Colonial pipeline shutdown highlights need for better OT cybersecurity practices

Colonial pipeline shutdown highlights need for better OT cybersecurity practices

In one of the most disruptive cybersecurity incidents to take place in the United States, Georgia-based Colonial Pipeline announced late Friday that it was the victim of a cyberattack, later confirmed to be a ransomware attack. The company said it proactively took specific systems offline and halted all pipeline operations.

[ Learn what you need to know about defending critical infrastructure . | Get the latest from CSO by signing up for our newsletters. ]

Colonial called in federal authorities and hired FireEye Mandiant to conduct an incident response investigation. On Sunday, the third day of its shutdown, Colonial said it was developing a system restart plan while keeping its four main oil lines offline. The company said it would bring its "full system back online only when we believe it is safe to do so, and in full compliance with the approval of all federal regulations."

To read this article in full, please click here



Support the originator by clicking the read the rest link below.