Public Header Nav
Power Plays

When, not if – preparing for the next cyber threat

Cybersecurity can feel like an amorphous threat — big, complex and hard to pin down. In this episode of Power Plays, experts from Kit Carson, Rappahannock and Associated share practical guidance for electric cooperatives such as how to prepare before an incident, who needs to be involved, what scenarios to plan for and how to build confidence across the organization.

Dan Trujillo: We’re adding smart devices, renewable energy resources, battery storage, automation, and we’re more connected than ever before. Those technologies bring a lot of benefits but also expand our cyber risk and attack surface. Because of that, cybersecurity has become a critical business function, not simply an IT responsibility.

Cybersecurity is something that has to be considered in every project from the beginning, not added afterwards. When you combine technology, policies, employee training, vendor security, and incident response planning, it reduces the risk across the organization.

Ultimately, cybersecurity is about trust. Our members trust us to provide reliable and secure services because at the end of the day, our co-op mission is to deliver a reliable service to our members, and cybersecurity has become the essential part of fulfilling that mission to help improve the quality of life of our members.

Teri Viswanath: That was Dan Trujillo from Kit Carson, and he’s highlighting the importance of taking a wider framing lens on developing cybersecurity programs. I’m Teri Viswanath. I’m your co-host, and I’m joined by our new Power Plays co-host, my colleague Esther Simon. Hey, Esther.

Esther Simon: Hi, Teri. Today, we’re going to dig into a topic that’s ever increasingly important for electric cooperatives. We’re going to talk about cybersecurity.

Viswanath: Cybersecurity has moved to a front-line, reliability, and boardroom issue for our electric cooperatives.

Simon: Two people we thought of right away that could best discuss this are Doug King, who leads cyber and information security with Rappahannock Electric Cooperative and BrilliT, as well as Associated’s IT manager

Viswanath: Chris Lazzaro is with Associated. We’re going to get you your question next, but Doug, I’m going to put you on the hot seat. I need you to help us understand why we need to have this conversation right now.

Doug King: Cooperatives are in a unique position because typically we’re small, we’re agile, we’re not-for-profit, and a lot of those staff members really wear multiple hats. Before an organization such as a cooperative really starts to lean into cybersecurity, I really think it needs to be a top-down approach, and that’s really chartering their information security program. The people who actually do the behind-the-scenes work on those keyboards, the cybersecurity, really have the structure so they can really perform at a really high level.

Simon: Are there certain trends that CEOs or boards in particular should be paying attention to in the realm of information security?

King: One of the things I work with my team very closely is to understand, beginning to end, what is our cooperative’s risk profile, whether it’s supply chain risk, whether it’s third-party risk management through our vendors, whether it’s employee risk, whether it’s your pure cybersecurity risk. I think the framing of that question really comes down to what is the risk appetite of that cooperative and how does that help them be more operationally sound so they can project their readiness out into the membership?

Viswanath: Hey, Chris, I want to have you step in here If a cooperative wants to strengthen its cybersecurity program but maybe they have a limited staff, budget, awareness, where do we begin with this?

Chris Lazzaro: That can be a really tough question to answer because it can seem very overwhelming for a cooperative to know where to start. I think it’s important to start with some common language of why is cybersecurity important and what problem is it setting out to solve. That might even sound maybe even too fundamental, like everybody gets this, but I don’t think we should assume that everybody gets this. Let’s start the conversation with some language that every single stakeholder, whether it’s the board, the executives, frontline employees, can really understand.

I would start that conversation by talking about disruption. What are we trying to avoid here? Fundamentally, it’s because a cyber attack can disrupt business in some of the most significant ways that we can imagine possible.

I had a peer. He works at an insurance company. They had a ransomware attack. The amount of disruption that caused for his business, he is still working through it a year and a half later.

Having that common language of, what are we trying to do? We’re trying to avoid that disruption. Let’s talk through scenarios. Everybody in a business understands scenarios and have three to five of those.

The job of a cyber function is to foresee that problem before it happens or when it starts to happen, when an attack is underway, to see it as fast as possible. That’s the monitoring side. Then to respond to it, to limit it as quickly as possible, to stop it, and then to recover from it, and then learn on the other side. That then is a very business-understandable summary of what we’re trying to do.

What we’re doing is we’re essentially building a new capability in the organization that doesn’t exist today, that capability of monitoring, responding, recovering, and learning. At some level, a cooperative has to carve out some time out of somebody’s schedule to own that capability.

Then that person has to build processes around it, and a process can be very simple at the outset. It can say, “Here’s who’s going to look for cyber events,” and you can look at your existing staff. You can say, “Our dispatchers, can we give them some tools to monitor?” You can get really creative around who’s monitoring. Who’s going to monitor? What initial tools are we going to use to give them to monitor? Maybe we’ll install some endpoint monitoring right off the bat. Maybe that’s an easy start for everybody. Then what are we going to do as an organization when something happens? And walk through that process for those first couple scenarios, and just start there.

I think a cooperative, just starting simple like that, could probably get their organization educated, have a few scenarios identified, and get some basic monitoring and some basic responsibilities in place and a couple essential processes in probably order of within 90 days.

Simon: Doug, I would ask, is there anything that you would have to add to that?

King: I think the biggest thing I would like to see when you’re talking about that is you really have to have a plan. You’re going to have to charter that at your board level.

You’re going to have to have the most senior executive team members in your board to sit down and charter that information security program, that cybersecurity program, to fund it appropriately, to give it the space it needs to breathe and to grow, and to really manage that risk that we’re talking about.

You’re going to have to have a chartering document that says, “This is our flag in the ground. This is where we shall not move from. These are our standards that we’re building from, and this is how we’re going to approach that risk.”

Without that charter, it’s really someone in IT taking on more responsibility. It’s someone else in an organization taking on yet more responsibility. It’s not going to be successful, because when those people have a bad day or they take some time off, your cybersecurity program, your information security program, does not function.

Simon: Before coming to CoBank, I was a CFO at an electric distribution co-op. One of, of course, the conversations, and I think it’s still a conversation throughout the country, is insurance.

Chris, from your example, do we pay the ransomware? Do we contact or notify authorities? Do we contact our insurance company, and then they come in with a response team? How does that change the nature of the conversation at that point?

Lazzaro: Depending on how the insurance provider looks at a cyber incident and what requirements they have, it can change how the response works.

We’ve had to adapt our managed service on the fly sometimes to what that means in the field, practically speaking. For example, some insurance providers could say, “Hey, you are the experts. You run the response. As long as you have certain things that get accomplished during the response and certain roles and certain responsibilities, certain capabilities defined in your program, we’ll see you a little bit more on the other side of it but get through your incident.” That’s one.

Another one that’s probably more common is we see a lot of insurance providers, they have their own list of pre-qualified responders. What they want to do is, during a cyber event, they want a handoff to their response organization to lead the response. And in some cases, our CyberDome responders will have to take a backseat and hand over all of the available information we and the distribution cooperative’s IT organization have collected, the actions we’ve taken so far, hand that to the responder organization and take more of a partnering and support approach, the cyber dome team would, while that responder works with the local IT organization at a cooperative.

That can have some benefits in some cases because it definitely makes the insurance process more streamlined and easy on the recovery side because insurance is essentially a component of recovery. We’re getting some financial recovery, not just system recovery, like we often think of recovery as being. But it can complicate the front side, because a lot of times, those providers who come in, they don’t know that cooperative’s IT organization, they don’t know the individuals who work there, they don’t know the business that well. They’re almost coming in from scratch.

In that case, really, our duty is to help get them up to speed as fast as possible so they can be effective in the role that the insurance provider needs them to play.

Simon: Doug, I want to ask you a little bit: how does Rappahannock or BrilliT fit into that response?

King: Before I get to that point, one of the things I wanted to talk about is the insurance aspect. You’re seeing the well of options for cybersecurity insurance dry up. There’s fewer and fewer carriers out there willing to take the financial risk involved with critical infrastructure. With that said, a lot of that risk, you’re not going to be able to offset, at least from a financial standpoint,

What Rappahannock did a few years ago, we decided, from a strategic standpoint, to start to really invest in and build out our team to a level that we haven’t experienced before.

What we’re able to do with that is we’re able to give ourselves a 24 by 7 enterprise security operations center. We’re able to staff ourselves appropriately. Most of our staff has worked either for or contracted to Fortune 500 companies.

We do traditional security as a service, but we also run a enterprise security operations center for cooperatives, and we do five-minute response times. What we’re really proud to say that when we do that, it’s five minutes or less before a human being on our side reaches out to that cooperative to advise them what we see, what the threat is or is not, and how we’re responding. We run that 24 hours a day, 7 days a week.

When someone around the world can reach out to you and harm your cooperative from an iPhone or from a simple PC, it behooves all of us to have a really fast response.

Viswanath: Yes, Doug, we know that right now the spend for cybersecurity, and I could be wrong on the numbers, but 10% seems low for an IT budget to allocate to cybersecurity.

We used to look at this central point. When the Ukraine grid was disrupted, it was a centralized attack. In Poland, a year ago, it was a really interesting change because it was a decentralized attack that had a wide swath of impact. In this AI arms race, how concerned are you, if we’re living in the moment, that this is going to be much more sophisticated than the cybersecurity attacks we’ve seen in the past?

King: Who would you like to address that question?

Viswanath: Oh, it’s really hard, so I’m going to throw this out. I’m going to put you both in the hot seat,

King: I’ll take a stab at it. Yes, you’re right, the spend is low. That $0.10 on the dollar, that’s equal to or less than what public school systems spend on their security. When you look at financial services organizations, they’re spending somewhere between 25 cents and 30 cents on the dollar. Critical infrastructure should be closer to that 20%, 25% spend on that, so it does matter.

Going back to AI and the ML, how fast can you weaponize your favorite AI platform race we’re in right now? That is very, very true. The silver lining on that, and we’ve seen attacks from very rapid social engineering campaigns, AI being used to scrape information off platforms like LinkedIn to deliver the perfect socially engineered phishing email to key employees, new to the organization, just trying to get their head above water, and they’re more than happy to respond to every email, type of scenario.

What we’re seeing, along with those kind of threats, is the defensive tools that we all have access to, they’re also getting better. There’s a little bit of a lag, but they’re also getting a lot better, and they’re getting a little bit more aggressive and a little bit more capable than what we’ve seen before in the last, say, three years or so. There is a silver lining on that.

I think for cooperatives, the message is lean into AI. If you have platforms that help you understand the security cameras’ feeds that are coming in and out of your substations or your buildings, leverage those when you can. If you don’t have enough employees to provide that 24 by 7 awareness on things like cyber and physical security, leverage AI where you can.

Viswanath: Thanks, Doug. Chris, Do we have to up our game in the reality that you’re facing?

Lazzaro: Yes, we do. Absolutely, we do. AI is definitely one of those waves of technology that is going to come through, and it presents both threat and opportunity to our cooperatives. What I would also say is that’s not new. I am not surprised by what AI is doing because I have seen every wave of technology, over time, create the exact same arms race. Really, if our organizations are set up to ride these technology waves well, and we realize that, “Oh my gosh, this is not some new thing that--We’ve never had technology that’s disrupted or created new threats before.” That’s just not the case. I think it’s more around having our cooperatives-- I really like what Doug said around cooperatives need to understand AI, and the macro maybe sense of that is cooperatives just need to be able to ride technology waves. This is just one of many, and there will be many more in the future.

What do we see with it right now? Yes, there are some threats, but I see the same thing Doug’s seeing, where I see the tools that are coming out from some of our vendors are incrementally getting better with AI capabilities themselves. Then I’m also seeing our cyber analysts using AI to provide more sophisticated review of alerts and alarms and things like that, and to do more sophisticated techniques to protect our systems.

Yes, it is an arms race. Yes, we absolutely need to be using AI now to get ahead of that arms race, and we need to track that arms race. Hey, if this surprises anybody in technology, you’re probably in the wrong job, because this is just part of your job. It’s staying up with this and enjoying that journey because it’s an important job and service that our cooperatives need.

Viswanath: Chris, you started out the program talking about your colleague in the insurance industry that, 18 months in, still reeling from a cybersecurity. Is there a good outcome here, guys, in terms of what post-recovery or learnings would look like?

King: I think, in all things, if you go through a challenging event, particularly cyber, you should really look at it as an opportunity to learn from it.

I’ve done a lot of work around the world, not just for co-ops, and it’s heartbreaking when you’re working with a client, either you’re performing in a limited engagement or you’re doing some PIN tests or some red team assessments. You come back the next year to do it again, and you find out the organization has not improved. In fact, they’ve gotten worse.

Lazzaro: Yes, I agree. I think there’s a heuristic that I like to think about, which is all of the people involved related to an organization that goes through an event like that, what do the relationships, what does the culture, what does the trust look like on the other side?

In my colleague’s company, the story he’s working through is on the other side of the event, there is chaos, there’s finger pointing, and there’s just really a lot of work that got spun up in a very disorganized way that they’re trying to get control of. When I look at the humans in the mix of that, all the signals aren’t good. On the other side, what does a good event look like? This might sound maybe counterintuitive, but trust should go up, confidence should go up, on the other side of an event. There shouldn’t be this feeling of chaos or finger-pointing or things like that.

Now, that doesn’t just happen by magic. You can imagine what sort of organization leads to one outcome versus what sort of organization leads to the more positive outcome. I think Doug hit the word, which is an organization that learns tends to be more on the positive side. An organization that thinks ahead, that has an imagination of what could happen and puts some discipline into what we’re going to do, tends to have better outcomes on the other side.

Simon: We’ve covered a lot of ground today talking about the landscape in cybersecurity. We started with preparedness in their cybersecurity area during an event, and then the response and post-event, and what that should look like. My question is, if our listeners remember just one thing from the conversation today, what do you hope it is? Doug, I’ll start with you.

King: Oh, that’s a tough one. I would just capstone it with this approach. It’s really a function of leadership and risk. If the leadership of the cooperative or a cooperative is looking at one individual or just a couple people to fully manage, in addition to their other responsibilities, everything when it comes to cybersecurity and information security, that is a mission that is doomed to fail for those individuals because it’s much, much bigger than that. It’s a function of the success of your cooperative. Again, making sure that team has dedicated resources, whether those be people or dollars or managed service providers, really matters.

Simon: That’s great. Chris?

Lazzaro: What I would throw out is one of the best ways to get that conversation started is to come up with some real scenarios and then walk people through them. Start with your executive team. Do a tabletop with them of what would happen in a cyber attack and do it in layman’s language. Do it in business terms so that they understand what’s going on. Then maybe even have them play different roles so they can feel and see what will happen to disrupt the organization if a ransomware event happens or if a supply chain attack happens, and make sure they understand that first.

That’s where I would start because if you can get your leaders to understand what those scenarios are and what they can do to the organization, you have made so much progress towards everything you’re going to need after that, because after that, it just naturally leads to questions of, who’s responsible for monitoring? What are we going to monitor? How do we stop that from happening? What do we do when that does happen? Who’s going to be involved?

Simon: I also posed the same question of Dan Trujillo at Kit Carson.

Trujillo: One practical takeaway is stop asking, “Could we be attacked?” And start asking, “What happens when we are?” Every co-op should schedule a tabletop exercise this month. Bring together your operations, IT, communications, leadership, and member service teams. And then walk through realistic scenarios, like maybe ransomware encrypts your billing system, maybe your SCADA environment loses visibility, maybe your phones or internet go down.

Then that starts creating and asking questions on who makes those decisions during the process, who communicates to your members, when and who contacts law enforcement or legal, and most critical one is who actually is responsible for restoring those systems. You don’t want these conversations happening the first time during an actual emergency.

Simon: As we wrap up, I just wanted to extend a sincere thank you to each of you for sharing your expertise and insights today to Rappahannock as well as Associated and Kit Carson. We not only appreciate the work that you do in helping protect electric cooperatives, but also your willingness to share practical advice and insight that our listeners can take back to their organizations. Thank you. We appreciate it.

Viswanath: And thanks for joining us today.