Five years ago, I wrote about the lessons yet to be learned from Stuxnet[1] and have read a recent article by an industry opinion leader on the same theme. The author states several lessons which I think are worth discussing and ends the article by asking the reader what they would add to the list[2]. […]
What have we learned since Stuxnet – when it comes to control system cyber security not much
For SCADASec Fifteen years ago, I wrote the blog – “Malicious vs unintentional cyber incidents – why it is necessary to include unintentional incidents” This blog was written weeks before Stuxnet and its impact on control systems and centrifuge damage were made public. Stuxnet demonstrated that cyberattacks could be made to look like equipment malfunctions […]
NERC Sensors
The fallacy that the electric grid is cybersecure by meeting the NERC CIPs is finally being exposed. Situational awareness is based on process sensor input that is incorrectly assumed to be uncompromised, authenticated, and correct. Because process sensors use non-routable protocols, they have not been considered to be NERC Cyber Assets. Depending on the situation, […]
Network tabletop exercises don’t include engineering and plant operations
If engineering and operations are left out of cybersecurity training and exercises, it’s no surprise that they’d also tend to be overlooked during the pressure of an actual incident. The complexity in manufacturing and industrial control systems is not understood by network security. Simply restarting IT and OT networks from a “golden backup” is not […]
Does anyone tell the truth anymore?
The more important question that you might want to ask is: *who* should you trust for your information? The recent (so-called) malware attack at the Vermont electric utility on 30-Dec-2016 (Friday) demonstrates that, due to political agendas, that intelligence information may be manipulated. Throughout most of Friday, DHS (and its various departments) and FBI, hosted […]
What are the unlearned lessons from Stuxnet
July 22, 2025 the US House Committee on Homeland Security held a hearing, “Fully Operational Stuxnet 15 Years Later & the Evolution of Cyber Threats to Critical Infrastructure”. Stuxnet was not an attack on the networks. Rather, Stuxnet was a stealth attack that damaged physical infrastructures by manipulating physics. Stuxnet used networks as a conduit […]
There have been many publicly documented control system cyberattacks that caused physical damage
Sinclair Koelemij stated in his July 20, 2025 article the only documented control system cyberattack that directly caused physical damage was Stuxnet. He is not the only one who feels this way. However, there have been numerous cases in every sector where there have been publicly documented control system cyberattacks that caused physical damage. There […]
Why won’t NERC identify control system incidents as being cyber-related?
NERC publishes Lessons Learned documents to provide industry participants with technical and understandable information that helps them maintain the reliability of the bulk electric system. NERC has a history of not identifying control system incidents as being cyber-related. NERC issued two Lessons Learned documents in 2025: “Loss of Monitoring and Control Due to a Communication […]
Misguided response to the Norwegian Dam and Oldsmar “cyberattacks”
Not all control system cyber incidents are malicious cyberattacks. They can be accidents or errors, too. In their haste to find OT cyberattacks, the OT cybersecurity community, including regulators, continue to jump to conclusions about what are OT cyberattacks while at the same time ignoring incidents that don’t look like cyber incidents they are used […]
Sam Houston State University paper – “The Need for Interdisciplinary Programs for Control System Cybersecurity”
The Institute for Homeland Security at Sam Houston State University published my paper – “The Need for Interdisciplinary Programs for Control System Cybersecurity”. The paper can be found at Weiss.2025-1018. Operational Technology (OT) / Control Systems support the critical infrastructures of electric power in traditional and renewable energy systems, water, oil/gas, chemicals, manufacturing, pipelines, rail, […]
