Hey @noahkagan , I am reading your book. I am building cyber security services for creators. Would you invest $1 in me? If so https://t.co/eF69xd0raf
#thedollarchallenge
@digitalbond@aginter Finding the right balance between IT and OT security is, of course, difficult, but both should be developed at the same time.
What do you think?
(5/5)
I listened to @digitalbond 's podcast with @aginter (great episode BTW). Dale asked a question along the lines: "If ransomware in IT can cripple the OT operation, shouldn't we rather invest in IT security than OT security?"
This made me think. This is my two cents. (1/5)
@digitalbond@aginter And thus, I think the security budget should be divided between IT and OT. There should be security layers in OT, such as network segmentation, network anomaly detection, patch management, asset inventory, log monitoring with SIEM, etc.
(4/5)
- The MicroSCADA installation had already reached its end-of-life. Newer versions provide better security features and defaults.
It is worth evaluating your environment to see whether these techniques could be used successfully there.
= New Technique Used to Target Electric Substation in Ukraine =
OT operators should analyze every OT attack deeply to understand how they can use the new information to increase their defenses.
There is a lot to learn from it. ๐งต๐
- OT living-off-the-land: a legitimate program called scilc.exe from MicroSCADA was used to execute a program to send commands to the circuit breakers.
- A newer version of CADDYWIPER was deployed using Group Policy to wipe the IT environment.