The Threat of Technological Obsolescence for Cybersecurity in the Energy Sector
摘要
While the general public imagines hackers to be creative intrusion or remote control virtuosos, an analysis of the facts shows that many of the successful attacks targeting critical equipment such as that used by players in the energy sector are made possible by the obsolescence of legacy software and less than perfect update policies. This chapter provides a documented explanation of the reality of exposure to cyber risk for companies in the energy sector, with its particularly long operating times and a supplier ecosystem that has undergone major changes over the past few decades. The increasing interconnection of systems, coupled with the intensification of process automation, has amplified the phenomenon. A situation that has not escaped the attention of the attacker community, which is seeking to exploit these new operational features from all directions. To avoid being subjected to these potentially dangerous circumstances in the future, the industry and public authorities, particularly in the United States and Europe, have introduced new rules to overcome this state of technological failure and reinforce the responsibility of stakeholders. The intention of this is to benefit collective security.