pwshub.com

Homeland security hopes to scuttle maritime cyber-threats

The US Department of Homeland Security is seeking help to assess the security of tech at maritime ports, to safeguard the 13 million jobs and $649 billion of economic activity generated by the nation’s docks.

The department’s ambitions were revealed this week in a request for information (RFI)

that aims to “produce a research study analyzing maritime port networks, to understand how the resources are deployed, as well as identify research, development, test, and evaluation needs that are unique to [maritime ports].”

That info will be used to create a "Maritime Port Resiliency and Security Research Testbed" that will help port stakeholders study, test and modify their systems.

"Our goal is to successfully design and develop a virtual testbed where tactics, techniques, and procedures can be created for effective response to threats to critical maritime infrastructure without impacting real-world operations," Homeland Security Science And Technology Directorate project manager Jason McCasland said. "For that to be successful, we require baseline information on the equipment US ports are utilizing in their daily operations."

Cybersecurity at maritime ports is a well-established concern. Last year alone LockBit paralyzed Japan's Nagoya Harbor last year, and a major Australian shipping logistics company was hit by a cyberattack that disrupted activities at ports down under.

Homeland Security, through its subsidiary the US Coast Guard, was given responsibility for port cybersecurity through an executive order signed by President Joe Biden this past February.

  • Critical infrastructure security will stay poor until everyone pulls together
  • America's enemies targeting US critical infrastructure should be 'wake-up call'
  • NCSC says cyber-readiness of UK's critical infrastructure isn't up to scratch
  • Seattle airport 'possible cyberattack' snarls travel yet again

Biden Administration officials in April urged port operators to improve their security posture due to the threat posed by nation-state threat actors against critical infrastructure, a recommendation echoed by the Department of Transportation.

"Recent events have highlighted the fragile and complicated nature of the [maritime transportation system], as well as primary, secondary, and further reaching effects once there is a tragic disruption," Homeland Sec noted under reasons for participation in the RFI.

Submissions are being sought from subject matter experts who work for or support the maritime port infrastructure space, and from businesses that manufacture equipment for ports. The deadline is October 4, after which point interviews will be conducted to further discuss the provided information.

It's not clear when the Testbed might emerge. We've asked DHS and USCG for details but at the time of publication have not received a response. ®

Source: theregister.com

Related stories
7 hours ago - Many left reeling from July's IT meltdown, but not to worry, it was all unavoidable Germany's Federal Office for Information Security (BSI) says one in ten organizations in the country affected by CrowdStrike's outage in July are dropping...
1 month ago - Computer scientists brainstorm in Pentagon-backed competition to design an AI program that scans open-source code for flaws bad actors could exploit
3 days ago - Enlarge / Andrew J. Pincus, attorney for TikTok and ByteDance, leaves the E. Barrett Prettyman US Court House with members of his legal team as the...
1 week ago - CFO says company hasn't been sued by any customers – yet CrowdStrike has yet to face a lawsuit over July's global IT meltdown, according to CFO Burt Podbere.…
3 weeks ago - Muhammad Zain Ul Abideen Rasheed used Instagram to ensnare 286 sextortion victims in 20 countries, an Australian judge said. Most of his victims were children.
Other stories
15 minutes ago - Write better code, urges Jen Easterly. And while you're at it, give crime gangs horrible names like 'Evil Ferret' Software developers who ship buggy, insecure code are the real villains in the cyber crime story, according to Jen Easterly,...
54 minutes ago - The Indian government has approved $2.7 billion in new spending for its space program.
55 minutes ago - heard you like apps — Windows App replaces Microsoft Remote Desktop on macOS, iOS, and Android. Enlarge / The...
55 minutes ago - LinkedIn limits opt-outs to future training, warns AI models may spout personal data.
55 minutes ago - BUSTED — iServer provided a simple service for phishing credentials to unlock phones. Getty Images ...