<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity - Opensoft Systems Ltd | News Page</title>
	<atom:link href="https://opensoftsystems.co.uk/category/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://opensoftsystems.co.uk/category/cybersecurity/</link>
	<description></description>
	<lastBuildDate>Fri, 20 Aug 2021 14:58:21 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>Poorly designed Digital Transformation and IIoT leave OT network vulnerable to cyber-attack</title>
		<link>https://opensoftsystems.co.uk/poorly-designed-digital-transformation-and-iiot-leave-ot-network-vulnerable-to-cyber-attack/</link>
		
		<dc:creator><![CDATA[Opensoft Systems Ltd]]></dc:creator>
		<pubDate>Fri, 20 Aug 2021 14:54:01 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://opensoftsystems.co.uk/?p=4942</guid>

					<description><![CDATA[<p>The post <a href="https://opensoftsystems.co.uk/poorly-designed-digital-transformation-and-iiot-leave-ot-network-vulnerable-to-cyber-attack/">Poorly designed Digital Transformation and IIoT leave OT network vulnerable to cyber-attack</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470718306 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >While digital transformation and IIoT are massively beneficial, if designed poorly and carried out incorrectly, they can create serious threats.</p></div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner">
	<div class="wpb_single_image wpb_content_element vc_align_center wpb_content_element  wpb_custom_81a4f7ef9830bf958462581aa01150fb"><div class="wpb_wrapper">
			
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img fetchpriority="high" decoding="async" width="1000" height="491" src="https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack.png" class="vc_single_image-img attachment-full" alt="Poorly designed Digital Transformation and IIoT leave OT network vulnerable to cyber-attack" title="Poorly designed Digital Transformation and IIoT leave OT network vulnerable to cyber-attack" srcset="https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack.png 1000w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack-768x377.png 768w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack-640x314.png 640w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack-400x196.png 400w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack-367x180.png 367w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/Poorly-designed-Digital-Transformation-and-IIoT-leave-OT-network-vulnerable-to-cyber-attack-600x295.png 600w" sizes="(max-width: 1000px) 100vw, 1000px" /></div>
		</div>
	</div>
</div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470691216 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Digitalisation and the adoption of new technologies that enable networking, information flow and data insight, can create vulnerabilities within the Operation Technology network that can be exploited by hackers who are progressively going after vital infrastructure with attacks that can potentially disrupt people’s daily life, such as power generation. This makes attacks on OT networks more critical and damaging than attacks on IT systems.</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470655225 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >In the past, industrial environments were thought safe from cyber-attack as OT networks were physically isolated from public networks such the internet or unsecure LAN. With the introduction of digitalisation, this is no longer the case. Digitalisation has merged IT and OT thus giving attackers a wider target to gain access to a facility’s integrated control and safety systems. Hackers today are well aware of the flaws in OT systems and are actively looking for ways to exploit them.</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470598003 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >No system is impenetrable, and vulnerabilities will continue to materialise within the OT field. Despite substantial investment, no plant can eliminate its risk exposure. And there’s no silver bullet technology that can eliminate the cyber security risk of the growing OT and IT convergence and human error.  Added to this is the fact that cyber threats are constantly changing. With hackers always a step ahead and regulation trying to keep pace, OT cyber security has become a huge challenge for most organisations.</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470552010 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Manufacturing companies planning on a digital transformation must take a holistic approach to their implementation. The approach must include designing and implementing a comprehensive Cyber Security Management System for OT networks, developing a defined OT security policies and procedures, risk assessment, and awareness training.</p><p style="font-size: 14px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470354766 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >For comprehensive cyber security management system, the National Cyber Security Centre (NCSC) has published several guidelines to help organisations design and implement a cyber secure and resilient OT Network systems. </p><h4 style="font-size: 20px" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470302266 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >5 Cyber Security Design Principles set by the NCSC</h4></div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><h5 style="font-size: 16px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470132455 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >1. Establish the context before designing a system</h5><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469938805 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >a. You must have a complete insight into all the elements of your system operation so that your protective measures have no blind spots. It is essential that you have a clear idea of the following:</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469790023 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" > What is the system for?<br />
 What is needed to operate it?<br />
 Who operates it?<br />
 Which risks are acceptable?<br />
 Which risks are NOT acceptable?<br />
</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469702392 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >b. Identify potential threats to your system and the capability level of the attacker to who can carry out the threat.<br />
c. Identify your suppliers’ role in creating and preserving system security.<br />
d. Know all the touchpoints at which data are accessed, controlled, and stored.<br />
e. Be clear about how you control, direct, and convey your cyber security risk management activities.<br />
f.  Be clear about the roles and responsibilities of everyone involved in designing and operating your OT network system.</p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >To implement this principle requires involvement from all parts of your organisation, particularly the cyber security engineers, IT engineers, functional safety engineers, process control specialists and process control operators.</p><h5 style="font-size: 16px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470057937 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >2. Make Compromise difficult by applying the following concepts and techniques:</h5><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469557862 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >a.  Don’t trust any external input. Transforms, validate, or render it.<br />
b.  Reduce attack surface by only exposing interfaces needed to operate your system.<br />
c.  Ensure your service providers are trustworthy and competent.<br />
d.  Ensure services and products deployed are suitably designed, configured, and correctly operated.<br />
e.  Reduce risks by removing chances for malware to get entry to the administrator’s device<br />
f.  Establish accountability by attributing operations to individuals rather than groups<br />
g. Design your system so it’s easy to maintain. A poorly maintained system is vulnerable.<br />
h.  Make it easier for operators to use a secure approach. Security breaches often happen because operators used a temporary fix for system inadequacies.</p><h5 style="font-size: 16px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470072072 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >3.  Make disruption difficult by employing the following measures:</h5><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469482525 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >a.  Deploying standby systems.<br />
b.  Doing Data back-ups.<br />
c.  Designing for scalability.<br />
d.  Identify bottlenecks and plan for outages.<br />
e.  Include high load and denial of service to your testing strategy.<br />
f.  If you’re relying on third-party service, have a plan to minimise disruption if their service fails.</p><h5 style="font-size: 16px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470082727 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >4.  Make compromise detection easier by designing your OT system to spot suspicious activity in real-time.</h5><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469362832 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >a.  Collect all relevant security events and logs in real-time.<br />
b.  Simplify communications flows between devices. This will make security analysis simpler.<br />
c.  Keep monitoring independent from the system being monitored.<br />
d.  Establish a baseline for normal to detect anomalies in your system.</p><h5 style="font-size: 16px;color: #000000;line-height: 1.5" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629470090786 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >5.  Reduce the impact of compromise by making it difficult for attackers to exploit your system in the event that they gained access to your system.</h5><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-03 vc_custom_1629469267054 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >a.  Segment assets on your network to contain the compromise.<br />
b.  Remove unnecessary functionality from software or production systems.<br />
c.  Be wary of creating management bypass.<br />
d.  Design a system that allows you to quickly rebuild to a verified clean state after you’ve resolved the fault that led to the compromise.<br />
e.  Anonymise exported data, and don’t rely on reporting tools to carry out the process. Maintain control of the process and implement your controls to anonymise data as close to the source as possible.<br />
f. Don't design functionality or deploy applications that allow arbitrary queries against your data.</p></div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629471030312 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" ><a href="https://www.ncsc.gov.uk/" target="_blank" rel="nofollow">For further guidelines and information on cyber security, visit the National Cyber Security Centre.</a></p><p style="font-size: 14px;color: #000000;line-height: 1.75" class="vc_custom_heading vc_do_custom_heading mb-3 vc_custom_1629470912918 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Digital transformation is inevitable and IIoT is here to stay. Your organisation can embrace it now or later. But you must be prepared for it, all the same.</p></div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><div class="vc_empty_space"   style="height: 55px"><span class="vc_empty_space_inner"></span></div>
	<div class="wpb_text_column wpb_content_element wpb_custom_7c91d232724f73626cc933bd95b25ff0" >
		<div class="wpb_wrapper">
			<p>Reference:</p>
<p><em>Cyber security design principles</em>. (2019, May 21). National Cyber Security Centre. <a href="https://www.ncsc.gov.uk/collection/cyber-security-design-principles/cyber-security-design-principles">https://www.ncsc.gov.uk/collection/cyber-security-design-principles/cyber-security-design-principles</a></p>
<p><em>A fictional case study exploring the application of our secure design principles.</em> (2020, May 22). National Cyber Security Centre. https://www.ncsc.gov.uk/collection/cyber-security-design-principles/examples/study-operational-tech</p>

		</div>
	</div>
</div></div></div>
</div><p>The post <a href="https://opensoftsystems.co.uk/poorly-designed-digital-transformation-and-iiot-leave-ot-network-vulnerable-to-cyber-attack/">Poorly designed Digital Transformation and IIoT leave OT network vulnerable to cyber-attack</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>ISA releases list of Top 20 Secure PLC Coding Practices</title>
		<link>https://opensoftsystems.co.uk/isa-releases-list-of-top-20-secure-plc-coding-practices/</link>
		
		<dc:creator><![CDATA[Opensoft Systems Ltd]]></dc:creator>
		<pubDate>Mon, 09 Aug 2021 12:56:19 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://opensoftsystems.co.uk/?p=4876</guid>

					<description><![CDATA[<p>The post <a href="https://opensoftsystems.co.uk/isa-releases-list-of-top-20-secure-plc-coding-practices/">ISA releases list of Top 20 Secure PLC Coding Practices</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner">
	<div class="wpb_single_image wpb_content_element vc_align_center wpb_content_element  wpb_custom_81a4f7ef9830bf958462581aa01150fb"><div class="wpb_wrapper">
			
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="1000" height="562" src="https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices.png" class="vc_single_image-img attachment-full" alt="ISA releases list of Top 20 Secure PLC Coding Practices" title="ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices" srcset="https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices.png 1000w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices-768x432.png 768w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices-640x360.png 640w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices-400x225.png 400w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices-367x206.png 367w, https://opensoftsystems.co.uk/wp-content/uploads/2021/08/ISA-releases-list-of-Top-20-Secure-PLC-Coding-Practices-600x337.png 600w" sizes="(max-width: 1000px) 100vw, 1000px" /></div>
		</div>
	</div>
</div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner">
	<div class="wpb_text_column wpb_content_element wpb_custom_7c91d232724f73626cc933bd95b25ff0" >
		<div class="wpb_wrapper">
			<p><strong><span style="color: #4e4e4e; font-family: 'Open Sans', sans-serif; font-size: 13.5pt;">ISA Global Cybersecurity Alliance (ISAGCA) publishes a list of ‘Top 20 secure PLC coding practices.’</span></strong></p>
<p>&nbsp;</p>
<p style="background: white; margin: 0cm 0cm 12.0pt 0cm;"><span style="font-size: 13.5pt; font-family: 'Open Sans',sans-serif; color: #4e4e4e;">The 44-pages document, which was created in collaboration with admeritia GmbH, is intended as a resource for PLC programmers to use in their daily work. The list of secure PLC coding practices was gathered from ISAGA members and leaders, as well as PLC programming experts from across the world.</span></p>
<p style="background: white; margin: 0cm 0cm 12.0pt 0cm;"><span style="font-size: 13.5pt; font-family: 'Open Sans',sans-serif; color: #4e4e4e;">Engineers implementing PLC ladder logic, sequential function charts, and other software can use the list to make sure their industrial control systems are secure.</span></p>
<p style="background: white; margin: 0cm 0cm 12.0pt 0cm;"><span style="font-size: 13.5pt; font-family: 'Open Sans',sans-serif; color: #4e4e4e;">The practices list in the document is aimed meant to use existing PLC or DCS functionality.</span></p>
<h4 style="text-align: center;"><strong><a href="https://www.plc-security.com/#download">Download your copy now:</a></strong></h4>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" >
	<a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-square vc_btn3-style-classic wpb_custom_6687b26f39488ddbb85ddb3c1ce8e111 vc_btn3-color-grey btn" href="https://opensoftsystems.co.uk/about-us/news/" title="">Back to News Page</a>	</div>
</div></div></div>
</div><p>The post <a href="https://opensoftsystems.co.uk/isa-releases-list-of-top-20-secure-plc-coding-practices/">ISA releases list of Top 20 Secure PLC Coding Practices</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Average cost of a data breach by security automation level in organizations worldwide from 2018 to 2020</title>
		<link>https://opensoftsystems.co.uk/cost-of-data-security-breach/</link>
		
		<dc:creator><![CDATA[Opensoft Systems Ltd]]></dc:creator>
		<pubDate>Thu, 05 Aug 2021 08:10:19 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://opensoftsystems.co.uk/?p=4774</guid>

					<description><![CDATA[<p>The post <a href="https://opensoftsystems.co.uk/cost-of-data-security-breach/">Average cost of a data breach by security automation level in organizations worldwide from 2018 to 2020</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><h4 style="font-size: 18px;color: #000000" class="vc_custom_heading vc_do_custom_heading mb-03 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >In 2020, failure to deploy security automation cost companies 6.03 million U.S. dollars on average, while companies with fully deployed security automation spent less at 2.45 million U.S. dollars on average.</h4>
	<div class="wpb_text_column wpb_content_element wpb_custom_7c91d232724f73626cc933bd95b25ff0" >
		<div class="wpb_wrapper">
			<p style="text-align: center;"><a href="https://www.statista.com/statistics/1176688/data-breach-cost-security-automation-level/" rel="nofollow"><img decoding="async" style="width: 100%; height: auto !important; max-width: 1000px; -ms-interpolation-mode: bicubic;" src="https://www.statista.com/graphic/1/1176688/data-breach-cost-security-automation-level.jpg" alt="Statistic: Average cost of a data breach by security automation level in organizations worldwide from 2018 to 2020 (in million U.S. dollars) | Statista" /></a><br />
Find more statistics at <a href="https://www.statista.com" rel="nofollow">Statista</a></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" >
	<a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-default vc_btn3-style-classic wpb_custom_6687b26f39488ddbb85ddb3c1ce8e111 vc_btn3-color-grey btn" href="https://opensoftsystems.co.uk/about-us/news/" title="">BACK TO NEWS PAGE</a>	</div>
</div></div></div>
</div><p>The post <a href="https://opensoftsystems.co.uk/cost-of-data-security-breach/">Average cost of a data breach by security automation level in organizations worldwide from 2018 to 2020</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Schneider Electric Issues Security Advisory to Counter PLC Vulnerability</title>
		<link>https://opensoftsystems.co.uk/schneider-electric-issues-security-advisory-to-counter-plc-vulnerability/</link>
		
		<dc:creator><![CDATA[Opensoft Systems Ltd]]></dc:creator>
		<pubDate>Wed, 21 Jul 2021 15:59:24 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">https://opensoftsystems.co.uk/?p=4681</guid>

					<description><![CDATA[<p>The post <a href="https://opensoftsystems.co.uk/schneider-electric-issues-security-advisory-to-counter-plc-vulnerability/">Schneider Electric Issues Security Advisory to Counter PLC Vulnerability</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner"><p style="font-size: 16px" class="vc_custom_heading vc_do_custom_heading mb-03 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Last year, cybersecurity researchers discovered vulnerabilities in some of Schneider Electric’s product including Modicon M580 and M340 PLCs. These vulnerabilities enable attackers to bypass security tools installed on these PLCs and exploit the undocumented Modbus commands to gain complete control of the plc.</p>
	<div class="wpb_single_image wpb_content_element vc_align_center wpb_content_element  wpb_custom_81a4f7ef9830bf958462581aa01150fb"><div class="wpb_wrapper">
			
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="1100" height="619" src="https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit.jpg" class="vc_single_image-img attachment-full" alt="Security Advisory to Counter PLC Vulnerability" title="Security Advisory to Counter PLC Vulnerability" srcset="https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit.jpg 1100w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-1024x576.jpg 1024w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-768x432.jpg 768w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-640x360.jpg 640w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-400x225.jpg 400w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-367x207.jpg 367w, https://opensoftsystems.co.uk/wp-content/uploads/2021/07/source-code-exploit-600x338.jpg 600w" sizes="(max-width: 1100px) 100vw, 1100px" /></div>
		</div>
	</div>
<p style="font-size: 16px" class="vc_custom_heading vc_do_custom_heading mb-03 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Using these commands attackers can take over the plc, gain native code execution on the device and make changes to the operation of the plc, while hiding the changes from the engineering workstation that manages it.</p><p style="font-size: 16px" class="vc_custom_heading vc_do_custom_heading mb-03 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" >Since the discovery, Schneider had been working on a patch which is expected to be released Q4 of 2021. In the meantime, SE had released a security advisory on 13 July 2021 for users of M580 and M340 to help protect their system from possible attack.</p><p style="font-size: 16px" class="vc_custom_heading vc_do_custom_heading mb-03 wpb_custom_aa365bd5046e8294520b4e73732b9d15 align-left" ><a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-01" target="_blank">Find the Schneider Electric security advisory here.</a></p></div></div></div><div class="vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f"><div class="vc_column_container col-md-12"><div class="wpb_wrapper vc_column-inner">
	<div class="wpb_text_column wpb_content_element wpb_custom_7c91d232724f73626cc933bd95b25ff0" >
		<div class="wpb_wrapper">
			<p>Other Schneider products affected are EcoStruxure Control Expert, EcoStruxure Process Expert, and SCADAPack RemoteConnect x70</p>

		</div>
	</div>
</div></div></div>
</div><p>The post <a href="https://opensoftsystems.co.uk/schneider-electric-issues-security-advisory-to-counter-plc-vulnerability/">Schneider Electric Issues Security Advisory to Counter PLC Vulnerability</a> appeared first on <a href="https://opensoftsystems.co.uk">Opensoft Systems Ltd</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
