The Risk of Not Knowing

“The big problems are where people don’t realize they have one in the first place.”  – Edward Deming Deming’s observation seems obvious enough. When you apply this to ICS cybersecurity, what are the “big problems” that companies don’t realize? In the power, petrochemical, and oil & gas industries, the stakes are high. These big problems – especially ... Read more

Don’t Lose Sight of the Forest for the Trees

In a recent interview with Chemical Processing magazine, I was asked about complying with alarm management standards such as ISA 18.2 and IEC 62682. I emphasized the obvious importance of complying with these standards. With compliance a given, we must guard against missing the forest for the trees. Striving for improved Operator Effectiveness (the forest) is the greater goal and focusing strictly on... Read more

A Tale of Two Lines

Change is part of daily industrial operations. Detecting a change and assessing the validity of that change are critical to effective ICS cybersecurity. Let’s say, for instance, that two lines have been removed from an SIS configuration file. Now let’s say this change blinds the operator to the availability of the SIS.How will you know this configuration change occurred? This particular change happens deep... Read more

Are We Chasing Our Tail?

Recent security alerts say your car isn’t secure and can be remotely controlled. Your house isn’t secure and can let the bad guys unlock the doors. Your watch isn’t secure and can let your confidential information out. Where does this end?As anyone in the security world will tell you, there is no such thing as a completely secure system. There are just levels of... Read more

When a Cybersecurity Stranger Calls

Ever since I was a kid, certain movies have stuck with me, surfacing unexpectedly. Some because they are irreverently funny; I still quote Caddyshack when on a golf course. Others because they explore some element of humanity; think The Deer Hunter and Apocalypse Now. And others simply scare the ever loving you-know-what out of me; The Exorcist was definitely one of those. The movie ... Read more

