I assume water treatment plants are considered critical infrastructure and have regulations to prevent unauthorized access.
Either someone messed up, or there is a resourceful attacker.
Either someone messed up, or there is a resourceful attacker.
* Remote access to systems that could kill people must be limited to people with the following thought out permissions and secured credentials
And more:
* The list of people who can access this system must be documented
* The accounts must have their password be changed every 6 months
* A committee must review the set of outstanding patches and upgrades for known issues every 4 months and prioritize what to fix
* I hope that someone is actually installing those patches and upgrades.
Surely they'll be capable of configuring a corporate VPN without a fat budget to have Cisco do it for them...right?