ABB/Ventyx/Industrial Defender – innovating world class technology together

Current and future ABB 800xA and Ventyx Network Manager customers are now well poised to address Security, Compliance and Change Management challenges given the exhaustive efforts of the ABB-Industrial Defender strategic partnership.  With a commitment to market leadership, ABB/Ventyx/Industrial Defender has completed interoperability testing   and rules development for the Automation Systems Manager solution for both 800xA and Network Manager platforms. Whether you are a power generator or o << More >>

Cyber attackers move to target critical infrastructure system suppliers

This week’s news identifies a cyber-attack perpetrated against a key supplier of automation system technologies used in multiple critical infrastructure sectors.  This latest news underscores the sophistication and the targeted nature of the attacks on critical infrastructure, as well as suppliers. It is representative of the determination and malicious intent of those intending to undermine global critical infrastructure. With DHS ICS CERT investigating 400% more incidents last year, it’s << More >>

Fandotech Acquisition Enables New Survive™ Services

Industrial Defender President and CEO, Brian Ahern chats with newest executive team member John Boyd, VP of Hosting, about the recent acquisition. Industrial Defender acquired Fandotech to enable the company’s new services launch; Survive™. The Survive services provide Onsite and Offsite Backup and Disaster Recovery of critical cyber assets for industrial control systems (ICS) environments to ensure operational continuity. Watch the discussion posted above or read the transcript below: << More >>

Cellular technology use in ICS and 3 ways to minimize risk

Recently, ICS-CERT published its January 2012 newsletter with some great advice regarding cellular technology use in ICS networks. The article, titled “Industrial Cellular Security”, discusses the types and uses for cellular devices as well as mitigation advice for dealing with ICS cellular device threats. The coverage of cellular technology for communications in remote areas has been covered several times before with respect to security.  The Additional Readings section below has links to << More >>

Security Basics: Network Segmentation

I recently attended a DHS/US-CERT “Introduction to Industrial Control Systems Cybersecurity” course and was disappointed that there was not more time devoted to mitigation. One of the topics glossed over in the mitigation section of the course was network segmentation, especially the separation of enterprise / business networks from plant and control networks. Now, Industrial Defender field personnel tell me that pretty much every site they visit is already doing plant / enterprise n << More >>

Cyber Warfare Conflation

There were another two pieces in the mass media last week on cyber warefare (CBS and ABC). The media generally gets the story straight, but spends little effort making sure the listener/reader understands it all. The problem is that there are several kinds of adversaries that get discussed, and several kinds of targets, with several kinds of motivations. If listeners and readers don’t already know what’s up, it is easy to mix up who is doing what to whom and get confused about how vu << More >>

ICSJWG 2010 Spring Conference

Highlights of the spring conference: The plant security working group of the WIB International Instrument User’s Association (www.wib.nl) has published report “M 2784 X10″ entitled “Process Control Domain – Security Requirements for Vendors”. Shell was a driving force behind this standard available for download here (note: WIB permission is needed to redistribute). Shell is starting to require their vendors to certify against M-2784 and Wurldtech is putting t << More >>

Application Whitelisting and Control Systems

I just got back from the Digital Bond SCADA Security Scientific Symposium (S4) where I presented on whitelisting. Whitelisting is the “hot new” host intrusion prevention system (HIPS) technology that some tout as the end of the anti-virus (AV) era. Anti-virus of course works by producing a “black list” of virus signatures. If data or a file matches a signature, the AV technology takes some sort of action to protect your system – anything from a popup alert to blocki << More >>