Algemene Rekenkamer NCA

Strengthening the digital defences: the cyber security and critical water structures

2019 NL2019waterCybersecurity — Categorised against INTOSAI ICS (GuidICS)
SCALE
  • Every critical water structure managed by the national directorate for public works and water management - the storm surge barriers, locks, weirs and pumping stations the country depends on.
  • Their operating systems largely date from the 1980s and 1990s and were built to run stand-alone, before being linked to wider networks.
  • One security operations centre watches the whole estate for cyber threats.
COMPLIANCE
  • A national data-processing and cyber-security act, with a companion act on the security of network and information systems, sets the baseline duties of critical-infrastructure operators.
  • An EU directive on network and information system security obliges member states to protect essential services.
  • A government accounts act, together with the ministry's own security programme and regulations, governs how the agency organises that protection and accounts for it.
ECONOMY
  • The audit puts no figure on the cost of protection: the resource in question is the staffing and expertise of a single security operations centre.
  • That centre reports a shortfall in both, with nothing to show it was resourced for the task it was given.
EFFICIENCY
  • Low-priority alerts may wait several days before anyone acts on them.
  • The target of detecting attacks instantly, set for the end of 2017, had not been met by the autumn of 2018.
  • Crisis maps and network reports that responders would depend on were not kept up to date.
EFFECTIVENESS
  • The security operations centre has no up-to-date picture of the cyber-security status of all critical water structures.
  • No scenario had been prepared for a crisis caused by a cyber attack, and head office held no information on its cascade effects.
  • How great the threat of an attack on the sea-defence and water-management sector actually is remains unclear.
1. Detection falls short of its own target, so an intrusion can pass unnoticed Monitoring Design

The detection and response strategy was not yet complete: 'the objective set for the end of 2017 of instantly detecting any cyber attacks directed against critical water structures had not been achieved by the autumn of 2018'. As a result the security operations centre 'does not have an up-to-date picture of the cyber security status of all critical water structures, which means that there is a risk of hackers being able to break into critical structures unnoticed'. A Monitoring gap rooted in a Design that was never finished, leaving the agency at risk of detecting an attack too late, or not at all.

  • Function: Security
  • Value: Assets
  • Stakeholders: Operator
  • Quality: Reliable, integrated information base Sound risk management
2. No scenario was prepared for a cyber crisis, and the response documents were out of date Business continuity Documentation

'No scenario had been constructed specifically for a crisis caused by a cyber attack. Moreover, no information was available at head office on the cascade effects caused by a cyber attack on the critical water structures.' Certain important documents relating to the response - crisis maps and network reports - 'were not kept up to date'. A Continuity gap compounded by Documentation: the response to a cyber crisis may be neither sufficiently rapid nor sufficiently effective.

  • Function: Security
  • Value: Assets
  • Quality: Sound risk management Reliability and availability
3. The monitoring centre reports too few people and too little expertise, and alerts queue for days Monitoring

The security operations centre 'claims to have a capacity problem - in terms of both staff and expertise. This lack of capacity causes delays, for example, in analysing reports of potential threats: the SOC claims that it may take several days before any action is taken in response to low-priority alerts.' Its staff would like to refine and professionalise their detection practices further, for instance by checking log data in ways that would surface suspicious patterns. A Monitoring function limited less by method than by the Human capital available to run it.

  • Function: Human resources
  • Value: Human capital
  • Stakeholders: Staff
  • Quality: Adequate resources and competences Adequately staffed, skilled workforce
4. Systems built before cyber security was a concern were later opened to wider networks Design

'The operating processes at critical water structures use computer systems many of which date back to the 1980s and 1990s, a time when the term cyber security was not in common use. Although these systems were originally designed to operate on a stand-alone basis, they have over the years been gradually linked up with bigger computer networks, for example in order to facilitate remote operation. However, this trend has made the systems more vulnerable to cyber threats.' A Design decision taken for operational convenience that changed the threat surface of an Asset, while it remains unclear how great the threat to the sea defence and water management sector actually is.

  • Function: IT, Infrastructure
  • Value: Assets, Domain knowledge
  • Quality: Appropriate use of technology and automation
Control focus
ICS phaseControl functionCases
Work processesMonitoring1. Detection falls short of its own target, so an intrusion can pass unnoticed<br/>3. The monitoring centre reports too few people and too little expertise, and alerts queue for days
Initial phaseDesign1. Detection falls short of its own target, so an intrusion can pass unnoticed<br/>4. Systems built before cyber security was a concern were later opened to wider networks
Organic elements of a processBusiness continuity2. No scenario was prepared for a cyber crisis, and the response documents were out of date
Functions applied to all stagesDocumentation2. No scenario was prepared for a cyber crisis, and the response documents were out of date
This page is part of CUBE, a knowledge-sharing initiative of the EUROSAI IT Working Group. Its purpose is to make what supreme audit institutions find easier to search, compare and reuse — by auditors, and by the wider public who rarely reach these reports in their original form. It presents an analysis prepared, with AI assistance, by Paweł Banaś (NIK — Najwyższa Izba Kontroli, Poland) on the basis of the publicly available report of Algemene Rekenkamer, categorised against the internal-control terminology of INTOSAI's Guidance on Auditing Internal Control (ICS), drafted by the Internal Control Standards Subcommittee, which NIK (Poland) chairs. The categorisation and the case selection are ours, not the audit institution's, and so is any error in them. Readers are warmly encouraged to go to the original report, linked above; this page is a way in, never a substitute. Underlying data.