Rising tensions in the Middle East in the wake of the killing of General Qasem Soleimani, the head of Iran’s military Quds Forces, has U.S. troops on high alert.
However, the strike has also put cybersecurity experts on notice. Alongside Russia and China, Iran is a formidable cyber adversary. Indeed, “incidents involving Iran have been the most sophisticated, costly, and consequential attacks in the history of the internet,” claims the Carnegie Endowment for International Peace, which has charted the rise of Iranian cyber warfare.
In the past, these attacks have targeted vulnerable infrastructure, such as Israel’s internet connectivity, Turkey’s power grid, Saudi Arabia’s oil and government offices, and the control system of a dam located 25 miles north of New York City.
However, U.S. businesses are also within Iran’s sights. In 2016, the Department of Justice indicted seven Iranians for a retaliatory cyber attack against U.S. banks that blocked customers from accessing their online accounts. Two years later, nine additional Iranians for were charged with executing one of “the largest state-sponsored computer hacking campaigns ever” targeted at more than 140 universities, 30 U.S. companies, and five government agencies.
A dark horse on the cyber landscape
Despite the progression of cyber hostility from Iran, very little is known about the state’s cyber warfare capabilities. It’s entirely possible that Iran already has a persistent presence on business or government networks and is simply lying in wait for orders to attack – a common practice among sophisticated hackers.
It’s important to note, however, that Iran is strategic and poised in its cyber attack strategy. It’s known for taking time to review its options and plan retaliation. This potential window gives U.S. organizations valuable time to shore up their defenses.
According to cyber security experts, now is the time for major organizations to do just that.
"If I were advising the pizzeria down the street, I'd say you're probably not high on the target list, but if you're operating a critical infrastructure or a high-profile, large corporation, I would raise the alert status for your cybersecurity teams," Michael Daniel, a former cybersecurity adviser to President Obama who now serves as president of the Cyber Threat Alliance, told NBC News.