Practical SCADA Security

Control System Security Threats, Security / Reliability Incidents, Useful Industrial Cyber Security Tips

David Alexander
Thursday, February 2, 2012

Eric Byres made a very good point in his blog article “S4 SCADA Security Symposium Takeaway: Time for a Revolution” about the user community needing to unite and put pressure on automation vendors to improve the security of their products.  I am writing to be, dare I say, more militant about this point.

The IT World Routinely Pressures Vendors for Better Security

I mentioned BugTraq in my last posting.  It is a tool that has worked well for end users of...

6
541 reads
Eric Byres
Friday, January 27, 2012

The Oscar season is upon us and instead of predicting who will win Academy Awards I am writing today to talk about what I see in my “Crystal Ball” for 2012.

 

What could 2012 do to top 2010 where the game changing Stuxnet worm was revealed, or 2011 when Stuxnet’s publicity led to hackers and criminals releasing 215 vulnerability disclosures for SCADA / Automation products.1  That is more vulnerabilities than were disclosed in the previous decade!

 

...

1,056 reads
Eric Byres
Friday, January 20, 2012

 I am flying home from Digital Bond’s S4 SCADA Security Symposium as I write this (BTW this was a stellar event where, even as a security expert, I learnt an amazing amount).  After listening to two days of excellent, but scary talks, the first thing that comes to mind is “SCADA/ICS security is in worse shape than I thought”. Much worse shape…

 

You have probably already read about the “Firesheep / Project Basecamp” ICS/SCADA...

1
1,769 reads
Frank Williams
Wednesday, January 11, 2012

Today is the day that Tofino Security is announcing that I have joined their team.  I am very excited about this, particularly because I believe that industrial cyber security is the next major impactful technology to hit the automation industries.

 

I am also excited to be joining Eric and Joann Byres and their group; people I have high regard for, as I believe Tofino Security technology is poised to lead the way in protecting the critical infrastructure industries.

 

However, enough cheerleading - this is a blog.  Here is my perspective on technology advancement in the automation industries over the past few decades, and my belief in where it is going next.

...
6
1,136 reads
Eric Byres
Wednesday, January 4, 2012

After suggesting a sous-vide oven as a gift idea for control engineers, I was looking forward to designing my own homemade system from PLC parts over the holidays.  However, my project never got off the ground as my wife Joann gave me the real thing.  (Perhaps she couldn’t stand the thought of having my home-built electronics in the kitchen…)

 

Thus, rather than building, I have been cooking and eating à la sous-vide.  A fair trade, I’d say.

 

The good news is that sous-vide...

2
1,087 reads