and jet fuel from Texas to New York. The FBI confirmed that DarkSide ransomware is responsible for the attack that compromised the Atlanta-based pipeline company. EPA
A Colonial Pipeline facility in Baltimore, Maryland. A cyberattack forced the shutdown of 5,500 miles of Colonial Pipeline's sprawling interstate system, which carries gasoline and jet fuel from Texas to New York. The FBI confirmed that DarkSide ransomware is responsible for the attack that compromised the Atlanta-based pipeline company. EPA
A Colonial Pipeline facility in Baltimore, Maryland. A cyberattack forced the shutdown of 5,500 miles of Colonial Pipeline's sprawling interstate system, which carries gasoline and jet fuel from Texas to New York. The FBI confirmed that DarkSide ransomware is responsible for the attack that compromised the Atlanta-based pipeline company. EPA
A Colonial Pipeline facility in Baltimore, Maryland. A cyberattack forced the shutdown of 5,500 miles of Colonial Pipeline's sprawling interstate system, which carries gasoline and jet fuel from Texas

Why is the energy industry prone to cyber attacks?


  • English
  • Arabic

The attack on a critical US artery for the transport of fuel has once again exposed the vulnerabilities of the energy industry to cyber attacks. The ransomware attack on the 2.5 million barrels per day Colonial Pipeline endangered access to fuel for the US East Coast. The pipeline, which was built in the 1960s, snakes across a distance of 8,850 kilometres and carries products sufficient to meet the total consumption of Germany, Europe’s largest economy and the world’s fourth-biggest.

So what makes the energy industry a target for attacks and why is it vulnerable?

Any impact on the energy sector can affect entire communities and even countries. An attack on a power plant or a pipeline can cause widespread blackouts, impact transportation, heating, and the functioning of critical activities in the economy.

The vulnerability in the energy industry originates from the use of legacy industrial control systems, particularly if these have not been upgraded for a number of years and are not fully integrated across systems, according to Mohammed AlMohtadi, chief information security officer at Abu Dhabi’s Injazat.

“These legacy systems therefore not only represent risk factors for energy organisations but can also have a widespread economic impact,” he said.

So how do large energy and utility companies become prey to attacks?

Threat actors usually attempt to steal trade secrets, confidential data and intellectual property, through ransomware attacks.

“While we anticipate breaches to be very sophisticated, in most cases they occur through simple phishing emails and other social engineering activities,” added Mr AlMohtadi.

A ransomware attack, such as the one on the Colonial Pipeline, involves hackers infecting networks with malicious software that encrypts data and leaves machines locked until the victims pay an extortion fee.

On Monday, DarkSide, the group behind the attack, said its aim was to "make money" but not create problems for society. In many cases, the attacks cost the economy much more than the ransom amount demanded.

In many cases, where a cybercriminal intends to inflict political and physical damage to a country or cause financial or reputational harm, the energy sector often becomes a prime target.

“[The] energy industry comes under critical infrastructure … if it is breached, the nation's financial and physical infrastructure could be potentially crippled,” said Avinash Advani, founder and chief executive of Dubai-based cybersecurity company CyberKnight.

Oil and gas infrastructure, nuclear plants, electricity grids, water companies and utility firms that supply the community with power, water, and treat sewage are potential targets.

The Covid-19 pandemic has exposed the energy industry's underbelly. As more people work from home to contain the spread of coronavirus, they unwittingly expose an organisation to cyber attacks.

“Employees at energy organisations are working from home and remotely accessing corporate assets … [they] become a critical attack vector and entry point for attackers,” said Mr Advani.

Researchers have found many coronavirus-related malicious e-mail campaigns and hundreds of downloadable files that attempt to infect user devices. Malicious files have been masked under the guise of pdf, mp4 and docx files. The names of files imply that they contain instructions on how to protect yourself from the virus or updates on the threat.

So how did the Colonial Pipeline become victim to a cyberattack?

“We assume the Colonial Pipeline, the biggest US pipeline system connecting oil supplies in Texas with New York, has been attacked through an insecure remote access,” Stefan Schachinger, network security product manager at computer security company Barracuda, said.

“Remote accesses are not insecure per definition but require proper security measures such as encryption and multi-factor authentication,” he added.

DarkSide, the ransomware group that claimed the Colonial Pipeline attack is new but experienced, industry experts said.

The group targets largely English-speaking countries and avoids the economies of former Soviet states, said Boston-based cyber security firm Cybereason. Its ransom demand typically ranges from $200,000 to $2 million. The group has published stolen data from more than 40 victims, who are believed to be just a fraction of the overall number.

Cyber attacks on energy infrastructure are typically politically or financially motivated.

“When there is an attack on the West, it usually originates from [entities inside] Russia or Eastern European countries with ties to Russia, Iran, China, or North Korea,” said Mr Advani.

However, there can be financially motivated criminal groups that may or may not be associated with a government.

President Joe Biden has said there is no evidence that the Russian government is responsible for the attack on the Colonial Pipeline, but that the country has "some responsibility" to address the ransomware attack and that he will seek global co-operation to battle similar hacks.

US Energy Secretary Jennifer Granholm told Bloomberg TV that supply in the country has so far not been impacted and that the company has said it hopes to restore operations by the end of this week.

“It tells you how utterly vulnerable we are,” Ms Granholm said. “We’re seeing all of these examples of ransomware attacks coming - whether it’s telecommunications or this critical infrastructure. And obviously in my lane I’m very worried about the energy infrastructure.”

She said the incident clearly highlighted the need of private sector companies to step up their investment in cyber defence.

Globally, around 61 per cent of companies surveyed by London-based Mimecast said they were affected by a ransomware attack last year. About 52 per cent of them paid the ransom but of those, only two-thirds recovered their data.

Given the serious implications of cyber attacks, the energy industry should not underestimate groups that target facilities. Many of these groups now have help desks, technical support, payroll processing, and subcontractors, according to Marty Edwards, vice president of operational technology security at Maryland-based cyber-security company Tenable.

“They are essentially full-fledged criminal corporations operating in the digital world.”

"If reports are accurate, the Colonial Pipeline incident has all of the markings of a possible ransomware attack that began in the IT environment and, out of precaution, forced the operator to shut down operations,” added Mr Edwards.

In 2012, the Shamoon virus attack on Saudi Aramco systems wiped the hard drives of some 30,000 computers clean.

The attacks were blamed on Iran, which denied responsibility.

In 2017, a $20 billion petrochemical project joint venture between Saudi Aramco and Dow Chemicals also experienced a spate of hacking attacks.

The financial fallout from cyber attacks in the Arabian Gulf in 2017 was estimated at more than $1bn, according to a 2018 report by Siemens. Three-quarters of regional oil and gas companies, or over 30 per cent of the global production of oil, have experienced some form of cyber-security breach in the past, according to DarkMatter, a UAE-based cyber security company.

The financial fallout from data breaches among a selected sample of companies in the UAE and Saudi Arabia rose 9.4 per cent, costing them $6.53m per breach, according to a 2020 study by IBM Security.

In 2017, Saudi Arabia, Opec's biggest producer, established the National Cybersecurity Authority (NCA) to combat cyber threats.

The UAE rolled out its first National Cybersecurity Strategy in 2019, followed by the formation of National Cybersecurity Council to develop policies and laws to strengthen cyber security and ensure the country is not vulnerable to attacks.

In December, Dubai Electronic Security Centre rolled out a cyber resilience plan that aims to safeguard the emirate's critical infrastructure including oil and gas sector. In June, Injazat opened a Cyber Fusion Centre in Abu Dhabi, expanding its cyber defence abilities and portfolio of services.

In the Middle East, companies such as Saudi Aramco, the world's largest exporter of oil, are enforcing stricter compliance on third-party vendors to ensure their facilities are protected against cyber attacks, that could impact the supply of oil globally.

Suppliers including general vendors and those specialising in outsourced infrastructure, customised software, network connectivity, and critical data processors need to obtain Saudi Aramco's cyber security standard certification.

.
.
The%20Super%20Mario%20Bros%20Movie
%3Cp%3E%3Cstrong%3EDirectors%3A%3C%2Fstrong%3E%20Aaron%20Horvath%20and%20Michael%20Jelenic%0D%3Cbr%3E%3Cstrong%3EStars%3A%3C%2Fstrong%3E%20Chris%20Pratt%2C%20Anya%20Taylor-Joy%2C%20Charlie%20Day%2C%20Jack%20Black%2C%20Seth%20Rogen%20and%20Keegan-Michael%20Key%0D%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%201%2F5%3C%2Fp%3E%0A
Key facilities
  • Olympic-size swimming pool with a split bulkhead for multi-use configurations, including water polo and 50m/25m training lanes
  • Premier League-standard football pitch
  • 400m Olympic running track
  • NBA-spec basketball court with auditorium
  • 600-seat auditorium
  • Spaces for historical and cultural exploration
  • An elevated football field that doubles as a helipad
  • Specialist robotics and science laboratories
  • AR and VR-enabled learning centres
  • Disruption Lab and Research Centre for developing entrepreneurial skills
Specs

Engine: 51.5kW electric motor

Range: 400km

Power: 134bhp

Torque: 175Nm

Price: From Dh98,800

Available: Now

BMW M5 specs

Engine: 4.4-litre twin-turbo V-8 petrol enging with additional electric motor

Power: 727hp

Torque: 1,000Nm

Transmission: 8-speed auto

Fuel consumption: 10.6L/100km

On sale: Now

Price: From Dh650,000

Bundesliga fixtures

Saturday, May 16 (kick-offs UAE time)

Borussia Dortmund v Schalke (4.30pm) 

RB Leipzig v Freiburg (4.30pm) 

Hoffenheim v Hertha Berlin (4.30pm) 

Fortuna Dusseldorf v Paderborn  (4.30pm) 

Augsburg v Wolfsburg (4.30pm) 

Eintracht Frankfurt v Borussia Monchengladbach (7.30pm)

Sunday, May 17

Cologne v Mainz (4.30pm),

Union Berlin v Bayern Munich (7pm)

Monday, May 18

Werder Bremen v Bayer Leverkusen (9.30pm)

NO OTHER LAND

Director: Basel Adra, Yuval Abraham, Rachel Szor, Hamdan Ballal

Stars: Basel Adra, Yuval Abraham

Rating: 3.5/5

MATCH INFO

Manchester United 6 (McTominay 2', 3'; Fernandes 20', 70' pen; Lindelof 37'; James 65')

Leeds United 2 (Cooper 41'; Dallas 73')

Man of the match: Scott McTominay (Manchester United)

'Moonshot'

Director: Chris Winterbauer

Stars: Lana Condor and Cole Sprouse 

Rating: 3/5

How to apply for a drone permit
  • Individuals must register on UAE Drone app or website using their UAE Pass
  • Add all their personal details, including name, nationality, passport number, Emiratis ID, email and phone number
  • Upload the training certificate from a centre accredited by the GCAA
  • Submit their request
What are the regulations?
  • Fly it within visual line of sight
  • Never over populated areas
  • Ensure maximum flying height of 400 feet (122 metres) above ground level is not crossed
  • Users must avoid flying over restricted areas listed on the UAE Drone app
  • Only fly the drone during the day, and never at night
  • Should have a live feed of the drone flight
  • Drones must weigh 5 kg or less
The%20specs
%3Cp%3E%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3ESingle%20front-axle%20electric%20motor%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E218hp%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E330Nm%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESingle-speed%20automatic%3Cbr%3E%3Cstrong%3EMax%20touring%20range%3A%20%3C%2Fstrong%3E402km%20(claimed)%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3EFrom%20Dh215%2C000%20(estimate)%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3ESeptember%3C%2Fp%3E%0A
Avengers: Endgame

Directors: Anthony Russo, Joe Russo

Starring: Robert Downey Jr, Chris Evans, Scarlett Johansson, Chris Hemsworth, Josh Brolin

4/5 stars 

The specs

Engine: 2.0-litre 4-cylinder turbo hybrid

Transmission: eight-speed automatic

Power: 390bhp

Torque: 400Nm

Price: Dh340,000 ($92,579

Tearful appearance

Chancellor Rachel Reeves set markets on edge as she appeared visibly distraught in parliament on Wednesday. 

Legislative setbacks for the government have blown a new hole in the budgetary calculations at a time when the deficit is stubbornly large and the economy is struggling to grow. 

She appeared with Keir Starmer on Thursday and the pair embraced, but he had failed to give her his backing as she cried a day earlier.

A spokesman said her upset demeanour was due to a personal matter.

Bharatanatyam

A ancient classical dance from the southern Indian state of Tamil Nadu. Intricate footwork and expressions are used to denote spiritual stories and ideas.

The biog

Favourite films: Casablanca and Lawrence of Arabia

Favourite books: Start with Why by Simon Sinek and Good to be Great by Jim Collins

Favourite dish: Grilled fish

Inspiration: Sheikh Zayed's visionary leadership taught me to embrace new challenges.

The specs

Engine: 3.9-litre twin-turbo V8
Power: 620hp from 5,750-7,500rpm
Torque: 760Nm from 3,000-5,750rpm
Transmission: Eight-speed dual-clutch auto
On sale: Now
Price: From Dh1.05 million ($286,000)

Global Fungi Facts

• Scientists estimate there could be as many as 3 million fungal species globally
• Only about 160,000 have been officially described leaving around 90% undiscovered
• Fungi account for roughly 90% of Earth's unknown biodiversity
• Forest fungi help tackle climate change, absorbing up to 36% of global fossil fuel emissions annually and storing around 5 billion tonnes of carbon in the planet's topsoil

The specs

Engine: four-litre V6 and 3.5-litre V6 twin-turbo

Transmission: six-speed and 10-speed

Power: 271 and 409 horsepower

Torque: 385 and 650Nm

Price: from Dh229,900 to Dh355,000

What are the influencer academy modules?
  1. Mastery of audio-visual content creation. 
  2. Cinematography, shots and movement.
  3. All aspects of post-production.
  4. Emerging technologies and VFX with AI and CGI.
  5. Understanding of marketing objectives and audience engagement.
  6. Tourism industry knowledge.
  7. Professional ethics.
RESULT

Deportivo La Coruna 2 Barcelona 4
Deportivo:
Perez (39'), Colak (63')
Barcelona: Coutinho (6'), Messi (37', 81', 84')

UAE SQUAD

Khalid Essa, Ali Khaseif, Fahad Al Dhanhani, Adel Al Hosani, Bandar Al Ahbabi, Mohammad Barghash, Salem Rashid, Khalifa Al Hammadi, Shaheen Abdulrahman, Hassan Al Mahrami, Walid Abbas, Mahmoud Khamis, Yousef Jaber, Majed Sorour, Majed Hassan, Ali Salmeen, Abdullah Ramadan, Abdullah Al Naqbi, Khalil Al Hammadi, Fabio De Lima, Khalfan Mubarak, Tahnoon Al Zaabi, Ali Saleh, Caio Canedo, Ali Mabkhout, Sebastian Tagliabue, Zayed Al Ameri