A Dissertation Submitted to the Department of Environmental
Total Page:16
File Type:pdf, Size:1020Kb
A dissertation submitted to the Department of Environmental Sciences and Policy of the Central European University in part fulfillment of the Degree of Doctor of Philosophy CEU eTD Collection THE REGIONAL SECURITIZATION OF CYBER-PHYSICAL ENERGY SYSTEMS Ion A. Iftimie September 2020 This dissertation is submitted in fulfilment of the Degree of Doctor of Philosophy awarded by the Department of Environmental Sciences and Policy at the Central European University. Cover photo: Central Europe Pipeline System (CEPS), The Fifteen Nations, 9/10, 1959 CEU eTD Collection 2 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU Notes on copyright and the ownership of intellectual property rights: (1) Copyright in text of this dissertation rests with the Author. Copies (by any process) either in full, or of extracts, may be made only in accordance with instructions given by the Author and lodged in the Central European University Library. Details may be obtained from the Librarian. This page must form part of any such copies made. Further copies (by any process) of copies made in accordance with such instructions may not be made without the permission (in writing) of the Author. (2) The ownership of any intellectual property rights which may be described in this dissertation is vested in the Central European University, subject to any prior agreement to the contrary, and may not be made available for use by third parties without the written permission of the University, which will prescribe the terms and conditions of any such agreement. (3) For bibliographic and reference purposes this dissertation should be referred to as: Iftimie, IA. 2020. The regional securitization of cyber-physical energy systems. Doctoral dissertation, Department of Environmental Sciences and Policy, Central European University, Vienna. Further information on the conditions under which disclosures and exploitation may take place is available from the Head of the Department of Environmental Sciences and Policy, Central European University. CEU eTD Collection 3 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU Author’s declaration: No portion of the work referred to in this dissertation has been submitted in support of an application for another degree or qualification of this or any other university or other institute of learning. Furthermore, this dissertation contains no materials previously written and/or published by another person, except where appropriate acknowledgment is made in the form of bibliographical reference, etc. Ion A. IFTIMIE CEU eTD Collection 4 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU Table of Contents Page Title 8 List of Tables 10 List of Figures 12 General Abbreviations 16 Abstract 18 Acknowledgements 19 Chapter 1: Introduction 19 1.1 Statement of the problem 21 1.2 The challenge to the traditional energy security environment 23 1.3 Aims and objectives 24 1.4 Approach/methodology 25 1.5 Structure 26 Chapter 2: Literature Review 27 2.1 Energy security during smart and sustainable low carbon energy transitions 27 2.1.1 A narrative summary of ‘traditional’ energy security thought 30 2.1.2 The contemporary thinking on energy security 34 2.1.3 The emerging climate change risks: framing and conceptualizing energy security during smart and sustainable low-carbon energy transitions 42 2.2 Digital transformation for energy transformation 43 2.2.1 What to protect? An anatomy of OT vulnerabilities to CEI 46 2.2.2 From what threats to protect? 50 2.2.3 By what means to protect CEI? 51 2.3 Collective security alliances 53 2.3.1 Empirical studies on CSAs under the Westphalian system 60 2.3.2 Post-Westphalian perspectives on collective security CEU eTD Collection 65 2.4 Securitization of geo-energy systems: energy security and the challenge of cyber diplomacy within collective security alliances 69 2.5 Summary of Literature Review 5 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU 71 Chapter 3: Methodology 71 3.1 Nested cyber security assessments of geo-energy systems 72 3.1.1 Cyber security in specific geo-energy contexts 76 3.2 The proposed CSA cyber security framework during smart and sustainable low-carbon energy transitions 77 3.2.1 Framing: the national positions on cyber security during smart and sustainable low-carbon energy transitions 79 3.2.2 Reframing: the regional positions on cyber security during smart and sustainable low-carbon energy transitions 81 3.3 The proposed framework approach 81 3.3.1 What to protect: critical energy systems in the context of energy security and environmental security 82 3.3.2 From which risks to protect: cyber threats to critical energy systems 83 3.3.3 By which means to protect—the means that Collective Security Alliances have at their disposal to increase the resilience of critical energy systems to cyber threats 86 3.4 Case study selection 87 3.5 Applying Baldwin’s questions at the national level 88 3.5.1 What to protect 92 3.5.2 From what threats to protect? 96 3.5.3 By what means to protect 99 3.6 Reframing: addressing the research questions for NATO 100 3.7 Contributions and Limitations 101 Chapter 4: Data Presentation 102 4.1 Cyber security and resilience of the Central Europe Pipeline System 104 4.2 The role of the NATO CEPS Programme in cyber security and resilience 105 4.3 Host Nations’ role in the cyber-physical protection of the CEPS infrastructure 106 4.3.1 Belgium and Luxembourg CEU eTD Collection 122 4.3.2 France 130 4.3.3 Germany 139 4.3.4 The Netherlands 147 4.4 NATO’s role in cyber-physical protection of critical energy systems and the environment 151 4.5 Conclusions 6 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU 157 Chapter 5: Discussion 158 5.1 How CSAs perceive, define, frame and manage cyber threats to vital energy systems 159 5.1.1 The Geo-STEPE divide 162 5.1.2 The stakeholder divide 163 5.2 Back to NATO CEPS: the need for a stakeholder analysis 164 5.2.1 Stakeholders of NATO CEPS cyber-energy security during smart and sustainable low-carbon energy transitions 168 5.2.2 The EU as a stakeholder of NATO CEPS cyber security 174 5.3 CSAs and the future of CEIP in the cyber domain 176 5.3.1 The impact of group politics on cyber threat prioritization 178 5.3.2 Redefining the cyber threat: back to the three perspectives 181 Chapter 6: Conclusions 186 Bibliography CEU eTD Collection 7 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU List of Tables Page Table 87 Table 1: List of major political, economic, and collective security alliances that CEPS host nations belong to. 91 Table 2: CARVER weighing scheme of system protection. 95 Table 3: Adversary Prioritization. 98 Table 4: GCI indicators per pillar with original and adjusted weights for CEPS OT. 109 Table 5. Results of CARVER cyber analysis for CEPS infrastructure in Belgium. 110 Table 6. Prioritization of what CEPS systems to protect from cyber-attacks in Belgium. 111 Table 7. Results of CEPS cyber threat analysis for Belgium. 112 Table 8. Prioritization of cyber threats against CEPS in Belgium. 113 Table 9. Prioritizing by what means to protect CEPS from main cyber threats in Belgium. 116 Table 10. Results of CARVER cyber analysis for CEPS infrastructure in Luxembourg. 117 Table 11. Prioritization of what CEPS systems to protect from cyber-attacks in Luxembourg. 118 Table 12. Results of CEPS cyber threat analysis for Luxembourg. 119 Table 13. Prioritization of cyber threats against CEPS in Luxembourg. 120 Table 14. Prioritizing by what means to protect CEPS from cyber-attacks in Luxembourg. 125 Table 15. Results of CARVER cyber analysis for CEPS infrastructure in France. 126 Table 16. Prioritization of what CEPS systems to protect from cyber-attacks in France. 127 Table 17. Results of CEPS cyber threat analysis for France. 128 Table 18. Prioritization of cyber threats against CEPS in France. 129 Table 19. Prioritizing by what means to protect CEPS from cyber-attacks in France. 133 Table 20. Results of CARVER cyber analysis for CEPS infrastructure in Germany. 134 Table 21. Prioritization of what CEPS systems to protect from cyber-attacks in Germany. 135 Table 22. Results of CEPS cyber threat analysis for Germany. 136 Table 23. Prioritization of cyber threats against CEPS in Germany. 137 Table 24. Prioritizing by what means to protect CEPS from cyber-attacks in Germany. CEU eTD Collection 141 Table 25. Results of CARVER cyber analysis for CEPS infrastructure in the Netherlands. 142 Table 26. Prioritization of what CEPS systems to protect from cyber-attacks in the Netherlands. 143 Table 27. Results of CEPS cyber threat analysis for the Netherlands. 144 Table 28. Prioritization of cyber threats against CEPS in the Netherlands. 8 IFTIMIE, I. (2020). The Securitization of Cyber-Physical Geo-Energy Systems. Dissertation submitted to the Department of Environmental Sciences and Policy of CEU 145 Table 29. Prioritizing by what means to protect CEPS from cyber-attacks in the Netherlands. 161 Table 30. New NATO and Old NATO legal, technical, organizational, capacity, and cross border cooperation considerations for cyber security of critical infrastructure.