October 23, 2020 By Carol J. Holahan
Categories: China , Cybersecurity & Cybercrime , Government Enforcement , Security & Privacy Alerts
On October 6, 2020, the Department of Homeland Security (“DHS”) released a 2020 Homeland Threat Assessment (“HTA”). According to Acting Secretary Chad F. Wolf, the “first of its kind report” identifies the primary threats facing the nation and analyzes the vast array of information coming from all DHS operational components that crosses his desk on a daily basis. “When the American people read this HTA they will be more aware of the traditional threats facing the Homeland like terrorism and organized crime. However, I think they will also realize that we face a significant threat in the Homeland from nation-states like China, Russia, and Iran.”
The genesis for the HTA is DHS' September 2019 publication, strategic framework for countering terrorism and targeted violence, which called for the DHS to produce an annual report on threats facing the Homeland in order to inform the public, government and private sector. According to the HTA, cyber threats to the nation from both nation-states and non-state actors will remain “acute” and the nation's critical infrastructure, including energy, health care and transportation sectors, should expect advanced threats of cyber-attacks. And these attacks, designed to disrupt, destroy and obtain both sensitive information and money, will be directed at the private sector as well as Federal, state, local, tribal and territorial governments. While the report identifies Russia and China as “the most capable nation-state cyber adversaries,” it also emphasizes that Iran and North Korea are a threat to U.S. critical infrastructure and systems.
Consistent with its “vital mission: to secure the nation from the many threats” it faces, the HTA's findings address seven separate areas and draw the following conclusions:
The HTA both identifies the threats facing the nations and explains how DHS will deploy its “tools and expertise” to combat those threats. Without a doubt, the COVID-19 pandemic is only exacerbating existing concerns about and opportunities for threats, both physical and cyber, against the U.S. and its citizens. While it is clear from the HTA that foreign terrorist attacks continue to remain a core priority of DHS's counterterrorism efforts, it is equally clear that the HTA recognizes and is preparing to thwart the growing threats from domestic terrorism.
While threats to the bulk power system are not singled out in the HTA, DHS' previous warnings of increased cyberattacks against the energy sector are discussed here. The very real nature of the potential for cyberattacks in the energy sector was again highlighted when, on October 21, the U.S. Justice Department unsealed an indictment against six Russian intelligence officers alleged to have masterminded a series of notoriously destructive cyberattacks between late 2015 and late 2019. Among those indicted were two officers allegedly responsible for using malware to successfully compromise three Ukrainian power distribution companies in late 2015. The attack caused a wide-spread blackout that left more than 250,000 Ukrainians without power in December 2015. This event is widely considered the first successful cyberattack on a power grid and serves as a tangible reminder of the energy sector's vulnerability to cyber interference.