30 Nov 2020 IT Insider | The Top 20 Cyber Attacks on Industrial Control Systems #2 | iSi
THE INDUSTRIAL SECURITY INSTITUTE
OT / industrial / ICS cybersecurity concepts from the perspective of the world’s most secure industrial sites. Truly secure sites ask different questions, and so get different answers. Subscribe to never miss and episode.
EPS. 2 – IT INSIDER
A disgruntled IT Insider shoulder-surfs remote access credentials entered by an ICS support technician visiting a remote office. The disgruntled insider later uses the credentials to login to the same distant ICS engineering workstation that the technician logged into. The insider looks around the workstation and eventually finds and starts a development copy of the plant HMI. The insider brings up screens more or less at random and presses whatever buttons seem likely to cause the most damage or confusion. These actions trigger a partial shutdown
THE TOP 20 CYBERATTACKS ON INDUSTRIAL CONTROL SYSTEMS
These Top 20 attacks have been selected to represent cyber threats to industrial sites across a wide range of circumstances, consequences and sophistication. No industrial operation is free of risk, and different industrial enterprises may legitimately have different “appetites” for certain types of risks. In this series we show how to use the Top 20 Cyberattacks to compare the strength of two security postures at a hypothetical water treatment plant: Defence in depth 2013 (software based security) vs. that same security posture plus a unidirectional security gateway device providing hardware-enfonced security). We ask the question, does either defensive posture reliably defeat each attack? Over the course of 20 episodes we build a score card that can be used to easily communicate risk reduction benefits to business decision-makers who are not familiar with cyber-security
ABOUT ANDERW GINTER
At Waterfall, Andrew leads a team of experts who work with the world’s most secure industrial sites. He is author of two books on industrial security, a co-author of the Industrial Internet Consortium’s Security Framework, and the co-host of the Industrial Security Podcast. Andrew spent 35 years designing SCADA system products for Hewlett Packard, IT/OT connectivity products for Agilent Technologies, and OT/ICS security products for Industrial Defender and Waterfall Security Solutions.
Dig deeper - download the accompanying ebook here
- The Enterprise Perspective on OT Security – Ed Amoroso | Episode #51 - January 19, 2021
- Zero Day Ransomware | The Top 20 Cyber Attacks on Industrial Control Systems #5 | iSi - January 12, 2021
- Unidirectional OT Zero Trust - January 10, 2021