ICS SCADA Networks: The Security Risks
The modern world is relying more and more on IT infrastructure to deliver or monitor critical and core services. Most people are familiar with the security required for business and consumer information systems; good passwords, anti-virus protection, malware protection, network firewalls, and more. Awareness is also increasing on the need for IoT (Internet of Things) devices to be well secured as they provide additional surface area and attack vectors for malicious cybercriminals on the Internet.
One area that is still mostly under the radar when it comes to most IT security is the protection of critical systems that are delivering the core utility services we all use. The energy supply infrastructure for electricity and domestic gas for example, but also the drinking water and waste removal systems. Critical core infrastructure also includes public and private transport systems, healthcare, food production and distribution, and manufacturing of items that are crucial to modern life that are manufactured using just in time processes, such as pharmaceuticals.
Traditionally many of the control systems for these processes were isolated, and self-contained, but they are increasingly being connected to networks. Reasons for this are often to provide a remote connection for monitoring and maintenance without having to travel to a site, but also there is an increasing desire to have remote control and analytics via sensors and other IoT devices to provide pre-emptive failure warnings and improved capacity planning.
Malware variants targeting critical infrastructure are designed to infiltrate the Industrial Control Systems (ICS) that are in place to control and monitor the critical infrastructure and manufacturing systems. There are other terms used when referring to these control systems: Supervisory Control and Data Acquisition (SCADA) and Distributed Control System (DCS).
Attacks on ICS
As the number of critical systems that are connected to the Internet has increased so have the risks they face, and the attacks that have been launched. Well known examples of attacks on control infrastructure include Stuxnet which was designed to infect and subtly damage the Uranium enrichment centrifuges in use by Iran, and Triton which is malware designed to disable safety control systems on industrial systems. Many others are operating in the wild as well.
ICS systems are a specialised area, as is network cybersecurity for information systems. It’s rare to find people who are experts in both of these areas. ICS experts are usually not up to date on emerging IT security risks and protection measures, and IT Security professionals are unlikely to understand ICS and SCADA systems as these can be decades old and use proprietary protocols. It’s vital for organisations looking at ICS security to call on internal and external expertise in both areas, then build multi-disciplinary teams tasked with addressing security threats and how to deal with attacks.
Dealing with attacks is vital. All the measures possible to protect ICS systems should be put in place, but ICS systems are so diverse and such tempting targets to malicious actors that if a determined and extended attack comes, it will likely succeed.
As Andy Bochman, Senior Grid Strategist for National & Homeland Security at the Idaho National Laboratory in the USA says: “No matter how good your company’s hygiene is, a targeted attack will penetrate your networks and systems. It may take the hackers weeks or months, but they will get in.”
So contingency plans need to be in place to deal with mitigation and recovery of any disruption to critical infrastructure if an ICS system is compromised. This is especially true in the EU due to the EU NIS directive that requires adequate cybersecurity measures to be in place for critical infrastructure systems, and prompt reporting and mitigation of any security breaches.
Protecting ICS systems
Implementing robust protections for critical infrastructure systems and their ICS and SCADA control systems is a specialised and multi-disciplinary task. Most organisations will have experts in their ICS systems, and possibly information systems IT security experts on staff. As mentioned above, it is unusual for these two groups to have a detailed knowledge of both areas.
Finding the time and available resources internally to build a team to protect ICS systems adequately can be difficult. However, it’s a task that has to be done given the critical nature of the infrastructure in question and the increasing risks from malicious cybercriminals. Renaissance, together with our IT security partners, including ICS security specialist Indegy, can help all organisations protect their critical or industrial process systems. Join us for an ICS webinar on the 25th of June to get an overview of how Indegy can help you protect your critical infrastructure systems. Alternatively, call us today to discuss your requirements.

