Addressing the challenge of cyber security maintenance through patch management
Adam Gauci, Sébastien Michelin, Mathieu Salles · CIRED - Open Access Proceedings Journal · 2017
In December 2015, a confirmed cyber-attack targeting several electric power utilities in Eastern Europe has resulted in a power outage that impacted hundreds of thousands of utility customers. This event strongly indicates that distribution system operators (DSOs) systems are vulnerable and are high risk of being targeted. With many new connected components inside the DSO's systems and readily available vulnerability information on the Internet, there is a greater risk of outages due do cyber-attack. To help reduce risk and potential cyber-attack surface, DSOs must implement a security organisation and adopt active security processes. This study will describe one of those processes that must be actively maintained. Mitigating risk and anticipating vulnerabilities on utility grids is not just about installing once at the latest technology. DSOs must also pay special attention to implement regular or routine maintenance of equipment, which includes patch management and necessary security updates in the system. DSOs are today facing difficulties to deploy an efficient patch management programme. A suggested methodology and a smart patch management system based on IEC62443-2-4 standard will be discussed, comprising: (i) a process for vulnerability detection, (ii) a tool to automatically assess DSO system components, (iii) a corrective patch implementation recommendation.