Wurldtech certifies 15th device using Achilles
With over 48 devices and 500+ vulnerabilities in their Delphi Database, Wurldtech is making considerable inroads on the devices with their 15th certified device. At what point does this make Achilles a de-facto standard? I think we've clearly reached that point.
Here's the press release:The Invensys I/A ZCP 270 Industrial Control System Is Achilles Certified Wurldtech Announces 15th Industrial Control System To Achieve Internationally Recognized Benchmark For Cyber Security & Robustness Vancouver, BC, Canada — September 15, 2009 — Wurldtech Security Technologies, provider of the award-winning Achilles Platform and other cyber security testing and certification solutions for critical infrastructure industries, today announced the 15th Achilles-certified control system, this time from Invensys Operations Management. The I/A ZCP 270 is the now the fourth control system from Invensys to meet the Level 1 criteria, along with the I/A FCP 270, Triconex Trident andTriconexTricon controllers, and joins a long series of certified products that have made the Achilles Certified designation the standard for cyber security certification in the industrial automation industry. “The security and robustness of our automation and control solutionsis of critical importance” said Ernie Rakaczky, Principal Security Architect for Invensys Operations Management. “By integrating the Achilles certification program requirements into the development lifecycle of our product portfolio, we are able to validate product robustness from design through deployment and help our customers maintain safe, secure and reliable industrial operations.” Leading By Example: Raising The Bar For All SuppliersOf Industrial Network Infrastructure As industry awareness continues to evolve, cyber security risks to process control networks grow in frequency and sophistication, and the costs associated with patch management and unexpected downtime increase, end-users of critical infrastructure continue to demand Achilles certified products as a simple, cost-effective way of improving the reliability of their industrial operations. “We congratulate Invensys Operations Management on another certified product in their control solutions portfolio,”said Tyler Williams, President of Wurldtech Security Technologies. “It is absolutely fantastic to see a manufacturer proactively demonstrating such a strong commitment to cyber security best practices, something we feel is absolutely mandatory for any supplier of critical industrial control solutions.” From FUD To Fact: One Small Step Really Is A Giant Leap Earlier this week, Wurldtech released a white paper on the benefits of industrial cyber security certification that provided a startling look at the overall landscape for what until now has been an relatively overlooked issue of critical network stack vulnerabilities in embedded devices - SCADA PLC’s, Distributed Control Systems, Safety Integrated Systems and emerging technologies such as Smart Meters. The analysis reviewed the obfuscated testing results of 43 embedded controllers and then compared the results with those having achieved Level 1 certification. The results were astounding, with sometimes up to a 75% percent reduction in actual identified vulnerabilities in a given device just by meeting the certification criteria. The paper went on to show how leading end-users such as BP and Shell are reacting to this information anddriving improvements through their supply chain by requiring Achilles-certified systems. “It is clear that operators can reduce their cyber risk exposure significantly by simply insisting that their suppliers meet this globally recognized and commonly accepted benchmark for system robustness,” said Dr. Nate Kube, CTO of Wurldtech. “It is cheap, easy and demonstrable, and it would be a shame to watch the advancements in automation and control made possible by the adoption of Industrial Ethernet crippled by preventable issues when something as simple as getting certified could have prevented it from happening. The risks are too high, and we can’t afford to wait, especially when we have such a compelling solution today.” Currently, the Achilles certification is available for all industrial control systems, whether wired or wireless, and certification tests are being developed for every category of IP-enabled network infrastructure. “We set out two years ago to produce a universal testing platform that every supplier of IP-enabled network infrastructure could use to improve the security and robustness of their products before being deployed in high-availability industrial environments,” Kubecontinued. “The associated certification program simply provides suppliers the means to validate and communicate another level of product quality to their customers and end-users the ability to make better choices about the products they select by choosing only those that carry the Achilles Certified logo.” Developed in 2007, the Achilles Certification Program provides a benchmark for the development and deployment of secure industrial Ethernet devices by testing control process resilience and robustness under real-world conditions and validating that operational integrity is not jeopardized. The Achilles Certification testing methodology employed by Wurldtech Labs is the result of more than three years of research, industry cooperation and end-user feedback. The Achilles Certification Program continues to develop as the de-facto standard for the industrial automation industry.