
Many people feel an incident must be malicious to count as a cyber incident. That is not the case, but incident response is usually organized as if every incident identified as cyber-related is a deliberate attack.
Colonel Herman Haupt, a US Army civil engineer, served as chief of railroads for the Army of the Potomac during the Civil War. Haupt’s mission was to keep the trains moving so the Army retained its operational mobility and clean-functioning supply lines. One of Haupt’s ideas holds lessons for us today, even with respect to such current concerns as cybersecurity. From Haupt’s point of view, it didn’t matter whether a railroad bridge was downed by a flash flood or a Confederate cavalry regiment. The bridge was out and needed to be fixed as soon as possible, and that’s what Haupt organized his engineering troops to do. As far as Haupt was concerned, a Pennsylvania thunderstorm and Jeb Stuart’s troopers were essentially equivalent: they both broke bridges. It wasn’t the intention; it was the outcome that mattered.
It should be evident but cyber incident response programs are not initiated until an incident is identified as being cyber-related. Stuxnet demonstrated that a sophisticated attacker could make a cyberattack look like an equipment malfunction, precluding a cyber incident response program. Moreover, the impact of a cyber incident may be the same, whether it’s malicious or unintentional. In some incidents, the only difference between the incident being malicious versus unintentional is the motivation of the individual involved — the impact is the same. GAO defines a cyber incident as “an event that jeopardizes the cybersecurity of an information system or the information the system processes, stores, or transmits; or an event that violates security policies, procedures, or acceptable use policies, whether resulting from malicious activity or not.” Professor Ross Anderson states that security engineering is about building systems to remain dependable in the face of malice, error, or mischance.
Control system cyber incidents continue to occur with potential or actual catastrophic consequences in every sector. The training to recognize control system incidents as being cyber-related is missing. Identifying control system incidents as being cyber-related is complicated when government and industry organizations rush to judgment by stating that incidents weren’t cyberattacks without knowing the actual cause, or set reporting thresholds that exclude many actual incidents as being cyber-related.
