Practical SCADA Security

Control System Security Threats, Security / Reliability Incidents, Useful Industrial Cyber Security Tips

submitted by: Eric Byres
on: Thu, 2013-04-11 15:43

In my last blog, I shared some secrets on how to successfully use patching in SCADA and control systems.

This week, I’ll look at the pros and cons of using compensating controls as an alternative to patching, and discuss the requirements for success.

submitted by: Eric Byres
on: Thu, 2013-04-04 16:17

If you have read my previous blogs on patching for control system security, you might think I am completely against patching. Guess what? I’m not against them!

submitted by: Eric Byres
on: Tue, 2013-03-26 12:11

In my last blog, I discussed the reasons why critical industrial infrastructure control systems are so vulnerable to attacks from security researchers and hackers, and explained why patching for such systems is not a workable solution.

submitted by: Eric Byres
on: Thu, 2013-03-14 16:40

As regular readers of this blog know, after Stuxnet, security researchers and hackers on the prowl for new targets to exploit shifted their efforts to critical industrial infrastructure.

Unfortunately, the Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) applications they are now focusing on are sitting ducks.

submitted by: Eric Byres
on: Thu, 2013-03-07 15:25

Last week I received am email (shown further down on this page) purporting to be from the US Internal Revenue Service (IRS).