Cisco Connect Romania conference was held this year on May 29, offering a prime occasion to celebrate together 25 years of Cisco’s presence in the Romanian market. This event also marked the 20th anniversary of this significant annual gathering in the IT&C industry, with Datanet Systems participating in every edition to date.
This year, leveraging the Datanet & Soitron partnership, we had a joint participation featuring presentations by Martin Lohnert, Managing Director of Void SOC, Cybersecurity Operations Center at Soitron Group, Void SOC, and Bogdan Șileanu, Senior Security Consultant at Datanet. A major highlight was our company booth, where the Datanet expert team was joined by a charming and interactive robot, engaging with visitors. With a record audience of over 1,100 participants, the event was a success on all fronts.
The Connect Romania 2024 conference kicked-off with Dorin Pena, General Manager of Cisco Romania, who unveiled key insights from Cisco’s recent „Cybersecurity Readiness 2024” report, highlighting that 49% of European companies experienced at least one cybersecurity incident in the past year. Among the speakers included Mihaela Rodica Suciu, General Manager at Distribuție Energie Electrică România, and Cătălina Niculiță, Cisco Solution Engineering Manager for Romania and CIS, as well as others.
Generative AI increases Cybersecurity Risks in 2024
Martin Lohnert, representing Datanet-Soitron, delivered the event’s most anticipated keynote, opening by expressing his gratitude to the Datanet Systems team for their professionalism throughout the 15+ year partnership with the Soitron Group.
Continuing, he shifted the focus to cybersecurity, highlighting the challenges posed by Generative AI technologies. Martin Lohnert referenced the „Allianz Risk Barometer” report, a comprehensive study identifying the foremost risks for businesses in 2024. Cyber incidents emerged as the top concern for over 3,000 organizations across 90 countries, marking the second consecutive year. Additionally, he emphasized how Generative AI empowers less experienced attackers to amplify their assault capabilities. Martin Lohnert substantiated this assertion by demonstrating the capabilities of ChatGPT 4.0, a prominent GenAI tool. He showcased its potential for being easily manipulated, providing all the essential information within 15 minutes, thus facilitating novice hackers in exploiting vulnerabilities.
What are the prime targets for beginner hackers? Industrial devices/equipment linked to the internet (PLCs, HMIs, and SCADA systems), controllers for lighting, heating, air conditioning, access systems, cameras and alarms, printers, and MFDs. These frequently lack authentication requirements, operate on outdated firmware and software that is challenging to update, and transmit unencrypted data, rendering them easily discernible..
The situation is also concerning in Romania
According to passive investigations conducted by Soitron, Romania has over 1,670 such vulnerable industrial devices/equipment connected to the internet, with 793 of them located solely in Bucharest. “Bored teenagers at home, with access to ChatGPT, can ‘play’ with any of these devices right now,” added Martin Lohnert. He also demonstrated a real-life demo on how to write malware sequences using ChatGPT to exploit vulnerabilities in outdated operating systems. The Soitron representative provided examples of equipment with firmware that hadn’t been updated in 10 years, despite the manufacturer’s website warning customers about this situation.
Access to the graphical interface of these systems can be obtained with minimal effort and without any authentication. As a result, attackers can access UPS systems, surveillance cameras, or controllers of photovoltaic systems with just a few simple clicks. This grants them access to sensitive information, confidential images, and even control over certain systems, enabling them to obtain information such as real-time energy production (in the case of photovoltaic panels) or firmware versions.
In a lighter moment, the story of a brewery outside Romania added a touch of humor to the proceedings. “During our investigations abroad, we stumbled upon a brewery that seemed to take security about as seriously as happy hour. Their SCADA system was like a tipsy bartender, with an emergency stop button as accessible as a coaster. We kindly emailed them, warning that anyone with a mouse could potentially tap out their taps. Yet, much like a stubborn beer stain, they brushed off our concerns. Surprisingly, when they finally upgraded their system but kept the emergency stop button,” recounted the Soitron-Datanet representative.
Closing Remarks from Soitron-Datanet. Cybersecurity Recommendations
In wrapping up, Martin Lohnert shared a set of cybersecurity guidelines tailored for companies in Romania:
- Elevate the awareness of cybersecurity and its significance: Often, it all starts with leadership. Management needs to grasp the importance of cybersecurity.
- Understand and safeguard your devices, networks, identities, data, etc.: While there are many protective devices and tools available, it’s paramount to first identify what devices are in use. Don’t overlook even the smallest internet-connected devices.
- Proactively monitor your organization’s infrastructure, risks, and emerging threats: This is among the simplest measures you can take. There’s an array of solutions ready to provide this service for you almost instantly.
- Be prepared for incidents and react promptly and accurately when they occur.
Splunk-Cisco, a winning integration
In the latter part of the event, our colleague Bogdan Șileanu, Senior Security Consultant, delivered the technical presentation: “Enhance visibility and security with Splunk integration in your Cisco infrastructure – practical use cases“.
Our colleague took the stage to delve into the distinct competitive advantages of Splunk and the valuable integrations it offers with Cisco. Splunk has long been renowned for its prowess in data collection from diverse sources, including servers, networks, devices, and applications, indexing them for easy retrieval, and providing sophisticated analytical capabilities. With Splunk, users can effortlessly visualize data, monitor it in real time, and integrate it to take immediate action on alerts.
Bogdan Șileanu underscored some key integrated Splunk-Cisco use cases, including:
- Monitoring IT infrastructure and conducting troubleshooting operations to ensure seamless availability;
- Swiftly detecting cyber threats, initiating rapid responses, and ensuring compliance with reporting standards;
- Gaining granular insights into IT environment performance;
- Analyzing data collected from IoT devices for enhanced monitoring and decision-making.
Datanet stands out as one of the select integrators in Romania with tangible expertise in projects that seamlessly integrate Cisco and Splunk technologies. Since January 2021, Datanet Systems has proudly served as an Associate Reseller for Splunk products in Romania.
We extend our sincere gratitude to all those who visited the Datanet booth at Cisco Connect Romania this year and eagerly anticipate reconnecting with you at the 2025 edition.