
ST. LOUIS--(BUSINESS WIRE)--Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.
My research highlights the multiple challenges with patching for SCADA and ICS systems
Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.
Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:
The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.
The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.
Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.
Patches are available for less than 50% of publically disclosed vulnerabilities.
Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.
When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a compensating control'. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.
Another compensating control is Tofino Security Profiles, available in Belden's Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.
My research highlights the multiple challenges with patching for SCADA and ICS systems, remarked Eric Byres. To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.
Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:
Patching for Control System Security - A Broken Model?; a presentation that summarizes its patching research,
Patching for Control System Security - A Broken Model? a peer reviewed published paper,
and Solving the SCADA/ICS Security Patch Problem, a White Paper.
Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.
Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden's Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries. www.tofinosecurity.com
About Belden
St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.co
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
12/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
12/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
12/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
12/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
12/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
12/03/2026
COW Jobs: Editor de V deo - Direct Response, Performance Ads - Brazil, Remote
Brie Clayton March 11, 2026
0 Comments
Editor(a) de V deo (Direct Respon...
12/03/2026
Avatar: Fire and Ash Graded with DaVinci Resolve Studio
Brie Clayton March 11, 2026
0 Comments
Colorist delivers premium cinematic color across 2D, 3D...
12/03/2026
Boston Conservatory to Timoth e Chalamet: We Care About Ballet and Opera Boston Conservatory at Berklee students and faculty respond to the actors recent comm...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Matrox Video will showcase its vision for the future of live production at NAB 2026 in Las Vegas, April 19-22, highlighting how broadcasters and media organizat...
11/03/2026
Geneva-based technology company, GlobalM SA, is presenting its GMX Distributed Video Gateway, a software-defined IP media transport platform designed to replace...
11/03/2026
Backlight (booth #N2829), the company behind Iconik and Wildmoka, which power video workflows for large media and entertainment organizations, has released the ...
11/03/2026
QuickLink, a leading provider of award-winning video production and remote guest contribution solutions, presents its latest StudioEdge models at The NAB Show ...
11/03/2026
Telestream, a global leader in media workflow technologies, today announced the expansion of Telestream Cloud Services with the introduction of UP, a new cloud-...
11/03/2026
Operative, the preferred advertising management provider for the world's leading media brands, today announced the launch of AOS for digital media, an AI-po...
11/03/2026
Calrec will be located in Central Hall, on Booth C6907
Choice without compromise
The broadcast industry is going through a rapid evolution that s signalling a...
11/03/2026
The new service is hosted and operated entirely in the Netherlands, combining data sovereignty, resilience, scalability, and predictable costs without relying...
11/03/2026
Ease Live, an Evertz company and leader in interactive graphical overlays, today announced the successful deployment of its platform on Red Bull TV for Premier ...
11/03/2026
Mediagenix, a global leader in smart content solutions to profitably connect the right content to the right audience, is advancing its Semantic Intelligence cap...
11/03/2026
Emergent, a leading provider of AI-enhanced media production solutions, today announced the official launch of Fusion, a powerful, no-code application builder d...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/03/2026
Utah Scientific today announced the expansion of its Technology Partner Program with the addition of Audinate, Bitfocus, and Skaarhoj, three industry leaders wh...
11/03/2026
DigitalGlue, creator of the creative.space on-premise managed storage platform, today revealed plans to launch creative.space Intelligence (CSI) at NAB 2026 (Bo...
11/03/2026
Maxon, maker of powerful, approachable software solutions for creators working in 2D and 3D design, motion graphics, visual effects, gaming, and more, has annou...
11/03/2026
Composer and Re-recording Mixer Michael Phillips Keeley has built his career around immersive storytelling. Working from his Dolby Atmos-equipped studio, Sound ...
11/03/2026
Leading video software provider Synamedia today announced that YES, the pay-TV subsidiary of the telco Bezeq (TASE: BEZQ), has selected Synamedia Iris to delive...
11/03/2026
As media companies face increasing cost pressures and operational complexity, at the 2026 NAB Show in Las Vegas, Viaccess-Orca (VO), a global leader in OTT / TV...
11/03/2026
Digital Alert Systems, a global leader in emergency communications solutions for media providers, today announced the release of Version 6 software for its DASD...
11/03/2026
First Medium-Earth Orbit (MEO) deployment of the emergency.lu platform for refugees and their host communities' use provides dependable broadband for humani...
11/03/2026
Foundry releases Nuke 17.0
Brie Clayton March 1, 2026
0 Comments
Native Gaussian Splat support, new 3D system based on USD, expanded machine learning ca...
11/03/2026
Preserving UNESCO World Heritage with URSA Cine Immersive
Brie Clayton March 1, 2026
0 Comments
The Explorers turned to France's cultural landmark...
11/03/2026
I Clicked This By Accident And It Made After Effects SO Much Faster
Graham Quince March 1, 2026
0 Comments
Discover how Region of Interest in Adobe A...
11/03/2026
Cine Gear Connect Brings a Focused All-Day Experience to Industry City, NY
Brie Clayton March 4, 2026
0 Comments
Registration is now open for Cine Gea...
11/03/2026
La Vor gine Edited and Finished with DaVinci Resolve Studio
Brie Clayton March 4, 2026
0 Comments
One of Colombia's most ambitious projects goes g...
11/03/2026
SoundMarket Launches 18,000 Tracks of Real Music by Award-Winning Composers for...
11/03/2026
Capta Center Supports NOVO19 Remote Production with Blackmagic Design
Brie Clayton March 5, 2026
0 Comments
The facility provides production and playo...
11/03/2026
DigitalGlue Ends the Post-Production Tax: creative.space Intelligence (CSI) Unif...
11/03/2026
Kochi Sun Sun Uses Blackmagic Replay for High School Volleyball Finals
Brie Clayton March 9, 2026
0 Comments
Versatile Blackmagic Replay system proves...
11/03/2026
Richard Bona Joins Berklee for Signature Series Concert The Grammy-winning Cameroonian bassist and vocalist collaborates with students and faculty in a progra...
11/03/2026
Launched today, NVIDIA Nemotron 3 Super is a 120 billion parameter open model with 12 billion active parameters designed to run complex agentic AI systems at sc...