{"id":10498,"date":"2018-03-26T17:47:21","date_gmt":"2018-03-26T16:47:21","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=10498\/"},"modified":"2020-01-02T11:30:48","modified_gmt":"2020-01-02T10:30:48","slug":"ics-news-1-en","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/","title":{"rendered":"Industrial Control System Cybersecurity News #1 &#8211; What to remember from 2017?"},"content":{"rendered":"<h2>&gt;&gt;Editorial:\u00a0What to remember from 2017?<\/h2>\n<p><em>Industrial Control Systems (ICS) are complex systems that aim to control industrial processes. ICS can be found in several sectors: energy, nuclear, transport, chemistry\u2026 In brief these systems control many of the critical productive assets of companies or states making their compromise by adversaries a high risk on the environment or people\u2019s lives.<\/em><\/p>\n<p>Thus, the <strong>cybersecurity of these systems is crucial<\/strong>. Moreover, securing these systems may be challenging due to their complexity (mainly because ICS are a mix of technologies and their lifetime is longer than usual information systems\u2019).<\/p>\n<p>In order to meet our clients\u2019 needs and answer to their future concerns, Wavestone has been conducting an <strong>ICS cybersecurity watch where every recent study<\/strong>, attack or incident and report regarding the security of Industrial Control Systems are studied. In 2017, more than <strong>80 news<\/strong> were reported from which we can retrieve a lot of teachings.<\/p>\n<h3>So, what did we notice this year?<\/h3>\n<p>First of all, <strong>ICS had its share of attacks<\/strong>. However, this year\u2019s attacks, more than the other years\u2019, had an unusual worldwide impact. Indeed, while ICS attacks were usually localized on a device (for instance on health devices), factory (for example a cryptomining malware found in a water utility \u2013 for more information see below) or a region (Dallas emergency sirens ignition in April 2017), 2017\u2019s attacks started locally and spread quickly impacting several production lines in the world (WannaCry and NotPetya).<\/p>\n<figure id=\"post-10499 media-10499\" class=\"align-none\">\n<figure id=\"post-10573 media-10573\" class=\"align-center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10573\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter.png\" alt=\"\" width=\"912\" height=\"539\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter.png 1272w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter-120x70.png 120w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter-323x191.png 323w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter-768x454.png 768w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Slide-newsletter-66x39.png 66w\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" \/><\/figure>\n<\/figure>\n<p>&nbsp;<\/p>\n<p>During 2017, many attacks have been reported in the news. Moreover, we noticed that several national agencies, governments or political figures alerted on ongoing attacks or attempts on critical infrastructure. The sector that was the most targeted seems to be the Energy sector. Indeed, several news were reported from Turkey (in January), USA (in March, July), Baltic States (in May), UK (in July) and Ireland (in July) showing that this sector was a privileged target by hackers (state sponsored or not).<\/p>\n<p>The <strong>energy sector wasn\u2019t the only hot topic of the year<\/strong>, as a matter of fact, <strong>autonomous cars<\/strong> cybersecurity hit many times the headlines (even if that topic may or may not be considered as related to industrial control systems). This is mainly due to the fact that cars\u2019 cybersecurity is a new market. Therefore, cybersecurity experts and researchers try to find vulnerabilities and exploits (for example vulnerability found in airbag control units), while car manufacturers launch partnerships and initiatives showing that cybersecurity is now one of their main concerns (for example GM invited ethical hackers to try and hack its cars).<\/p>\n<p>Finally, the ICS cybersecurity market tends to grow as demonstrated by the several fundraisings and partnerships signed during this year. In a broader perspective, we can notice t<strong>hree kinds of actors<\/strong> in the ICS cybersecurity market:<\/p>\n<ul>\n<li><strong>ICS cybersecurity companies<\/strong>: usually small-sized companies or start-ups. They are pure-players that develop and put in the market ICS-dedicated solutions (Sentryo, CyberX, Nozomi \u2026);<\/li>\n<li><strong>ICS vendors<\/strong>: we noticed last year, some vendors that conceive ICS launched partnerships with ICS cybersecurity companies to improve their systems\u2019 security (for example Siemens-PAS partnership in September, Schneider-Claroty partnership in August);<\/li>\n<li><strong>IT security companies<\/strong>: these companies (well known in the IT world) tailor their solutions for industrial context. They show a growing interest for ICS by publishing reports and attack analysis (for example Kaspersky, McAfee).*<\/li>\n<\/ul>\n<h3>So, what is coming next?<\/h3>\n<p>It may be easy to say that the ICS cybersecurity will still (unfortunately) hit the headlines. Especially with alerts of attacks targeting life threatening system such as the safety instrumented systems controllers. But, we may see more and more news on specific sectors such as maritime, transport, health\u2026 that weren\u2019t somehow as exposed in the media as the energy or nuclear sector. The ICS cybersecurity market may continue to grow especially with partnerships and acquisitions. Industrial Control Systems will continue to face new threats, challenges and changes.<\/p>\n<h2>&gt;&gt;Latest news:<\/h2>\n<figure id=\"post-10532 media-10532\" class=\"align-none\"><\/figure>\n<table style=\"width: 701px; height: 3639px; border-color: #ffffff; border-right-color: #ffffff;\" border=\"1\" cellpadding=\"10\">\n<tbody>\n<tr>\n<td style=\"width: 156.91px;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-10506\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image1-1.png\" alt=\"\" width=\"326\" height=\"138\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image1-1.png 326w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image1-1-71x30.png 71w\" sizes=\"auto, (max-width: 326px) 100vw, 326px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>CyberX raises $18 million in series B funding to combat rising threats to IIoT and critical infrastructure, bringing total funding to $30 million (CyberX, February 27<sup>th<\/sup>)<\/strong><\/p>\n<p>CyberX announced that the company raised $18 million dollars to develop threat detection in the Industrial Internet of Things (IIoT) and critical infrastructures. The company develops a threat monitoring and risk mitigation platform that includes ICS-specific threat intelligence. <a href=\"https:\/\/cyberx-labs.com\/en\/press-releases\/cyberx-raises-18-million-series-b-funding-combat-rising-threats-iiot-critical-infrastructure-bringing-total-funding-30-million\/\">Link to the press release<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10510\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image2.png-437x114.jpg\" alt=\"\" width=\"437\" height=\"114\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image2.png-437x114.jpg 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image2.png-71x19.jpg 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image2.png.jpg 447w\" sizes=\"auto, (max-width: 437px) 100vw, 437px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Fun with Modbus 0x5A (<em>Security Insider, February 9th<\/em>)<\/strong><\/p>\n<p>During the last edition of Defcon in Las Vegas, Wavestone presented its latest study regarding the ModBus protocol cybersecurity and specifically the function 90. An attacker may thanks to this function start, stop a controller or force it to send a determined output value,\u00a0 <a href=\"http:\/\/www.securityinsider-wavestone.com\/2018\/02\/fun-with-modbus-0x5a.html\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10512\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image3-268x191.jpg\" alt=\"\" width=\"268\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image3-268x191.jpg 268w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image3-55x39.jpg 55w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image3-345x245.jpg 345w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image3.jpg 409w\" sizes=\"auto, (max-width: 268px) 100vw, 268px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>ICS detection challenge results (<em>Dale Peterson, February 7th<\/em>)<\/strong><\/p>\n<p>At the S4x18 in January, took place the ICS Detection Challenge. The 4 companies that completed the challenge are: Claroty, Gravwell, Nozomi Networks and Security Matters. The first part of the challenge consists on evaluating the ICS Detection class of 3 products which are: Claroty, Nozomi Networks and Security Matters. It was won by Claroty over Nozomi Networks and Security Matters. The competitors&#8217; products had to detect cyber-attacks and incidents occurring on an oil&amp;gas company. <a href=\"https:\/\/dale-peterson.com\/2018\/02\/11\/ics-detection-challenge-results-part-1\/\">Link to the results<\/a><\/p>\n<p>The second part which consists in the asset detection phase was also won by Claroty even though Nozomi provided the most details in their asset inventory. <a href=\"https:\/\/dale-peterson.com\/2018\/02\/13\/ics-detection-challenge-part-ii\/?utm_content=buffer46f44&amp;utm_medium=social&amp;utm_source=twitter.com&amp;utm_campaign=buffer\">Link to the results<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10514\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image4-287x191.jpg\" alt=\"\" width=\"287\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image4-287x191.jpg 287w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image4-59x39.jpg 59w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image4.jpg 720w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Water utility in Europe hit by cryptocurrency malware mining attack (<em>eWeek, February 7th<\/em>)<\/strong><\/p>\n<p>The security firm Radiflow discovered a cryptocurrency mining malware in the network of a water service provider in Europe. The malware was downloaded from a malicious advertising site infecting the Human Machine Interface and then spread to the SCADA network that was still running Microsoft Windows XP OS. The malware degraded the system performance. Tough the degradation wasn\u2019t noticed by the operators. <a href=\"http:\/\/www.eweek.com\/security\/water-utility-in-europe-hit-by-cryptocurrency-malware-mining-attack\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10516\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image5-323x191.jpg\" alt=\"\" width=\"323\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image5-323x191.jpg 323w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image5-120x70.jpg 120w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image5-66x39.jpg 66w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image5.jpg 436w\" sizes=\"auto, (max-width: 323px) 100vw, 323px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Ukraine power distributor plans cyber defense system for $20 million (<em>Reuters, February 6th<\/em>)<\/strong><\/p>\n<p>Ukraine\u2019s state-run power distributor Ukrenergo, which was a target for cyber-attacks in the past two years (December 2016 and December 2017), will invest up to $20 million in a new cyber defense system. The acting head of Ukrainian state power distributor Ukrenergo, told that the company and international consultants had identified about 20 threats that would be eliminated with the new system. The main goal of this system is to make \u201cphysically impossible for external threats to affect the Ukrainian energy system\u201d. <a href=\"https:\/\/www.reuters.com\/article\/us-ukraine-cyber-ukrenergo\/ukraine-power-distributor-plans-cyber-defense-system-for-20-million-idUSKBN1FQ1TD\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10518\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image6.jpg\" alt=\"\" width=\"297\" height=\"178\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image6.jpg 297w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image6-65x39.jpg 65w\" sizes=\"auto, (max-width: 297px) 100vw, 297px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Increasing number of industrial systems accessible from web (<em>study\u00a0Security Week, February 2nd<\/em>)<\/strong><\/p>\n<p>According to a new report published by Positive Technologies, the number of industrial control systems (ICS) accessible from the Internet has increased significantly during the past year. Most of vulnerabilities of these systems could be exploited remotely without needing to obtain any privileges in advance. The most common types of vulnerabilities were remote code execution (24%), information disclosure (17%), and buffer overflows (12%).Most of these systems are accessible via HTTP, followed by the Fox building automation protocol associated with Honeywell\u2019s Niagara framework, Ethernet\/IP, BACnet, and the Lantronix discovery protocol. <a href=\"https:\/\/www.securityweek.com\/increasing-number-industrial-systems-accessible-web-study\">Link to the article<\/a> | <a href=\"https:\/\/www.securityweek.com\/increasing-number-industrial-systems-accessible-web-study\">Link to the report<\/a> [PDF]<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10520\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image7-337x191.jpg\" alt=\"\" width=\"337\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image7-337x191.jpg 337w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image7-69x39.jpg 69w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image7.jpg 454w\" sizes=\"auto, (max-width: 337px) 100vw, 337px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Flaws in gas station software let hackers change prices, steal fuel, erase evidence (<em>Motherboard, January 31st<\/em>)<\/strong><\/p>\n<p>Security researchers were able to connect to a web interface that manages gas station thanks to Shodan (search engine of connected devices). After using the default admin login and password, and then a hardcoded username and password, the researchers were able to shut down fuel pumps, hijack credit card payments, and steal card numbers. <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/43qkgb\/flaws-in-gas-station-software-let-hackers-change-prices-steal-fuel-erase-evidence\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10522\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image8-340x191.jpg\" alt=\"\" width=\"340\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image8-340x191.jpg 340w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image8-69x39.jpg 69w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image8.jpg 433w\" sizes=\"auto, (max-width: 340px) 100vw, 340px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Government warns critical industry firms to prepare for cyberattacks (<em>Sky news, January 29th<\/em>)<\/strong><\/p>\n<p>All companies which are involved in critical industry and essential services, such as energy, transport, water, health and digital infrastructure, have been warned by the British government that they face sanctions if they do not include cybersecurity rules in their systems.The fines come as the government implements the Network and Information Systems (NIS) Directive, which would cover events such as the WannaCry attack. <a href=\"https:\/\/news.sky.com\/story\/government-warns-critical-industry-firms-to-prepare-for-cyberattacks-11226555\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10524\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image10-148x191.png\" alt=\"\" width=\"148\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image10-148x191.png 148w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image10-30x39.png 30w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image10.png 311w\" sizes=\"auto, (max-width: 148px) 100vw, 148px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Gemalto licensing tool exposes ICS, corporate systems to attacks (<em>Security week, January 22nd<\/em>)<\/strong><\/p>\n<p>Kaspersky Lab researchers found 14 vulnerabilities in Gemalto Sentinel LDK (software) and the associated USB Dongle (SafeNet). The USB dongle is used to activate the software. When connected, drivers are installed and the port 1947 is added to the list of exceptions in the Windows firewall. This port can be exploited to identify remotely accessible devices. <a href=\"https:\/\/www.securityweek.com\/gemalto-licensing-tool-exposes-ics-corporate-systems-attacks\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10526\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image11-316x191.png\" alt=\"\" width=\"316\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image11-316x191.png 316w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image11-768x464.png 768w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image11-65x39.png 65w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image11.png 1046w\" sizes=\"auto, (max-width: 316px) 100vw, 316px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>SamSam ransomware hits hospitals, city councils, ICS firms (<em>Bleeping Computer, January 19th<\/em>)<\/strong><\/p>\n<p>Samsam ransomware hit several hospitals, city councils and an ICS firm. Hancock Health admitted paying the ransom ($55.000) even though they had backups. The Samsam ransomware spread by brute forcing RDP connections. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/samsam-ransomware-hits-hospitals-city-councils-ics-firms\/?utm_source=dlvr.it&amp;utm_medium=twitter\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10528\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image12.jpg\" alt=\"\" width=\"376\" height=\"169\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image12.jpg 376w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image12-71x32.jpg 71w\" sizes=\"auto, (max-width: 376px) 100vw, 376px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Industrial systems scrambling to catch up with Meltdown, Spectre (<em>The Register, January 18th<\/em>)<\/strong><\/p>\n<p>Meltdown and Spectre vulnerabilities also had an impact on industrial control systems. Some vendors decided to publicly communicate about their vulnerable products (OSISoft for example), other vendors like Emerson and General electric keep the information only for their customers and finally some vendors are still investigating if their products are vulnerable to Meltdown and Spectre. <a href=\"https:\/\/www.theregister.co.uk\/2018\/01\/18\/ics_cert_meltdown_responses\/\">Link to the article<\/a><br \/>\n<em>For more information on Meltdown and Spectre vulnerabilities, you can read this <a href=\"http:\/\/www.securityinsider-wavestone.com\/2018\/01\/meltdown-spectre-attaques-par-canaux-auxilliaires.html\">post by Wavestone on Security Insider<\/a> [French]<\/em><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10530\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image13-287x191.jpg\" alt=\"\" width=\"287\" height=\"191\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image13-287x191.jpg 287w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image13-59x39.jpg 59w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image13.jpg 350w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Researchers find 147 vulnerabilities in 34 SCADA mobile applications\u00a0(<em>SC Magazine, January 11th<\/em>)<\/strong><\/p>\n<p>IoActive and Embedi researchers found 147 vulnerabilities in 34 mobile applications used in tandem with Supervisory Control and Data Acquisition (SCADA) systems. The top vulnerabilities were: code tampering flaws, insecure authorization, insecure data storage&#8230; This security weaknesses could allow an attacker to compromise industrial network infrastructure by exploiting the vulnerable applications. <a href=\"https:\/\/www.scmagazine.com\/the-top-security-weaknesses-were-code-tampering-flaws-which-were-found-in-94-percent-of-apps\/article\/736656\/\">Link to the article<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 156.91px; text-align: center;\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-10532\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image14.png\" alt=\"\" width=\"246\" height=\"72\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image14.png 246w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image14-71x21.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/image14-245x72.png 245w\" sizes=\"auto, (max-width: 246px) 100vw, 246px\" \/><\/td>\n<td style=\"width: 495.799px; text-align: left;\"><strong>Industrial Cybersecurity Firm Nozomi Networks Raises $15 Million (<em>Security Week, January 10th<\/em>)<\/strong><\/p>\n<p>Nozomi is an industrial cybersecurity firm that has recently raised $23.8 million. Nozomi\u2019s offering which is \u201cSCADAguardian\u201d, consists on using machine learning and behavioral analysis to detect zero-day attacks in real-time. This technology allows rapid response to alerts by ICS incident alerting and notification systems. The company said the additional funding will be used to support worldwide expansion of marketing, sales, support and product innovation. <a href=\"https:\/\/www.securityweek.com\/industrial-cybersecurity-firm-nozomi-networks-raises-15-million\">Link to the article<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>&gt;&gt;Main ICS vulnerabilities<\/h2>\n<table style=\"height: 705px; width: 701px; border-color: #ffffff;\" cellpadding=\"3\">\n<tbody>\n<tr style=\"height: 26px; background-color: #d1cdcd;\">\n<td style=\"width: 67.6042px; height: 26px; text-align: center;\"><strong>Date<\/strong><\/td>\n<td style=\"width: 66.4931px; height: 26px; text-align: center;\"><strong>CVSS v3<\/strong><\/td>\n<td style=\"width: 128.715px; height: 26px; text-align: center;\"><strong>Equipment<\/strong><\/td>\n<td style=\"width: 308.715px; height: 26px; text-align: center;\"><strong>Vulnerability<\/strong><\/td>\n<td style=\"width: 82.0486px; height: 26px; text-align: center;\"><strong>Advisory<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 53px;\">\n<td style=\"width: 67.6042px; height: 53px; text-align: center;\">Feb. 15<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 53px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 53px;\">Nortek Linear eMerge E3 Series<\/td>\n<td style=\"width: 308.715px; height: 53px;\">Command Injection<\/td>\n<td style=\"width: 82.0486px; height: 53px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-046-02\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 74px;\">\n<td style=\"width: 67.6042px; height: 74px; text-align: center;\">Feb. 15<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 74px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 74px;\">GE D60 Line Distance Relay<\/td>\n<td style=\"width: 308.715px; height: 74px;\">Stack-based Buffer Overflow, Improper Restriction of Operations within the Bounds of a Memory Buffer<\/td>\n<td style=\"width: 82.0486px; height: 74px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-046-02\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 98px;\">\n<td style=\"width: 67.6042px; height: 98px; text-align: center;\">Feb. 13<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 98px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 98px;\">Wago PFC200 Series<\/td>\n<td style=\"width: 308.715px; height: 98px;\">Execution of some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime.<\/td>\n<td style=\"width: 82.0486px; height: 98px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-044-01\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"width: 67.6042px; height: 54px; text-align: center;\">Feb. 8<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 54px; text-align: center;\">9.9<\/td>\n<td style=\"width: 128.715px; height: 54px;\">Gemalto Sentinel License Manager<\/td>\n<td style=\"width: 308.715px; height: 54px;\">Null Pointer Dereference, Buffer Overflows, Improper Access Control.<\/td>\n<td style=\"width: 82.0486px; height: 54px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-032-03\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 74px;\">\n<td style=\"width: 67.6042px; height: 74px; text-align: center;\">Feb. 1<sup>st<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 74px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 74px;\">3S-Smart Software Solutions GmbH Codesys Web Server<\/td>\n<td style=\"width: 308.715px; height: 74px;\">Stack-based Buffer Overflow.<\/td>\n<td style=\"width: 82.0486px; height: 74px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-032-02\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 12.042px;\">\n<td style=\"width: 67.6042px; height: 12.042px; text-align: center;\">Jan. 25<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 12.042px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 12.042px;\">Nari PCS-9611<\/td>\n<td style=\"width: 308.715px; height: 12.042px;\">Improper Input Validation.<\/td>\n<td style=\"width: 82.0486px; height: 12.042px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-025-01\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"width: 67.6042px; height: 54px; text-align: center;\">Jan. 11<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 54px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 54px;\">Phoenix Contact FL Switch<\/td>\n<td style=\"width: 308.715px; height: 54px;\">Improper Authorization, Information Exposure.<\/td>\n<td style=\"width: 82.0486px; height: 54px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-011-03\">Link<\/a><\/td>\n<\/tr>\n<tr style=\"height: 74px;\">\n<td style=\"width: 67.6042px; height: 74px; text-align: center;\">Jan. 9<sup>th<\/sup><\/td>\n<td style=\"width: 66.4931px; height: 74px; text-align: center;\">9.8<\/td>\n<td style=\"width: 128.715px; height: 74px;\">General Motors and Shanghai OnStar (SOS) iOS Client.<\/td>\n<td style=\"width: 308.715px; height: 74px;\">Cleartext Storage of Sensitive Information, Man-in-the-Middle, Improper Authentication.<\/td>\n<td style=\"width: 82.0486px; height: 74px; text-align: center;\"><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-234-04\">Link<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>&gt;&gt;Recent and upcoming ICS events<\/h2>\n<figure id=\"post-10532 media-10532\" class=\"align-none\"><\/figure>\n<table style=\"height: 679px; width: 701px;\" border=\"1\" cellpadding=\"10\">\n<tbody>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\">\n<figure id=\"post-10556 media-10556\" class=\"align-center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/figure>\n<p>Apr. 24-26<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/icscybersecurity.iqpc.co.uk\/\">ICS Cyber security<\/a><\/p>\n<p>London, UK<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/p>\n<p>Apr. 24-26<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/www.industrialiotseries.com\/europe\/\">Industrial control systems (ICS) Cyber Security Conference<\/a><\/p>\n<p>Singapore<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/p>\n<p>Apr. 9-10<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/www.cs4ca.com\/mena\/\">Cyber Security for critical assets MENA<\/a><\/p>\n<p>Dubai, UAE<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/p>\n<p>Mar. 27-29<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/cybersecurityme.iqpc.ae\/\">Cyber Security for Energy &amp; Utilities<\/a><\/p>\n<p>Abu Dhabi, UAE<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/p>\n<p>Mar.\u00a013-14<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/www.maritimecybersec.com\/\">Maritime Cyber Security<\/a><\/p>\n<p>London, U.K<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 104.688px; text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10556\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/flat-icon-date.png\" alt=\"\" width=\"50\" height=\"49\" \/><\/p>\n<p>Mar. 6-7<\/td>\n<td style=\"width: 558.021px;\"><a href=\"https:\/\/www.cs4ca.com\/usa\/\">Cyber Security for critical assets USA<\/a><\/p>\n<p>Houston, USA<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&gt;&gt;Editorial:\u00a0What to remember from 2017? Industrial Control Systems (ICS) are complex systems that aim to control industrial processes. ICS can be found in several sectors: energy, nuclear, transport, chemistry\u2026 In brief these systems control many of the critical productive assets&#8230;<\/p>\n","protected":false},"author":1310,"featured_media":10576,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2777,3274],"tags":[2772,2943,3336,2944],"coauthors":[2942,2945],"class_list":["post-10498","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-digital-trust","category-manufacturing-industry-4-0-en","tag-cybersecurity","tag-ics","tag-manuf-industry-4-0-en","tag-newsletter"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight<\/title>\n<meta name=\"description\" content=\"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2018-03-26T16:47:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-01-02T10:30:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"4500\" \/>\n\t<meta property=\"og:image:height\" content=\"4500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ilias Sidqui, Fatima-Zahra Rabi\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ilias Sidqui, Fatima-Zahra Rabi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\"},\"author\":{\"name\":\"Ilias Sidqui\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8a9e8f00314811983c1914c09b557dd8\"},\"headline\":\"Industrial Control System Cybersecurity News #1 &#8211; What to remember from 2017?\",\"datePublished\":\"2018-03-26T16:47:21+00:00\",\"dateModified\":\"2020-01-02T10:30:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\"},\"wordCount\":1890,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg\",\"keywords\":[\"cybersecurity\",\"ICS\",\"manuf &amp; industry 4.0\",\"Newsletter\"],\"articleSection\":[\"Cybersecurity &amp; Digital Trust\",\"Manufacturing &amp; Industry 4.0\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\",\"name\":\"Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg\",\"datePublished\":\"2018-03-26T16:47:21+00:00\",\"dateModified\":\"2020-01-02T10:30:48+00:00\",\"description\":\"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg\",\"width\":4500,\"height\":4500,\"caption\":\"Warehouse icons flat set of storage decorative elements illustration\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Industrial Control System Cybersecurity News #1 &#8211; What to remember from 2017?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8a9e8f00314811983c1914c09b557dd8\",\"name\":\"Ilias Sidqui\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/ilias-sidqui\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight","description":"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/","og_locale":"en_US","og_type":"article","og_title":"Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight","og_description":"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/","og_site_name":"RiskInsight","article_published_time":"2018-03-26T16:47:21+00:00","article_modified_time":"2020-01-02T10:30:48+00:00","og_image":[{"width":4500,"height":4500,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg","type":"image\/jpeg"}],"author":"Ilias Sidqui, Fatima-Zahra Rabi","twitter_misc":{"Written by":"Ilias Sidqui, Fatima-Zahra Rabi","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/"},"author":{"name":"Ilias Sidqui","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8a9e8f00314811983c1914c09b557dd8"},"headline":"Industrial Control System Cybersecurity News #1 &#8211; What to remember from 2017?","datePublished":"2018-03-26T16:47:21+00:00","dateModified":"2020-01-02T10:30:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/"},"wordCount":1890,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg","keywords":["cybersecurity","ICS","manuf &amp; industry 4.0","Newsletter"],"articleSection":["Cybersecurity &amp; Digital Trust","Manufacturing &amp; Industry 4.0"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/","name":"Industrial Control System Cybersecurity News #1 - What to remember from 2017? - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg","datePublished":"2018-03-26T16:47:21+00:00","dateModified":"2020-01-02T10:30:48+00:00","description":"This is the first Industrial Control Systems (ICS) newsletter. First an editorial to examine what to remember of 2017 and then the latest news.","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/03\/Fotolia_73639054_Subscription_Monthly_XXL-supply-chain-copyright-macrovector-Fotolia.jpg","width":4500,"height":4500,"caption":"Warehouse icons flat set of storage decorative elements illustration"},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2018\/03\/ics-news-1-en\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"Industrial Control System Cybersecurity News #1 &#8211; What to remember from 2017?"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8a9e8f00314811983c1914c09b557dd8","name":"Ilias Sidqui","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/ilias-sidqui\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/10498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1310"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=10498"}],"version-history":[{"count":40,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/10498\/revisions"}],"predecessor-version":[{"id":10572,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/10498\/revisions\/10572"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/10576"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=10498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=10498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=10498"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=10498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}