Close Menu
Machinery Asia
  • Home
  • Industry News
  • Heavy Machinery
  • Backhoe Loader
  • Excavators
  • Skid Steer
  • Videos
  • News & Media
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Machinery Asia
Subscribe
  • Home
  • Industry News
  • Heavy Machinery
  • Backhoe Loader
  • Excavators
  • Skid Steer
  • Videos
  • News & Media
Machinery Asia
You are at:Home » The race to reengineer cyber security
Industry News

The race to reengineer cyber security

Machinery AsiaBy Machinery AsiaSeptember 9, 2026No Comments8 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email Tumblr

It took six days for Colonial Pipeline Co.’s more than 5,500 miles of connected refined oil delivery infrastructure. from Houston to New York City, was back online after a ransomware cyberattack on May 7, 2021 forced the company to shut down operations and pay $4.4 million for restoration.

The Wall Street Journal reported that a criminal group of hackers gained control of the pipeline system, which supplies about 45 percent of refined petroleum products to 14 states on the East Coast, by compromising one of the company’s virtual private networks. As the backlash from the breach spread across the country in the days that followed, fuel shortages led to long lines and panic buying at some gas pumps amid fears the pipeline could be offline indefinitely.

“We continue to see this evolution of people-oriented systems due to a growing awareness of the potential impact.”

—Nick Andersen, Deputy Director of the Cybersecurity and Infrastructure Agency

After exchanging the ransom for a hacker’s decryption tool that didn’t work properly, then-Colonial Pipeline Co. CEO Joseph Blount, who has since retired, said paying the ransom was “the hardest decision I’ve ever made in my career.” In an interview on national public radio, he added: “If having this decryption tool gets you faster, then it’s the decision that had to be made. It was the right decision for the country.”

For many cybersecurity experts, the incident was a “huge wake-up call” to a war brewing over how to protect cyber data and its real-world assets, says Lucian Niemeyer, CEO of the Bethesda, Maryland-based nonprofit Building Cyber ​​Security. In early June, he joined representatives from the National Academy of Construction, the National Academy of Engineering, and the United Engineering Foundation in Washington, DC, to discuss improving ground-level engineering defenses.

“We’ve determined that there needs to be, for the engineering community, an acknowledgment of the risk, regardless of what the owner wants, and that’s important,” Niemeyer said in his opening remarks at the inaugural National Cyber ​​Security Summit, with about 50 invited attendees. “There has to be a subset of controls that are mandatory. They’re like an electrical system. You have to put certain technologies in with certain protections.”

In an agenda featuring cybersecurity experts from across the country and a keynote address by Nicholas M. Andersen, Acting Director of the Cybersecurity and Infrastructure Agency, a unit of the U.S. Department of Homeland Security, attendees were briefed on how cyber threats can manifest into public safety risks through compromised operational systems that manage water, energy and telecommunications.

Andersen called data breaches by criminal groups “almost as concerning” as attacks by foreign nations. He said he believes bad actors are more likely to target infrastructure systems because they don’t understand how damage to those systems can escalate quickly. “At least the nation state actors are prepositioning [themselves] within the infrastructure, and they are aware [of what] they’re getting involved,” he said. “The criminal groups that we keep seeing involved in the space, or potential ransomware actors, don’t always know the consequences of where they’re getting involved.”

Andersen added that “In some ways, they’re actually less responsible for an actor within that space. We continue to see [an] evolution of people-oriented systems due to a growing awareness of the potential impact.”

Looking for quick answers on construction and engineering topics?
Try Ask ENR, our new intelligent AI search tool.

Ask ENR →



ENR Construction Cost Data Panel

BEGIN



Lucian Niemeyer
Ed Gibson Jr
Nicholas Andersen

panel of senior experts from the National Security Agency

Cyber ​​Security Summit Speakers (above, l to r) Lucian Niemeyer, Edd Gibson Jr. and Nicholas Andersen; and a group of senior experts from the National Security Agency. US Cyber ​​Command and US Department of Defense
Photos courtesy of Cyber ​​Security Summit

Engineering cybersecurity standards

Following the Colonial Pipeline ransomware attack, the US Department of Energy released recommendations on securing clean energy systems on the nation’s electric grid titled Cybersecurity Considerations for Distributed Energy Resources on the US Electric Grid.

In a call-to-action document released after the summit, the National Academy of Engineering urged that the construction industry should build on these recommendations to create engineering standards for cybersecurity. He notes that engineering standards, professional licensing and insurance “did not develop in isolation.” All “evolved together, each driven by catastrophe, each reinforcing the other, and each expressing the same underlying social compact between the profession and the public it serves.”

The engineering academy added in a statement: that today’s built environment consists of “no longer purely physical objects…[but] cyber-physical systems: hospitals, schools, water treatment plants, transport, robotics and energy systems [that] all rely on networked controls, building automation, [internet of things] devices and infrastructure connected to the cloud”.

According to the academy, keeping these systems safe requires establishing a new standard of care “owned by the design and construction professions” that is “integrated into licenses, codes and contracts,” such as fire, structural and electrical safety, with the support of insurance companies to “reduce price risk and treat failures as professional negligence.”

“The key issue is that this is not a one-party solution. It will take people from all walks of our industry to make this happen.”

—Edd Gibson Jr., CEO of the National Academy of Construction

The standard would be reinforced through “inspection, commissioning and delivery with documented training of owners,” according to the group, there is no time to waste in adopting this standard, “while stakeholders have the opportunity to shape the standards” and not react to the catastrophe.

National Academy of Construction President and CEO Edd Gibson Jr. said moving forward on the report’s action items requires the participation of participants from across the industry.

“The key issue is that this is not a one-party solution,” he said. “It will take people from all walks of our industry to make this happen.” Gibson said the mission includes educating people entering the construction industry and those already in the workforce.

“It needs contractors, designers, especially owners to understand what kind of problems their facilities can face, and obviously governments involved in trying to protect the general public,” he said. “It’s hard when these things are slow, but that’s what’s needed because there’s a lot of people who have to commit to it.” He called the cyber risk “a clear and present danger to our country.”

The “X” factor of AI

According to a filing with the California attorney general’s office, Turner Construction on Aug. 18 notified about 6,098 people of a data breach that resulted in their information, including bank account information, dates of birth, wages and Social Security numbers, being illegally removed from the contractor’s systems between July 2 and July 15 by the Payout King ransomware group.

The hacker claimed in an online post that the information accessed also included engineering documents, contracts, confidentiality agreements, some passport numbers and military project files.

In a statement provided to ENR, a Turner spokesperson noted that cybersecurity is a “growing challenge” for all organizations. “The increasing use of technology in the construction industry makes protection systems, information and projects more important than ever,” the spokesman said. “Upon discovering unauthorized access to certain systems, Turner engaged leading third-party cybersecurity and forensics experts to investigate. We took steps to further secure our systems and continued to conduct a detailed review of the incident.”

Turner said the experience “reinforces the importance of preparedness, resilience and having the right resources and relationships in place before an incident occurs.” For the company, a leading data center contractor, the incident also reinforces the importance of open communication during an event, the spokesman said.

“No one company should control the future. It also means a global response is necessary, requiring new partnerships to raise security standards.”

—100 technological companies in an open letter to policy makers and executives in the technological sector

As much as artificial intelligence has made knowledge more accessible, it has also given bad actors more tools for destruction, Andersen told summit attendees. “We continue to see significant pivots, where we not only see malicious cyber actors continuing to target our infrastructure… [but also that] the level of knowledge needed to do that” is lower, he pointed out. “We’ve done ourselves no favors by making personal technology in particular so open and available.”

Last month, data center hyperscalers Google, Microsoft and OpenAI joined a group of 100 tech companies in an open letter to their industry executives and public policymakers calling for greater cyber defense around AI assets and infrastructure, which are expected to exceed $1 trillion in value by 2029, according to market intelligence firm International Data Corp. As its technology improves, AI cyberattacks will become more sophisticated, adding that “status quo” security measures “will not be enough.”

Public services such as hospitals, water treatment plants and power grids “are at risk pending a national security crisis,” the letter said.

The group called for boosting cyber defenses using AI to make security tasks “faster, cheaper and better”, adding that cyber capabilities are advancing globally. “This can be a net positive: no one company should control the future. It also means that a global response is necessary, requiring new partnerships to raise security standards and find new solutions to emerging cyber threats,” the letter said.

Niemeyer, one of 20 new members named to US Energy Secretary Chris Wright’s cybersecurity advisory council, added: “We have a lot of work to do. It’s dense.”

Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSubsurface conditions platform CivilGrid raises $26 million
Next Article ENR 2026 Top 400 Review +: Memphis Hospital Campus Moves Forward
Machinery Asia
  • Website

Related Posts

ENR 2026 Top 400 Review +: A historic Chicago bridge enters a new era

September 9, 2026

ENR 2026 Top 400 Review +: Memphis Hospital Campus Moves Forward

September 9, 2026

Subsurface conditions platform CivilGrid raises $26 million

September 9, 2026
Leave A Reply Cancel Reply

  • Facebook
  • Twitter
  • Instagram
  • Pinterest
Don't Miss

ENR 2026 Top 400 Review +: A historic Chicago bridge enters a new era

ENR 2026 Top 400 Review +: Memphis Hospital Campus Moves Forward

The race to reengineer cyber security

Subsurface conditions platform CivilGrid raises $26 million

Popular Posts

ENR 2026 Top 400 Review +: A historic Chicago bridge enters a new era

September 9, 2026

ENR 2026 Top 400 Review +: Memphis Hospital Campus Moves Forward

September 9, 2026

The race to reengineer cyber security

September 9, 2026

Subsurface conditions platform CivilGrid raises $26 million

September 9, 2026
Heavy Machinery

How do you build a generator trailer for heavy rear loads?

September 7, 2026

What size car trailer load winch do you need?

July 29, 2026

How to choose a manual winch for your car trailer loading needs

July 27, 2026

How to choose heavy-duty car tow ramps for safe loading

July 27, 2026

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Type above and press Enter to search. Press Esc to cancel.