Australia is at a new frontier of property and infrastructure investment, one in which investors don’t require sweeping views of the Sydney Harbour. Data center investment has skyrocketed in Australia; in June, Amazon announced it would invest AU$20 billion (US$13.3bn) to expand data center infrastructure in Australia.
Both Sydney and Melbourne rank among the top 10 markets for data centers in Asia-Pacific. A more stringent set of cybersecurity regulations, a multitude of subsea cables to Asia, and reliable energy sources are making Australia an attractive location for global and local data center organizations.
But if the Australian government wants to become a global leader in developing and adopting trusted, secure, and responsible artificial intelligence, we need to have even stricter cybersecurity protocols for all data center infrastructure.
In Australia, under the SOCI Act 2018, data centers are considered a critical infrastructure asset. This means there are compulsory security measures in place, such as providing ownership information to the Register of Critical Infrastructure assets, reporting cyber incidents, and complying with a written critical infrastructure risk management program.
Within this risk management plan, inclusion of operational technology cybersecurity is critical.
An attractive victim
In an age where data is the new gold, it is no surprise that data centers are a prime target for cybercriminals. And the amount of data they can store is nearly unfathomable: take one data center in Melbourne, which can famously store 800 petabytes of data – the equivalent of roughly 176 million DVDs (for those that can remember what a DVD is).
This makes the infiltration of a data center and its network highly desirable for cybercriminals – not just for the information contained within, but also for the potential ransom payment they could command to release it.
Recently, Indonesia’s national data center was compromised by a cyberattack. This disrupted several government services, including immigration, where long lines amassed at airports as automated passport machines stopped working.
The nefarious group asked for a ransom payment of nearly AU$12 million (US$8m). The government refused to pay.
Due to the widespread disruption caused by infiltrating a data center, it is plausible that other organizations would pay a ransom to ensure the network is back up and running quickly.
Other cyberattacks could include targeting the operational technology, which creates the specific environment data centers need to function. There are multiple entry points a cybercriminal can use to gain access, particularly when you consider the assets and endpoints that connect to the data center.
Cybersecurity for security cameras?
Heating, Ventilation, and Air Conditioning (HVAC) systems, temperature sensors, emergency power generators, physical access control systems, CCTV cameras, and building management systems (BMS) are crucial to ensuring optimal, highly available environments in data centers.
Many of these systems are third-party operational technology (OT) or Internet of Things (IoT) devices. Most of the time, these systems are not securely connected to the Internet, creating a chasm of loopholes in the data center’s cybersecurity infrastructure.
Cybercriminals know these devices are easy entry points. Once infiltrated, it may allow the nefarious actor to gain access to a much wider network.
Let’s take the HVAC system as an example. If the cooling system were to malfunction due to a cyberattack, an outage would lead to a rapid temperature increase, and to prevent overheating or the risk of fire, the data center would need to shut down.
This is not just theoretical, as 13 vulnerabilities were recently found to be affecting the Tridium Niagara Framework – a software platform that connects, manages, and controls building and industrial systems like HVAC, lighting, security, and manufacturing equipment.
While this scenario may not risk the infiltration of the data itself, it would shut down the use of the data center. This would lead to a loss of revenue for the data center owner along with widespread disruption for its customers.
Meanwhile, easily-exploitable assets like wireless CCTV cameras use stripped down operational security systems and minimal encryption or authentication. Nozomi security researchers recently discovered vulnerabilities in several popular CCTV devices.
For data centers to be truly “safe”, the risk management plan outlined in the SOCI Act needs to include an in-depth, automated asset inventory of all OT and IoT devices connected to the network.
This way, the security team can visualize information about each asset and its risk profile. It also helps to detect cyber incidents and operational anomalies, identifying equipment or network stability issues before they cause harm.
An automated system can greatly assist the team in categorizing and prioritizing risks, ensuring the most critical issues are addressed first.
There would be a real irony if the cameras installed for security became the downfall of the data center’s cybersecurity network, causing widespread disruption to businesses and services all over Australia and beyond.
It’s why, as the Australian government looks to make itself a data center leader, it needs to ensure that every aspect of the data center is secure – and not just at the IT server level. Every device, asset, and entry point needs to be more secure than it is now, because we’re seeing time and time again that cyber criminals are relentless in finding the smallest cracks in a door to gain entry.
Comments