But proponents warned that mandates are essential to ensure adequate safeguards. a Amid a spate of increasingly sophisticated attacks on private companies that operate power plants, dams, and other critical infrastructure. Al-Qaeda VideoWeeks after the law was passed, the Department of Homeland Security warned hackers who had tried for months to infiltrate computer systems for a number of natural gas pipeline operators. ABC News reported that the FBI had received an Al Qaeda video calling for “electronic jihad” against critical US infrastructure. The computer security company McAfee Corp. warned in 2011 of coordinated, sustained cyberattacks on global energy companies. The hacking episodes showed how enticing fuel systems are to cyber criminals like the Russia-affiliated group who used DarkSide ransomware to hold Colonial’s computer systems hostage around May 7th. The company was forced to shut down its roughly 855-kilometer pipeline system that supplies about 45% of the fuel consumed on the east coast, resulting in outages at gas stations and on the east coast paying a $ 5 million ransom before service five Was resumed days later. It is not clear whether mandates thwarted the attack and the investigation is still ongoing. Colonial is committed to “reviewing any proposal that draws lessons from this event that strengthens or hardens our infrastructure”. The oil and pipeline trading groups steadfastly insist that this is not the time for mandatory federal mandates. “It is premature to discuss regulation until we have a full understanding of the details of the colonial attack,” said Suzanne Lemieux, API manager for operational security and emergency response. “However, we are determined to continue our solid coordination with all levels of government.” added in a statement that he was broadly coordinated with the chamber on the matter in 2012 and warned of a single regulatory approach that meets all requirements John Stoody, a spokesman for the Association of Oil Pipe Lines, of which Colonial Pipeline is a member, said : “We want the TSA to do everything right, what it is up to.” Overwhelm TSA every day with hundreds of thousands of cyberattack reports that would not help anyone, “he said. PartnershipChevron said in an emailed statement that federal regulation “Should take a risk-based approach”, the company Flexibil it offers security against threats. And Exxon noted that the rapid evolution of cyber threats means that “all formal and mandated cybersecurity requirements for the industry are often out of date when they are completed.” The Transportation Security Administration has long followed a similar approach. A branch manager in the agency’s surface operations office said last year there were “very few regulations” and a “collaborative approach to industry introducing security measures”. This is evident from a presentation archived on the agency’s website. The TSA chose not to regulate the regulations, according to Fox, the retired TSA pipeline safety manager, partnering with industry is more efficient, Fox said in a telephone interview. “With this partnership, we could make a phone call and say we need you to do this and that and it would respond the next day.” Republican FilibusterFox said he didn’t think the Lieberman bill would have prevented the colonial cyberattack. You can regulate what you want, ”said Fox. “We have regulations on speed limits, gun controls and all sorts of things. So if you regulate something, it doesn’t mean it won’t happen.” Ultimately, in 2012, Lieberman and Collins watered down their accounts to win the Republicans over to survive. They dropped mandates and fines in favor of a measure that would only create optional requirements. But even the reduced bill was not enough. Persistent concerns about liability and data protection haunted the legislation, and the chamber also rejected the new version. It was defeated twice by a Republican-led filibuster and eventually fell nine votes below the 60 votes required to break the November 2012 debate. Amy Myers Jaffe, professor at Tufts University and author of Energy's Digital Future, said the colonial cyberattack could hint at the Gulf of Mexico oil well that exploded in 2010, killing 11 workers and the worst oil spill in history the United States triggered. An overly cozy relationship between federal regulators and oil companies has been blamed for contributing to the disaster, Jaffe said. "It is shocking to me to believe that an industry that loves to brag about its safety records would ever have advocated having government-led standards that are mandatory for cybersecurity in vital energy infrastructures."

