Semperis study shows cybersecurity risk to water and electric utilities (Image Credit:getty-images-zoIRCpgrG1o-unsplash)Semperis has released its latest study, which shows that water and electric utilities are at serious risk of disruption from cyber attacks. The study looks at utilities in the US and UK and is titled, The State of Critical Infrastructure Resilience, Evaluating Cyber Threats to Water and Electric Utilities. It shows how nation-state attackers are actively targeting critical national infrastructure.

Chris Inglis, Semperis Strategic Advisor and first U.S. National Cybersecurity Director (Image Credit: Semperis)
Chris Inglis, Semperis Strategic Advisor and first U.S. National Cybersecurity Director

Chris Inglis, Semperis Strategic Advisor and first U.S. National Cybersecurity Director, said, “Many public utilities likely don’t realise that China has infiltrated their infrastructure.

“For instance, Chinese-sponsored threat actors like Volt Typhoon are known to prefer Living off the Land attacks, which are difficult to detect and can remain dormant, planting backdoors, gathering information or waiting to strike for months or even years.”

Key findings show the scale of the risk

The report’s key findings show the scale of utilities’ risk. 62% admitted to being attacked in the last 12 months, with 80% saying they faced repeated attacks. The US suffered a higher rate of attacks than the UK, 64% vs. 57%. The authors also question why the remaining 38% think they weren’t targeted. This leads the report’s authors to say that all organisations need to adopt an assume-breach model.

Of particular interest is that 59% confirmed that nation-state attackers were behind the attacks. This is an important stat because attribution is typically extremely difficult. There is little detail on where those attributions came from. However, as critical national infrastructure, most utilities will be able to call on national cybersecurity bodies. They will have the resources to make such claims.

Of those countries named, all targeted the UK more than the US. North Korea was the most likely to attack both countries, followed by Russia. Attacks from Iran and China were much lower than the other countries in the US, but China was just as active in the UK as North Korea and Russia.

The stat also threw up some worrying comments. According to the research “experts agree that many more might simply lack the ability to detect stealthier attacks.” That implies that the attacks detected may represent a much smaller percentage than the figures show.

Attacks lead to deliberate data destruction

In 54% of cases where attacks were successful, data was permanently corrupted or destroyed. It is not clear if this was due to a failure to pay a ransom or happened even if a ransom was paid.

There is, however, some good news on data. It seems that 84% were able to restore services within 24 hours. Compared to some of the multi-day, multi-week and multi-month outages, this is a key step forward in terms of resiliency. However, with the increase in legislation around the need for resiliency, there is still more to be done. Customers will want to see restoration within hours and no longer.

Semperis sees identity under direct threat

But perhaps the most worrying statistic is that 82% are believed to have suffered some form of compromise to their primary identity systems. That includes Active Directory, Entra ID and Okta. It seems that US utilities are seeing a higher level of attack against identity but the report offers no insight into why.

Is it the use of outsourced systems? Is this the long tail of earlier attacks where attackers are exploiting previous vulnerabilities that remain unpatched? Are UK systems better maintained or even using older technology that is less visible?

Irrespective of the reason, it highlights the need to move towards zero-trust environments. They deliver a more secure identity approach than role-based systems.

What are the biggest threats?

There were five key categories of threats that Semperis identified through this research. They are:

  • Supply chain compromise: Risks to the UK are seen as higher than the US (43% vs 40%). This might be due to more complex supply chains with a much larger number of smaller suppliers.
  • Legacy systems: Again the UK (47%) is more at risk than the US (35%). It would have been interesting to have seen some qualitative research from Semperis around this. What type of legacy system? Is this core IT, cybersecurity, IoT or something else?
  • Nation-State threats: The US (35%) is marginally more at risk than the UK (34%). However, figures from other industries show a significant uptick in attacks against the UK from nation-state attackers.
  • Compromise of Identity Systems: The US (33%) has seen more issues here than the UK (30%). However, as outlined above, there is little detail on why this is.
  • Insider threats: The US (31%) is far more likely to suffer from an insider threat than the UK (23%). Once again, details on why are not given, which is very disappointing.

Enterprise Times: What does this mean?

This research presents more numbers, but at just 15 pages, it is not a difficult read. It shows the scale of attacks on utilities and the need to do more to protect them.

We are in an age where critical national infrastructure is a legitimate target for cyber attacks as part of an asymmetrical warfare strategy. Yet, we should not assume that most of those attacks are from nation-state actors.

The rise in hacktivism and attacks from cybersecurity gangs is also on the rise. Some are sponsored by or provided tools by nation-state groups that use them as proxies. As armed conflicts continue to rage around the world, they are also pulling many more groups into the sphere of influence of those nation-state actors. The problem is that attribution is notoriously difficult and, as we’ve seen before, wrong.

Utilities in the US and UK are predominantly privatised. That means that their primary business focus is on the shareholders. This requires them to balance the payment of dividends with spending on the business. This is where government regulators need to look at resiliency as part of their remit and put more pressure on those businesses.

As can be seen here, over a third do not have an assume-breached mentality. That needs to change, and the various utilities need to improve cooperation to create a more secure environment.

Previous articleNews from the week beginning 31st March 2025
Next articleModel ML acquires AI Powered presentations review tool Flippr
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here