Why are unintentional ICS cyber incidents important to address

Jan. 28, 2013
NIST defines a cyber incident to be communications between systems (or people and systems) that affect confidentiality, integrity, or availability. The NIST definition does not require an incident to be malicious to be defined as a cyber incident. There are several issues associated with unintentional cyber incidents:
- They can cause significant impacts. There have already been four unintentional control system cyber incidents in the US that caused major damage and killed people.
NIST defines a cyber incident to be communications between systems (or people and systems) that affect confidentiality, integrity, or availability. The NIST definition does not require an incident to be malicious to be defined as a cyber incident. There are several issues associated with unintentional cyber incidents:- They can cause significant impacts. There have already been four unintentional control system cyber incidents in the US that caused major damage and killed people.- It may not be possible to tell the difference between a malicious attack versus an unintentional incident. As an example, the only difference between 2008 Florida Outage being a malicious attack versus an unintentional incident was the motivation of the engineer in the substation in removing all equipment protection?- An unintentional incident can make a system less robust making it easier to attack

The following actual case best explains the situation: Engineers at a major brewery thought the company's bottling systems were secured until someone with access logged in and inadvertently changed a timer for a maintenance device on a bottle filler. It was supposed to squirt grease into the bearing every 20 minutes but was changed to once every 8 hours. The bearing soon froze. The line that filled 1,200 bottles/minute ground to a halt creating a $100,000 loss. The plant engineer stated: "With well-intentioned engineers monkeying around in the automation system, who needs terrorists or disgruntled employees?"

Joe Weiss

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...