Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Are Cyber Attacks More than Critical Infrastructure Can C.H.E.W.?

By Carl Herberger
September 23, 2014

In August 2013, Former Assistant Defense Secretary for Homeland Defense & Americas’ Security Affairs, Dr. Paul Stockton sat on a panel that discussed cybersecurity challenges facing the electric sector and some of the vulnerabilities in the U.S. electric grid system. He stated that if there was a successful computer network hack that brings down the grid for a significant period of time, critical lifeline infrastructure is going to fail. Failure of infrastructure such as hospital, transportation, food and pharmaceutical distribution could threaten public health and safety.

Given this backdrop, wouldn’t you believe that it would be prudent to ask some very hard questions to understand the preparedness of our power generating industry in order to protect the populace from such a failure? For example – how real is this scenario and what is the trend? If real, what are the mitigation steps and sense of urgency?

From a cyber-attack perspective, this year has been a watershed year for the electric and critical infrastructure industry. After generally resisting the notion of vulnerabilities because of the stated traditional controls of “air gaps” between the internet and power generation equipment and heavy use of “proprietary SCADA IP protocols,” the industry has finally had to acknowledge the increased threats and risks to normal service delivery. This acknowledgement came from an onslaught of recent successful attacks and some new announced plausible attack vectors such as the much reported “Energetic Bear”malware reports. So, what is going on? Is this something of a real concern and if so, or not, what are the takeaways?

To leverage an acronym developed from Richard Clarke, a former Special Advisor of cybersecurity during the Bush administration, the origin of the cyber-attack risks fall into four major categories as follows:

Cybercrime: The notion that someone is going to attack you with the primary motive being financial gain from the endeavor.

Hacktivism: The motive of attacking someone based upon a difference in ideologies. The primary focus of these attacks is not financial but rather to persuade or dissuade certain actions or “voices.”

Espionage: Straight forward motive to gain information on another organization in pursuit of leverage (e.g. political, financial, capitalistic, marketshare, etc.).

War (Cyber): This is the notion of a nation-state or transnational threat trying to tear down the centers-of-power of an adversary via a cyber-attack.  This could be to target non-military targets like critical infrastructure or financial service, or more traditional targets such as the military industrial complex.

Given these motives one can clearly see how an average small rural electric utility may find itself both inundated with attacks from customers who are not lock-step with service fee increases, to hacktivists who don’t condone the methods of power generation, or to foreign intelligence operatives who are attempting to find a weak link in our power grid infrastructure.

The task is clearly daunting and real. Threats such as Stuxnet, Night Dragon, Shamoon, Dragonfly and Energetic Bear have targeted critical infrastructures around the globe over the past few years and represent harbingers for increased concerns.

Although you can assemble a list of threats for nearly any industry today, it may be unbalanced to call out the power generation industry. However, I believe that the power generation industry in particular needs to rise above the normal corporate culture of security controls and become obsessive about removing risks and compulsive about action. After all, these organizations may literally be holding life and death decisions in their hands – and this makes their actions rather profound and very unique.

In the end, I hope we can agree that the klaxon is sounding and actions need to be impactful to avoid catastrophes.

KEYWORDS: cyber attack electric grid security infrastructure cyber security

Share This Story

Carl Herberger is the Vice President of Security Solutions at Radware, a leader in application delivery and security solutions that assures the availability, performance, and resilience of business-critical applications for over 10,000 enterprises and carriers worldwide. A recognized information security expert, Herberger draws on his extensive information security background in both the private and public sectors. He began his career in the U.S. Air Force as a computer warfare specialist at the Pentagon and managed critical operational intelligence programs aiding both the National Security Council and Secretary of the Air Force. Herberger founded Allied InfoSecurity and held executive security positions at BarclayCard US, SunGard and Campbell Soup Co.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Stacked books

Safe Learning 101 Program Supports Schools in Strengthening Campus Security

SEC 2026 Benchmark Banner

Events

May 21, 2026

From Referral to Response: Managing Domestic Violence Threats in the Workplace

Domestic violence remains a complex driver of workplace violence, creating high-risk scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing