Unfettered Blog

Fatalities reported after massive explosion at power plant in Connecticut...


Smoke Plume from Power Plant

From news reports:

An explosion that sounded like a
sonic boom blew out walls of an unfinished power plant and set off a
fire during a test of natural gas lines Sunday, killing at least five
workers, injuring a dozen or more and leaving crews picking through
debris for more possible victims.


My book on ICS Cyber Security


My book, Protecting Industrial Control Systems from Electronic Threats, has gone to the publisher. It is anticipated it will be published and available by the by end of April. The preorder URL is http://www.momentumpress.net/books/cyber-security-industrial-control-systems

Joe Weiss


The impact of new media on automation-- Yaskawa releases iTunes app!


 Yaskawa has released an iTunes app, and it runs on the  iPhone and iPod Touch too.

$avings Predictor Now Available on iTunes

New energy savings application for iPho


CISCO Executive Briefing Sessions on ICS Security


Tuesday to Thursday, I presented a control system cyber security discussion for CISCO’s Executive Collaboration Roundtable (ECRT). The sessions were for electric utilities and addressed NERC CIP, Smart Grid, NRC cyber security, and most importantly engineering prudency. More than 40 attendees from approximately 32 utilities attended via TelePresence and WebEx. Most were from IT. There were some common assumptions and themes:


Leadership Focus Podcast: Cyber Security


Each year the damage to critical infrastructure
from network incidentsand cyber attacks is measured
in the billions of dollars.

Traci Purdum, senior digital editor, talks
to Eric Byres, chief technology officer of Byres
Security Inc., to understand the risks and learn
how to mitigate them.


The January Control Online Edition is posted for your reading pleasure!


<!--DWLayoutTable--> Logo

Control's January issue is now online and ready for viewing.

From 'Sound Off! Editors' Blog'

More on the MIcroLogix vulnerability-- Rockwell's statement


I recently posted a vulnerability in several models of the Rockwell Automation MicroLogix product line, and noted that, per the security researcher, Eyal Udassin of C4, Rockwell had been completely cooperative with the security researcher in working out a solution to the problem.


Taken to the Cleaners?


The following news release popped up in my mailbox this morning:

London, 20  January 2010 A survey released today reveals that in the last year, 4,500 memory sticks have been forgotten in people's pockets as they take their clothes to be washed at the local dry cleaners.

From 'Sound Off! Editors' Blog'

IT and Operations are still in different worlds


Today, the Silicon Valley ISSA Chapter held their January Monthly meeting. The topic was security trends of 2010. It was advertised as a discussion on what's in store for information security professionals for year 2010. In this panel discussion, the CISO/CSO panel members presented their viewpoint on how the security function must evolve and mature to keep pace with new business trends, threats, compliance demands and shifting strategies. The speaker panel included:
David Hahn - Senior Vice President and Group Information Security Officer, Wells Fargo


Rockwell Micrologix security vulnerability disclosed--Rockwell works to fix the issue


The following was posted, among other places, on the SCADASEC listserv. Eyal Udassin, a well-known and well respected security researcher with significant experience with control system functional security has discovered a vulnerability in some of Rockwell's products, and he and Rockwell have moved quickly to fix the vulnerability.

 

Here's the text of Udassin's report: