Why. Control System Cyber Security Sucks. CERN Control Centre. CERN Computer Centre



Similar documents
8/27/2015. Brad Schuette IT Manager City of Punta Gorda (941) Don t Wait Another Day

Why Endpoint Encryption Can Fail to Deliver

AUDIT REPORT. Cybersecurity Controls Over a Major National Nuclear Security Administration Information System

Goals. Understanding security testing

Common Cyber Threats. Common cyber threats include:

Defense-in-Depth Strategies for Secure, Open Remote Access to Control System Networks

Simply Sophisticated. Information Security and Compliance

Technology Risk Management Are you ready?

How to set up a CSIRT in an ITIL driven organization. Christian Proschinger Raiffeisen Informatik GmbH

Can We Become Resilient to Cyber Attacks?

Developing Secure Software in the Age of Advanced Persistent Threats

SOMEBODY'S WATCHING YOU! Maritime Cyber Security White Paper. Safeguarding data through increased awareness

IoT & INFOSEC: A REPORT FROM THE TRENCHES - AGC IT Conference- July 2015 MIKE.ZUSMAN@CARVESYSTEMS.COM

How To Test A Control System With A Network Security Tool Like Nesus

Anthony J. Keane, MSc, PhD and Jason Flood, MSc Information Security & Digital Forensics Research Group Institute of Technology Blanchardstown

Penetration Testing Getting the Most out of Your Assessment. Chris Wilkinson Crowe Horwath LLP September 22, 2010

2012 CIP Spring Compliance Workshop May Testing, Ports & Services and Patch Management

Security Management. Keeping the IT Security Administrator Busy

Presented by Evan Sylvester, CISSP

Industrial Control System Cyber Security

PCI COMPLIANCE GUIDE For Merchants and Service Members

Leveraging Regulatory Compliance to Improve Cyber Security

Application Security Testing How to find software vulnerabilities before you ship or procure code

Information Shield Solution Matrix for CIP Security Standards

Need for Database Security. Whitepaper

Tips and Best Practices for Managing a Private Cloud

I. EXECUTIVE SUMMARY. Date: June 30, Sabina Sitaru, Chief Innovation Officer, Metro Hartford Innovation Services

Cyber R &D Research Roundtable

The President s Critical Infrastructure Protection Board. Office of Energy Assurance U.S. Department of Energy 202/

The State-of-the-State of Control System Cyber Security

Building Insecurity Lisa Kaiser

Car Cybersecurity: What do the automakers really think? 2015 Survey of Automakers and Suppliers Conducted by Ponemon Institute

Presentation for : The New England Board of Higher Education. Hot Topics in IT Security and Data Privacy

ARE YOU RUNING LINUX RIGHT?

Cybersecurity Awareness. Part 1

Open Source Incident Management Tool for CSIRTs

Software Application Control and SDLC

Cyber Security Compliance (NERC CIP V5)

R 143 CYBERSECURITY RECOMMENDATION FOR MEDIA VENDORS SYSTEMS, SOFTWARE & SERVICES

DEVELOPING A CYBERSECURITY POLICY ARCHITECTURE

Information Technology Policy

A Security Risk Management Framework for Networked Medical Devices

Cybersecurity. Are you prepared?

Five keys to a more secure data environment

Everything You Wanted to Know about DISA STIGs but were Afraid to Ask

Click to edit Master title style

Developing A Successful Patch Management Process

Creating Value through Innovative IT Auditing

Cyber-Security Risk in the Global Organization:

Continuous Network Monitoring

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

PAKITI Patching Status System

High Speed Internet - User Guide. Welcome to. your world.

Stronger than Firewalls And Cheaper Too

Security Frameworks. An Enterprise Approach to Security. Robert Belka Frazier, CISSP

Information Technology Engineers Examination. Information Security Specialist Examination. (Level 4) Syllabus

What Directors need to know about Cybersecurity?

NSA/DHS Centers of Academic Excellence for Information Assurance/Cyber Defense

Hacking Database for Owning your Data

CYBER SECURITY: A REPORT FROM THE TRENCHES 2015 AGC NATIONAL & CHAPTER LEADERSHIP CONFERENCE MIKE.ZUSMAN@CARVESYSTEMS.COM

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections

Cyber Security and Open Source Community Call Summary

Patch and Vulnerability Management Program

BIG SHIFT TO CLOUD-BASED SECURITY

SCADA and Security Are they Mutually Exclusive? Terry M. Draper, PE, PMP

California Department of Technology, Office of Technology Services WINDOWS SERVER GUIDELINE

Making Database Security an IT Security Priority

Network Security Policy

Encryption and Tokenization: Protecting Customer Data. Your Payments Universally Amplified. Tia D. Ilori Sue Zloth September 18, 2013

Trend Micro Worry- Free Business Security st time setup Tips & Tricks

Big Data, Big Risk, Big Rewards. Hussein Syed

Enterprise Managed PBX Telephony

Cyber Essentials KAMI VANIEA 2

Getting software security Right

i-pcgrid Workshop 2015 Cyber Security for Substation Automation The Jagged Line between Utility and Vendors

CONTINUOUS DIAGNOSTICS BEGINS WITH REDSEAL

Information Technology Policy

Transcription:

Why CERN Control Centre Control System Cyber Security Sucks CERN Computer Centre Why Control System Cyber-Security Sucks

CERN Business Modell

Beam Bunch Proton Why Control System Cyber-Security Sucks Accumulate protons,

accelerate them

to highest energies

& continuously take photos

of their collisions

to get the Nobel Prize

Typical Control Systems (1)

Typical Control Systems (2)

Why CERN Control Centre Control System Cyber Security Sucks CERN Computer Centre Why Control System Cyber-Security Sucks

Why worry?

Really! Why worry?

Computer Centre: SDLC, regression testing, nightly builds Full configuration mgmt. Redundancy & virtualization Few exceptions Control Systems: Heavy compliance testing (vendor & utility) to keep warranties & certification (e.g. SIL) Rare maintenance windows Fear to brick a $100k device Lots of legacy, old or embedded devices Why Control System Cyber-Security Sucks Black Hat, August 6-7th 2014, Las Vegas (US) Why Patching Sucks

Computer Centre: (Externally sponsored) pen testing & vulnerability scanning Decades of experience/knowledge Responsible disclosure & CSIRTs Control Systems: Security not integral part or thru obscurity Fulfil use cases, but fail to abuse cases Default passwords & undoc d backdoors Few laws; too many guidelines Unwillingness to share incidents No security certification (yet?) Why Control System Cyber-Security Sucks Why Ignorance Sucks

Computer Science: Our kids are the users/programmers of tomorrow Why are students still weak on security? BSc CV: programming, O/S, DBs, web, MSc CV: ditto, now add security Do we need more professionalism? Control System Engineering: Get a Computer Science education Stop reinventing standard IT, but embrace IT methods Why Control System Cyber-Security Sucks Why Unprofessionalism Sucks

Patch promptly: Merge control system IT with standard IT Robustify: Hack.the.box! & disclose responsibly Change of Minds: Make security part of everyone s CV! Why Control System Cyber-Security Sucks Summary

Thx!