In May 2021, The Colonial Pipeline was hit with a ransomware attack. The real world consequences were seen around the world with queues of cars snaking around petrol stations, panicked people filling plastic bags with fuel, and petrol prices creeping up in real time. The threat group, DarkSide, had orchestrated a massive ransomware attack that led Colonial Pipeline to shut down the pipeline for days in order to mitigate the intrusion. The attack occurred because a VPN only had a password and didn’t have the additional protection of Multi-Factor Authentication (MFA).

Since then, utilities have been consistently targeted as attackers know the devastating impact that downtime will have on the critical services that everyone relies upon. In the past few years alone, multiple American water companies have been attacked by nation state actors. Nearly two dozen Danish energy companies were attacked in May 2023 and resulted in several of the power companies shutting off their connection to the internet to limit the damage. Most recently in the UK, Southern Water faced a ransomware attack that cost £45 million.

Alarmingly, a common factor in these breaches has been the use of third party access to gain entry. Attackers are increasingly targeting poorly secured credentials as an identity security blind spot when it comes to third-party access. This leaves organisations exposed to ransomware attacks,  credential theft, lateral movement and supply-chain-driven outages, particularly in OT and hybrid IT/OT environments.

Multi-factor authentication (MFA) must become the foundation of third-party risk management across utilities, and organisations must evaluate the security and privacy practices of third parties before engaging in work. Despite clear guidance from governments and regulators, such as NIST, CISA, and critical infrastructure mandates, MFA adoption remains inconsistent beyond the core workforce, despite a government directive mandating it following the Colonial Pipeline attack.

While implementing MFA is simple, there are some common pitfalls that organisations make when starting out:

Not understanding that MFA can also be used to exploit people: As fast as a security control is developed, attackers are looking for ways to circumvent it. Attackers can exploit human fragilities   by conducting “MFA bombing” campaigns, whereby they bombard targets’ devices with MFA notifications, hoping that the sheer annoyance will cause the victim to accept one. To counteract this, national security agencies recommend phishing-resistant MFA  that uses cryptography to stop attackers from stealing or intercepting login credentials.. Instead, authentication happens automatically and cryptographically between the user’s device and the legitimate service, so attackers can’t overwhelm users with prompts or trick them into tapping “approve.”

Not including third parties: third party access has been a major attack vector, with attackers targeting your suppliers as a weak link into your organisation. Ensure your vendors must align to the same MFA controls like your internal staff do in order to access your networks or digital assets. Make it a requirement of your contract that your supplier complies with best practice guidance on MFA. In the UK the National Cyber Security Centre (NCSC) has mandated MFA as part of the Cyber Essential Program. Internationally, CISA and others recently released a joint advisory, outlining key actions for organisations to take. Aligning closely with established best practices, it includes strong password hygiene and educating and training users to recognise suspicious MFA activity and the risks associated with approving suspicious login requests.

Not considering the user experience: Humans are on the front line of security and attackers know how to exploit human weakness to secure access. It’s therefore crucial that organisations bring their people along with them and provide the training and tools they need to keep themselves safe. If you include security controls like MFA that are simple and easy to use, staff and users are more likely to make security-conscious choices.

Organisations can simplify things for their staff and security teams by implementing the principle of least privilege, which assigns conditional access policies to users to ensure that they only get the access they are configured to. Another additional protection is to leverage anomaly detection to identify anomalous logins by looking at metrics such as location, device authenticating, and time of day to determine if the auth request is normal or abnormal. If abnormal, you can block the request and notify administrators of anomalous logins.

Over 80% of breaches involve stolen or weak passwords, these could easily be prevented with the additional protection of MFA. Utilities in particular can no longer treat MFA as optional. For these organisations, the consequences extend far beyond data loss and regulatory fallout, with threats to operational disruption, system downtime and increased safety risks. Don’t let your suppliers be a weak link, encourage and expect your vendors to use robust MFA solutions, so it becomes part of a wider security awareness strategy.

Author: Michael Downs, VP at SecurEnvoy

Michael Downs

For more news: https://essmag.co.uk/category/news/