Challenges of industrial cybersecurity by Evgeny Goncharov, Kaspersky CERT
#1
Challenges of industrial cybersecurity


an article by Evgeny Goncharov, Head of @KasperskyICS CERT


Quote:In their swift development over the past decade, modern enterprises in energy, petrochemistry, metallurgy, pharmaceuticals, food processing, transport, logistics and other sectors have crossed the invisible line separating the physical world of machines and mechanisms from the virtual world of computer software. They have essentially evolved into cyber-physical systems, where instructions in machine code control physical objects. These cyber-physical systems are built using modern IT technologies. They are connected to each other and to the external cyber-world with wired and wireless communication channels. Although this makes effectively using and further developing such systems much easier, it also makes them vulnerable to computer attacks.
The danger posed by cyber-physical technologies to the industrial process and equipment is increasingly acknowledged by specialists working at industrial enterprises, information security researchers and government agencies of most countries. At the same time, most people who are responsible for or otherwise involved in ensuring the cybersecurity of industrial enterprises admit that implementing security measures is a very long process. As a rule, they cite a variety of reasons and factors that make progress towards protecting industrial facilities from cyberthreats difficult and slow or even downright impossible.
In this paper, we have summarized our knowledge and expertise accumulated over years of practical work (conducting security audits and penetration tests, investigating incidents, detecting and preventing attacks, designing and deploying protection, providing training to cybersecurity specialists and employees at industrial enterprises, participating in the development of recommendations and requirements for industry regulators) and communication with experts representing industrial enterprises, academic institutions and government agencies from different countries.
We have developed a list of factors that, in our opinion, affect, now and in the foreseeable future, the threat landscape and the development, implementation and use of organizational and technical measures designed to protect industrial facilities, as well as the major industrial cybersecurity issues which are not likely to be resolved in the near future.

Read more: https://ics-cert.kaspersky.com/reports/2...rsecurity/
[-] The following 2 users say Thank You to browneylad for this post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.0.5 / 19.0.7 Update
Changes in 19.0.7 ...harlan4096 — 05:52
AnyDesk 9.5.8 for Windows
AnyDesk 9.5.8 for ...harlan4096 — 05:50
Notepad++ v8.8.3
Notepad++ v8.8.3 s...harlan4096 — 05:49
Intel releases new Arc PRO graphics driv...
Intel’s new GPU dr...harlan4096 — 05:48
Microsoft caused and fixed a WSUS Synchr...
Reports about prob...harlan4096 — 05:47

[-]
Birthdays
Today's Birthdays
avatar (49)WillieVot
Upcoming Birthdays
avatar (45)RidgeDimb
avatar (36)ipumaqar
avatar (50)tanliorsPeri
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (38)boineDon
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (39)ywixazok
avatar (37)ixoqe
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>