What is cybersecurity?

Key pillars of cybersecurity at Iberdrola

Cybersecurity

Today's society relies on the Internet for all the activities it undertakes during the day, from work to leisure, from finance to storing personal data or to communicating with others. The role of cybersecurity is growing in parallel with the concern for protecting our digital data. Find out about its importance, how we defend ourselves against cyber attacks at Iberdrola and our tips to prevent them.

 
Ciberseguridad
The importance of cybersecurity is growing in parallel to the number of digital users, devices and programmes and the volume of data exposed on the internet.

In a world increasingly reliant on the Internet, the need to prevent online scams and maintain cyber security is becoming more prominent. Any individual or company, regardless of size, is a potential target for cyber attack. Internet users leave a trail of digital information and businesses have key assets that criminals may seek to exploit. Sometimes it is money or financial information, sometimes it is personal data, and sometimes it is even infrastructure.

Knowing the importance of cybersecurity and the types of cyber attacks can help you better understand the risks and find ways to prevent and deal with them.

Definition and scope of cybersecurity

Cybersecurity is the set of capabilities, technologies, standards, processes and best practices designed to protect the cyberinfrastructure against attacks, damage or unauthorised access. Cybersecurity is the ability to prevent, identify, detect, respond to and mitigate or eliminate deficiencies, vulnerabilities, attacks and internal and external threats that may pose a risk to the Company's cyberinfrastructure, with the aim of eliminating or minimising damages of any kind that may be caused to the company.

Like a barrier, cybersecurity slows or minimises attacks. "A robust cybersecurity strategy can provide a good security posture against malicious attacks designed to access, alter, delete, destroy or extort an organisation's or user's systems and sensitive data," notes TechTarget. Cybersecurity is also critical to prevent attacks aimed at disabling or disrupting the operation of a system or device.

With an increasing number of users, devices, technologies and programmes, along with the growing deployment of data – much of which is sensitive or confidential – the importance of cybersecurity continues to grow. In addition, the growing volume and sophistication of digital scams further exacerbates the problem. While these attacks can affect different levels —for instance, governments, businesses or institutions— the key is to pay special attention to the role of humans. In fact, according to cybersecurity company Proofpoint, "more than 99 % of cyber attacks require human interaction".

In this context it is essential to distinguish between Information Technology (IT) and Operational Technology (OT) environments.

  • IT cybersecurity focuses on protecting the systems that manage corporate information, such as applications, networks, data and devices used for processing and storing information;
  • OT cybersecurity aims to protect the systems that control and monitor the company's critical physical and operational processes.

In an energy company such as Iberdrola, these two areas are increasingly interconnected, making it essential to ensure comprehensive protection that safeguards both the confidentiality, integrity and availability of information and the continuity and security of operations.

The most common cyber threats

Cybersecurity works to prevent and minimise online threats. However, cyber attacks are becoming increasingly sophisticated and stealthy in order to circumvent the defence barriers of computer systems. These are the most common threats facing cybersecurity today:

Icon

Malicious software

'Malware' is a contraction of 'malicious software' designed to damage or infiltrate systems without the user's knowledge. It often appears when a dangerous link or email attachment is clicked. Some of them are the following:

  • Icon

    Worms

    They spread from one device to another without human intervention, exploiting vulnerabilities.

  • Icon

    Trojans

    They are used to hide other malware. It infiltrates a victim's device by presenting itself as legitimate software and allows attackers to gain unauthorised access.

  • Icon

    Ransomware

    It blocks or denies access to a device and its files until the user pays a ransom to the hacker.

  • Icon

    Spyware

    Collects information from a device or network to send to the attacker.

More information
Icon

Distributed Denial of Service ( DDoS ) attack

Prevents users from accessing information, services and other resources. This type of attack occurs by overloading or flooding a target machine with requests to the point where normal traffic cannot be processed and, as a result, causes a denial of service to legitimate users.

More information
Icon

Social engineering attack

Different techniques and mechanisms by which the attacker uses a human emotion - often fear or a sense of urgency - to convince the user to perform an action, such as providing personal information that can be used later or sending money. These include phishing, vishing and smishing.

More information
Icon

Disinformation

Based on creating or disseminating false or misleading information to manipulate public opinion. The aim is to have a negative impact on the target audience in order to create a negative view of certain facts or the image of certain entities through manipulation of information.

More information
Icon

Supply chain attacks

Cyber criminals can compromise service providers or software vendors to infiltrate the networks of their customers, who become their victims.

More information

Source: European Union Agency for Cybersecurity (ENISA), Cisco.

 SEE INFOGRAPHIC: The most common cyber threats? [PDF]

The most common cyber threats. Cybersecurity seeks to prevent and minimise online threats, which are becoming increasingly sophisticated and stealthy. Among the most common are malicious programmes, or malware, designed to damage or infiltrate systems: worms spread between devices by exploiting vulnerabilities; Trojans disguise themselves as legitimate software to gain unauthorised access; ransomware blocks access to a device or files and demands a ransom; and spyware collects information to send to the attacker.Also of note are denial-of-service (DDoS) attacks, which overwhelm a system and prevent access to information or services; social engineering, which manipulates people through deceptive tactics such as phishing, vishing or smishing; disinformation, which spreads false or misleading content to influence public opinion; and supply chain attacks, which compromise service or software providers to gain access to their customers' networks.

Why it is key in an electrified and digital world

The consolidation of a more electrified and connected energy model entails a profound transformation of infrastructure. Smart grids, storage systems, distributed renewable generation and electric mobility incorporate digital technologies that enable energy to be managed more efficiently and flexibly.

This evolution requires strengthening the protection of infrastructure that is increasingly critical to society.

The protection of energy infrastructure

Energy infrastructure forms part of the essential services that enable households, businesses and industries to function. Ensuring its availability and security requires anticipating new threats through advanced monitoring, analysis and response capabilities.

Cybersecurity helps to:

  • Protect smart grids

    Ensuring secure communication between millions of connected devices.

  • Ensure operational continuity

    Reducing the impact of potential incidents on energy systems.

  • Improving energy management

    Using data and digital technologies securely.

  • Promoting renewable energy

    Facilitating the integration of new renewable and distributed solutions.

Artificial intelligence and cybersecurity: opportunity and challenge

Artificial intelligence is transforming the way organisations detect, analyse and respond to digital threats. Its ability to process large volumes of information enables it to identify anomalous patterns, anticipate risks and improve response times to potential incidents.

At the same time, AI also poses new security challenges. Cybercriminals can use these technologies to develop more sophisticated attacks, automate malicious processes or create new forms of social engineering. Therefore, the responsible development of artificial intelligence must be accompanied by governance measures, data protection and security controls that ensure the reliable use of this technology.

A recent example occurred in Hong Kong where, according to the local police, an employee of a company transferred approximately $25 million after taking part in a fake video call in which cybercriminals used artificial intelligence to impersonate the chief financial officer and other colleagues. It is because of cases such as these that campaigns and technologies are being developed to streamline tasks such as system recognition, vulnerability scanning and the detection of unauthorised access attempts. For example: the campaign identified by the National Cybersecurity Institute (INCIBE) in Spain, in which an artificial intelligence-based tool called CyberStrikeAI was used to automate various stages of an attack on corporate security devices.

Innovation and the future of cybersecurity in the energy industry

Cybersecurity is crucial in the energy industry due to the increasing interconnectedness of systems and dependence on technology. Smart grids, industrial control systems and other internet-enabled devices are already an essential part of the industry, bringing efficiency and control. However, these developments require closer security scrutiny to avoid exposure to vulnerabilities exploited by attackers or hackers. 

Some expected innovations or trends in cybersecurity in the energy industry are the following: 

  • Integration of emerging technologies. The adoption of technologies such as the internet of things (IoT), artificial intelligence (AI) and machine learning can help early detection of security breaches and optimise responses.
  • Blockchain. This technology is being explored to improve transaction security and data management in the energy supply chain. It provides an immutable record that helps prevent fraud and attacks. At Iberdrola, we have become the first company to use blockchain to certify participation in the General Shareholders' Meeting.
  • Cloud security. With the proliferation of cloud services, robust security measures and encryption techniques are expected to be implemented to protect stored and transmitted data, as well as agreements with strong vendors that provide secure technologies and services. 
  • Response automation. The goal would be to achieve threat response automation. Systems capable of identifying, analysing and responding on the spot could help minimise the impact of attacks and reaction time.
  • Training and awareness. To cope with the increasing sophistication of attacks, continuous training of staff at all levels of the company in cybersecurity and awareness of best practices will be critical.
  • Collaboration. Training and technical support between energy industry entities, government agencies and cybersecurity companies will be key to sharing knowledge in the face of cyber-attacks.
  • Legislation. Regulations and standards relating to cybersecurity in the energy sector are likely to increase to ensure the protection of critical infrastructure assets.

How to report cyber attacks

At Iberdrola, we have developed the vulnerabilities mailbox, a contact platform for reporting possible security incidents on our websites. Through this form, we can receive comments from a security researchers community that contribute to securing the products and services for all of the Group's companies. Once we have been alerted, we will investigate and resolve any vulnerabilities detected on our platforms. 

The information required for alerting about attacks or incidents are the affected web page or site, a brief description of the vulnerability, steps to reproduce it and documentation that can illustrate the problem.

Tips for users to avoid data harvesting

Cybersecurity starts with our own online activity. Here are some tips to keep your data safe:

  • Keep your passwords secure and up to date

    Passwords are the first line of defence in protecting your online accounts. It is important to use unique and complex passwords, avoid including personal information or common words in them and change them regularly. Of course, never share them.

  • Update your devices and their software

    Keeping your devices and software up to date is essential to ensure the security of your data. Updates often include crucial security patches to prevent or eliminate known vulnerabilities.

  • Beware of emails, unsolicited messages and suspicious links

    Phishing is one of the main ways in which cybercriminals try to breach our personal data. It is essential to be cautious, refrain from opening emails from unknown senders and avoid clicking on links or downloading attachments from suspicious messages, as they may contain malware. Always check their legitimacy.

  • Use a secure network

    Only use reliable connections and networks (such as a Virtual Private Network, or VPN) – which encrypts your internet traffic – especially when carrying out transactions or entering confidential data. Avoid public or unsecured Wi-Fi networks.

  • Privacy settings on social networks

    Review and adjust the privacy settings on your social media accounts to control who can see your personal information. Make sure it is only visible to people you trust. Avoid posting sensitive information such as your address, family details, phone number or financial details.

  • Anti-virus and anti-malware installation

    Install and regularly update antivirus and anti-malware software on your devices to detect and remove potential threats.

  • Data backup

    Make regular backups of your important data. In the event of an attack or loss of information, you will be able to restore it.