apu cybersecurity briefing

15
Cybersecurity Update Public Utilities Board October 27, 2021 1

Upload: others

Post on 20-Apr-2022

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: APU Cybersecurity Briefing

Cybersecurity Update

Public Utilities BoardOctober 27, 2021

1

Page 2: APU Cybersecurity Briefing

Yesterday

2

Page 3: APU Cybersecurity Briefing

Today

3

Field Staff

Data Center

Electric

Water

Telecommuters

Cloud ServicesData

DataData

Business Partners

Data DataData

Page 4: APU Cybersecurity Briefing

Threats

● Organized Crime Groups● Nation States● Black Hat ● Hactivists● Insiders Gone Rogue

4

● Malware● Ransomware● Data Theft● Denial of Service ● Phishing

Types of Attacks Bad Actors

Page 5: APU Cybersecurity Briefing

Cyber Attacks

5

Data BreachesRansomware

Energy / Water Breaches

Colonial Pipeline – Ransomware, Fuel pipeline shutdown

Oldsmar Water – Increased sodium hydroxide to dangerous levels

Supply Chain Hack

Police Dept.

Page 6: APU Cybersecurity Briefing

Protecting APU & Customer Data

● Risk Management● Defense In Depth - Layering● Least Privilege● Privacy● Zero Trust

6

Guiding Principles

Page 7: APU Cybersecurity Briefing

NIST Cybersecurity Framework

7

800-53

National Institute of Standards & Technology

Page 8: APU Cybersecurity Briefing

Billing / Customer

InfoMeter Data Work &

Asset Mgt

All other City Department

Systems

CustomersCloud

Services

Business Partners

City Network Environment

8

Remote City Employees

Page 9: APU Cybersecurity Briefing

How We Protect APU & Data

● Physical Security◌ Badges, Doors, Locks,◌ Guards, Cameras

● Firewalls ● Email Filtering● Website Filtering

9

● User Access Controls● Network Permissions● End-point Security● Encryption● Operating System Patching● Vulnerability Scanning

Technical Controls

Page 10: APU Cybersecurity Briefing

How We Protect APU & Data

● Policies & Procedures◌ Technology Use◌ Passwords ◌ Customer Data Access◌ Third-Party Agreements / NDAs◌ Change Management

● Cybersecurity Plan● Security Assessments

10

● Awareness and Training● Cyber Liability Insurance● Industry Information Sharing

Administrative Controls

Page 11: APU Cybersecurity Briefing

Recent Improvements

● 24/7 Security Operations Center (SOC)● Security Information & Event Management (SIEM)● Next Generation Firewalls● Malicious Domain Blocking● Email Link Protection / External Alert● Remote Access Control● Laptop Hard Drive Encryption● Water Reclamation Facility SCADA Network● New Backup Solution with Immutable Storage

11

Page 12: APU Cybersecurity Briefing

Current Initiatives

● System Upgrades (Middleware, Meter Data Management, …)● IVR Payment Processing (migrate to Cloud)● Cybersecurity Incident Response Plan Update● Water Network and Camera Upgrade● Social Engineering (Phishing) Assessment

12

Page 13: APU Cybersecurity Briefing

The Future

● Continuous and Incremental Improvements● System Upgrades

◌ Customer Information / Web Portal◌ Work and Asset Management◌ Advanced Meter Infrastructure, …

● Zero Trust Architecture● Multi-Factor Authentication● City WiFi Improvements● Selective Cloud Services

13

Page 14: APU Cybersecurity Briefing

Cloud Security Responsibility

14

XaaS <X> “as a Service”• IaaS = Infrastructure• PaaS = Platform• SaaS = Software

Data

Application/Database

Operating System

Servers, Virtualization

Compute, Network, Storage

Physical Facility

Middleware

Anah

eim

On Premises IaaS PaaS SaaS

Clou

d Pr

ovid

erAn

ahei

m

Clou

d Pr

ovid

erAn

ahei

m

Clou

d Pr

ovid

erA

Types of Cloud Services

Page 15: APU Cybersecurity Briefing

Security is a Journey, not a Destination

Thank you

15