Back in May this year, President Trump issued an executive order banning US energy sector entities from acquiring electric equipment from foreign adversaries, citing potential cybersecurity threats.
Two months later, the Energy Department’s Office of Electricity wants to know what measures the sector has employed to safeguard its supply chain from cyber attacks, reports Nextgov. In particular, a request for information from Energy “asks whether energy sector asset owners and/or vendors identify, evaluate, and/or mitigate foreign ownership control or influence in the context of adversaries potentially accessing company and utility data, product development, and source code…”
This renewed pressure from the government speaks to a wider issue facing energy companies — increased scrutiny and accountability for the vendors they work with and the overall security of their supply chains.
Below are several best practices the energy sector can employ to mitigate third-party cyber risk.
Assess and continuously monitor each vendor’s security posture
While there’s certainly a renewed focus on vendor risk management, supply chains have been a source of cybersecurity concern among regulators for quite some time. In 2018, a major utility was fined $2.7 million for an inadvertent third-party breach, while that same year a cyber attack on a petrochemical company nearly destroyed a Saudi Arabian chemical plant.
In order to mitigate third-party cyber risk, utilities need an effective means to understand and assess the security posture of their vendors. One way to gain this context and visibility is through the use of security ratings, a data-driven, dynamic measurement of an organization’s cybersecurity performance.
This standardized, easily understandable KPI can be used by utilities companies across the lifecycle of their vendor relationships. During the onboarding and vendor selection phases, security ratings allow busy security professionals to quickly assess potential vendors and partners for cyber risk — replacing time-consuming and unscalable point-in-time security assessments. Once the contract is signed, security teams can then continuously monitor the security performance of each vendor in their portfolio. If and when a partner’s security posture drops below an agreed-upon threshold, security leaders can receive an alert and then work collaboratively with the supplier to remediate the issue.