Why no-one gets SCADA security right

SCADA is an acronym for Supervisory Control and Data Acquisition.  That’s a bit of a mouthful and unless you’ve studied Engineering it’s not clear what it means, so here’s a simple definition: SCADA is computer controlled physical processes.  The common examples given are power stations and water treatment plants, but it’s much more than that.  Building management systems…

Decline of the PCI empire

The Payment Card Industry Data Security Standard – PCI DSS – is a standard with 255 controls that you must comply with if you store, process or transmit credit card information.  Complying with the standard is the cost of doing e-commerce today.  The cost is high, and going to get higher, and as with all monopoly empires…

Running with Scissors

There are things that we just shouldn’t do – like running with scissors.  We can be told not to do them.  We can know intellectually not to do them.  But until we’ve stabbed ourselves or someone else it just doesn’t sink in. I’ve been seeing a lot of discussion recently on attack as pro-active defence – especially related…

