Practical SCADA Security

Control System Security Threats, Security / Reliability Incidents, Useful Industrial Cyber Security Tips

Eric Byres
Thursday, March 14, 2013

As regular readers of this blog know, after Stuxnet, security researchers and hackers on the prowl for new targets to exploit shifted their efforts to critical industrial infrastructure.

 

Unfortunately, the Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) applications they are now focusing on are sitting ducks.

 

Up until recently SCADA and ICS systems have been designed with reliability and safety in mind; security has been a minor consideration. Products that have never faced security tests are now under attack from sophisticated...

8
4,327 reads
Eric Byres
Thursday, March 7, 2013

Last week I received am email (shown further down on this page) purporting to be from the US Internal Revenue Service (IRS).

 

Phishing, like fishing, can be profitable. Image Credit:...

3,224 reads
ghale
Thursday, February 28, 2013

Editor’s Note: This is an excerpt from ISSSource.

 

It wasn’t that long ago when cyber security seemed like a foreign language to those folks entrusted with running companies. It was not like they didn’t know about it, but it just was not top of mind.

 

Not anymore.

 

With cyber threats evolving to the point where they are affecting their companies and their customer’s companies, chief executives are taking a new look and approach to how they attack cyber security.

 

They know meeting objectives and delivering on business...

3,431 reads
bob.lockhart
Monday, February 18, 2013

Editor's Note: this is an excerpt from the Pike Research Blog.

 

The story goes that a group of business people were stranded on a desert island with a bountiful supply of canned and therefore imperishable food, but no way to open the cans. As the group struggled to find a solution the lone economist in the group piped up, “Assume a can opener…”

 

...

2
3,806 reads
Eric Byres
Thursday, February 7, 2013

We all agree that SCADA and Industrial Control System security needs to improve. However there is a lot of disagreement on what exactly needs to happen to make security for industrial systems easier to deploy and more effective. Last week’s blog exchange between me and Dale Peterson, is just one example of those differences. Now this week...

1
4,004 reads