U.S. Unprepared for Cyber Attack, Simulation Shows

slfisher 0 Tallied Votes 544 Views Share

40 million people were without power in the eastern United States, more than 60 million cellphones were out of service, and Wall Street was closed for a week due to a terrorist cyberattack against the United States.

No, it didn't really happen. But it could.

Coverage of a simulated cyber attack on the United States, held yesterday by the , will be aired on CNN on Saturday, February 20 and Sunday, February 21 at 8:00pm, 11:00pm and 2:00am ET each night under the title “We Were Warned: Cyber Shockwave."

"The simulation envisioned an attack that unfolds over a single day in July 2011," the Bipartisan Policy Center said. "When the Cabinet convenes to face this crisis, 20 million of the nation's smart phones have already stopped working. The attack, the result of a malware program that had been planted in phones months earlier through a popular “March Madness” basketball bracket application, disrupts mobile service for millions. The attack escalates, shutting down an electronic energy trading platform and crippling the power grid on the Eastern seaboard."

Participants included a number of present and past Congressional and Presidential advisors, playing their roles in real time, without knowing the scenario in advance, the Center said.

"Americans need to know that they should not expect to have their cellphone and other communications to be private -- not if the government is going to have to take aggressive action to tamp down the threat," said Jamie S. Gorelick, a deputy attorney general under President Bill Clinton, in an article in the Washington Post, going on to recommend that the Obama administration seek legislation for comprehensive authority to deal with a cyber emergency.

Such legislation is already under discussion. "However, the worst-case scenario presented in a Washington hotel ballroom Tuesday would almost certainly overwhelm the administration's proposed cyber defenses," according to an article in the Los Angeles Times.

The private sector is not prepared to defend against a cyber act of war and that the government needed to play a role, said Stewart Baker, a former assistant secretary at the Department of Homeland Security who played the "cyber coordinator," the Post said.

To make the scenario even worse, "For reasons never explained, homemade bombs exploded by electric power stations and gas pipelines in Tennessee and Kentucky. And a monster Category 4 hurricane slammed into the Gulf Coast," the Times added.

Dani AI

Generated

As noted, that exercise was useful because it treated cyber disruption as an operational problem that cascades across sectors rather than as an isolated IT incident. The practical takeaway is simple: move from “if” to “when” planning, and use a risk-based resilience framework as the organizing principle (for example, the NIST Cybersecurity Framework). (nist.gov)

Two technical gaps keep showing up in these scenarios. First, consumer-facing mobile apps and third‑party distribution channels create supply‑chain and endpoint risks; enterprises should treat mobile apps and BYOD with the same lifecycle controls as servers and workstations (MDM/EMM, app vetting, code signing, endpoint telemetry). () Second, industrial and utility control systems need OT‑specific controls: network segregation, application whitelisting for PLCs/RTUs, and tailored monitoring and patching processes. (csrc.nist.rip)

A short, practical checklist for network and infrastructure teams:

  • Map critical dependencies and single points of failure (power, telecom, DNS, trading systems).
  • Enforce segmentation (enterprise vs OT), strict egress filtering, and deny‑by‑default ACLs.
  • Harden endpoints and mobile devices via MDM, app whitelisting, and certificate pinning.
  • Keep offline, tested backups and documented recovery playbooks; rehearse restores regularly.
  • Centralize logs, tune detection rules, and automate IOC sharing with partners.
  • Pre‑negotiate communications and legal escalation paths for emergency actions.

Turn tabletop lessons into policy. Use an incident‑handling lifecycle in playbooks (prepare → detect → analyze → contain → eradicate → recover → lessons learned), align exercises to those phases, and make sure reporting/assistance channels are practiced — including CISA reporting and coordination routes. (csrc.nist.gov)

Further reading and templates are available from the NIST publications and CISA pages linked above; they provide concrete checklists and exercise guides that map directly to the checklist here. (nist.gov)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.