Attacks on Energy Companies Three Times More Likely to Succeed, Compared with Banking and Finance

Businesses Urged to be 'Radical' in How They Organise Their Defences

Abu Dhabi, UAE– Energy is overtaking banking and finance as a target for cyber-criminals in the Middle East, yet companies in the sector are leaving themselves significantly more open to a successful attack, leading international experts have told the Security in Energy conference in Abu Dhabi.

Co-located within the Abu Dhabi International Petroleum Exhibition and Conference (ADIPEC), Security in Energy recognises the increasingly critical importance of IT systems to oil and gas operations.

In an opening address to delegates, Ibrahim Al Shamrani, Executive Director of Operations at Saudi Arabia’s National Cyber Security Center, said 300 new malware samples were being discovered each day, and that his organisation was facing a growing number of attacks on the energy industry.

“The energy sector is trending to be the second most targeted sector in the country in 2017, behind the government and ahead of the financial and telecommunications sectors,” Al Shamrani said. “However, attackers are three times more successful in compromising energy companies than they are in the financial sector. In this era, if oil and gas companies think they haven’t been attacked, or even compromised, I can tell them, you are not looking hard enough.”

Recent figures from McAfee estimate the global cost of cyber-related crime, or illicit activity, is between US $375 billion and US $550 billion per year.

In a keynote address to the Security in Energy conference, Don Randall, former Head of Security and Chief Information Security Officer (CISO) at the Bank of England, said he believed that figure was probably around US $400 billion, and growing at between 10 and 20 percent per year.

“When we look at the types of issues that could affect the oil and gas or energy industries, the three principles are still hacking, phishing, and false identity,” Randall told the conference. “It doesn’t matter if you’re in the financial sector, in energy, utilities, the government, or anything else – the cyberattack will be the same, it’s just the consequences that are different.”

For those making attacks, the chances of getting caught are low. Randal said that in the first six months of 2017, there were 350,000 attacks reported in the UK, but it’s estimated that figure only represents 40 percent of the actual number of attacks taking place. He added that only 10 percent of reported attacks are then investigated by law enforcement, and only 1.5 percent result in any kind of judicial process.

In his Bank of England role, Randall helped develop new security protocols, including the creation of a specific Information Security Division, headed by himself as the Chief Information Security Officer, reporting directly to the board.

That model is now widespread in banking, completely separating the department that runs the IT infrastructure, from the team responsible for recognising and responding to threats.

“I think we have to be quite radical in how we structure the responsibility and role of those who are there to police cyber activities,” Randall said. “Seriously look at who is policing your IT, and ask is that the same person who is managing it, maintaining it, implementing it, and looking after it – and potentially covering it up? That’s the issue. You’ve got to work in harmony with the IT department, but you’ve got to have an independence there.”

Held under the patronage of His Highness Sheikh Khalifa Bin Zayed Al Nahyan, President of the UAE, hosted by the Abu Dhabi National Oil Company (ADNOC), and organised by the Global Energy division of dmg events, ADIPEC is one of the world’s leading oil and gas events, and the largest in Africa and the Middle East.

-Ends-

About ADIPEC
Held under the patronage of the President of the United Arab Emirates, His Highness Sheikh Khalifa Bin Zayed Al Nahyan, and organised by the Global Energy division of dmg events, ADIPEC is the global meeting point for oil and gas professionals. Standing as one of the world’s top energy events, and the largest in the Middle East and North Africa, ADIPEC is a knowledge-sharing platform that enables industry experts to exchange ideas and information that shape the future of the energy sector. The 20th edition of ADIPEC will take place from 13-16 November, at the Abu Dhabi National Exhibition Centre (ADNEC). ADIPEC 2017 will be hosted by the Abu Dhabi National Oil Company (ADNOC) and supported by the UAE Ministry of Energy, Masdar, the Abu Dhabi Chamber, the Abu Dhabi Department of Culture and Tourism, Abu Dhabi Ports and the Department of Education and Knowledge. dmg Global Energy is committed to helping the growing international energy community bridge gaps by bringing oil and gas professionals face to face with new technologies and business opportunities.

For media enquiries, please contact:
Nour Soliman
Senior Marketing Manager, DMG Events Global Energy
Twofour54, Park Rotana Offices, 6th Floor
PO Box 769256, Abu Dhabi, UAE
T: +971 (0)2 6970 515

Wallis 
ADIPEC@wallispr.com
T
: +971 4 275 4100
Mark Robinson (English):  +971 (0)55 127 9764
Feras Hamzah (Arabic):      +971 (0)50 798 4784

© Press Release 2017