Hackers shut down plant by targeting its safety system
engadget.com
engadget.com
Damaging the plant equipment such that repair takes a long time. Depending on the control systems available, something like turning off coolant circulation, and running the engine at high load could cause problems quickly.
Running the equipment to provide out of spec output which could damage things outside the plant. Possibly transmission lines or other outside equipment or equipment at other plants. Maybe increasing output voltage could ruin outside equipment, and altering output frequency could cause problems with other plants that try to be in frequency lock.
These sorts of things could be much worse than an unscheduled outage; in many locations the local power grid spans many power plants and can absorb the loss of one plant, and if not, the local grid is probably fairly unreliable, and critical loads have local generation available.
https://en.wikipedia.org/wiki/Safety_instrumented_system
The only purpose of a SIS in a CPS (Cyber Physical System) is to take over and bring the plant/processes down safely when things go wrong but before they get out of control.So it seems it did its job here. The big question is how the malware got onto the engineering workstation to begin with. These are usually very segmented (firewalls, data diodes, etc.)
Maybe things shouldn't be able to be accessed from the internet...
Most modern industrial equipment has this sort of telemetry data collection. You don't hear about hacks very often. A lot of manufacturers seem to do a pretty good job of security (or of covering up hacks).
I did a project for an 'embedded' controller software house a long time ago and asked why they used Windows (which was just quite hackable at the time and I wouldn't use it today for critical operations but that might just be because it used to be so bad at a time when I mostly used Solaris which was unbreakable compared) and why it was connected to the internet; answer was obvious; software for Win was easier to outsource to far away countries (in NL you find great engineers but costly and you cannot fire them easily; this company traded quality to be able to do it cheap and be able to do it project basis) and networking because it's too expensive to go to the client and update the software manually. So it was just always connected. The first versions where directly on the internet, the latter versions via a gateway computer but it was both pretty easy to get into. Cannot imagine other reasons to have it open from the outside besides that? Just convenience of maintenance.
When a disaster happens.
Politics as usual, and it's not the politicians fault (who are mostly limited by the whims of public opinion), but that there won't be enough political momentum for action until there's a disaster. The fault, like most things in politics, is of human nature.
It's unnatural for large groups of people to be motivated to take serious preventive action against something that has never happened before and has been up to then only a theoretical concern for experts.
Security education and practices need to be taken more seriously by executives.