Efficient Plant Jan./Feb. 2024 - 28

column | cybersecurity insights
Security
Resides in
PLC Run
Mode
Steve Mustard, CEO,
National Automation Inc.
Marco Ayala, Global Director
ICS Security, 1898 & Co.
T
ODAY THERE'S A whole
industry dedicated to reducing
cybersecurity risk, including
standards, guidelines, frameworks, tools,
and subject-matter experts. Ultimately
the organization owns the risk and is best
placed to manage it.
ISA/IEC62443, the only consensus-based
international standard for
industrial-automation and control-systems
cybersecurity, is a comprehensive roadmap
for organizations to effectively manage their
industrial cybersecurity risk, but there is
no silver bullet. Like safety, cybersecurity
requires constant vigilance, especially when
it comes to seemingly trivial issues. ISA/
IEC62443 lays out a plan, but the success of
that plan is in the hands of the plantmanagement
team.
One of the simplest examples of this
Steve Mustard serves as the President
of National Automation Inc., Spring, TX
(au2mation.com), and served as the 2021
president of the International Society
of Automation (ISA, isa.org). Mustard
works with companies to improve their
performance through the identification
of process bottlenecks and the intelligent
introduction of technology to remove them.
Marco Ayala is the Director and ICS
cybersecurity section lead at 1898 & Co.
(part of Burns & McDonnell), Kansas City,
MO (1898andco.burnsmcd.com), and
the International Society of Automation
(ISA) Vice President for Automation
and Technology for 2023. He is active in
cybersecurity efforts for the oil and gas,
maritime port, offshore facilities, and
chemical sectors.
vigilance is the PLC or controller key
switch. This physical key can have different
modes depending on the manufacturer,
but there are at least two modes that are
common to such devices: Program and
Run. A third, Remote, is often present. In
Run mode, the PLC or controller cannot be
modified locally or remotely over the network.
In Program mode, the device can be
modified. Remote mode usually allows the
programmer to remotely change the status
of the device.
The ISA Global Cybersecurity Alliance,
which sponsors the PLC Security Top 20
List (plc-security.com/index.html), recommends
that operators, " keep the PLC in Run
mode. If PLCs are not in Run mode, there
should be an alarm to the operators. "
The key switch is the most effective
means of preventing unauthorized modification
of critical PLC or controller code.
Despite this, the key is routinely left in the
Program or Remote position because it
is convenient for the maintenance team.
The rationale for this approach is that it
eliminates productivity loss that results
from walking up to the device with the
key, changing position, walking back to the
workstation, making changes, and then
restoring the key position and removing
the key. While this is true, it overlooks the
potential loss of productivity involved in a
cybersecurity incident caused by unauthorized
modification of the PLC or controller.
There are more examples of productivity
savings creating cybersecurity vulnerabilities
to be found in a typical operational
environment. How confident are you that
your cybersecurity vulnerabilities are being
managed in a vigilant manner? EP
A typical example of a potential cybersecurity threat is a controller set in remote mode with a key left
in the lock during normal operation.
28 | EFFICIENTPLANTMAG.COM
JAN/FEB 2024
http://www.plc-security.com/index.html http://www.au2mation.com http://www.isa.org http://1898andco.burnsmcd.com http://www.EFFICIENTPLANTMAG.COM

Efficient Plant Jan./Feb. 2024

Table of Contents for the Digital Edition of Efficient Plant Jan./Feb. 2024

Efficient Plant Jan./Feb. 2024 - Cover1
Efficient Plant Jan./Feb. 2024 - Cover2
Efficient Plant Jan./Feb. 2024 - 1
Efficient Plant Jan./Feb. 2024 - 2
Efficient Plant Jan./Feb. 2024 - 3
Efficient Plant Jan./Feb. 2024 - 4
Efficient Plant Jan./Feb. 2024 - 5
Efficient Plant Jan./Feb. 2024 - 6
Efficient Plant Jan./Feb. 2024 - 7
Efficient Plant Jan./Feb. 2024 - 8
Efficient Plant Jan./Feb. 2024 - 9
Efficient Plant Jan./Feb. 2024 - 10
Efficient Plant Jan./Feb. 2024 - 11
Efficient Plant Jan./Feb. 2024 - 12
Efficient Plant Jan./Feb. 2024 - 13
Efficient Plant Jan./Feb. 2024 - 14
Efficient Plant Jan./Feb. 2024 - 15
Efficient Plant Jan./Feb. 2024 - 16
Efficient Plant Jan./Feb. 2024 - 17
Efficient Plant Jan./Feb. 2024 - 18
Efficient Plant Jan./Feb. 2024 - 19
Efficient Plant Jan./Feb. 2024 - 20
Efficient Plant Jan./Feb. 2024 - 21
Efficient Plant Jan./Feb. 2024 - 22
Efficient Plant Jan./Feb. 2024 - 23
Efficient Plant Jan./Feb. 2024 - 24
Efficient Plant Jan./Feb. 2024 - 25
Efficient Plant Jan./Feb. 2024 - 26
Efficient Plant Jan./Feb. 2024 - 27
Efficient Plant Jan./Feb. 2024 - 28
Efficient Plant Jan./Feb. 2024 - Cover3
Efficient Plant Jan./Feb. 2024 - Cover4
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-jan-feb-2024
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-april-2022
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-october-2021
https://www.nxtbook.com/atp/MaintenanceTechnology/efficient-plant-june-2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanfeb2021
https://www.nxtbook.com/atp/MaintenanceTechnology/epjulyaug2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epjune2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epfeb2020
https://www.nxtbook.com/atp/MaintenanceTechnology/epjan2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovdec2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epseptoct2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epfebruary2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanuary2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epdecember2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovember2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epoctober2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epseptember2019
https://www.nxtbook.com/atp/MaintenanceTechnology/epaugust2018
https://www.nxtbook.com/atp/MaintenanceTechnology/0818schneider
https://www.nxtbook.com/atp/MaintenanceTechnology/epjuly2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epjune2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epmay2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epapril2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epmarch2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epfebruary2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epjanuary2018
https://www.nxtbook.com/atp/MaintenanceTechnology/epdecember2017
https://www.nxtbook.com/atp/MaintenanceTechnology/epnovember2017
https://www.nxtbook.com/atp/MaintenanceTechnology/epoctober2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtsept2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtaugust2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjuly2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjune2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmay2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtapril2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmarch2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtfebruary2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjanuary2017
https://www.nxtbook.com/atp/MaintenanceTechnology/mtdecember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtnovember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtoctober2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtseptember2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtaugust2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjuly2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjune2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmay2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtapril2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtmarch2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtfebruary2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtjanuary2016
https://www.nxtbook.com/atp/MaintenanceTechnology/mtdecember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtnovember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtoctober2015
https://www.nxtbook.com/atp/MaintenanceTechnology/mtseptember2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTAugust2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJuly2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJune2015
https://www.nxtbook.com/atp/MaintenanceTechnology/M
https://www.nxtbook.com/atp/MaintenanceTechnology/0415endress
https://www.nxtbook.com/atp/MaintenanceTechnology/MTApril2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTMarch2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTFebruary2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJanuary2015
https://www.nxtbook.com/atp/MaintenanceTechnology/MTDecember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTNovember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTOctober2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTSeptember2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTAugust2014
https://www.nxtbook.com/atp/MaintenanceTechnology/MTJuly2014
https://www.nxtbookmedia.com