{"id":11522,"date":"2015-12-17T09:30:18","date_gmt":"2015-12-17T17:30:18","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=11522"},"modified":"2020-04-21T14:27:52","modified_gmt":"2020-04-21T21:27:52","slug":"the-cybersecurity-canon-lights-out-a-cyberattack-a-nation-unprepared-surviving-the-aftermath","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2015\/12\/the-cybersecurity-canon-lights-out-a-cyberattack-a-nation-unprepared-surviving-the-aftermath\/","title":{"rendered":"The Cybersecurity Canon: Lights Out: A Cyberattack, A Nation Unprepared, Surviving the Aftermath"},"content":{"rendered":"<p><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red.png\"><div style=\"max-width:100%\" data-width=\"500\"><span class=\"ar-custom\" style=\"padding-bottom:43.6%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter size-large wp-image-9648 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-500x218.png\" alt=\"cybersec canon red\" width=\"500\" height=\"218\" srcset=\"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-500x218.png 500w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-230x100.png 230w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-510x223.png 510w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-91x40.png 91w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red.png 786w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/span><\/div><\/a><\/p>\n<p><em>We modeled the Cybersecurity Canon after the Baseball or Rock &amp; Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. <a href=\"https:\/\/paloaltonetworks.com\/threat-research\/cybercanon\/nominate-a-book.html\" target=\"_blank\" rel=\"noopener noreferrer\">Please write a review and nominate your favorite<\/a>.\u00a0<\/em><\/p>\n<p><em>The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!<\/em><\/p>\n<p><strong>Book Review by <a href=\"https:\/\/www.paloaltonetworks.com\/threat-research\/cybercanon\/cyber-security-canon-bios.html\" target=\"_blank\" rel=\"noopener noreferrer\">Canon Committee Member, Ben Rothke<\/a>:\u00a0<\/strong><em>Lights Out: A Cyberattack, A Nation Unprepared, Surviving the Aftermath <\/em>(2015)<em>\u00a0<\/em>by Ted Koppel<!--more--><\/p>\n<h3>Executive Summary<\/h3>\n<p>One of the most successful television commercials in history was for the financial firm E. F. Hutton, based around the catchphrase, \"When E. F. Hutton talks, people listen.\"<\/p>\n<p>In the world of broadcast journalism, when Ted Koppel speaks, people listen. And when he writes, people read. And read indeed, as his new book <a href=\"http:\/\/www.amazon.com\/gp\/product\/055341996X\/ref=as_li_tl?ie=UTF8&amp;camp=1789&amp;creative=390957&amp;creativeASIN=055341996X&amp;linkCode=as2&amp;tag=benrothkswebp-20&amp;linkId=DIE2N3V6BQLBONKD\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Lights Out: A Cyberattack, A Nation Unprepared, Surviving the Aftermath<\/em><\/a> is in the Amazon top 200.<\/p>\n<p>Yet, with his over 50 years of journalistic experience, this book shows that, just because you are a world-renowned reporter, that doesn\u2019t mean you always get the story right.<\/p>\n<h3>Review<\/h3>\n<p>The problem with Ted Koppel\u2019s book is that his approach to the topic is anything but structured and methodical. He sets up a straw man question, never fully identifies the threats facing the power grid, and never gives specific weights to those threats, such that the reader is left with Chicken Little meets the power grid. The book\u2019s premise is that a major and devastating cyberattack on America\u2019s power grid is imminent. While it\u2019s a disturbing hypothesis, never once does Koppel detail how such an attack would actually take place.<\/p>\n<p>Throughout the book, Koppel sets up his straw man and uses terms such as <em>imagine,<\/em> <em>may, could<\/em> and similar, tenuous phrases. While these doomsday and worst-case scenarios are indeed terrifying, never does the book detail the specific <em>how<\/em>. Much of the book contains details of Koppel\u2019s travels and narratives of the people he meets. From <em>preppers<\/em> in Montana, to leaders of the Mormon Church, whose doctrines include planning for cataclysmic events, and more. This is a detail of Ted\u2019s great adventure.<\/p>\n<p>One of the more disturbing interviews is with Jeh Johnson, Secretary of the Department of Homeland Security. Johnson comes across somewhat clueless of the energy sector cyberthreat, about which Koppel noted that, while Johnson\u2019s answer to Koppel\u2019s question lasted 13 minutes, he never addressed the question, and it was an area in which Johnson conceded that he had little expertise.<\/p>\n<p>Koppel admits that he is not proficient in the complicated energy sector. To help him navigate through the arcane world of grid reliance standards and the evolving relationship between power industry groups and federal regulators, Koppel engaged the services of Dr. Ryan Ellis of the Cyber Security Project at Harvard University. Koppel notes that he sent transcripts of key interviews and rough drafts of relevant chapters to Dr. Ellis for his review and comments. Incredulously and disconcertingly, Koppel states that he didn\u2019t always follow the advice of Dr. Ellis.<\/p>\n<p>What Koppel did is speak to a lot of very senior people and put what he gleaned into writing. What\u2019s conspicuously missing is his speaking to any cybersecurity expert with experience in SCADA, malware or related areas. In an <a href=\"http:\/\/www.csoonline.com\/article\/3004637\/critical-infrastructure\/ted-koppel-discusses-the-inevitable-cyberattack-on-us-infrastructure.html\" target=\"_blank\" rel=\"noopener noreferrer\">interview<\/a> for CSO Online, Koppel was asked if he interviewed penetration testers who have experience in the electric generation and transmission sector. Incredulously, he said \u201cno.\u201d I don\u2019t think Koppel understands the significance of that exclusion, and therein is the fundamental problem with this book.<\/p>\n<p>There are indeed threats to the power grid. But, if you want to know about those \u2013 the real threats and how they can be dealt with \u2013 this is not your book.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We modeled the Cybersecurity Canon after the Baseball or Rock &amp; Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting &hellip;<\/p>\n","protected":false},"author":40,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[155,4521],"tags":[251],"coauthors":[1379],"class_list":["post-11522","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-2","category-canon","tag-cybersecurity-canon"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/11522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=11522"}],"version-history":[{"count":3,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/11522\/revisions"}],"predecessor-version":[{"id":109917,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/11522\/revisions\/109917"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=11522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=11522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=11522"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=11522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}