Other categories

Group InsureTech Adjusting Marine Technical Services Assistance Investment Management Richards Hogg Lindley Claims Solutions

Cyber is an emerging and fast-moving market where businesses are becoming increasingly aware of their potential liabilities, heightened risk of damage and the potential repercussions both financial and reputational, particularly following high profile incidents.


In this article, Chris Brown, Managing Director, Green Energy interviews Laetitia Fouquet Head of Speciality Lines & Global Head of Cyber, Charles Taylor Adjusting to share her expertise about how cyber-attacks affect the Natural Resources sector and how businesses can manage this evolving risk.

1. Are there many cyber-attacks within the Natural Resources sector and if so, what kind of attacks are most common?

There have been cyber-attacks affecting the industry for some time. Not all are publicised for obvious reasons, but we should not mistake low mediatisation for a paucity of attacks. Where in other industries attacks tend to result in data breaches affecting many consumers, in the Natural Resources sector, the main aim of attackers seems to be more around stopping operations and holding an organisation to ransom or extracting corporate sensitive data or espionage. Below are some examples.

2012

Aramco became the victim of a ransomware attack which affected around 30,000 computers with the aim to disrupt energy production and prevent resource flow to international markets. The malware overwrote data to destroy its reboot capacity but also had the capacity to extract data.

2015

Korea Hydro and Nuclear Power Co were the victims of a series of attacks aimed at causing nuclear reactors to malfunction, but this was not successful although it did lead to a leak of non-classified but personal data.

2016

The Israel Electric Authority suffered a phishing attack after one employee was the victim of a phishing attack which then spread onto the network. The power grid was not affected but it took 2 days to resume normal operations.

2017

NotPetya hit organisations worldwide, including the Russian oil company Rosneft. Initially thought for financial gain, the attack aimed to cause disruption as it used a wiper.

2017

A cyber attack against a Saudi Arabian petrochemical plant, where the intention was to sabotage the firm’s operations and trigger an explosion. Interestingly this did not succeed due to an error in attacker’s computer code that instead shut down the plant’s production systems.

2019

Pemex had reported an attack that affected its computer systems and left the company with little communication systems for weeks.

2020

The U.S. Department of Homeland Security advised a ransomware attack had brought down a U.S. natural gas compressor facility for two days.

2021

More recently, in November 2021, the Australian government-owned energy company CS was hit by a ransomware attack. The hackers had infiltrated its corporate network, but the incident had not impacted the electricity generation or distribution.

2022

The German subsidiary of Rosneft reported an attack.

Subsidiaries of operators or contractors are viewed as a way to access bigger final targets, like in the Ukraine power grid attack where 4 subcontractors involved in the monitoring and distribution supply chain were targeted in spear fishing attacks accessing the main frame of the power grid by seizing Supervisory Control and Data Acquisition (SCADA) controls and remotely switching off substations. Additional attacks included a denial of service on customer call centres stopping communications about the black out.

Similarly, it is easier to fool people into disclosing their system access details than trying to enter by brute force. We see a lot of social engineering at the start of a bigger attack.

2. What are the likely impacts of cyber-attacks?

There is a real potential for property damage especially since the industry is encouraged to have better connectivity between IT and Operational Technology (OT). We could be mistaken for thinking that this only applies to the “back office“ systems, with social engineering leading to payment diversion, or “standard” IT issues where the attack touches emails, orders or the finance systems, however there have been attacks which touched physical assets.

This was the case for the Ukrainian attack when hackers took down almost a quarter of Ukraine’s power grid for 7 hours. The hackers had combined the use of malware to direct utilities’ industrial control computers to disconnect the substations and a wiper virus that made the computers inoperable.

Generally, when production is stopped the financial consequences will include repairs with some element of uninsured improvements to security and removing obsolete systems, migrating some systems to the Cloud and loss of revenue and/or reputational harm.

An attack on IT which leads to an attack on OT may have serious repercussions by inflicting property damage, stopping production and revenue loss, but also through the threat of pollution either by causing the release of material impacting the environment or not detecting a pollution event. The industry uses SCADA, Distributed Control Systems (DCSs) and Programmable Logic Controllers (PLCs) and relies on a supply chain that can be vulnerable to cyber-attack. Increased security measures are needed as plant Industrial Control Systems (ICSs) become more integrated with other potentially vulnerable (usually older and no longer supported) corporate IT systems.

In 2020, a crack in the Colonial Pipeline leaked at least 1.2 million gallons of gasoline into a small nature preserve on the edge of the Charlotte, TX, suburbs. Whilst the leak was not caused by a cyber-attack, the pipeline leaked for weeks without being detected.

Following the 2017 attacks on Ukraine, systems used to monitor the area around the Chernobyl power station - following the disaster in 1986 – were rendered inaccessible leading to a decision to revert to manual monitoring. Consequently, the plant monitoring systems are now operated by the International Atomic Energy Agency (IAEA).

Cyber-attacks can also have severe financial implication, through preventing visibility across deliveries, order communications and invoicing facilities, which may then create a breach of contractual obligations and penalties, as well as reputational harm. We should also consider that access to corporate information can lead to further attacks, be leveraged in a secondary extorsion, or sold on the dark web.

3. Why is the Natural Resources sector at risk and what are some of the migration strategies?

Because of increased connectivity, complex supply chains and the need to subcontract some of these services there may be a mix of old and new systems and access given to outsiders which increase the risk of an attack.

A holistic strategy is necessary to prevent access to both industrial equipment and computer systems to ensure the physical security of the assets. Investment in robust security, endpoint monitoring, behavioural monitoring is necessary. Additionally, appropriate staff awareness and training, penetration testing and/or simulated attacks exercises should be considered, with a clear and tested cyber incident response strategy put in place. In some cases, we have seen that the cyber response plan was saved on affected servers – a clear vulnerability. It is important to look beyond just having the minimum security such as antivirus software and a firewall. Attacks are becoming ever more sophisticated, so protocols need to be reviewed very regularly and adapted. We have seen examples where threat actors have gained access to networks and systems by exploiting default Multi-Factor Authentication (MFA) protocols and a Windows vulnerability (PrintNightmare).

4. How does the geo-political climate affect risk exposure?

We are seeing a lot of cyber activity as a result of the Russian/Ukrainian conflict with, in particular attackers openly declaring their allegiance to support the Russian actions (like Conti below) whilst others vowed to support Ukraine or the rest of the world (such as Anonymous).




On 14 January 2022, a cyberattack took down more than a dozen of Ukraine's government websites with malware affecting the State Emergency Service and the Motor Transport Insurance Bureau. Since the invasion took place in late February 2022, further cyberattacks have targeted multiple government and bank services, mostly with denial of service and in early March 2022, it was the German subsidiary of the Russian energy company Rosneft who reported an attack. Reports have suggested that the hacker group "Anonymous" was suspected of being behind the attack which, it said, was due to Russia's invasion of Ukraine. This attack was said not to have affected production and may have been done as a “warning” to Russia.

If indeed, there may be retaliation, using cyber-attacks as a means of cyberwar; the position in relation to coverage of such attacks is still under review.

5. How does the insurance market develop its response to geo-political related cyber risks?

Standard cyber policies are geared more to the professional, financial, and retail sectors and were driven by data privacy, so they have taken time to adapt to other sectors such as manufacturing, marine, aviation and natural resources. With the drive to move to affirmative cover, we have seen quite a few cases where this has left gaps or overlaps, particularly to silent cyber.

Standard cyber policies will generally cover cyber extorsion payment (within the limit or sub limited cover), IT Investigation and remediation costs, including data restoration, data privacy costs, legal representation and notification costs (GDPR), as well as fines and penalties and data subjects’ claims, communications and monitoring costs, business interruption losses and increased costs of working.

They would not cover any betterment or improvements to IT/OT systems or sometimes purchase of new licences (depending on the wording). This may be particularly relevant when the OT system is old and moving to a new software would render the OT inoperable. They also usually don’t extend to obtaining new licences or recertification, to having to pay contractual penalties and do not cover physical damage, bodily injury, damage to third party property or contingent business interruption, pollution, and war.

There are possible extensions that can be purchased or in some cases extended definitions for: Payment Card Industry Data Security Standard fines, penalties and assessments, bricking (the purchase of new equipment to replace beyond repair and unusable damaged electronic devices, often because of damaged firmware) or for errors caused during normal operations rather than intrusion onto IT systems as well as digital assets coverage and data recreation.

Natural resources businesses are seeking cover for not only the possible loss of revenue but also for:

• Physical damage to plant, machinery, and assets

• Replacement of licences

• Set up of up-to-date systems and removal of obsolete systems (IT/OT) or to find solutions which enable a migration to the Cloud

• Regulatory exposures under cyber security legislation (e.g., NIS Directive) and industry specific regulation (e.g., NERC CIP) as well as data protection legislation (e.g. GDPR)

• Third party property damage, bodily injury and environmental liability

• Reputational harm loss and mitigation as well as dealing with supply chain or shared IP exposures.

In January 2022, the Lloyd’s Market Association (LMA) published four new cyberwar exclusions with clauses excluding coverage for “war” from cyber insurance policies. War is defined broadly to mean the use of physical force by a state against another state or as part of a civil war or unrest but also “military or usurped power or confiscation or nationalisation or requisition or destruction of or damage to property”. The definition emphasises on an action directed by a nation state. We have not yet seen this being applied but continue to closely monitor current developments.
 


Laetitia Fouquet

Head of Speciality Lines & Global Head of Cyber, Charles Taylor Adjusting
laetitia.fouquet@charlestaylor.com

Expertise:
Cyber, Medical Malpractice & Life Science, Liability

Location:
London

Get in touch

Find out how our wide range of services can support and benefit your business.