Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Infrastructure:Electric,Gas & Water

Securing the Next Generation Business Network

By Andrew Ginter
April 1, 2010
Andrew Ginter says that most critical infrastructure control systems were not designed with security in mind, and history has proven that these systems are vulnerable to attack and to performance failures.


An increasing focus for companies managing critical infrastructures is the security of process control systems. At the same time, enterprises increasingly rely on access to real-time data in order to drive faster time-to-revenue through the use of business intelligence systems. Access to real-time data requires connectivity into the heart of critical infrastructure process control and SCADA networks, including those in the electric power, oil and gas, transportation, water and chemical sectors. 

Most critical infrastructure control systems were not designed with security in mind, and history has proven that these systems are vulnerable to attack and to performance failures. Truth be told, many plant networks were designed to be “air gapped” – they were never designed for connectivity to business networks, or for remote access from other networks. However, it turns out that simply applying proven enterprise security policies to control systems is not the answer. 

So how should security executives secure their critical revenue-generating assets where the risk of a security breach has not only significant economic and social impact, but potentially physical, life-threatening impact as well? More still, what do enterprise security professionals need to know about this environment to work with the operations staff to properly secure and defend against these threats?


Connecting These Two Networks Introduces Real Risk on Both Sides

Enterprise security personnel looking at a control system connected to the enterprise network may see a vulnerable source of and reservoir of malware-infected systems. Many control system hosts are running older, unpatched operating systems. The most elementary security technologies like host anti-virus scanning and host firewalls are not in widespread use, nor are elementary security processes like host hardening and the use of strong passwords.

In contrast, operations personnel looking at the enterprise network connected to the control network see a source of attack that is not under control. Operations computers and networks tend to be under tight physical security and tight change management controls. 

In the end, both perspectives are aspects of the greater truth and both perspectives must be taken into account when securing control system assets.


A Different Line of Defense is Required

Corporate standards selected for enterprise networks do not meet the needs of control networks. Security can have a tendency to look at control systems as just another computer, but treating the two types of systems as equivalents can lead to unexpected and perhaps even catastrophic results. The truth of the matter is that the unique characteristics of operations networks and systems mean that many conventional enterprise security solutions not only don’t work on control networks, they may impair the operation of the system or stop it from operating completely. 
 
Case in point: Governance/Risk/Compliance inspired regulations focus first on confidentiality, then integrity and availability. Operations inspired standards focus on safety first, which means availability and integrity are critical. The biggest difference is that control systems are often directly connected to pipelines, electrical grids, water supplies and chemical plants. Undoubtedly, a security breach here can have severe consequences including loss of revenue, environmental damage, power outages and even loss of life. As a result, the imperative for security is seen as an aspect of the imperative for safety.

Clearly, security solutions that protect critical infrastructures need to be designed and optimized for control networks. Some of these unique requirements include:

• Recognition of the importance of perimeter protection and internal monitoring for safety critical systems that cannot tolerate after-market changes that focus on intrusion prevention;
• Recognition of unique network protocols so as not to cause unnecessary alerting;
• Configuration of control system intrusion sensors to detect the known, good traffic and alarm on anything else;
• Careful design in adding host intrusion detection sensors so that they consume minimal CPU and network bandwidth to avoid disrupting time-critical operations; and,
• Support for access control for remote devices such as PLCs, RTUs and distributed controllers.


Conclusion and Recommendations

As organizations increasingly merge their security systems to support business requirements, the responsibility for securing all of these important assets from cyber attack can converge as well. Companies can benefit from having an enterprise view across all security systems, but the products in the control world need to be optimized for the unique needs of this environment.

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Andrew Ginter is vice president of Industrial Security at Waterfall Security Solutions. He has managed the development of commercial products for computer networking, industrial control systems, control system to enterprise middleware, and industrial cyber security. Andrew is currently the co-chair of the ISA SP-99 WG1 working group and represents Waterfall Security Solutions to NIST, NERC-CIP and other ISA SP-99 working groups and other standards bodise. He frequently writes and speaks frequently on industrial control system cyber security topics. Andrew has degrees in Applied Mathematics and Computer Science from the University of Calgary, as well as ISP, ITCP and CISSP accreditations.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

Coding

What Security Leaders Say About the First AI-Developed Zero-Day Exploit

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • A Roadmap to the Next Generation

    See More
  • West

    Inspiring the next generation of cyber leaders

    See More
  • Defining the Next Generation of Security Services in the C-Suite's Language; security technology, security services

    Defining the Next Generation of Security Services in the C-Suite's Language

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • intelligent.jpg

    Intelligent Network Video: Understanding Modern Video Surveillance Systems, Second Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing