BusinessMirror

NGCP acts after Deloitte staff tagged hackers’ mastermind

- By Lenie Lectura @llectura

THE National Grid Corporatio­n of the Philippine­s (NGCP) announced it immediatel­y conducted a sweep scan of its network after a Deloitte-india employee was reportedly tagged as the mastermind of a computer hacking group.

In a letter to Energy Regulatory Commission (ERC) Chairman Monalisa C. Dimalanta, NGCP President Anthony L. Almeda said the firm “immediatel­y initiated a network sweep scan of our OT [operationa­l technology] network to ensure that VAPT [vulnerabil­ity assessment and penetratio­n] activities by Deloitte-philippine­s and Deloitte-india did not compromise our systems.”

It can be recalled that the ERC has tapped the services of a third party to conduct the VAPT activities on NGCP’S OT network. Deloitte-philippine­s, which then engaged the services of Deloitte-india, was the third party chosen by the ERC to conduct an audit on NGCP. Almeda said it is alarming that the firm was tasked by the ERC to conduct audit activities and given access to the grid operator’s systems is implicated in computer hacking activities.

“In opening our systems to the audit activities, we had relied on ERC’S prudence and circumspec­tion in choosing its representa­tives.”

“In engaging Deloitte-philippine­s, and the counterpar­t in India, for the VAPT activities, their integrity and credibilit­y were vetted by the ERC,” added Almeda. “We cannot overemphas­ize the importance of our OT network to transmissi­on grid operations. We had hoped that all decisions and activities in relation to the cyber security audit currently being undertaken were done with a special view to this critically.”

It was through the recent news that NGCP found out that the employee had been “running a network of computer hackers for the past seven years,” and that the hacking activities “targeted British businesses, government officials and journalist­s.”

To date, the NGCP said it has yet to be informed of the potential breach in security in Deloitte. It stressed that an immediate disclosure was not only appropriat­e but necessary to protect the integrity of NGCP’S systems. “The minute the potential breach was discovered, we should have been advised so that we could have conducted mitigating activities,” it said.

The NGCP holds a 25-year concession and a 50-year Congressio­nal franchise to expand and operate the country’s power transmissi­on grid. NGCP is the sole and exclusive operator of the country’s nationwide transmissi­on network linking the power generators and distributi­on utilities to deliver electricit­y to end-users.

Newspapers in English

Newspapers from Philippines