Efficient Plant January 2018 - 19

feature | operational strategies

A RECENT TWO-PART blog by
Mille Gandelsman and Yariv Lenchner
of Indegy (indegy.com, New York) put
the New Year into perspective with
regard to industrial cybersecurity.
Part I examined threats that industrial IT and OT security professionals
can expect in 2018 and beyond. Part
II highlighted some things that are
on the horizon for the industrialcontrol-system (ICS) security area.
The discussion began with the authors'
acknowledgement of the increase
and acceleration in connectivity and
digital transformation in industry over
the past few years-and the fact that
continuing advances in such initiatives
will be introducing new cybersecurity
challenges and landscape changes.
Their predictions, divided into a
bad news/good news scenario, are
summed up here.

THE BAD NEWS
Ransomware will continue wreaking
havoc on industrial organizations.

JANUARY 2018

In 2017, global ransomware outbreaks such
threat: It has quietly developed a cyber
as WannaCry, NotPetya, and Bad Rabbit,
army capable of unleashing attacks against
caused widespread disruptions among
critical infrastructure that could have globorganizations in all industries, including
al implications.
manufacturing and transportation services.
Russia also has developed cyberIt's a good bet this trend will continue.
weapon capabilities. It has been accused of
The ransomware variants of 2017
extensive attacks on Ukraine's power grid,
weren't specifically designed for industrial
cutting off electricity to nearly a quarter of
networks. But, since these environments
a million people in December 2015, and
included many legacy Windows-based
taking down a transmission station in 2016.
systems that weren't properly patched or
In November 2017, during her annual
secured, they were easily compromised.
speech in London's Guildhall, U. K. Prime
Thus, it's important to apply appropriate
Minister Theresa May accused Russia of
patches and strengthen security controls to
attacking Britain's national power grid and
protect these systems.
its telecom companies.
Fortunately, the disrupThese developments,
tion to industrial organizaaccording to Gandelsman
Industry still
tions caused by ransomware
and Lenchner, point to
has work to do
in 2017 did not directly
what is known as a "Red
when
it
comes
affect automation controlButton" capability, whereby
to dealing with
lers. Controllers continued
adversaries have gained a
to operate manufacturing
foothold inside industricyberthreats.
and other processes, even
al networks and critical
after Windows-based opinfrastructure and are caerator and engineering workstations were
pable of shutting down power grids, water
compromised and became unavailable.
supplies, and other crucial operations with
Gandelsman and Lenchner do, however,
the push of a button.
predict that a new, more damaging type of
Introduction of IIoT (Industrial Interransomware will specifically target controlnet of Things) technology without full
lers. They cite a study conducted at Georgia
consideration of security will continue.
Tech (Georgia Institute of Technology,
The constant need to modernize industrial
gatech.edu, Atlanta) in early 2017, wherein
systems, increase productivity, and improve
researchers designed a cross-vendor ranmaintenance procedures is driving the
somware worm capable of targeting PLCs
implementation of IIoT technologies. This
that are exposed online. Given the fact this
trend can expose already-vulnerable ICS
proof of concept now exists, Gandelsman
networks to cyberthreats they have never
and Lenchner expect to see a threat in the
before faced.
wild in 2018.
Designed by various industrial vendors,
There's a real possibility of a 'red
many IIoT technologies may not include
button' cyber weapon. While much of the
hacker protection. In turn, those devices
world's attention recently has been focused
might expose an ICS to a wide array of cyon North Korea's development of nuclear
berthreats and exploitation attempts. Since
weapons and long-range ballistic missiles,
OT environments lack visibility and securithe country poses another significant
ty controls, it is very difficult to detect such
EFFICIENTPLANTMAG.COM |

19


http://www.indegy.com http://www.gatech.edu http://www.EFFICIENTPLANTMAG.COM

Table of Contents for the Digital Edition of Efficient Plant January 2018

Efficient Plant January 2018 - 1
Efficient Plant January 2018 - Cover1
Efficient Plant January 2018 - GF1
Efficient Plant January 2018 - GF2
Efficient Plant January 2018 - Cover2
Efficient Plant January 2018 - 1
Efficient Plant January 2018 - 2
Efficient Plant January 2018 - 3
Efficient Plant January 2018 - 4
Efficient Plant January 2018 - 5
Efficient Plant January 2018 - 6
Efficient Plant January 2018 - 7
Efficient Plant January 2018 - 8
Efficient Plant January 2018 - 9
Efficient Plant January 2018 - 10
Efficient Plant January 2018 - 11
Efficient Plant January 2018 - 12
Efficient Plant January 2018 - 13
Efficient Plant January 2018 - 14
Efficient Plant January 2018 - 15
Efficient Plant January 2018 - 16
Efficient Plant January 2018 - 17
Efficient Plant January 2018 - 18
Efficient Plant January 2018 - 19
Efficient Plant January 2018 - 20
Efficient Plant January 2018 - 21
Efficient Plant January 2018 - 22
Efficient Plant January 2018 - 23
Efficient Plant January 2018 - 24
Efficient Plant January 2018 - 25
Efficient Plant January 2018 - 26
Efficient Plant January 2018 - 27
Efficient Plant January 2018 - 28
Efficient Plant January 2018 - 29
Efficient Plant January 2018 - 30
Efficient Plant January 2018 - 31
Efficient Plant January 2018 - 32
Efficient Plant January 2018 - 33
Efficient Plant January 2018 - 34
Efficient Plant January 2018 - 35
Efficient Plant January 2018 - 36
Efficient Plant January 2018 - 37
Efficient Plant January 2018 - 38
Efficient Plant January 2018 - 39
Efficient Plant January 2018 - 40
Efficient Plant January 2018 - 41
Efficient Plant January 2018 - 42
Efficient Plant January 2018 - 43
Efficient Plant January 2018 - 44
Efficient Plant January 2018 - 45
Efficient Plant January 2018 - 46
Efficient Plant January 2018 - 47
Efficient Plant January 2018 - 48
Efficient Plant January 2018 - Cover3
Efficient Plant January 2018 - Cover4
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-jan-feb-2024
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-april-2022
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-october-2021
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-june-2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanfeb2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epjulyaug2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epjune2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epfeb2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epjan2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovdec2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epseptoct2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epfebruary2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanuary2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epdecember2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovember2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epoctober2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epseptember2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epaugust2018
https://www.nxtbook.com/atp/MaintenanceTechnology/0818schneider
https://www.nxtbook.com/atp/MaintenanceTechnology/epjuly2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epjune2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epfebruary2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanuary2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epdecember2017
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovember2017
https://www.nxtbook.com/atp/MaintenanceTechnology/epoctober2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtsept2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtaugust2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjuly2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjune2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmay2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtapril2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmarch2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtfebruary2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjanuary2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtdecember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtnovember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtoctober2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtseptember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtaugust2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjuly2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjune2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmay2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtapril2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmarch2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtfebruary2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjanuary2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtdecember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtnovember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtoctober2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtseptember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTAugust2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJuly2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJune2015
https://www.nxtbook.com/atp/MaintenanceTechnology/M
https://www.nxtbook.com/atp/MaintenanceTechnology/0415endress
https://www.nxtbook.com/atp/MaintenanceTechnology/MTApril2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTMarch2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTFebruary2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJanuary2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTDecember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTNovember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTOctober2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTSeptember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTAugust2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJuly2014
https://www.nxtbookmedia.com