ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

67% of Energy Sector Breaches Linked to Software and IT Vendors, SecurityScorecard Reports

Energy sector faces surge in supply chain risks amid growing dependence on vendors

SecurityScorecard and KPMG LLP today released a co-authored new cybersecurity research report on the 250 largest U.S. energy companies. In “A Quantitative Analysis of Cyber Risks in the U.S. Energy Supply Chain,” security researchers and industry subject professionals provide a detailed analysis of cybersecurity vulnerabilities across the energy sector and its supply chains.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241023313100/en/

(Graphic: Business Wire)

(Graphic: Business Wire)

Novel insights into energy sector cybersecurity

This report arrives at a pivotal moment as regulatory bodies worldwide intensify cybersecurity requirements and initiatives for the U.S. energy sector. It aligns with global efforts to bolster cybersecurity across the energy supply chain, reflecting commitments made during the June 2024 G7 summit to enhance defenses against escalating cyber threats. The White House just convened the fourth round of International Counter Ransomware Initiative (CRI) meetings. CRI’s 68 members issued a joint statement following the meeting, which continued “the joint commitment to develop a collective resilience to ransomware.” In parallel, the U.S. Department of Energy is actively convening energy sector leaders to advance the Supply Chain Cybersecurity Principles.

SecurityScorecard’s latest research highlights frequent threats, such as ransomware attacks on conventional IT systems, which are often enough to cause widespread disruption across the energy sector. Much attention has been paid to potential attacks on industrial control systems (ICS) and operational technology (OT), which will continue to be a focus for risk mitigation. As the shift to cleaner energy accelerates, however, the sector’s vulnerabilities may grow, as a greener, more interconnected grid becomes increasingly reliant on software, making it more susceptible to cyberattacks.

Ryan Sherstobitoff, Senior Vice President of Threat Research and Intelligence at SecurityScorecard, said:

“The energy sector's growing dependence on third-party vendors highlights a critical vulnerability — its security is only as strong as its weakest link. Our research shows that this rising reliance poses significant risks. It’s time for the industry to take decisive action and strengthen cybersecurity measures before a breach turns into a national emergency.”

Key findings

  • Third-party risks are disproportionately high in the energy sector: Third-party risk drives almost half (45%) of breaches in the energy sector. This is significantly higher than the global rate of 29%. Additionally, 90% of companies that suffered multiple breaches were hit via third-party vendors.
  • U.S. energy scores a "B” on cybersecurity: The U.S. energy industry scores a "B" on average based on SecurityScorecard’s scoring methodology. 81% of companies have either an A or B rating, but the remaining 19% with weak scores pose a significant risk to the entire supply chain.
  • Software and IT vendors are the leading cause of third-party breaches: Software and IT vendors outside the energy sector are the main source of third-party breaches. Of the incidents studied, 67% of third-party breaches were due to software and IT vendors, with only four involving other energy companies.
  • Renewable energy companies fall behind: Oil & natural gas companies scored well above average with an “A−,” while renewable energy firms lagged behind with a “B−” score.
  • Vulnerabilities condensed in key risk factors: 92% of companies had their lowest scores in just 3 of 10 risk factors: application security (40%), network security (23%), and DNS (Domain Name System) health (29%).

Cybersecurity recommendations for the energy industry

Based on this analysis, the SecurityScorecard STRIKE team offers actionable insights for enhancing cybersecurity in the energy sector:

  • Prioritize software & IT vendors: Focus on mitigating risks from software and IT vendors, which pose the highest third-party risks.
  • Emphasize product security in new acquisitions: Help ensure that new technology acquisitions are secure, following initiatives like CISA's "Secure by Design" and integrating the U.S. Department of Energy Supply Chain Cybersecurity Principles.
  • Prioritize the improvement of security around renewable energy sources: Strengthen security programs to protect against potential supply chain risks and geopolitical threats, particularly from nation-states.
  • Prepare for disruptions and balance other risks: Prepare for disruption without neglecting the pervasive risk of data breaches and other common cyber threats.
  • Learn from attacks on foreign targets: Gain valuable insights by studying ransomware attacks on foreign counterparts to improve resilience and cybersecurity defenses.

Prasanna Govindankutty, Principal, Cyber Security US Sector Leader, at KPMG, said: “The energy industry is a complex system that is undergoing a generational transition with a heavy reliance on a steady supply chain. With geopolitical and technology-based threats on the rise, this complex system is facing an equally generational risk exposure that could harm citizens and businesses alike. Organizations that are able to quantify these risks and establish mitigation measures will increase their odds of success in the energy transition journey.”

Methodology

SecurityScorecard researchers compiled a sample of 250 top U.S. energy companies, based on market capitalization and the various sectors of the industry that they represent. These sectors cover: the successive stages of the traditional oil & gas supply chain; the existence of vertically integrated oil & gas companies covering that whole supply chain; the consumption of some energy via utilities; and the emergence of companies devoted to renewable energy sources.

Additional resources

About STRIKE

The STRIKE threat intelligence team combines unique threat intelligence, incident response experience, and supply chain cyber risk expertise. Backed by SecurityScorecard technology, STRIKE is a strategic advisor to CISOs worldwide, empowering the entire digital ecosystem to identify, measure, and resolve cyber risk.

About SecurityScorecard

Funded by world-class investors, including Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings, response, and resilience, with more than 12 million companies continuously rated.

Founded in 2014 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard’s patented security ratings technology is used by over 25,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight.

SecurityScorecard makes the world safer by transforming how companies understand, improve, and communicate cybersecurity risks to their boards, employees, and vendors. SecurityScorecard achieved the Federal Risk and Authorization Management Program (FedRAMP) Ready designation, highlighting the company’s robust security standards to protect customer information, and is listed as a free cyber tool and service by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Every organization has the universal right to its trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

Contacts

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.