IT Security and the Plant Floor
A few months ago, while attending a conference on “Cybersecurity for Process Control,” we heard a question from a very smart network engineer at Cisco that got us thinking. He asked: “Why not just apply the already developed practices and technologies from information technology security to plant floor security— isn’t that good enough to solve the problem?” A week later, an IT security specialist said: “None of this would be a problem if those plant floor people just used proper security policies. What’s wrong with them?” Both of these questions are valid. In the dozens of industrial cybersecurity incidents we’ve investigated over the past five years, had the facility followed good IT security practices in network design, password handling, and access controls, virtually none of the problems would have occurred. So why don’t we just deploy the standard IT practices for our process control systems and stop making such a big deal of plant floor security? Are process engineers so stupid, lazy, or stubborn that they won’t just do what IT says? Process engineers are certainly not stupid, lazy, or stubborn (OK, there are a few exceptions). Certainly some don’t deploy the proper IT security measures because they don’t understand them, but most hesitate because they sense that somehow many IT practices don’t mix well with the plant floor environment. And they’re correct, for four very good reasons. |
|
Read more...
|
|
We've got some very exciting news here at WingTip! Effective immediately, WingTip is now the delivery and support organization for Byres Security's Tofino Products within our territories. Byres Security Inc. develops industrial
security technologies for critical infrastructure companies in the oil
and gas, power, chemical and manufacturing sectors. Our flagship
product, the Tofino™ Industrial Security Solution,
is a unique hardware and software security system that provides Zone
Level Security™ (ZLS™) – tailored protection for zones of control
devices.
Tofino is simple to implement, does not require shutdowns,
and takes care of security while focus is maintained on keeping
processes running safely and efficiently. You view a very well done overview video by clicking HERE.
History and milestones
The company was formed by Eric and Joann Byres in 2006 after acquiring the technology that Eric Byres,
CTO, developed while working as founder and head of the British
Columbia Institute of Technology (BCIT) Critical Infrastructure
Security Centre.
Eric’s background as a controls engineer has resulted in cyber
security technology that approaches security from a different
perspective, i.e. from the perspective of what works in rugged, 24/7
process control environments that are managed and maintained by process
control specialists.
|
|
New Tofino™ VPN module makes secure remote SCADA communication easy
July 31st, 2009
Byres Security Inc. is announcing the
introduction of the Tofino™ Virtual Private (VPN) product line designed
specifically to be simple to use and to securely connect facilities and
people together over untrusted networks, such as the Internet.
Available as of July 31st, 2009.
|
|
Read more...
|
|
|
|
<< Start < Prev 1 2 Next > End >>
|
| Results 1 - 4 of 7 |