Practical SCADA Security

Control System Security Threats, Security / Reliability Incidents, Useful Industrial Cyber Security Tips

submitted by: Eric Byres
on: Thu, 2011-09-15 09:30

A few weeks ago, I received an email from a user asking about antivirus protection for SCADA systems. Now I think antivirus is an essential tool for ICS and SCADA systems. However, this is what he wrote:

My security supplier tells me that attacks from Stuxnet (and next-Stuxnet like worms) can be avoided by protecting WinCC computers using an antivirus product. This will make the PLC perfectly safe, they tell me.

submitted by: Eric Byres
on: Thu, 2011-09-01 21:00

Today is a big news day for Byres Security Inc. (BSI), as we are announcing that our company has been acquired by Belden Inc.

We (Joann Byres and Eric Byres) are writing this article to let you know what the future has in store for us, and for our company.

What will stay the same?

Byres Security Inc. will run as an independent business unit under Belden, and the Tofino Security brand will remain the same.

BSI will continue:

submitted by: Eric Byres
on: Wed, 2011-08-17 11:08

Last week I discussed the first steps to take to get started to improve ICS and SCADA Security in your facility.  Those steps included:

  • Step 1 - Conducting a Security Risk Assessment,
  • Step 2 - Learning Industrial Cyber Security Fundamentals, and
  • Step 3 - Understanding the Unique Requirements of ICS and SCADA Cyber Security.

This week I discuss the remainder of the process.

submitted by: Eric Byres
on: Wed, 2011-08-10 15:02

The furor over the Siemens vulnerabilities and the fear that Son-of-Stuxnet could be around the corner has raised awareness of the need for cyber security to be taken seriously by the process and critical infrastructure industries.

submitted by: Eric Byres
on: Thu, 2011-08-04 15:07

My optimism regarding Siemens and its approach to SCADA/ICS security has just taken another big hit. There are major security problems at Siemens and they are not close to fixing them.

I am embarrassed I gave them such high marks in my previous blogs.