{"id":854,"date":"2021-02-22T17:02:00","date_gmt":"2021-02-22T17:02:00","guid":{"rendered":"https:\/\/dev.cryptoloc.au\/?p=854"},"modified":"2023-10-03T06:21:41","modified_gmt":"2023-10-03T06:21:41","slug":"why-the-mining-industry-should-be-taking-cybersecurity-seriously","status":"publish","type":"post","link":"https:\/\/127.0.0.1\/why-the-mining-industry-should-be-taking-cybersecurity-seriously\/","title":{"rendered":"Why the mining industry should be taking cybersecurity seriously"},"content":{"rendered":"\n

Cybersecurity is a dangerous blind spot for the mining industry \u2013 but it shouldn\u2019t take a catastrophic event for businesses to start taking this threat seriously.<\/p>\n\n\n\n

Report after report has found that the mining industry is failing to grasp the seriousness of cybersecurity attacks. PricewaterhouseCoopers\u2019 Mine 2020: Rocky but Resilient<\/em> <\/a>report, for instance, found that the percentage of mining and metals CEOs who are extremely concerned about cyber threats has actually gone down in recent years, from 21 per cent in 2018 to 12 per cent in 2020 \u2013 despite a four-fold increase in the number of reported cyber breaches among mining companies over a similar period.<\/p>\n\n\n\n

In 2019, State of Play\u2019s Cybersecurity report<\/em><\/a> analysed Australia\u2019s largest mining companies, including BHP, Rio Tinto, South32 and Anglo American, and found that 98 per cent of top-level executives believed it would take a catastrophic event to drive an industry-wide response to cybersecurity.<\/p>\n\n\n\n

What can go wrong?<\/h3>\n\n\n\n

Cryptoloc founder and chairman Jamie Wilson says the stakes are high when it comes to cybersecurity and the mining industry. In today\u2019s increasingly automated and interconnected world, a successful attack could put mining operations, equipment and data at risk \u2013 and it could threaten people\u2019s lives.<\/p>\n\n\n\n

\u201cIf someone hacks into a mining system, then they can take control of that system and its operations remotely,\u201d he warns. \u201cSo if you\u2019ve got autonomous vehicles running around, they could take control of those vehicles. You don\u2019t want trucks on a mine site crashing into each other, into equipment, or into human beings.<\/p>\n\n\n\n

\u201cAnd that\u2019s just the tip of the iceberg \u2013 what if you\u2019ve got people underground, and a bad actor shuts off their air supply?\u201d<\/p>\n\n\n\n

Wilson notes that cyber espionage is another major concern for mining organisations that are \u201crich in data and information\u201d, all of which could be leveraged by cyber attackers. In 2011, for instance, BHP was targeted by attackers<\/a> seeking to gain access to market pricing for key commodities.<\/p>\n\n\n\n

Phishing attacks, usually in the form of malware attached or linked to in an email, are increasingly common in the mining industry. A Symantec internet security threat report<\/a> found that more than 38 per cent of the users in the mining industry had been hit by a malicious email, a higher percentage than any other industry.<\/p>\n\n\n\n

This is no idle threat, either \u2013 Canadian mining company Goldcorp lost over 14 gigabytes of corporate data<\/a> in a 2016 attack; a cyber attack on a German steel mill caused \u201cmassive damage\u201d to a blast furnace<\/a> in 2014; and Norsk Hydro, one of the world\u2019s largest aluminium companies, was dealt up to $70 million in damage<\/a> after opening an email infected with ransomware in 2018.<\/p>\n\n\n\n

Why is the mining industry vulnerable?<\/h3>\n\n\n\n

Thomas Leen, Global Head of Cybersecurity at BHP, has said that the mining industry has \u201ca low level of cybersecurity maturity<\/a>\u201d, mainly due to \u201clegacy environments that lack basic capabilities\u201d.<\/p>\n\n\n\n

Cryptoloc\u2019s Jamie Wilson agrees that mining is particularly vulnerable to cyber attacks because of the archaic processes and technologies that are commonplace in the industry.<\/p>\n\n\n\n

\u201cSome of the mining systems that are currently in use were developed as far back as the 1970s,\u201d he says. \u201cWe\u2019re talking about very specialised machines that run on very specialised software. These machines are worth large sums of money, and downtime is extremely costly. So it\u2019s a major challenge for some of these companies to say, \u2018You know what, let\u2019s overhaul our system and start taking cybersecurity seriously\u2019.<\/p>\n\n\n\n

\u201cHonestly, I get it. I can see why mining executives put cybersecurity at the bottom of the priority list, because the cost of making the necessary updates is substantial in terms of downtime. You start running behind time and you\u2019re looking at massive amounts of money.<\/p>\n\n\n\n

\u201cThat\u2019s why most of these executives aren\u2019t going to take it seriously until they fall victim to a catastrophic cyber attack. That\u2019s when they\u2019ll turn around and say, \u2018We\u2019ve got to do something because it\u2019s happened now and it will happen again\u2019.<\/p>\n\n\n\n

\u201cUntil that happens, until a disaster forces their hand, you\u2019re really looking at an industry that prioritises revenue over security.\u201d<\/p>\n\n\n\n

Short of a catastrophic event, Wilson believes the mining industry will only change its approach to cyber security if it is forced to by government-led initiatives and legislation.<\/p>\n\n\n\n

\u201cIt reminds me of the industry\u2019s approach to health and safety,\u201d he says. \u201cThere was a time, not that long ago, when businesses wouldn\u2019t worry about putting up safety nets and scaffolding and things like that. Today, health and safety is everyone\u2019s number one priority, because they have to comply with strict legal obligations.<\/p>\n\n\n\n

\u201cWe need to see those types of expectations being applied to cyber security \u2013 it needs to be a basic policy, for instance, for mining companies to start securely encrypting their data, so they can control who has access to their information.<\/p>\n\n\n\n

\u201cBut it needs to be driven from the top down. We need to see the government putting forward cyber practices and policies to protect the people \u2013 because otherwise, there\u2019s too much profit at stake for the industry to police itself.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"

Cybersecurity is a dangerous blind spot for the mining industry \u2013 but it shouldn\u2019t take a catastrophic event for businesses to start taking this threat seriously. Report after report has found that the mining industry is failing to grasp the seriousness of cybersecurity attacks. PricewaterhouseCoopers\u2019 Mine 2020: Rocky but Resilient report, for instance, found that the percentage […]<\/p>\n","protected":false},"author":3,"featured_media":1104,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts\/854"}],"collection":[{"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/comments?post=854"}],"version-history":[{"count":2,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts\/854\/revisions"}],"predecessor-version":[{"id":1142,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts\/854\/revisions\/1142"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/media\/1104"}],"wp:attachment":[{"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/media?parent=854"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/categories?post=854"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/127.0.0.1\/wp-json\/wp\/v2\/tags?post=854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}