News from ISSSource
- Understanding Sensor Data Integrity
An energy company knew there was a problem with drift and misconfigurations with their sensors. Yes, they were smart sensors, but they didn’t know how much they could trust them, after all, one area had one type of reading, another area had a different reading and yet another area had something different. It just seemed like they were all talking a different language. There was definitely an inconsistency challenge.
Read more - No Hype, Just Create a Product Strategy
Change and the evolution of security products is inevitable, so asset owners should not get caught up in the hype of buying one product thinking it will solve all their security problems, but rather, take a clear thoughtful approach and lay out a solid strategy. “When we talk about products, we have to be careful. Companies, especially senior management, believe they can solve problems by buying a product. It can help, but it won’t be a solid answer,” said Dale Peterson, founder and chief executive at Digital Bond, last week during a keynote at the PAS Optics 2020 virtual conference. “You really need to come up with a product strategy.”
Read more - LyondellBasell: From Attack to Solid Security
Nine years ago, one manufacturing facility for chemical giant LyondellBasell fell victim to a Conficker virus attack that had already been out for four years which ended up shutting down some firewalls but ultimately did not shut down the plant. “This was a known virus and there were known fixes, but we were not prepared for it,” said Michael Norris, director of business systems security at LyondellBasell during a session entitled “Building & Maturing IT/OT Risk Management: An Ongoing Journey” Tuesday at the PAS Optics 2020 virtual conference.
Read more - Remote Access Leads to FL Water Supply Tampering
A quick thinking worker watched and quickly fixed an attack as a hacker using a Florida water treatment plant’s remote access capabilities broke in Friday and increased the amount of sodium hydroxide, or lye, to extremely dangerous levels. In these times of increased work from home, questions remain as to how secure are company’s remote access capabilities, and how vigilant are those providers in seeing what is going on? In this case, it appears the water company’s remote access was not secure, but worker vigilance was on target.
Read more - PAS: From Raising Capital to Being Acquired
There comes a time in any company’s lifetime where they have to make a decision on what they have to do if they want to grow: Acquisition, raise capital, be acquired or go the organic route. PAS Global wanted to grow and they first thought raising capital was the way to go. Afterall, they did it before and it worked, why not do it again. After first looking to raise capital about a year ago, at some point in the spring, they shifted gears and looked to be acquired.
Read more
Safety & Security
How OT Cybersecurity Is Improved by Process Safety Best Practices
IT cybersecurity traditionally focuses on the “CIA Triad”, which stands for Confidentiality, Integrity, and Availability. The practices associated with this model are intended to ensure data is: Kept private, not compromised in any way, and available when needed.
OT (Operational Technology) is concerned with the automation systems that facilitate safe production in process and manufacturing industries. OT cybersecurity differs from the IT cybersecurity model because it is not only concerned with data protection, but also with the prevention of cyber espionage and the risk of impact to process safety, reliability, and the environment.
PETRONAS Upstream Improves Operational Performance Through Digital Transformation and Collaboration
PETRONAS, a global oil and gas company headquartered in Malaysia, is executing a major initiative for operational excellence, digitalization, and remote operations.
Initial results show significant improvement gains in process safety, reliability, and cost-effective process operations. This is the result of a multi-year progressive implementation project across 37 oil and gas facilities.
OnDemand Webcast: Petroleum Development Oman’s Journey to Safe & Secure Production
Petroleum Development Oman (PDO), is the leading exploration and production company in the Sultanate of Oman. PDO delivers the majority of the country’s crude oil production and natural gas supply, along with energy from renewable resources.
The company had three main objectives in 2020: Reduce production cost, increase efficiency, and improve the capacity and capability of the Omani people and businesses to secure sustainable commercial benefits for the country.
OnDemand Webcast: Mind the Gap: Understand the Distance Between IT and OT Cyber Incident Forensic Analysis and Safe Restart
Petroleum Development Oman (PDO), is the leading exploration and production company in the Sultanate of Oman. PDO delivers the majority of the country’s crude oil production and natural gas supply, along with energy from renewable resources.
The company had three main objectives in 2020: reduce production cost, increase efficiency, and improve the capacity and capability of the Omani people and businesses to secure sustainable commercial benefits for the country.
Security
OT/ICS Cybersecurity: You Cannot Secure What You Cannot See
With smarter, integrated automation comes a difficult challenge that has repercussions from the boardroom to manufacturing operations: ICS cybersecurity. It is generally well understood that you cannot secure what you cannot see. That is why accurate, up-to-date visibility of the system inventory is a key element of any cybersecurity solution.
The truth is most ICS inventories reflect only non-proprietary, IT-based assets, which are roughly 20 percent of the cyber assets required for a comprehensive ICS cybersecurity program. The remaining 80 percent are proprietary, OT-based assets that make retrieving inventory data difficult as there are no common sets of protocols, such as WMI or SNMP, available. In a growing threat landscape, insufficient control system security is no longer tenable.
ICS Asset Identification: It’s More Than Just Security
Without a solid understanding of the assets on your ICS network, it’s impossible to develop and implement a strategy to manage risk and ensure reliable operations. Asset identification was the No. 1 concern of 338 ICS security professionals participating in the SANS 2019 State of OT/ICS Cybersecurity Survey.
Historically, asset identification has been associated with time-consuming and costly efforts to identify and maintain an accurate inventory, with more than half of operators spending 20–80 percent of their time just finding and validating plant information. Despite this operational focus and perhaps due to mismatched expectations, this critical and fundamental step is not always the board’s top priority for the CISO.
OT/ICS Cybersecurity: Protecting the Industrial Endpoints That Matter Most
With cyber incidents and reported vulnerabilities on the rise, industrial cybersecurity leaders must deploy proactive industrial endpoint detection and response (EDR) across the entire process control network.
Failure to reduce industrial endpoint attack surfaces (e.g. insecure configurations, missing patches, vulnerabilities) increases the risk of malicious changes or unintended misconfigurations.
Reduce OT/ICS Risk: Find and Remediate Hidden Vulnerabilities on ICS Assets
Why have our best efforts to secure industrial facilities fallen short? The answer is that we have taken an IT-centric versus a production-centric approach to ICS cybersecurity. This has left the systems responsible for safety and production vulnerable to malicious attacks or unintended incidents.
An over-reliance on IT-centric perimeter defenses, combined with an inability to see vulnerabilities lurking deep within industrial control system (ICS) environments, has left our critical infrastructure vulnerable. In addition, learn about current ICS vulnerability management challenges, as well as how you can find and remediate vulnerabilities hidden within ICS environments by taking a more production-centric approach to managing vulnerabilities on Level 2, 1, and 0 ICS assets.
The Power of Regulation Versus Well-Oiled Industry Standards
The power industry is currently on NERC CIP Version 6 of its regulatory requirements with future regulations expected on supply chain security. Oil and gas (O&G) has no such regulatory regime, but it does have standards that it uses to reduce cybersecurity risk, such as NIST 800-82 and IEC 62443.
For O&G, compliance is an internally generated activity. So, which of these two approaches – regulated or not regulated – is best for industrial control system (ICS) cybersecurity? Does following a government mandated regime better secure an industry, or is self-regulation the answer?
Safety
Control Loop Performance: Are You in Control of Your Control Loops?
Operations Risk Management (ORM) is a layered approach designed to ensure safe and profitable operation. ORM focuses on the automation and control functions of process operations. Control loops are the first line of defense against risks to safety, the environment, production, efficiency, and profitability.
Optimizing loop performance reduces risk in several ways. When control loops work properly, the process can achieve nameplate production rates, on-spec quality, and maximum efficiency. Process upsets do not occur. Process intervention by the operator is needed less often and mistakes in the intervention are less likely. Safety systems have less need to activate. Shutdowns do not occur, helping reduce the most hazardous and risky step for most processes – the startup.
Understanding and Applying the ANSI/ISA 18.2 Standard
Alarm Management has become an ever-increasing topic of discussion in the power and processing industries.
In 2003, ISA started developing a standard around this subject. After six years of hard work, the ANSI/ISA-18.2-2009 Management of Alarm Systems for the Process Industries standard was published. Take a look at the scope, regulatory impact, requirements, recommendations, alarm definitions, and other details of the standard.
What is Your SIS Doing When You’re Not Watching?
Organizations spend significant capital on safety instrumented systems (SIS) and as much or more on maintaining them over time. Now is the time to examine the necessary administrative tasks associated with managing independent protection layers (IPLs) with a particular emphasis on SIS. Some of these tasks are often overlooked and significant risks exist if they are not done properly and consistently.
In addition, international standards such as IEC 61508 and 61511 were should improve industrial risk management after several major process safety-related accidents in the 1980s. While helpful, these standards have also spawned a large and complex body of knowledge and specialized vocabulary for the design, operations, and maintenance of an SIS.
White Paper: Pushing Process Limits Without Compromising Safety
Numerous accident investigations highlight lack of proper overview displays and alarms as root causes or contributing factors to accidents.
One example of this is the Texas City incident in 2005, in which “the control board display did not provide adequate information on the imbalance of flows in and out of the tower to alert the operators to the dangerously high level.”

