DHS Pursues New Pipeline Cybersecurity Mandates

(Bloomberg) -- Pipeline operators who fail to report cybersecurity attacks to the Department of Homeland Security could face fines of $7,000 a day or more under regulations being released Thursday in response to the ransomware attack that temporarily paralyzed the nation’s biggest fuel pipeline.

The so-called security directive being issued by Homeland Security will be followed in the near future by an additional set of rules for pipeline operators, according to senior department officials who asked not to be identified.

The new mandates, a shift from a long-held system of voluntary guidelines and self-reporting, is in response to the ransomware attack on Colonial Pipeline Co.

In addition to requiring pipeline owners to report incidents, Thursday’s security directive to companies that operate about 100 critical pipelines would stipulate that a designated representative be available around the clock as the point of contact, one of the officials said during a background briefing with reporters.

The directive would also require operators to compare their practices with Transportation Security Administration guidelines and identify and report risks, the official said.

That has pipeline operators concerned the new measures could be harmful to the department’s voluntary system.

“Pipeline operators want to avoid a ‘ready, fire, aim’ approach from the government where we fail to incorporate lessons learned from Colonial or potentially make things worse by regulating the wrong thing or doing it in the wrong way,” said John Stoody, a spokesman for the Association of Oil Pipe Lines, which counts Colonial among its members, said before the regulations were unveiled.

The department officials said they still planned to work collaboratively with the pipeline industry, even as Homeland Security works to craft more structured oversight.

Unlike power plants, U.S. pipelines have not been required to follow any federal cybersecurity mandates, even though Homeland Security was given the authority to impose them through its Transportation Security Administration when it was created in the wake of the Sept. 11, 2001, terrorist attacks.

That’s been an approach the industry has championed -- and fought for as well. An effort in 2012 to require cyber regulations for pipelines and other significant infrastructure through legislation failed after intense lobbying by oil companies and other corporate interests.

The new measures come after hackers who stole data and locked computers forced the shutdown of Colonial’s roughly 5,500-mile-long (8,851-kilometers) pipeline system for nearly a week. The pipeline, which provides about 45% of the fuel used on the East Coast, was turned back on after company paid a $5 million ransom, but not before the shutdown caused shortages at gas stations.

“Any potential regulations should enhance reciprocal information sharing and liability protections, as well as build upon our robust existing public-private coordination to streamline and elevate our efforts to protect the nation’s critical infrastructure,” said Suzanne Lemieux, the American Petroleum Institute’s manager of operations security and emergency response.

© 2021 Bloomberg L.P.

DHS Pursues New Pipeline Cybersecurity Mandates DHS Pursues New Pipeline Cybersecurity Mandates Reviewed by Crude Oil Brokers on 22:26 Rating: 5

No comments:

Trending Oil Industry News

About Crude Oil Brokers Ltd

Crude Oil Brokers Ltd is a dedicated global crude oil buyer and seller brokering or facilitating company. We are a United Kingdom and Nigerian based firm, privately owned and devoted to the oil buying and selling brokering.

We have buyers and sellers of;

1. Nigerian Bonny Light Crude Oil, BLCO

2. D2 Diesel Fuel, JP54 Jet Fuel, Mazut etc.

3. Saudi Light Crude Oil, SLCO

4. Iraqi Light Crude Oil

If you are a buyer or seller of crude oil or other petroleum products or have mandate to buy or sell any of the above oil products, do contact us because we could be of help.

To contact Crude Oil Brokers, click here ». To learn more about Crude Oil Brokers Ltd, click here


Crude Oil Brokers

Powered by Blogger.