Restoration Following a Potential Attack
CF: If there is an outage, does restoration differ between outages that are caused by natural disaster, etc., versus a cyberattack?
PH: The answer would depend on how localized that attack was and how quickly an incident response team could identify where the actual attack happened, what device, server or person was compromised, and can they remove that and then get it back up and going. The answer to that question is totally dependent on the scope of that attack. And it depends on the malware used as well. I would think that given the critical nature of the grid, all hands would be brought to bear in an incident response kind of engagement to get it up and going. And hopefully large infrastructure wouldn’t have to be replaced like in a physical natural disaster.