Sony Pixel Power calrec Sony

Belden Research Shows at Patching for Industrial Cyber Security is a Broken Model

14/03/2013

ST. LOUIS--(BUSINESS WIRE)--Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.

My research highlights the multiple challenges with patching for SCADA and ICS systems

Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.

Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:

The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.

The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.

Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.

Patches are available for less than 50% of publically disclosed vulnerabilities.

Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.

When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a compensating control'. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.

Another compensating control is Tofino Security Profiles, available in Belden's Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.

My research highlights the multiple challenges with patching for SCADA and ICS systems, remarked Eric Byres. To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.

Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:

Patching for Control System Security - A Broken Model?; a presentation that summarizes its patching research,

Patching for Control System Security - A Broken Model? a peer reviewed published paper,

and Solving the SCADA/ICS Security Patch Problem, a White Paper.

Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.

Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden's Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries. www.tofinosecurity.com

About Belden

St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.co
LINK: http://us.vocuspr.com/Newsroom/ViewAttachment.aspx?SiteName=belden&Ent...
See more stories from belden

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

12/03/2026

Gray Stresses Importance of DRM for NextGen TV in FCC Sports Probe

Share Copy link Facebook X Linkedin Bluesky Email...

12/03/2026

Nebraska's HuskerVision Deploy Lawo IP Tech for Studio Upgrade

Share Copy link Facebook X Linkedin Bluesky Email...

12/03/2026

Comcast NBCU, Telemundo Station Group Announce $600,000 In Grants

Share Copy link Facebook X Linkedin Bluesky Email...

12/03/2026

EditShare To Highlight Analytical AI Capabilities At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

12/03/2026

FreeWheel Launches AI Agent Infrastructure

Share Copy link Facebook X Linkedin Bluesky Email...

12/03/2026

COW Jobs: Editor de Vdeo - Direct Response, Performance Ads - Brazil, Remote

COW Jobs: Editor de V deo - Direct Response, Performance Ads - Brazil, Remote Brie Clayton March 11, 2026 0 Comments Editor(a) de V deo (Direct Respon...

12/03/2026

Avatar: Fire and Ash Graded with DaVinci Resolve Studio

Avatar: Fire and Ash Graded with DaVinci Resolve Studio Brie Clayton March 11, 2026 0 Comments Colorist delivers premium cinematic color across 2D, 3D...

12/03/2026

Boston Conservatory to Timothe Chalamet: We Care About Ballet and Opera

Boston Conservatory to Timoth e Chalamet: We Care About Ballet and Opera Boston Conservatory at Berklee students and faculty respond to the actors recent comm...

11/03/2026

Calrec To Unlock Hybrid Workflows At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

Matrox Video Enables the Next Era of Software-Defined Med...

Matrox Video will showcase its vision for the future of live production at NAB 2026 in Las Vegas, April 19-22, highlighting how broadcasters and media organizat...

11/03/2026

GlobalM Showcases Distributed Video Gateway Architecture...

Geneva-based technology company, GlobalM SA, is presenting its GMX Distributed Video Gateway, a software-defined IP media transport platform designed to replace...

11/03/2026

Video is King - 2026 Iconik Media Stats Report Finds Vide...

Backlight (booth #N2829), the company behind Iconik and Wildmoka, which power video workflows for large media and entertainment organizations, has released the ...

11/03/2026

QuickLinks Latest StudioEdge Models to Make North America...

QuickLink, a leading provider of award-winning video production and remote guest contribution solutions, presents its latest StudioEdge models at The NAB Show ...

11/03/2026

Telestream Expands Its Cloud Services with the Introducti...

Telestream, a global leader in media workflow technologies, today announced the expansion of Telestream Cloud Services with the introduction of UP, a new cloud-...

11/03/2026

Operative Launches AOS Configuration for Digital-First Mo...

Operative, the preferred advertising management provider for the world's leading media brands, today announced the launch of AOS for digital media, an AI-po...

11/03/2026

Calrec Redefines Broadcast Workflows at NAB 2026

Calrec will be located in Central Hall, on Booth C6907 Choice without compromise The broadcast industry is going through a rapid evolution that s signalling a...

11/03/2026

Worldstream and Cubbit launch sovereign S3 cloud storage...

The new service is hosted and operated entirely in the Netherlands, combining data sovereignty, resilience, scalability, and predictable costs without relying...

11/03/2026

Ease Live powers interactive Premier Padel experiences on...

Ease Live, an Evertz company and leader in interactive graphical overlays, today announced the successful deployment of its platform on Red Bull TV for Premier ...

11/03/2026

Mediagenix Title Management Accelerates Content Monetizat...

Mediagenix, a global leader in smart content solutions to profitably connect the right content to the right audience, is advancing its Semantic Intelligence cap...

11/03/2026

Emergent Launches Fusion- The Interactive Anything Platfo...

Emergent, a leading provider of AI-enhanced media production solutions, today announced the official launch of Fusion, a powerful, no-code application builder d...

11/03/2026

Techex Names Matt McKee as Senior Director of Sales, Americas

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

IAB Tech Lab Announces Content Monetization Protocol for AI LLMs

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

Mondae Hott Joins Kokusai Denki as Northeast Sales Manager

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

Gray Media to Air Cincinnati Reds' Games on WXIX FOX19

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

Shure Audio Solutions Deliver Super Bowl Win

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

UK's First Live Broadcast Using New n40 Private 5G Spectrum

Share Copy link Facebook X Linkedin Bluesky Email...

11/03/2026

Utah Scientific Expands Technology Partner Program With I...

Utah Scientific today announced the expansion of its Technology Partner Program with the addition of Audinate, Bitfocus, and Skaarhoj, three industry leaders wh...

11/03/2026

DigitalGlue Ends the Post Production Tax creativespace In...

DigitalGlue, creator of the creative.space on-premise managed storage platform, today revealed plans to launch creative.space Intelligence (CSI) at NAB 2026 (Bo...

11/03/2026

Maxon and Tencent Cloud Partner to Integrate HY 3D into C...

Maxon, maker of powerful, approachable software solutions for creators working in 2D and 3D design, motion graphics, visual effects, gaming, and more, has annou...

11/03/2026

NUGEN Audio Halo Vision Plug In Serves as Spatial Compass...

Composer and Re-recording Mixer Michael Phillips Keeley has built his career around immersive storytelling. Working from his Dolby Atmos-equipped studio, Sound ...

11/03/2026

YES selects Synamedia Iris to power advanced advertising

Leading video software provider Synamedia today announced that YES, the pay-TV subsidiary of the telco Bezeq (TASE: BEZQ), has selected Synamedia Iris to delive...

11/03/2026

Cost Savings Scalability and Smarter Monetization Viacces...

As media companies face increasing cost pressures and operational complexity, at the 2026 NAB Show in Las Vegas, Viaccess-Orca (VO), a global leader in OTT / TV...

11/03/2026

Digital Alert Systems Unveils Version 6 Software for DASD...

Digital Alert Systems, a global leader in emergency communications solutions for media providers, today announced the release of Version 6 software for its DASD...

11/03/2026

SES Brings Satellite Connectivity to Refugees in Chad

First Medium-Earth Orbit (MEO) deployment of the emergency.lu platform for refugees and their host communities' use provides dependable broadband for humani...

11/03/2026

Foundry releases Nuke 17.0

Foundry releases Nuke 17.0 Brie Clayton March 1, 2026 0 Comments Native Gaussian Splat support, new 3D system based on USD, expanded machine learning ca...

11/03/2026

Preserving UNESCO World Heritage with URSA Cine Immersive

Preserving UNESCO World Heritage with URSA Cine Immersive Brie Clayton March 1, 2026 0 Comments The Explorers turned to France's cultural landmark...

11/03/2026

I Clicked This By Accident And It Made After Effects SO Much Faster

I Clicked This By Accident And It Made After Effects SO Much Faster Graham Quince March 1, 2026 0 Comments Discover how Region of Interest in Adobe A...

11/03/2026

Cine Gear Connect Brings a Focused All-Day Experience to Industry City, NY

Cine Gear Connect Brings a Focused All-Day Experience to Industry City, NY Brie Clayton March 4, 2026 0 Comments Registration is now open for Cine Gea...

11/03/2026

La Vorgine Edited and Finished with DaVinci Resolve Studio

La Vor gine Edited and Finished with DaVinci Resolve Studio Brie Clayton March 4, 2026 0 Comments One of Colombia's most ambitious projects goes g...

11/03/2026

SoundMarket Launches 18,000+ Tracks of Real Music by Award-Winning Composers for Editors and Post Professionals

SoundMarket Launches 18,000 Tracks of Real Music by Award-Winning Composers for...

11/03/2026

Capta Center Supports NOVO19 Remote Production with Blackmagic Design

Capta Center Supports NOVO19 Remote Production with Blackmagic Design Brie Clayton March 5, 2026 0 Comments The facility provides production and playo...

11/03/2026

DigitalGlue Ends the Post-Production Tax: creative.space Intelligence (CSI) Unifies On-Premise Storage with Forensic AI at NAB 2026

DigitalGlue Ends the Post-Production Tax: creative.space Intelligence (CSI) Unif...

11/03/2026

Kochi Sun Sun Uses Blackmagic Replay for High School Volleyball Finals

Kochi Sun Sun Uses Blackmagic Replay for High School Volleyball Finals Brie Clayton March 9, 2026 0 Comments Versatile Blackmagic Replay system proves...

11/03/2026

Richard Bona Joins Berklee for Signature Series Concert

Richard Bona Joins Berklee for Signature Series Concert The Grammy-winning Cameroonian bassist and vocalist collaborates with students and faculty in a progra...

11/03/2026

New NVIDIA Nemotron 3 Super Delivers 5x Higher Throughput for Agentic AI

Launched today, NVIDIA Nemotron 3 Super is a 120 billion parameter open model with 12 billion active parameters designed to run complex agentic AI systems at sc...