• No results found

Are you prepared to be next? Invensys Cyber Security

N/A
N/A
Protected

Academic year: 2021

Share "Are you prepared to be next? Invensys Cyber Security"

Copied!
25
0
0

Loading.... (view fulltext now)

Full text

(1)
(2)
(3)

Sven Grone – Critical Controls Solutions Consultant

Presenting on behalf of

Glen Bounds Global Modernization Consultant

Are you prepared to be next?

(4)

Agenda

• Cyber Security Defined

• Industrial Network Overview

• Industrial Network Security Challenges • Defense In Depth Solutions

• Industry Leading Network Security Solutions

• Best of Breed System Security & Monitoring Solutions • Security Focused Implementations

(5)

Cyber Security Defined

•The ability to control and prevent unauthorized external or internal access to critical infrastructure systems

– Why it’s important

• Increases (plant) safety • Reduces down time

• Compliance to internal & country-specific regulations • Protection of intellectual

(6)

ICS/SCADA vulnerabilities have increased more than 600%since 2010!

Cyber-Espionage malware program steals sensitive documents from government for5 YEARS before being discovered!

Power company targeted by approximately

10,000cyber attacks per month!

Software Defined Radio (SDR) wireless hack targets proprietarySCADA wireless technology.

(7)

Why Care?

CLIENTS

THREATS

INVENSYS

Mitigate business interruption Manage business risk

More frequent More hostile

Vulnerabilities in offerings Protect against legal action

Still...

• Never happened to our company • Our networks are isolated

• Not my Responsibility • Don’t see the benefit

• Additional security hinders process • Does not increase revenue

• There are more important issues... Sound familiar?

(8)

Evolution of Threats

• Nature of threats diversifying – Targeted - destructive

– Stealth - data gathering & IP theft – Time delayed

– Hardware control vs. software corruption – Communities of hackers (e.g. Anonymous)

• Motivation changing

– State sponsored espionage – Politically driven

– Corporate competition – Disgruntled employees – Criminal

• Not just external (malicious) attack

– Unintentional introduction (USB, contactor Laptop) – Covert hardware vulnerabilities

– Obsolete operating system vulnerabilities

(9)

Priorities for Cyber Security

Availability

Traditional IT

Availability

Automation

There is a need to strike a balance between competing goals. The right question is “What’s the appropriate amount of security?”

(10)
(11)

Industrial Network Security

Challenges

• Increased Complexity and Connectivity • Corporate Access, Remote Access

Wireless, PCs, TCP/IP

• Evolving Threat Landscape

• Advanced Persistent Threat Attacks (APT)

• Stuxnet, Duqu, Flame, Gauss, Shamoon, ??? • Malware (Drive-by Exploits)

• Cloud-based Solutions • Insider Threat

(12)

Defense In Depth Solutions

• Industry Leading Network Security Solutions

Juniper, Enterasys, Cisco, Ultra Electronics

Best of Breed System Security and Monitoring Solutions

McAfee, Symantec, Orion Solarwinds, Enterasys NETSIGHT

Established Software & Hardware Vendors

Microsoft, Dell, HP

Experienced and Certified Security Consultants with 3rd party

(13)

Industry Leading Network Security

Solutions

• Juniper SRX and SSG Firewalls with Integrated IPS

Enterasys & Cisco Switches providing Edge to Core and Industrial connectivity

(14)

Best of Breed System Security &

Monitoring Solutions

• McAfee - Endpoint Security Solutions • Symantec - Backup Solutions

(15)

Security Focused Implementations

• Networking technology utilized to create logical segmentation and

redundant connectivity

• Custom Active Directory Security Configurations which include robust

(16)

Consulting Service Offerings

• Vendor Independent Vulnerability Assessments

• On-Site Network Assessment, Design, Implementation • Network / System Audit, Hardening, Security Evaluations • Information Security Program Development / Training

• Change Control and Disaster Recovery Process Design / Review • Incident / Emergency Response

(17)
(18)

Security-Enhanced Solutions

Microsoft Patch Management

• Individual assessments and manual updates

Host Endpoint Protection

• Host Intrusion Prevention • Anti Virus / Anti Spyware • BIOS Lockdown

Host Backup

• Disaster recovery • System restoration

Vulnerability Assessments

• System hardening / audit

Local Security Policies

• Access Control • Account Management • User Rights Assignments

Microsoft Windows Active Directory

• Centralized system management • Individual User logons

• Group-based security policies

Microsoft Patch Management

• Centralized distribution

Centralized Endpoint Protection

• Host Intrusion Prevention • Anti Virus / Anti Spyware • Device Management (DLP) Centralized Backup • Disaster recovery • System restoration Network Segmentation • Network-based AV / AS • Network-based IPS • Strict access policies

Centralized monitoring

• System Management • System Statistics • System Availability • Alerting and reporting

Isolated Systems Networked Systems

(19)

Zoned Network Segregation

DMZ Edge Switch Demilitarized Zone Secure Network Gateway + IPS

Any System that requires access to the IT Network

(20)

Plant / Enterprise Control

– Pi to Pi – Alarms Management – Data Historian – WSUS – ePO

(21)

1. Designing and building a secure operating environment is priority #1 at Invensys

2. All products designed with security in mind to comply with Industry and Corporate Standards

3. Dedicated ICST personnel assigned to each Security Project

• Backed up by secondary team members • Proven / certified expertise

• Domain knowledge • Immediate response

“Safety and Cyber Security are job one at Invensys”

(22)

The Top 5 Cyber Security Questions

Questions for CEOs

How is our executive leadership informed about the current level and business impact of cyber risks to our company?

What is the current level and business impact of cyber risks to our company? What is our plan to address identified risks?

How does our cyber security program apply industry standards and best practices?

How many and what types of cyber incidents do we detect in a normal week? What is the threshold for notifying our executive leadership?

(23)
(24)

Wrap Up!

1. Cyber threats are a reality – not if, but when

2. Types of threats are evolving, access vectors expanding - simple

isolation not adequate defense

3. Risk depends on many factors and needs to assessed, with

appropriate protection put in place

4. Threats are evolving at the pace of technology – system hardware

and software currency and management is key

5. Defense in Depth strategy is the bare minimum needed to

establish a base for Cyber Security

6. Additional security layers are needed (hardware, software, people,

practices)

(25)

© Invensys 00/00/00

THANK YOU

THANK YOU

[email protected]

Critical Controls Solutions Consultant

References

Related documents

Purpose – The purpose of this paper is to explore barriers and benefits of establishing relationships between humanitarian organizations (HOs) and logistics service providers (LSPs)

We show that the opportunistic use of patents by NPEs will also generate a negative relationship between private value and citations which buttresses our main hypothesis: when

2-Propenoic acid, 2-[butyl[(heptadecafluorooctyl)sulfonyl]amino]ethyl ester 383-07-3 2-Propenoic acid, 2-methyl-, 2-[ethyl[(heptadecafluorooctyl)sulfonyl]amino] ethylester

The Border Security, Economic Opportunity, and Immigration Modernization Act (S. 744), for example, would require carriers to collect electronic machine-readable biographic data

1987 - American Occupational Therapy Foundation, distinguished service for the promotion of knowledge and research as a member of the Editorial Board of Occupational Therapy Journal

Alan itseohjautuva sääntely toteutuu ammattikunnan sisäisin normein (tilintarkastusalan standardit ja suosi- tukset) ja yhteiskunnan mielenkiinto tilintarkastuksen oikeellisuuteen

• Discover how media representations structure our perception of reality, often through unnoticed communications. • Evaluate the reliability of sources of

Linked as a virtual power plant with smart grid applications the technology can help balancing the electricity system above a base load agreement by both