
Knocking down the legs of the industrial security triad. [Research Saturday]
CyberWire Daily
00:00
Industrial Control System Security
Industrial control system security wasn't off the thought and that wasn't anybody's fault, it's just how it organically grew. When we first started seeing industrial control systems they weren't more than a handful of devices tied together with serial communications point to point connections. So authentication and authorization wasn't in play at those times because there was only one device that was able to connect to it. But then when the hype came to bring everything to TCP IP stack and put everything on Ethernet they just took those wide open protocols and they put them on Ethernet which was already being scrutinized by attack tools.
Play episode from 13:23
Transcript


