<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why aren't the Operational Sides of Public Utilities airgapped from the Internet? in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/28432#M3508</link>
    <description>&lt;P&gt;I recall reading an article a year or two ago about this very topic.&amp;nbsp; Their fundamental assertion was that utilities, and other industrial control systems are primarily SCADA.&amp;nbsp; SCADA systems were never intended to be "networked".&amp;nbsp; An instance may well have internal connections extending the geography, but it was a closed system overall.&amp;nbsp; Then, along comes the Internet, and everybody just slaps a web interface on their product and calls it good.&amp;nbsp; This leaves years of built up security issues that were never important enough to address, as the air gap protected them sufficiently.&amp;nbsp; Things like hard coded support passwords from the vendor, little things, you know.&amp;nbsp; Makes a lot of sense in an economics and general evolution of tech sort of way, terrifying in the actual outcome.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2019 17:27:17 GMT</pubDate>
    <dc:creator>mgorman</dc:creator>
    <dc:date>2019-09-27T17:27:17Z</dc:date>
    <item>
      <title>Why aren't the Operational Sides of Public Utilities airgapped from the Internet?</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27895#M3441</link>
      <description>&lt;P&gt;&lt;A href="https://www.utilitydive.com/news/nerc-finds-first-remote-hacker-interference-on-us-grid-from-cyberattack/562478/" target="_blank" rel="noopener"&gt;Announced&lt;/A&gt; yesterday (09 Sept 2019) was an infiltration of a public utility through a known firewall vulnerability.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why? How can public utilities logically defend having their operational services ever having access to the internet?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just baffles me.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 14:37:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27895#M3441</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-09-10T14:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't the Operational Sides of Public Utilities airgapped from the Internet?</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27904#M3442</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;A href="https://www.utilitydive.com/news/nerc-finds-first-remote-hacker-interference-on-us-grid-from-cyberattack/562478/" target="_blank" rel="noopener"&gt;Announced&lt;/A&gt; yesterday (09 Sept 2019) was an infiltration of a public utility through a known firewall vulnerability.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why? How can public utilities logically defend having their operational services ever having access to the internet?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just baffles me.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Mark,&lt;/P&gt;&lt;P&gt;No surprise here: remote management. Saves going out in the middle of the night in a thunder storm to monitor status. Ease of use always supersedes security; you knew that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 16:02:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27904#M3442</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-09-10T16:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't the Operational Sides of Public Utilities airgapped from the Internet?</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27909#M3443</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;&amp;nbsp;I knew you would read and comment and you know me too well already. Of course I was being facetious and the answer is obvious.&amp;nbsp; It is the lowest common denominator, man's laziness, that usually drives most decisions. No one wants to do what is hard (and right!).&amp;nbsp; No one wants to go against the current culture. No one wants to spend a dime more then what they have to and usually two dimes less.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ElecPowCo that my son works for has their backoffice totally separated from their operations.&amp;nbsp; They are never in the news for these type of events.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 16:39:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/27909#M3443</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-09-10T16:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't the Operational Sides of Public Utilities airgapped from the Internet?</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/28063#M3466</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't help but wonder why critical systems were published solely to facilitate remote management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally, connections from outside should be made though a VPN gateway that uses AAA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Sep 2019 20:00:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/28063#M3466</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-09-14T20:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why aren't the Operational Sides of Public Utilities airgapped from the Internet?</title>
      <link>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/28432#M3508</link>
      <description>&lt;P&gt;I recall reading an article a year or two ago about this very topic.&amp;nbsp; Their fundamental assertion was that utilities, and other industrial control systems are primarily SCADA.&amp;nbsp; SCADA systems were never intended to be "networked".&amp;nbsp; An instance may well have internal connections extending the geography, but it was a closed system overall.&amp;nbsp; Then, along comes the Internet, and everybody just slaps a web interface on their product and calls it good.&amp;nbsp; This leaves years of built up security issues that were never important enough to address, as the air gap protected them sufficiently.&amp;nbsp; Things like hard coded support passwords from the vendor, little things, you know.&amp;nbsp; Makes a lot of sense in an economics and general evolution of tech sort of way, terrifying in the actual outcome.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 17:27:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Why-aren-t-the-Operational-Sides-of-Public-Utilities-airgapped/m-p/28432#M3508</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2019-09-27T17:27:17Z</dc:date>
    </item>
  </channel>
</rss>

