Cyber-attack fatality 'is possible and plausible'

22 January 2013
By James Hayes
Mobile version
Share |
Nachreiner: “Security must not be an afterthought”

Nachreiner: “Security must not be an afterthought”

2013 could be the first year in which a cyber-attack leads to a human death, a Web security expert has warned.

Corey Nachreiner, director of security strategy at security management firm WatchGuard Technologies, argues that the accelerated proliferation of both networked devices and online threats over the next 12 months will create a ‘perfect storm’ of vulnerable connected systems that, if targeted, could increase the chances of a ‘fatal malfunction’.

Networked road vehicles, Internet-ready medical devices, and intelligent buildings are among the emerging connected physical domains that will start to be targeted in 2013 by cyber criminals, hacktivists, pranksters, and other ‘malicious actors’ – including nation states –Nachreiner believes.

“Our lives become more dependent on computing devices every day,” he said. 

“They are increasingly embedded in the infrastructure that provides us with energy and water. 

“And all the time we are actively engaged in connecting all these devices together. 

“Yet some of our most critical systems now suffer from fundamental vulnerabilities.”

Nachreiner warns that with more connected computer components embedded in cars, phones, TVs, navigation aids, and even medical devices, “digitally-dealt death is not only possible, it is plausible… though I hope that I am wrong”.

He also points out that technology now exists for roadside hackers to interfere with satnav tools, causing drivers to make life-threatening driving decisions, for instance, or even hack into automotive systems and cause airbags to inflate. 

Medical systems themselves are also becoming increasingly connected through to public networks, which introduces another range of vulnerabilities, says Nachreiner: 

“Recently, a researcher [at the Breakpoint conference, Melbourne] even showed how to wirelessly deliver an 830V shock to an insecure pacemaker”.

Other scenarios include intelligent buildings, where unauthorised online access to control systems for lifts and escalators could result in people being trapped when in need of urgent medical treatment, or critically injured due to sudden motion stoppages.

“We are connecting around the ‘air gaps’ that used to protect things like industrial control systems, in-building transport mechanisms, and medical systems,” Nachreiner explains.

“Despite the risks, security is often still an afterthought when innovative technical systems are being developed.”

Nachreiner is calling for a more regulated approach to software development, to ensure that insecure coding results in financial penalties for those responsible for flawed software.

Latest Issue

E&T cover image 1606

"Where would Frankenstein and his creative mind fit into today's workplace? Should we fear technological developments or embrace them?"

E&T jobs

  • Graduate Electrical Engineers

    AECOM
    • United Kingdom and Ireland
    • Competitive

    Due to the diverse nature of our business there are many different teams each with very different responsibilities.

    • Recruiter: AECOM

    Apply for this job

  • Network Innovation Engineer / Analyst - UK Power Sector

    Premium job

    Nortech Management Ltd
    • Birmingham, West Midlands or Pershore (Worcestershire)
    • £30,000 - £35,000 (depending on experience) + benefits

    Network Innovation Engineer / Analyst to join a team of talented technology enthusiasts who design and support the low carbon networks of the future.

    • Recruiter: Nortech Management Ltd

    Apply for this job

  • Electrical Engineer with Strong telecoms background

    Premium job

    Sure South Atlantic Ltd
    • Falkland Islands

    Sure South Atlantic Ltd currently has a unique engineering opportunity in their Falkland Islands office. Surrounded by the Atlantic Ocean, teeming ...

    • Recruiter: Sure South Atlantic Ltd

    Apply for this job

  • Cyber, Communication, Information and Data Scientist roles

    Premium job

    Dstl
    • Porton Down, Salisbury
    • Competitive salaries

    Information is everything. Use it to serve your country and help keep us safe.

    • Recruiter: Dstl

    Apply for this job

  • Production Engineer

    Premium job

    Compact Engineering
    • Thirsk / Leeds / Banbury / Colchester / Cambridge
    • Salary will be competitive and commensurate with experience, knowledge, aptitude and capability

    A Production Engineer with some knowledge and understanding of radiant energy transfer.

    • Recruiter: Compact Engineering

    Apply for this job

  • Electronics Engineer

    Premium job

    Nikon Metrology Europe
    • Tring, Hertfordshire

    Nikon Metrology is looking for an Electronics Engineer to join our Electronics Team based in Tring (UK).

    • Recruiter: Nikon Metrology Europe

    Apply for this job

  • Engineering Manager

    BAE Systems
    • Hampshire, England, Portsmouth
    • Competitive package

    Would you like to play a vital role in managing and implementing the correct governance in order to enable BAE Systems to provide assurance and integrity of supply chain data? We currently have a vacancy for an Engineering Manager - Product Integrity

    • Recruiter: BAE Systems

    Apply for this job

  • Engineering Project Manager - Electrical & Automation

    Nestle
    • York, North Yorkshire
    • c£45,000 + Car Allowance + Bonus + Excellent Benefits

    Nestlé Product Technology Centre in York currently has an excellent opportunity for an Engineering Project Manager

    • Recruiter: Nestle

    Apply for this job

  • Consultant Engineer - Test

    BAE Systems
    • Farnborough, Hampshire, England
    • Negotiable

    Consultant Engineer - Test Would you like to be a lead within an exciting team working on one of the UK's largest defence projects? We currently have a vacancy for a Consultant Engineer - Test at our site in Ash Vale. As a Consultant Engineer - Test, you

    • Recruiter: BAE Systems

    Apply for this job

  • ELECTRICAL PROJECT ENGINEER

    SSE
    • Reading, Berkshire
    • SALARY: £37,588 TO £55,669 + CAR (SSE8/9), DEPENDING ON SKILLS AND EXPERIENCE

    SSE are looking to recruit an Electrical Project Engineer into office in Reading

    • Recruiter: SSE

    Apply for this job

More jobs ▶

Subscribe

Choose the way you would like to access the latest news and developments in your field.

Subscribe to E&T