ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Securing SCADA systems

protecting scada systems
protecting scada systems

Tom Huckle at BlueVoyant explains why SCADA-based systems are seen as the weak link

 

As digital transformation initiatives continue to accelerate post-pandemic, we are witnessing more converged, connected, and automated systems than ever before.

 

In particular, we’ve seen recent rapid growth in connectivity for operational technology (OT) and industrial control systems (ICS), as IT and OT also come together. Previously somewhat isolated, OT is now not only being connected to corporate networks, but it is also becoming cloud-connected to access better scalability, flexibility, and availability.

 

However, this creates an increased attack surface and more opportunities for hackers, leading to several high-profile incidents in the past few years. One of the most notable was the Colonial Pipeline ransomware attack in 2021, with all operations being halted in order to contain the attack.

 

To take advantage of cloud technologies, as well as industrial IoT and edge computing, many organisations need to modernise their ageing legacy systems. This can be difficult and complex to achieve. Work often includes Supervisory Control and Data Acquisition (SCADA-based) critical national infrastructure (CNI) systems. These systems were never originally designed to be online – and this means that security has on the majority of occasions, been an afterthought.

 

To understand their original purpose, how they came to be connected, and the risk they present from a security perspective, we need to look at the history of SCADA-based CNI systems.

 

Never designed to be online

SCADA-based CNI systems were never designed to be online. SCADA is a control system architecture composed of computers, networked data communications and graphical user interfaces for high-level supervision of machines and processes.

 

These systems tie together decentralised facilities such as power, oil, and gas pipelines, water distribution, and wastewater collection systems and were designed to be open, robust, and easily operated and repaired. However, a consequence of this accessibility is that they can be highly vulnerable.

 

These systems have evolved through several generations, with the initial models requiring no connectivity. But growing digital infrastructure required a second generation of SCADA systems, connected through a local area network (LAN).

 

This architecture, however, was chaotic and network protocols were unstandardised. Securing this network was difficult and was therefore not a priority for developers.

 

Over time, as more components have been integrated into the SCADA architecture and as geographic distances grew between facilities, reducing costs became a key focus. The use of existing phone lines, combined with non-standardised or insecure protocols, brought a perfect storm of insecurity to these essential communications, navigation and identification systems.

 

Connecting to the web creates vulnerabilities

This evolution of systems without security at the forefront meant that, once offices connected SCADA-based CNI systems to web-based technologies, they were left vulnerable to all types of commonly seen network attacks.

 

As with most vulnerabilities present in network architectures, an emphasis on convenience overrode security measures. The desire for increased response times, reduced operator time, and the flexibility to monitor SCADA systems anywhere, anytime, have all culminated in the current security weaknesses observed in CNI.

 

The current risk level is high and has been steadily growing for several years. Some of the most notorious attacks show real growth in scale. The 2017 global cyber attack NotPetya, the 2020 ransomware attack on EDP Renewables North America, and REvil’s targeting of Spanish state-owned railway operator Administrador de Infraestructuras Ferroviarias unfortunately demonstrate how CNI attacks can severely impact a country’s economy.

 

Governments have increased their own defensive measures to meet these risks, but they face several challenges. CNI-architecture is still difficult to manage, and cyber criminals are only increasing in confidence, organisation, and capability.

 

Governments have repeatedly warned about the additional risks brought about by global events, in which advanced adversaries target CNI as part of hybrid warfare. These state-sponsored groups use CNI attacks to set the conditions for any decisive action they might later take, causing disruption and weakening defences. Examples can be found in 2015 and 2016 when certain parts of Ukraine’s power grid were shut down by malware that had been inserted into the infrastructure by a foreign state actor.

 

The threat level is also dependent on the industry’s ability to defend itself. For example, if a water treatment plant shuns its security responsibilities and becomes an easy target, they will be tested for monetary gains or even just for the hacker’s own publicity.

 

Protecting SCADA-based systems

With this in mind, what should organisations do to protect CNI and SCADA-based systems?

 

Organisations need to ensure they have a clear understanding of ICS cyber security and of the associated impacts of system reliability and company safety in the event of an attack. To truly mitigate CNI security risk, critical industries need to consider security as important as performance and safety.

 

However, normal cyber security practices are an essential foundation, so these industries should focus on regular patch management, least privilege access, account hygiene, encrypting information exchanges, running anti-virus scans, taking care with USB drives or other external media, performing technical audits and risk management processes, and maintaining a resourced and capable internal security team.

 

ICS experts need thorough vetting to limit insider threat risks and organisations should ensure that they conform to standard certification metrics across ICS processes, systems, personnel, and cyber security. There are many other baseline security measures that can be taken as part of a holistic cyber security program but adhering to the basics will mitigate a large amount of risk.

 

By defining cyber threats in the broadest possible terms, organisations can also set informed protocols and best practices based on both actual and expected ICS cyber incidents and can inform which security technologies need to be developed and employed as part of the overall strategy. These threats include intentional, unintentional, natural, and other electronic threats such as electromagnetic pulse (EMP) and electronic warfare against electronic devices.

 

In addition to these best practices, it is essential that organisations develop and obtain IT technologies to bolster the security of workstations using commercial off-the-shelf operating systems (COTS). Involving subject matter experts with control system experience at these planning sessions will provide organisations with confidence and familiarise them with the cyber threats they should be securing against and will help to change the culture.

 

The move to cloud is complex

The movement to cloud does not leave SCADA environments behind, but it is more complex. For example, many cloud vendors offer software to enable SCADA monitoring from anywhere, simultaneously creating yet another entry point for attackers to exploit.

 

The adherence and adoption of a standards-based approach will help manage this complex environment, as well as the adoption of the NIST cyber security framework will help manage and control these complex environments.

 

And finally, incorporating IoT into SCADA networks does bring its own issues, predominantly the increased attack surface for hackers and the difficulty of maintaining and tracking all the devices.

 

However, moving to a more open architecture and away from proprietary technologies means these issues will potentially start to disappear. Interoperability, modularity, standards conformity, compliance with security standards, scalability and portability will all become possible.

 

A cyber security strategy for protecting SCADA is not going to be a one-time endeavour and security teams will need to plan what cyber defences to implement carefully, and then adopt measures to keep threat protection running effectively over the long-term.

 

As with everything in cyber security, it is an ever evolving environment and to remain effective, you must always strive to adapt and be prepared to overcome adversity. Remaining idle, whilst the industry and threats advance is a sure way to become a target.

 


 

Tom Huckle is Director of Information Security and Compliance EMEA, BlueVoyant

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543