Archive for the "Cybersecurity" Category

Sort by:

Catastrophe: Should’a, Would’a, Could’a

“I should prefer Mozart. Mostly I listen to 70s hits.” “I should eat a hot breakfast, but usually have a powerbar instead.” “I should work-out three or four times a week, maybe I walk around the block twice.” Should has become moralistic.  It is typically used as a kind of anti-verb, ascribing — often anticipating [...]

@Belden @Tofino tested by @DigitalBond: It works!

Recently, several ICS end users in the Middle East and Asia have been exposed to attacks directly on the control systems through firewalls that have been misconfigured, or not configured correctly, for Modbus and OPC data. These attacks have caused wee…

@Belden @Tofino tested by @DigitalBond: It works!

Recently, several ICS end users in the Middle East and Asia have been exposed to attacks directly on the control systems through firewalls that have been misconfigured, or not configured correctly, for Modbus and OPC data. These attacks have caused wee…

Back to the Future?

A friend and I were discussing some new security features in a well known brand of Programmable Logic Controller (PLC). The features are almost exactly what most IT security experts have been demanding for years. Unfortunately, they are also very complex, arcane, and difficult for a typical engineer to want to mess with. If it [...]

The MIT Report on the Electric Grid: Control Systems Were Not Adequately Addressed

MIT issued the report, "The Future of the Electric Grid – An Interdisciplinary MIT Study." Chapter 9 is "Data Communications, Cybersecurity, and Information Privacy." According to the report, the U.S. should implement standards to…

What We Have Here Is a Failure to Communicate

Nancy Bartels of Control magazine and ControlGlobal.com hijacking Joe’s blog here. This story would be funny if it wasn’t so scary. Wired magazine has broken the real story (or the latest iteration of the real story). The link is here. So it wasn’t evi…

The Illinois Water Hack Is a Test of the System for Disclosure – Is It Broken?

My blog on the Illinois water hack was directly based on a formal disclosure announcement by the Illinois State Terrorism and Intelligence Center – STIC (Note: My blog did not identify the state involved. That disclosure came from DHS). The STIC disclo…

Is the WaterISAC Helping the Water Industry? – The Illinois Water Hack Raises Serious Questions

Per the WaterISAC portal, the WaterISAC (Information Sharing and Analysis Center) is a community of water sector professionals who share a common purpose: to protect public health and the environment. The WaterISAC provides email notifications about th…

Water System Hack – The System Is Broken

Last week, a disclosure was made about a public water district SCADA system hack. There are a number of very important issues in this disclosure:read more

Observations of Joe Weiss’ ACS Conference

Although I was invited to attend one of Joe’s social gatherings several years ago, I have never attended any of his conferences, until this past week.  Despite the fact that critics of Mr. Weiss have stated that he is self-serving, contrary to popular belief, he is not.  Joe encourages people to meet, network and discuss [...]