Cyber Risk Compendium

Sabotage

BSI ID: G 0.41

Sabotage refers to the deliberate manipulation or damage of property or processes with the aim of causing harm to the victim. Data centres or communication links belonging to public authorities or companies can be particularly attractive targets, as a great deal can be achieved here with relatively little effort. The complex infrastructure of a data centre can be selectively manipulated by targeted interference with important components, possibly by external perpetrators, but above all by internal perpetrators, in order to cause operational disruptions. Particularly at risk are inadequately protected building services or communications infrastructure and central supply points that may not be monitored for organisational or technical reasons and are easily accessible to outsiders without being observed.

Examples:

  • In a large data centre, manipulation of the UPS led to a temporary total failure. The perpetrator had repeatedly switched the UPS to bypass manually and then manipulated the building's main power supply. A total of four failures occurred in three years. In some cases, hardware damage was even caused. The interruptions to operations lasted between 40 and 130 minutes.

  • A data centre also housed sanitary facilities. By blocking the drains and simultaneously opening the water supply, water penetrated central technical components. The damage caused in this way led to interruptions in the productive system.

  • Sabotage poses a particular risk to electronic archives, as they usually store many sensitive documents in a small space. This means that targeted, low-cost manipulation can cause significant damage under certain circumstances.