Showing posts with label ICS news. Show all posts
Showing posts with label ICS news. Show all posts

Monday, November 23, 2015

Frost & Sullivan recognizes Waterfall Security Solutions for Customer Value Excellence through Technology Convergence for 4th consecutive year

For the fourth year in a row, Frost & Sullivan has recognized Waterfall with a Customer Value Excellence through Technology Convergence award.

This honor is awarded to a company that exhibits exceptional technology convergence impact and customer impact, proving the company’s ability to have consistent growth potential, ROI benefits and a significant impact on the security industry.

Ashay Abbhi, senior analyst at Frost & Sullivan, said, “Frost & Sullivan considers Waterfall’s pioneering solution to potentially become the standard in cybersecurity across industries, brought about by its disruptive technological convergence to secure the most vulnerable and sensitive point of attack – the data.”

Highlighted in the solution assessment is Waterfall’s Application Data Control (ADC) solution, which provides fine-grained policy controls for data in motion through Waterfall’s Unidirectional Security Gateway and FLIP products. The ADC add-on provides in-line controls for data movement, content restrictions, in-line anti-virus scanning and other/custom scanning and verification of files, BLOBs and any suspect or sensitive content. ADC controls can be applied to support data exfiltration prevention as well as powerful controls over data permitted back into critical networks.

“Waterfall enables safe IT/OT integration while ensuring the amalgamation of data from these silos is secured and the vulnerability removed by moving the data in only one direction instead of the customary bidirectional movement,” Abbhi added.

We’re honored to have earned Frost & Sullivan’s recognition once again. This award is testament to the needs for stronger-than-firewall security solutions for industrial control systems and further validates our product and commitment to safeguarding these important assets.

To learn more about our technology and how it protects ICS, visit our Resources page.


Thursday, September 24, 2015

Security Nugget: Air Compressors Help Secure Generators

At large generators, per-unit air compressors and Unidirectional Gateways are reducing risk and reducing compliance costs.


The latest CIP V5 transition guidance explains how to assess the impact of segmented networks. Large generating sites are duplicating site-wide resources, such as pneumatic air compressors and control systems, for every generating unit. NERC CIP V5 states that if there is a strong security perimeter around each control system segment, and no segment can influence more than 1500 MW of generation, then the site has no Medium Impact cyber systems. This is a significant incentive; Low Impact systems cost much less to administer than Medium Impact systems.


Done properly, increased redundancy and segmentation can dramatically reduce compliance costs and the cost of risks. The right way to segment generating networks is with Unidirectional Security Gateways. Per-unit physical redundancy and per-unit network segmentation with Unidirectional Gateways turns one large, valuable target into many smaller, much harder targets. Unidirectional segmentation eliminates the single biggest risk to generating networks: the risk of remote attacks reaching through firewalls into control system networks. It does not matter how mundane or how sophisticated the attack, it does not matter whether the attack is from corporate insiders or the Internet, Unidirectional Security Gateways physically prevent all message from external networks that may put a control network at risk.


The bottom line: CIP-compliant segmentation substantially reduces compliance costs. Per-unit Unidirectional Security Gateways substantially reduce risks and costs. Investing a tiny fraction of compliance cost savings into risk reduction with Unidirectional Security Gateways is just good business.

Thursday, July 16, 2015

Digital Bond Labs assess FLIP technology’s unidirectional security

Last month, Digital Bond Labs, a cybersecurity lab focused on finding new security and reliability vulnerabilities in control-system components, performed a security assessment of Waterfall’s FLIP product line. We have great confidence in our solutions at Waterfall, and DigitalBond’s testing verified what we were already convinced of, that the FLIP cannot be transformed into a bidirectional communication channel, nor can it be controlled remotely.

The Waterfall FLIP is type of a hardware-enforced unidirectional security gateway. The technology replicates control system servers to IT networks without enabling anything to move in the opposite direction. When needed, the Waterfall FLIP also replicates servers from IT networks to control networks, for as long as is needed. For example, FLIP products are routinely deployed to replicate historian data out of control system networks nearly continuously, and reverse orientation several times per day so that the FLIP software can fetch anti-virus and other security updates and transmit them to the control system.

Digital Bond’s findings were in line with Waterfalls marketing message for FLIP, stating that:

  • It could find no way to transform the FLIP into an interactive bidirectional channel, and that “the FLIP is always a one-way system.”
  • IT could find no way to remotely control the FLIP mechanism that reverses direction from either the “inside” or “outside” networks.

Digital Bond concluded that, since the FLIP is unidirectional at all times, and the direction cannot be remotely controlled, “the FLIP is a much stronger security mechanism than a firewall.” Digital Bond Labs’ researchers also concluded that the FLIP “provides a defensive advantage versus. traditional thumb drive data transfers” because the FLIP “provides a single entry point to the control system network that can be hardened and monitored versus thumb drive transfer, which introduces a risk of infection to every system that the thumb drive is connected to.”

Unidirectional security gateways prevent IT security issues from weakening operational technology (OT) security. The verification from Digital Bond Labs serves as assurance that Waterfall solutions are capable of protecting reliability-critical systems and process equipment from security threats. Cyberattacks aimed at control systems have much greater potential consequences than attacks on IT systems. Unidirectional security gateways stop IT network attacks from becoming OT problems.


Waterfall also has FLIP technology solutions for Substations. Learn more on our product page.

Tuesday, May 12, 2015

April news roundup: The results are in…

Critical infrastructure security was a major topic among analyst firms and researchers in April. If you didn’t stay up to date with the findings throughout the month, we prepared a brief recap for you. Included are findings from Dell’s survey on cybersecurity and a report by the Organization of American States. Read more in this month’s news roundup.

Hacks on critical infrastructure are more common than you think (The Inquirer - April 7, 2015)
In a recent report, the Organization of American States found that hackers commonly seek to destroy major critical infrastructures. The report shows that 54 percent of the 575 companies polled encountered attempts to manipulate control systems. Even more troublesome is that 60 percent of the companies detected attempts to steal data.

Cyberattacks on SCADA and industry double in 2014, says Dell (Fox News – April 8, 2015)
Analysis from Dell’s intelligence network shows attacks against SCADA systems have doubled in the last few years. These attacks on industrial systems can cause more damage than traditional hacking because of the risks they pose to critical infrastructures. Of the attacks that Dell investigated, most were against Finland, the U.K. and the U.S. since industrial control systems are commonly used in these countries. Dell also noticed a rise in point-of-sales malware and attacks on payment infrastructure, leading to some of the highest-profile breaches in history.

Are you prepared? This year's fastest growing security threats (Business News Daily - April 14, 2015)
In a more detailed article about the Dell study, Business News Daily offers some key insights from the results. Attacks against SCADA systems are the third largest security threat that businesses should be planning for in 2015. These attacks often go unreported, and when combined with the U.S.’s aging infrastructure, they present huge security risks.

The U.S.’s energy infrastructure will need major changes, says Obama report (Washington Post – April 21, 2015)
According to a recent report released by the Obama administration, the U.S. electric grid will require major changes to adapt to future national security challenges. The report comes in the wake of new developments to the grid system, increased threats from hackers and climate extremes, among other developments.


Protect cybersecurity spending to avoid attacks on energy infrastructure (Newsweek - April 27, 2015)
According to analysts, defense budget cuts have left the U.K. open to cyberattacks. Ewan Lawson, senior military research fellow at the Royal United Services Institute, recommends increasing budgets for cybersecurity to prevent attacks on energy infrastructure. He also points to the German steel mill attack, which caused massive damage to the plant control system. An additional report by cybersecurity firm Cylance Corporation shows Iranian actors have hacked into critical infrastructures in the U.K., France, Germany and the U.S.

Did you miss March’s critical infrastructure security news? Check it out in last month’s industrial security news roundup.