A lot of industrial networks have a big hole in their cyber security

June 12, 2014

Despite the fact that the Stuxnet virus made headlines when it attacked programmable logic controllers running Iran's nuclear centrifuges,  a similar attack on industrial facilities in the U.S. would be remarkably easy to pull off.

That was the take-away I got from a session during an event called the Big M, organized by the Society of Manufacturing Engineers. The cyber security panel included Bruce Billedeaux, a senior consultant at Maverick Technologies. Maverick is a systems integrator that does a lot of industrial control work. Billedeaux remarked that though there's more sensitivity to cyber security issues today,  it would still be relatively easy to compromise computer-controlled equipment in most industrial plants. "I have never been asked about the contents of the computer I bring into a plant," he said. Ditto for the USB sticks he occasionally brings in. That's worrying because once the bad guys have gotten behind a plant's firewall, they can exploit the firewall to do a lot of damage, he says.

It seems that third-party support of plant-floor equipment has been a blind spot for a lot of industrial cyber security efforts. "There is almost no outbound protection for industrial equipment in a lot of cases," Billedeaux said. "No one has validated the person on the other end of the line. If you have a VPN coming into the plant, most facilities have no idea whether the remote machine has been compromised or not."

And here is a scenario he outlined that, I noticed, had several audience members shifting in their chairs uncomfortably: Suppose it is late at night and you are trying to get a line up and running quickly because downtime costs thousands of dollars a minute. But you are missing a critical piece of driver software and the manufacture's web site is down, so you can't download it. You start searching. You eventually find the driver somewhere else. But if the site with the driver sits is a domain that looks something like ***.ru, are you still going to download that driver? And in the heat of the moment, will you take time to scan it first?

Billedeaux's message was that manufacturers have to plan ahead to avoid sticky situations like this.

About the Author

Lee Teschler | Editor

Leland was Editor-in-Chief of Machine Design. He has 34 years of Service and holds a B.S. Engineering from the University of Michigan, a B.S. Electrical Engineering from the University of Michigan;, and a MBA from Cleveland State University. Prior to joining Penton, Lee worked as a Communications design engineer for the U.S. Government.

Sponsored Recommendations

Food Production: How SEW-EURODRIVE Drives Excellence

Feb. 18, 2025
Optimize food production with SEW-EURODRIVE’s hygienic, energy-efficient automation and drive solutions for precision, reliability, and sustainability.

Optimizing Agricultural Operations with SEW-EURODRIVE

Feb. 18, 2025
Boost efficiency with SEW-EURODRIVE's durable drive solutions for agriculture. Reliable, efficient, and tailored for you!

Ensure Safety with Explosion-Proof Pumps for Critical Applications

Feb. 10, 2025
For high-risk environments, reliability is paramount. Learn how KNF's explosion-proof pumps provide enhanced safety and performance in demanding OEM and process applications, ...

Revolutionizing Pump Efficiency with Advanced Drive Technology

Feb. 10, 2025
Discover how KNF’s innovative MI Motors are transforming pump intelligence and system integration. With enhanced efficiency and smarter control, this breakthrough technology optimizes...

Voice your opinion!

To join the conversation, and become an exclusive member of Machine Design, create an account today!