yhtomit week2
Manto - the Power Industry may change its Business Model (VIF 03_02) (3:22)
How prepared are managers of the critical infrastructures to respond to the cascading effects of a major cyber-attack?
Denial of Service attacks which are implicit in traditional cyber-attacks or electromagnetic pulse attacks, or what some may call intentional electrical interference attacks, are complex and very serious. Not only because of how vulnerable we are, but also because of how unaware of our vulnerabilities we are. That’s due to several different factors. First of all, our society has stumbled our way into maximizing efficiency by minimizing resiliency, and we have grown so much more effective and so much more interdependent on all of these technologies that most of us are totally unaware of what most of those vulnerabilities are. As we begin to learn about them, it becomes difficult to understand not only how we’re impacted but also what in the world we might be able to do about it.
It will begin to shift how we do things and I’ll give you a quick example in the power industry. For example, the power industry in America today is basically a collection of regional power grids. For the most part, it is very unlikely that the local community will do well or thrive if there was a 16-18 month power outage. However, some communities that make their own power might be able to do better than those that are dependent solely on power from other communities at great distance away from them. For that reason, I think you will see a move in the next 20-30 years for the business model of power companies and utilities to change, where they will make much more use of what’s called distributed energy. That’s where you make more of your power locally and store it locally. You might see as much as 20-30 percent of the power used by most companies and communities turning out to be locally developed and stored. When we get to that position, we will be a far more secure country, because our energy security will not just be a house of cards that will be easily folded, but something that will be more resilient.
Also, in cases such as EMP, it’s a lot easier to EMP protect something that might be the power structure of a building or campus, then something that might be half of a state. The same thing might be true of cyber security. If you really understand cyber security and controls well, it might be easier to audit the ones that are under your prevue and control as opposed to those under organizations not under your control. Again, if we take cyber security seriously and critical infrastructure security seriously, we will want to have less reliance on others and more ability to help ourselves and our neighbors.