Fixing Your Nuisance Alarms Just Got a LOT Easier

The most popular alarm management presentation we have ever done has been the one on fixing “Bad Actor” alarms. I like it because I get to refer to some of my favorite schlocky sci-fi movies – and it turns out that lots of engineers like those as well!   Nuisance alarm reduction is an important step. We recommend it at the beginning of an alarm improvement effort because it is easy, fast, cheap, and... Read more

ICS Cybersecurity Cognitive Dissonance

ICS Cybersecurity's Cognitive Dissonance

In the recently released survey from SANS, Securing Industrial Control Systems—2017, there were two results that stood out more than most. The first came from a question assessing which control systems had the greatest impact if compromised and exploited; the second related to which systems had the strongest data collection and analysis. In the case of impact, survey respondents ranked computer assets with... Read more

Ready, Set…Hang On, Maybe We Are Not Ready

Recently, the NATO Cooperative Cyber Defence Center of Excellence (CCDCOE) executed their annual Locked Shields exercise in which participating blue team countries defended networks from a NATO-supported red team attacks. In 2016, participating countries saw industrial control systems added to the list of cyber assets they were required to defend. So, how did the U.S. do in this exercise? Unfortunately, in its inaugural... Read more

WannaCry: A Serious Threat and Patching Challenge for Critical Infrastructure

It happened. The ransomware known as WannaCry was confirmed this week as having made it into industrial process facilities. This should put all companies who rely upon industrial control systems (ICS) – particularly companies classified as critical infrastructure – on high alert. Why? Because the choices available to protect the systems within an industrial facility’s network are much more... Read more

Avoid the ICS Cybersecurity Blind Spot

The Verizon Data Breach Investigations Report (DBIR) is as interesting for the unexamined risks as it is for the examined ones. If you look at the cyber assets on which the report gathered security data (page 10), there is not a single industrial control system (ICS) category listed. Why is this important? Because ICS are the systems that have direct responsibility for running volatile chemical and oil... Read more

Displaying results 6-10 (of 39)
 |<  <  1 2 3 4 5 6 7 8  >  >| 

This site would like to place a cookie on your browser to help us better deliver relevant and valuable content to you.