Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
11/8/2019
03:15 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Fortress Launches Collaboration to Help Protect the Power Grid from Cyber Threats

Fortress Information Security launches the Asset to Vendor Network (A2V), a new platform where electric energy companies can collectively help reduce the costs of protecting the U.S. power grid from cyber threats.

ORLANDO, Fla., Nov. 8, 2019 /PRNewswire/ -- Fortress Information Security
(Fortress) today announced the launch of the Asset to Vendor Network for Power
Utilities (A2V), a joint venture with American Electric Power (NYSE: AEP). A2V
is designed to address concerns about protecting the U.S. power grid from cyber
threats by promoting collaboration among electric companies. A2V will help
reduce the costs associated with cybersecurity regulatory compliance in an
effort to cope with budgetary limitations.

"Building the A2V Network is consistent with Fortress' mission to secure
critical infrastructure," according to Alex Santos, the CEO of Fortress. "Our
team is looking forward to working with AEP and other electric energy companies
in taking this next step to secure the North American grid."

Power utilities share many of the same supply chain vendors for equipment,
software and services for their Bulk Electric Systems (BES), an industry trait
that has been identified by malicious actors and is resulting in an increasing
number of attacks on the power grid.

To address emerging supply chain risks to the power grid, the Federal Energy
Regulatory Commission (FERC) has issued new rules that require utilities to
develop a plan for managing cyber risk related to their supply chain. The plan
includes procedures for prioritizing vendors based on risk and requirements for
completing standardized risk assessments on each vendor, as well as verifying
the authenticity of software manufacturers and the integrity of software
updates.

The deadline for completion of the plan is currently June 2020. Utilities that
fail to meet this deadline can face various levels of penalties, ranging as high
as $1,000,000 per day.

The volume of supply chain vendors providing equipment, software, and services
to power utilities makes the completion of this goal challenging and costly for
individual companies, and ultimately their customers, as well as potentially
burdensome for the vendors.

Fortress is launching A2V to share technology and information to support
security efforts for these vendors. The technology and data basis for A2V were
developed in collaboration with AEP and include a substantial library of
completed vendor risk assessments that comply with the new regulations.
Fortress, an experienced partner with a proven track record in cybersecurity,
will operate the A2V platform.

Power companies who join A2V will be able to purchase vendor assessments for
much less than it would cost for them to conduct the assessment themselves.
Participating utilities also will be able to contribute their own completed
assessments for purchase by the network and receive a portion of the proceeds.
This will help them recover some of their investments in vendor assessments and
help reduce overall operating and maintenance (O&M) costs associated with cyber
security compliance.

Stephen Swick, Director of Cybersecurity Intelligence and Defense for AEP, said,
"Power utilities need to work together to accomplish our shared goal of a secure
power grid. A2V offers the opportunity for companies to collaborate and help
mitigate the significant costs of protecting the grid."

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/3/2020
Data Loss Spikes Under COVID-19 Lockdowns
Seth Rosenblatt, Contributing Writer,  5/28/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-10548
PUBLISHED: 2020-06-04
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CVE-2020-10549
PUBLISHED: 2020-06-04
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CVE-2020-10546
PUBLISHED: 2020-06-04
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CVE-2020-10547
PUBLISHED: 2020-06-04
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
CVE-2020-11094
PUBLISHED: 2020-06-04
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is ever enabled on a system that is open to untrusted users as ...