- Blue Coat Selects Norman Shark As Malware Analysis Technology Partner
- Norman Shark to Announce Malware Analyzer G2 v4.0 and Updated Network Threat Discovery at Black Hat 2013
- Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India
- Norman Shark to Launch Norman Shark Network Protection Solution at RSA, Demos to be Available
- Norman AS splits company to maximize revenue
- Long Shadow Of Stuxnet Inspires Custom Anti-Malware Project
- Defense In Depth Enables Protection Of Critical Pipeline Assets
- Norman Shark to Sponsor Third Annual Securing Our eCity Cybersecurity Symposium 2012
- Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year
- Systematic cyber attacks against Israeli and Palestinian targets going on for a year
- Protecting Today’s SCADA-Based Mass Transit Systems Should Begin with a Defense-in-Depth
- The Wake Up Call: Hackers are Reported to have Caught the World’s Major Oil and Gas Companies Napping
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Presents New Episode of Video Series to Continue Focus on Cybercrime Prevention among Executives
- Norman Shark Named as a Gartner “Vendor to Watch” in New Market Trends Report, Cites Norman Shark Network Threat Discovery and Malware Analyzer G2 Network Protection Solutions
- Norman Shark is shifting its U.S. headquarters from Washington, D.C., to San Diego
- Web security firm beefs up San Diego operation
- The Many Faces of Gh0st Rat
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Announces SCADA Security OEM Partnership with Kongsberg Maritime to Protect Critical Oil, Gas and Maritime Industrial Environments Globally
- Norman Shark Customers Secured Against Flamer
Industrial Control Systems (ICS) – such as supervisory control and data acquisition (SCADA) systems – manage and monitor critical storage, refining and distribution operations at many energy pipeline companies. These systems collect data from points throughout the operation and communicate control commands to equipment located both locally and remotely.
These systems have typically run behind the scenes, but have more recently become front and center as information about real and potential cyberattacks have appeared in the media. Hostile governments, competitors, terrorist groups, disgruntled employees and other malicious intruders know these systems offer a trove of confidential and potentially very damaging data.
The types of critical infrastructure that industrial control systems manage include physical and IT assets, networks and services that, if disrupted or destroyed, could have a serious impact on the health, security and/or economic well being of both people in the immediate area and the country at large.
Due to the critical nature of ICSs and the facilities they control and manage, all levels of management at these facilities must put security of these systems at the top of their agendas.
Until recently, security concerns over ICSs were limited to physical attacks. Because these were closed systems, managers assumed that if operational consoles were isolated and only authorized personnel were allowed to gain access to the network, any security issues were covered. There was limited risk of malfeasance since few people had the technical expertise to operate the system and data communication paths were isolated.
Today’s situation is completely different. IT teams at energy companies have recognized that lower costs, easier accessibility and improved efficiency can be gained thorough connecting their IP-based operations network to their ICSs. Today’s systems are directly or indirectly connected to corporate networks and the Internet, which exponentially increases the security risks to which they are exposed far beyond physical attacks. Multiple factors have contributed to the increased exposure of industrial control systems, these include:
1) Technical information availability – public information about infrastructure and control systems is available to potential hackers and intruders. Potential hackers can easily find design and maintenance documents and technical standards for critical systems on the Internet, threatening overall security.
2) Remote connections that are vulnerable – Connections such as virtual private networks (VPNs) and wireless networks are used for remote diagnostics, maintenance and examination of system status. If users fail to incorporate robust identification, authentication and encryption into their communications, the integrity of any information transmitted is in question.
3) Networking of control systems – Organizations have increased connectivity through the integration of their control systems and enterprise networks. Any breach at any point in the network, exposes all the information – ICS-related data, e-mails, corporate information, et al. to intruders.

