Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
11/8/2019
03:15 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Fortress Launches Collaboration to Help Protect the Power Grid from Cyber Threats

Fortress Information Security launches the Asset to Vendor Network (A2V), a new platform where electric energy companies can collectively help reduce the costs of protecting the U.S. power grid from cyber threats.

ORLANDO, Fla., Nov. 8, 2019 /PRNewswire/ -- Fortress Information Security
(Fortress) today announced the launch of the Asset to Vendor Network for Power
Utilities (A2V), a joint venture with American Electric Power (NYSE: AEP). A2V
is designed to address concerns about protecting the U.S. power grid from cyber
threats by promoting collaboration among electric companies. A2V will help
reduce the costs associated with cybersecurity regulatory compliance in an
effort to cope with budgetary limitations.

"Building the A2V Network is consistent with Fortress' mission to secure
critical infrastructure," according to Alex Santos, the CEO of Fortress. "Our
team is looking forward to working with AEP and other electric energy companies
in taking this next step to secure the North American grid."

Power utilities share many of the same supply chain vendors for equipment,
software and services for their Bulk Electric Systems (BES), an industry trait
that has been identified by malicious actors and is resulting in an increasing
number of attacks on the power grid.

To address emerging supply chain risks to the power grid, the Federal Energy
Regulatory Commission (FERC) has issued new rules that require utilities to
develop a plan for managing cyber risk related to their supply chain. The plan
includes procedures for prioritizing vendors based on risk and requirements for
completing standardized risk assessments on each vendor, as well as verifying
the authenticity of software manufacturers and the integrity of software
updates.

The deadline for completion of the plan is currently June 2020. Utilities that
fail to meet this deadline can face various levels of penalties, ranging as high
as $1,000,000 per day.

The volume of supply chain vendors providing equipment, software, and services
to power utilities makes the completion of this goal challenging and costly for
individual companies, and ultimately their customers, as well as potentially
burdensome for the vendors.

Fortress is launching A2V to share technology and information to support
security efforts for these vendors. The technology and data basis for A2V were
developed in collaboration with AEP and include a substantial library of
completed vendor risk assessments that comply with the new regulations.
Fortress, an experienced partner with a proven track record in cybersecurity,
will operate the A2V platform.

Power companies who join A2V will be able to purchase vendor assessments for
much less than it would cost for them to conduct the assessment themselves.
Participating utilities also will be able to contribute their own completed
assessments for purchase by the network and receive a portion of the proceeds.
This will help them recover some of their investments in vendor assessments and
help reduce overall operating and maintenance (O&M) costs associated with cyber
security compliance.

Stephen Swick, Director of Cybersecurity Intelligence and Defense for AEP, said,
"Power utilities need to work together to accomplish our shared goal of a secure
power grid. A2V offers the opportunity for companies to collaborate and help
mitigate the significant costs of protecting the grid."

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Browsers to Enforce Shorter Certificate Life Spans: What Businesses Should Know
Kelly Sheridan, Staff Editor, Dark Reading,  7/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17366
PUBLISHED: 2020-08-05
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate...
CVE-2020-9036
PUBLISHED: 2020-08-05
Jeedom through 4.0.38 allows XSS.
CVE-2020-15127
PUBLISHED: 2020-08-05
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flip...
CVE-2020-15132
PUBLISHED: 2020-08-05
In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th...
CVE-2020-7298
PUBLISHED: 2020-08-05
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.