Dominion Energy [NYSE: D]

Advancing Cyber-security to a New Level

Network penetration testing is discussed in a variety of government and trade fora, but remains an under-developed aspect of most large enterprise cybersecurity programs.  When companies speak of penetration testing, they often mean hiring a third party to perform a limited number of tests.  A typical third party will charge a large enterprise $300-400K to perform six to eight scaled tests in a year. Large government and private sector enterprises have thousands of applications - hundreds of which are either critical or external-facing. Only a very tiny percentage of applications will be tested despite patches, upgrades, and enhancements being applied across the enterprise on a regular basis. Any of those changes could result in the introduction of new vulnerabilities and malicious exploits, which remain undetected.

Dominion Energy’s Corporate Intelligence and Security (CIS) organization, which converges its cyber and physical security functions with its threat intelligence collection and processing mechanisms, pursued an evolution of its penetration testing program, starting in 2019. The core of the program is the vendor-led penetration testing exercises. CIS uses vendor partnering to conduct tests on a limited number of regulatory-required or critical new systems. The third party generates a report and findings are evaluated and remediated. Over the years, we have used a number of different firms and, most recently, have been utilizing Accenture after they purchased the firm Revolutionary Security which had our contract at the time. Accenture brought to bear a deeper, more robust set of capabilities and talent which provided effective results for Dominion Energy. The sheer number of applications and systems which are tested is necessarily small relative to the size of the company and the amount of constant growth and innovation within its information network.

Dominion Energy recognized the need for more frequent penetration testing and adopted the approach of adding in-house staff to the cyber security team. Since it is increasingly difficult to recruit and retain experienced penetration testers with the requisite level of technical knowledge, skills, and abilities into a large company, Dominion Energy took the approach of hiring very capable personnel, with a strong IT background, and training them in-house. While the team is small in size, because they are in-house and have the full-time job of penetration tester, they are able to review many more systems, processes, APIs, file shares or server/workstation hardening scenarios. Leveraging our Accenture relationship, we used their expertise to build out the structure of that program and to provide an initial baseline level of training for those personnel. After several years of growth, dominion is at the stage of deploying its team on independent tests and the company is seeing strong results from it.

“The current phase of our evolution is in leveraging the cyber range capability to build relationships and muscle memory with our government partners. In preparation for a major cyberattack, groups such as the FBI Cyber Action Team (CAT) or the National Guard’s cyber brigade or DHS-CISA will be on site to help mitigate the threat.”

A hidden benefit of having an in-house penetration testing team is it can serve as the “red team” for internal exercises. Groups within CIS’s Threat Response and Analysis Center (TRAC) in Richmond, Virginia, need training against other humans to grow their skills at defending against sophisticated, nation state attacks. Nation state adversaries effectively have unlimited people, money, and time. They will pivot their attack methods when they encounter effective defenses, and they are constantly adapting and updating their tactics, techniques, and procedures. 

Dominion Energy also took the approach of investing in our own bespoke cyber range. A cyber range is a collection of equipment which mimics the enterprise information and operational technology environments. It can be configured to replicate any aspect of the company’s digital environments and, because it is an isolated, stand-alone environment, it is also fully destructible. Malware can be safely introduced, zero-day exploits can be utilized. It is a true game field for both learning new ways to be an effective penetration tester and also learning how to detect and mitigate those attacks for the TRAC. Dominion runs quarterly red team/blue team exercises within our cyber range, making both internal teams stronger.

The current phase of our evolution is in leveraging the cyber range capability to build relationships and muscle memory with our government partners. In preparation for a major cyberattack, groups such as the FBI Cyber Action Team (CAT) or the National Guard’s cyber brigade or DHS-CISA will be on site to help mitigate the threat. The first time those teams show up should not be the first time they are learning the essential aspects of Dominion Energy’s environment. Time spent learning the environment and building trust is time where the attack continues to spread and cause damage – that should happen during a training simulation.

To mitigate that challenge, Dominion Energy launched an exercise known as Cyber Fortress. A first of its kind in the nation, Cyber Fortress utilizes our cyber range and brings together government partners, at a Dominion Energy location, for five days of active cyber war games. Offensive cyber experts from groups such as the Army, Air Force, and National Guard partner with the penetration testers to simulate current TTPs for hostile nation states. Defensive cyber experts from FBI, DHS and the national guard partner with the TRAC analysts to defend the red team attacks. Our first Cyber Fortress exercise took place in fall of   2022. Not only did we grow trust and build muscle memory, but process improvements emerged which would otherwise have gone undiscovered. Handling of evidence from a vendor compromise or insider threat incident was one such lesson. Another was discovering the need for memoranda of understanding promulgated in advance for deployment of government analysts and to dispatch the National Guard. That lesson has allowed us to get the paperwork in place now, so there are no delays during a cyberattack.

Penetration testing is a critical component to any cyber program. Having sufficient, ongoing testing, at a level of suitable sophistication, which uses the latest TTPs, is not an easy achievement - but it is necessary.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.