Magazine

FM College ~ News & Articles

Security Resides In PLC Run Mode

Mar 29, 2024 | Public | 0 comments

Today there’s a whole industry dedicated to reducing cybersecurity risk, including standards, guidelines, frameworks, tools, and subject-matter experts. Ultimately the organization owns the risk and is best placed to manage it.

ISA/IEC62443, the only consensus-based international standard for industrial-automation and control-systems cybersecurity, is a comprehensive roadmap for organizations to effectively manage their industrial cybersecurity risk, but there is no silver bullet. Like safety, cybersecurity requires constant vigilance, especially when it comes to seemingly trivial issues. ISA/IEC62443 lays out a plan, but the success of that plan is in the hands of the plant-management team.

One of the simplest examples of this vigilance is the PLC or controller key switch. This physical key can have different modes depending on the manufacturer, but there are at least two modes that are common to such devices: Program and Run. A third, Remote, is often present. In Run mode, the PLC or controller cannot be modified locally or remotely over the network. In Program mode, the device can be modified. Remote mode usually allows the programmer to remotely change the status of the device.

The ISA Global Cybersecurity Alliance, which sponsors the PLC Security Top 20 List (plc-security.com/index.html), recommends that operators, “keep the PLC in Run mode. If PLCs are not in Run mode, there should be an alarm to the operators.”

The key switch is the most effective means of preventing unauthorized modification of critical PLC or controller code. Despite this, the key is routinely left in the Program or Remote position because it is convenient for the maintenance team. The rationale for this approach is that it eliminates productivity loss that results from walking up to the device with the key, changing position, walking back to the workstation, making changes, and then restoring the key position and removing the key. While this is true, it overlooks the potential loss of productivity involved in a cybersecurity incident caused by unauthorized modification of the PLC or controller.

There are more examples of productivity savings creating cybersecurity vulnerabilities to be found in a typical operational environment. How confident are you that your cybersecurity vulnerabilities are being managed in a vigilant manner? 

EP Editorial Staff | February 27, 2024

By Steve Mustard, CEO, National Automation Inc. and Marco Ayala, Global Director ICS Security, 1898 & Co.

Steve Mustard serves as the President of National Automation Inc., Spring, TX (au2mation.com), and served as the 2021 president of the International Society of Automation (ISA, isa.org). Mustard works with companies to improve their performance through the identification of process bottlenecks and the intelligent introduction of technology to remove them.

Marco Ayala is the Director and ICS cybersecurity section lead at 1898 & Co. (part of Burns & McDonnell), Kansas City, MO (1898andco.burnsmcd.com), and the International Society of Automation (ISA) Vice President for Automation and Technology for 2023. He is active in cybersecurity efforts for the oil and gas, maritime port, offshore facilities, and chemical sectors.

The post "Security Resides In PLC Run Mode" appeared first on Efficient Plant

0 Comments

Submit a Comment

Practicing preventative maintenance

  An important part of building maintenance is creating a strategy to mitigate as many issues as you can ahead of...

New regional park coming to South Langley

  Metro Vancouver is creating a new regional park in south Langley, which will connect green spaces and continue the...

Improvements set for Thompson Regional Airport

  The federal government is providing $30 million to the Thompson Regional Airport for the construction of a new...

Overcoming the Challenges of Hotels and Dorms with Energy Management Thermostats

For hotels, dormitories, public housing, and assisted living facilities, balancing occupant comfort, energy, and...

Communication Proves to Be Essential Task During Design Phase

Projects go over more smoothly when people are transparent and communicating openly. Communication is such an essential...