


The exponential growth in remote working triggered by the pandemic has led to an unprecedented level of integration between Enterprise IT systems, Operating Technologies (OT) and the Web. This has led to a call for tighter legislation and international standards,to fight cybercrime. However, while good laws have a key role to play in combating cybercrime, legislation alone is not enough, and an overreliance on it can prove to be counterproductive.
The Covid19 pandemic has increased the world’s reliance on the internet by many folds. The International Energy Agency estimates that in 2020 alone, global internet traffic grew by 40 percent; most of it driven by an increase in video streaming and video conferencing; both key aspects of remote working. This growth comes on top of a 15-fold increase since the beginning of the decade. If current trends are anything to go by, it is very unlikely that the world will return to pre-pandemic working patterns in the near future. This presents unique challenges in relation to cybersecurity to companies, especially public and private utilities.
When it comes to cyberattacks, typically, businesses have focused on protecting their enterprise systems, while governments have focused on protecting critical infrastructure (eg. Water, Electricity, Transport.) However, for utilities, this distinction has little relevance. This is because, for utilities, protecting enterprise systems would include protecting Operating Technology (software) platforms that run critical infrastructure. Cybersecurity frameworks often involve partitioning Operating Technologies (OT) systems from Information Technology (IT) systems; to protect the former from the latter which are seen as more vulnerable. Most utilities go to great extents to enforce this separation through one-way firewalls etc, but some even go to the extent of physically separating their OT from IT. It is still common practice to store all OT software onsite, with no remote access or access only through dedicated Wide Area Networks (WANs). But it is a fact that in the post-pandemic remote-working world, such separation will become increasingly harder.
"It is more important to build capacity; meaning expertise to anticipate, detect and prevent attacks, capable of responding to new threats on an ongoing basis with agility in the fast-changing global environment"
In this environment, it is understandable that there are calls for stronger legislation. While there is no denying that strong laws have a role to play in cyber security, relying too heavily on legislation can have its drawbacks and prove counterproductive. It is more important to build capacity; meaning expertise to anticipate, detect and prevent attacks, capable of responding to new threats on an ongoing basis with agility in the fast-changing global environment. Developing threat scenarios based on prevailing geo-political, geo-economic and technological conditions to anticipate threats, cannot be achieved in the absence of cooperation across organizations, governments, civil-society and communities, both nationally and internationally. Because cyberattacks on utilities will have significant downstream impacts, identifying sources based on emerging motivations for attacks would be impossible without such extensive collaboration. For example, a few years ago Australia’s Bureau of Meteorology (BoM), the government agency responsible for weather forecasting, came under a serious cyberattack. Though the real intention of the attack is not clear, the impact of denial of service would have had impacts far beyond weather forecasting, potentially disrupting aviation, shipping and military exercises. It is hard to see how tougher laws would have prevented, or even foreseen, this attack. But collaborative threat assessments that took into account these downstream impacts, would have at least identified the exposure.
Further, legislation that goes too far, such as suggestions to criminalise the mere possession of malware, as opposed to criminalising only their use as is the state of current legislation in many countries, can have detrimental effects. As, in the interest of fairness, law enforcement might spend valuable resources looking for relatively benign malware, diverting attention from more serious threats. It might also create multiple backdoor points of entry which can be used by hackers. Excessive intrusions can also slow down performance of OT and impede performance of critical infrastructure.
The Budapest Convention on Cybercrime, with 66 countries participating, is one of the most comprehensive international frameworks available at the moment to fight cybercrime. The convention gets the balance between laws and capacity-building more or less right, as it has three components; (1) criminalising conduct including illegal access, systems interference computer fraud and using the web for illegal activities such as child pornography (2) procedural powers to investigate cybercrime, and (3) enabling international cooperation and capacity building. The convention specifies minimum standards for national legislation, based on acts of crime rather than things like possession of malware, but it goes much further; developing and enabling frameworks or building cooperation between governments, between businesses and governments, and enabling the utilization of a broad range of expertise in building capability. I believe the best way forward for utilities is to make use of current legal frameworks. Rather than push for tougher laws. Organizations should campaign for the implementation of frameworks enabled by the Budapest Convention on capacity building, to anticipate, detect and prevent attacks. While on the other hand the focus of legislation should be defining and criminalising acts of cybercrimes and providing oversight ensuring governments and organizations act in the best interests of the community.