467
CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet
(www.privacyguides.org)
This is a most excellent place for technology news and articles.
So are we just kind of admitting that there exists no way to expose any networked device to the internet securely? Because if it's not possible for PLCs I don't see why it would be possible for any device. If water utilities have to take these offline, then how does that advice not apply for every internet-capable device in every commercial and industrial facility worldwide?
There are ways, but they are costly and complicated and do not stop all attacks. So the golden rule is that if critical infrastructure doesn't need to connect to the internet, it shouldn't.