21st Century Five Eyes

11038596256?profile=RESIZE_400xThe Five Eyes agencies recently issued cybersecurity guidance and best practices for smart cities.  The document describes potential risks and provides recommendations for addressing them.   Those readers who do not follow the novels Tom Clancy and John le Carre may not be familiar with The Five Eyes.  The Five Eyes are the intelligence agencies of the US, Canada, Britain, Australia, and New Zealand that share intelligence.[1]

Smart cities integrate Information and Communication Technologies (ICT), community-wide data, and intelligent solutions to optimize governance and communities that connect Operational Technology (OT), managing physical infrastructure with IoT devices, cloud computing, AI, and 5G communications.

Smart cities provide numerous benefits for authorities and citizens. Still, the associated cybersecurity risks should not be ignored as they can be an attractive target for threat actors, profit-driven cybercriminals, and state-sponsored threat actors looking to obtain valuable information or cause disruption or destruction.  The cybersecurity guidance for smart cities is provided by US agencies CISA, NSA, and FBI, the UK’s National Cyber Security Centre, Canada’s Centre for Cyber Security, the Australian Cyber Security Centre, and New Zealand’s National Cyber Security Centre.

One of the risks associated with smart cities is the expanded and interconnected attack surface created when previously separate systems are integrated into a single network.  This enables an attacker who has gained initial access to the network to move laterally and causes cascading, cross-sector disruptions of infrastructure operations.  “For example, malicious actors accessing a local government IoT sensor network might be able to obtain lateral access into emergency alert systems if the systems are interconnected,” the agencies explained.

Another risk comes from the ICT supply chain and the vendors that provide hardware and software.  Threat actors can abuse supply chain vulnerabilities to steal valuable data, cause disruption, or weaken confidence in the integrity of systems.  “Illicit access gained through a vulnerable ICT supply chain could allow the degradation or disruption of infrastructure operations and the compromise or theft of sensitive data from utility operations, emergency service communications, or visual surveillance technologies.  Smart city IT vendors may also have access to vast amounts of sensitive data from multiple communities to support integrating infrastructure services, including sensitive government information and Personally Identifiable Information (PII), which would be an attractive target for malicious actors,” the agencies said.

Another major risk category is related to the automation of infrastructure operations, such as traffic and wastewater management.  This automation can introduce new vulnerabilities, and the volume of data and the complexity of automation can lead to reduced visibility.  To address these risks, owners should keep track of the individuals and vendors responsible for the overall system and each segment, ensuring no ambiguity regarding roles and responsibilities to avoid degrading cybersecurity posture and incident response capabilities.

When it comes to supply chains and vendors, they should be carefully vetted, and risks should be assessed.  “This includes scrutinizing vendors from nation-states associated with cyberattacks or those subject to national legislation requiring them to hand over data to foreign intelligence services,” the agencies said.

Specific recommendations described in the guidance include applying the least privilege principle and implementing a zero-trust architecture, enforcing multi-factor authentication, securely managing assets, improving the security of devices, protecting Internet-exposed systems, patching systems, conducting training, and developing and exercising incident response and recovery plans.

The Five Eyes guidance summarizes the recommendations for securing smart cities and includes links to numerous useful resources provided by various government agencies.

 

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  For questions, comments, or assistance, please get in touch with the office directly at 1-844-492-7225, or feedback@redskyalliance.com 

Weekly Cyber Intelligence Briefings:

Reporting: https://www.redskyalliance.org/
Website: https://www.redskyalliance.com/
LinkedIn: https://www.linkedin.com/company/64265941    
Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/5504229295967742989    

 

[1]https://www.securityweek.com/five-eyes-agencies-issue-cybersecurity-guidance-for-smart-cities/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!