Case Study 3 – Destructive Attack on Ukrainian Power Supply Sample Clauses

Case Study 3 – Destructive Attack on Ukrainian Power Supply. This is a watershed incident in cyberspace, primarily because it's the first confirmed case of cyber-enabled disruption to electricity supply on a regional scale. Often when discussing cyber-attacks, it is difficult to extract the real-world impact, which tends to be a second or third order effect. However, in this case the physical impact on thousands of citizens brought home the very tangible effects that a cyber-attack can have. INCIDENT: Three Ukrainian energy distribution companies were victim to cyber-attack in December 2015, resulting in electricity outages for approximately 225,000 customers across the Ivano-Frankivsk region of Western Ukraine. Attackers gained unauthorised entry into a regional electricity distribution company's corporate network and ICS. Subsequently seven 110 kV and twenty-three 35kV substations were disconnected for three hours. A recent article highlights that customisable malware known as Industroyer was likely to be at the root of the attack24. METHODOLOGY: Spear-phishing emails with malicious Microsoft Word attachments containing BlackEnergy 3 (BE3) malware. BE3 did not directly cause the outage, but rather was used to gain access to the business networks of electricity supply companies. Attackers reportedly gained access to networks more than six months prior to the December 2015 power outage. This was followed by the theft of credentials from corporate networks. The corporate VPNs and remote access tools were used to enter and manipulate ICS networks. KillDisk malware was then deployed to erase the master boot record on targeted systems and log deletion to hide presence on networks. In one instance, attackers launched a telephone DoS attack to delay customers reporting outages to the affected company's call centre. IMPACT: Attackers overwrote the firmware on critical devices used by the affected companies, forcing operators to control devices manually, leading to a significant drop in productivity. The length of the power outages was limited because technicians on site manually overrode circuit breakers and restored power after a few hours. However, more than two months after the attack, control centres were still not fully operational.

Related to Case Study 3 – Destructive Attack on Ukrainian Power Supply

  • Prior Disaster Relief Contract Violation Under Sections 2155.006 and 2261.053 of the Texas Government Code (relating to convictions and penalties regarding Hurricane Xxxx, Hurricane Xxxxxxx, and other disasters), the Contractor certifies that the individual or business entity named in this Contract and any related Solicitation Response is not ineligible to receive this Contract and acknowledges that this Contract may be terminated and payment withheld if this certification is inaccurate.

  • CONDITIONS FOR EMERGENCY/HURRICANE OR DISASTER - TERM CONTRACTS It is hereby made a part of this Invitation for Bids that before, during and after a public emergency, disaster, hurricane, flood, or other acts of God that Orange County shall require a “first priority” basis for goods and services. It is vital and imperative that the majority of citizens are protected from any emergency situation which threatens public health and safety, as determined by the County. Contractor agrees to rent/sell/lease all goods and services to the County or other governmental entities as opposed to a private citizen, on a first priority basis. The County expects to pay contractual prices for all goods or services required during an emergency situation. Contractor shall furnish a twenty-four (24) hour phone number in the event of such an emergency.

  • Erosion Prevention and Control Purchaser’s Operations shall be conducted reasonably to minimize soil erosion. Equipment shall not be operated when ground conditions are such that excessive damage will result. Purchaser shall adjust the kinds and intensity of erosion control work done to ground and weather condi- tions and the need for controlling runoff. Erosion control work shall be kept current immediately preceding ex- pected seasonal periods of precipitation or runoff.

  • Contract Closure Contracting Officer shall give appropriate written notice to Purchaser when Purchaser has complied with the terms of this contract. Purchaser shall be paid refunds due from Timber Sale Account un- der B4.24 and excess cooperative deposits under B4.218.

  • Accidents and Dangerous Occurrences The Hirer must report all accidents involving injury to the public to a member of the Village Hall management committee as soon as possible and complete the relevant section in the Village Hall’s accident book. Any failure of equipment belonging to the Village Hall or brought in by the Hirer must also be reported as soon as possible. Certain types of accident or injury must be reported on a special form to the local authority. The Hall Secretary will give assistance in completing this form. This is in accordance with the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 1995 (RIDDOR).

  • Workplace Violence Prevention and Crisis Response (applicable to any Party and any subcontractors and sub-grantees whose employees or other service providers deliver social or mental health services directly to individual recipients of such services): Party shall establish a written workplace violence prevention and crisis response policy meeting the requirements of Act 109 (2016), 33 VSA §8201(b), for the benefit of employees delivering direct social or mental health services. Party shall, in preparing its policy, consult with the guidelines promulgated by the U.S. Occupational Safety and Health Administration for Preventing Workplace Violence for Healthcare and Social Services Workers, as those guidelines may from time to time be amended. Party, through its violence protection and crisis response committee, shall evaluate the efficacy of its policy, and update the policy as appropriate, at least annually. The policy and any written evaluations thereof shall be provided to employees delivering direct social or mental health services. Party will ensure that any subcontractor and sub-grantee who hires employees (or contracts with service providers) who deliver social or mental health services directly to individual recipients of such services, complies with all requirements of this Section.

  • Elements Unsatisfactory Needs Improvement Proficient Exemplary IV-A-1. Reflective Practice Demonstrates limited reflection on practice and/or use of insights gained to improve practice. May reflect on the effectiveness of lessons/ units and interactions with students but not with colleagues and/or rarely uses insights to improve practice. Regularly reflects on the effectiveness of lessons, units, and interactions with students, both individually and with colleagues, and uses insights gained to improve practice and student learning. Regularly reflects on the effectiveness of lessons, units, and interactions with students, both individually and with colleagues; and uses and shares with colleagues, insights gained to improve practice and student learning. Is able to model this element.

  • Adverse Weather Shall be only weather that satisfies all of the following conditions: (1) unusually severe precipitation, sleet, snow, hail, or extreme temperature or air conditions in excess of the norm for the location and time of year it occurred based on the closest weather station data averaged over the past five years, (2) that is unanticipated and would cause unsafe work conditions and/or is unsuitable for scheduled work that should not be performed during inclement weather (i.e., exterior finishes), and (3) at the Project.

  • No Physical Presence of Quorum and Participation by Audio or Video; Disaster Declaration The ability of the Board to meet in person with a quorum physically present at its meeting location may be affected by the Governor or the Director of the Ill. Dept. of Public Health issuing a disaster declaration related to a public health emergency. The Board President or, if the office is vacant or the President is absent or unable to perform the office’s duties, the Vice President determines that an in- person meeting or a meeting conducted under the Quorum and Participation by Audio or Video Means subhead above, is not practical or prudent because of the disaster declaration; if neither the President nor Vice President are present or able to perform this determination, the Superintendent shall serve as the duly authorized designee for purposes of making this determination. The individual who makes this determination for the Board shall put it in writing, include it on the Board’s published notice and agenda for the audio or video meeting and in the meeting minutes, and ensure that the Board meets every OMA requirement for the Board to meet by video or audio conference without the physical presence of a quorum.

  • Communicable Disease Bodily injury" or "property damage" which arises out of the transmission of a communi- cable disease by an "insured";