{"id":19031,"date":"2022-05-12T10:45:29","date_gmt":"2022-05-12T18:45:29","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/05\/12\/news-12764\/"},"modified":"2022-05-12T10:45:29","modified_gmt":"2022-05-12T18:45:29","slug":"news-12764","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/05\/12\/news-12764\/","title":{"rendered":"The Hidden Race to Protect the US Bioeconomy From Hacker Threats"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/627c5538bdc4ad545af73cde\/master\/pass\/BIO-ISAC-Security-GettyImages-1227679769.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Thu, 12 May 2022 12:30:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/lily-hay-newman\">Lily Hay Newman<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">A new partnership<\/span> between the cybersecurity nonprofit Bioeconomy Information Sharing and Analysis Center (BIO-ISAC) and the Johns Hopkins University Applied Physics Laboratory (APL), which works on emerging research with US government agencies, is highlighting the need for more resources to better secure biomedical, bioindustrial, and biomanufacturing entities.<\/p>\n<p class=\"paywall\">The Covid-19 pandemic sparked regular people around the world to think about the logistics of vaccine development and production in a tangible and immediate way. But the so-called bioeconomy is silently embedded everywhere, from breeding programs used in agriculture to the development of biofuels. And as <a href=\"https:\/\/www.wired.com\/story\/colonial-pipeline-ransomware-attack\/\">industry<\/a> <a href=\"https:\/\/www.wired.com\/story\/kaseya-supply-chain-ransomware-attack-msps\/\">after<\/a> <a href=\"https:\/\/www.wired.com\/story\/devastating-twitch-hack-sends-streamers-reeling\/\">industry<\/a> faces a reckoning about the state of their cybersecurity defenses, researchers are increasingly realizing that the bioeconomy is vulnerable. During the pandemic, for example, <a href=\"https:\/\/www.wired.com\/story\/russias-latest-hacking-target-covid-19-vaccine-projects\/\">Russia<\/a>, China, and other state actors <a href=\"https:\/\/www.wired.com\/story\/hackers-targeting-covid-19-vaccine-cold-chain\/\">raced to hack<\/a> vaccine makers and distributors for intelligence gathering, in a scramble that US officials <a href=\"https:\/\/www.wired.com\/story\/china-hackers-covid-19-spying-vaccine\/\">warned<\/a> could have been disruptive.<\/p>\n<p class=\"paywall\">\u201cA lot of the bioeconomy is small companies; that\u2019s the real lifeblood of American biotech,\u201d says BIO-ISAC cofounder Charles Fracchia. \u201cImagine if Moderna got hacked four years ago, even with some totally non-sophisticated malware, or they faced a ransomware attack. Small companies can go bankrupt really easily, and then we lose the work they&#x27;re doing for the future. I&#x27;m very grateful that APL understood the mission of the BIO-ISAC and joined as a founding member. They want to help.\u201d<\/p>\n<p class=\"paywall\">Information sharing and analysis centers exist for many industries, from financial services to health care. And Charles Frick, a principal staff member at APL, says that the lab has been supporting ISACs and collaborating with them for many years. During the George W. Bush and Barack Obama administrations, Frick says, APL collaborated with the Department of Homeland Security and the National Security Agency to study the most efficient methods for large-scale threat intelligence sharing and security automation. APL participated in a 2018 financial services pilot for automatically screening and processing machine-readable threat intelligence data in which a process that had one taken 14 hours got whittled down to eight minutes.<\/p>\n<p class=\"paywall\">All of this matters, because digital attacks on critical services and trends in attacks creep up quickly. The more information an organization can not only gather but also share, the better chance others have of defending themselves against similar hacks. APL&#x27;s funding for the BIO-ISAC will go toward regular operations, including research, information sharing, and <a href=\"https:\/\/www.wired.com\/story\/tardigrade-malware-biomanufacturing\/\">public disclosures<\/a>. And crucially, it will also support incident response services the BIO-ISAC is launching so biotech and biomanufacturing organizations have someone to call if they&#x27;re dealing with a digital attack or otherwise suspect that something is wrong. The services will be pay what you can to make them accessible to as many organizations as possible. Depending on demand, though, the BIO-ISAC may not have the capacity immediately to respond to every request. But the group hopes to begin filling a crucial gap in the services that are currently available.<\/p>\n<p class=\"paywall\">\u201cAs we start identifying threats, it&#x27;s a natural fit for us to say, well, we have an existing set of capabilities and skills that can be applied to this area, and we&#x27;ve demonstrated our ability to work with ISACs in collaboration,&quot; says Brian Haberman, an APL program area manager. &quot;So this accomplishes our mission of supporting national priorities in a much faster way when you\u2019re not going it alone. It&#x27;s the biggest bang for your buck.&quot;<\/p>\n<p class=\"paywall\">A few years ago, the idea of <a href=\"https:\/\/www.wired.com\/story\/election-security-critical-infrastructure\/\">designating US election systems<\/a> as government \u201ccritical infrastructure\u201d was controversial to some. The designation simply unlocks funding and expanded resources from US government agencies, including the Cybersecurity and Infrastructure Security Agency, for critical sectors that work in the public interest. But while health care, food, and agriculture industries obviously have critical infrastructure designations that cover parts of the bioeconomy, the sector as a whole doesn&#x27;t specifically have its own designation. Instead the US government has classified the bioeconomy with a \u201ccritical emerging tech\u201d\u00a0label. \u00a0As a result, groups like the BIO-ISAC are working ad hoc in a largely open field.<\/p>\n<p class=\"paywall\">\u201cThe bioeconomy is an emerging sector of our economy if we really want to make meaningful change and impact, now is the time to get involved\u2014not after it\u2019s already this big thing and we try to go in reverse,&quot; says Andrew Kilianski, senior director for emerging infectious diseases at the International AIDS Vaccine Initiative. &quot;We\u2019ve done some of these sectors where we try to build out IT infrastructure and cybersecurity defenses later and it doesn\u2019t work well.&quot; Kiliansk worked closely with the US government&#x27;s Covid Operation Warp Speed initiative and a new member of the BIO-ISAC&#x27;s national security advisory board.<\/p>\n<p class=\"paywall\">\u201cThere&#x27;s that squishy, beautiful life sciences spirit that, hey, we share everything, we\u2019re open,&quot; Kilianski adds. &quot;But now these discoveries have huge commercial value, not just societal value, and that makes all of this even more sensitive.\u201d<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/biotech-security-threats\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/627c5538bdc4ad545af73cde\/master\/pass\/BIO-ISAC-Security-GettyImages-1227679769.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Thu, 12 May 2022 12:30:00 +0000<\/strong><\/p>\n<p>A biotech threat intelligence group is gaining supporters as urgency mounts around an overlooked vulnerable sector.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358],"class_list":["post-19031","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19031","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19031"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19031\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19031"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19031"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}