Critical infrastructure systems needs better security, says survey

Critical infrastructure systems needs better security, says survey

By Robert Westervelt | Feb 1, 2010

The systems that run power plants, manage the distribution of hazardous chemicals and help monitor water treatment plants are in a dire need of stronger safeguards, according to a survey of more than 600 IT and security executives who work for many of the companies that run them.

Critical infrastructure facilities in the United States and other developed countries are connected to the Internet and their underlying management systems are threatened by a constant barrage of cyberattacks, according to a new report "In the Crossfire: Critical Infrastructure in the Age of Cyber War."

The report sums up the findings of a global survey of IT and security executives at more than 600 enterprises that own and operate critical infrastructure. It was released today by the Center for Strategic and International Studies (CSIS). The study was funded by security vendor McAfee Inc. and was released at the World Economic Forum in Davos, Switzerland.

The survey found that SCADA systems, the critical network and control systems that run dams, power plants, gas and oil refineries and other facilities are being attacked by a variety of methods, individuals and criminal gangs with various interests. Two-thirds of those surveyed (76%) said their SCADA systems were connected to an IP network or the Internet. About half of those said the connection created SCADA system security issues that aren't being addressed.

The kinds of attacks facing critical infrastructure facilities mirror those targeting government agencies and government contractors. It also reflects the wide variety of ongoing attacks targeting the private sector. The issues were highlighted recently in attacks that targeted employees at Google Inc., Adobe Systems Inc. and dozens of other firms exploiting a flaw in Microsoft Internet Explorer 6.

 
 

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.