Skip to content

Missing Awareness

Short Description (one paragraph)

Description

  • trying to wiggle out of security features via deflection to obscurity
  • cyber-security hygiene
  • everything configuration related
  • missing encryption even if available
  • available JTAG/SWD interface left enabled on production devices
  • Intentional misconfiguration for ease of use, e.g., leaving rtu’s in upload mode
  • lack of hardening
  • why are security best-practises not applied? missing knowledge?
  • culture
  • OT guys know something that the IT guys know not

Rationale

  • why did we include this item in the top 10?

Known Attacks/Examples

Potential Sources

How-To Test (have to discuss)

  • maybe add this to a separate section?

Mitigation/Countermeasures

Design and Implementation

  • mitigations for developers/builders

Operational

  • mitigations for integrators/builders

References

Standards

  • links to relevant standards

Background information

  • links to blogs, etc.

Tooling

  • for testing, etc.