<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ICS Security on Cutaway Security</title><link>https://www.cutawaysecurity.com/tags/ics-security/</link><description>Recent content in ICS Security on Cutaway Security</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Sat, 18 May 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://www.cutawaysecurity.com/tags/ics-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Architecting Safety Using Cybersecurity Requirements and Assessments</title><link>https://www.cutawaysecurity.com/blog/architecting-safety-using-cybersecurity-requirements-and-assessments/</link><pubDate>Sat, 18 May 2024 00:00:00 +0000</pubDate><guid>https://www.cutawaysecurity.com/blog/architecting-safety-using-cybersecurity-requirements-and-assessments/</guid><description>&lt;p>&lt;a href="https://nexusconnect.io/articles/architecting-safety-using-cybersecurity-requirements-and-assessments" target="_blank" rel="noreferrer">Originally posted&lt;/a> at Claroty NexusConnect on May 9, 2024&lt;/p>

&lt;h3 class="relative group">The Cybersecurity Safety Challenge
 &lt;div id="the-cybersecurity-safety-challenge" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-cybersecurity-safety-challenge" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h3>
&lt;p>I started thinking about the safety issues for security assessments when I was asked to attend a conference for amusement rides and parks. Safety has always been paramount in this industry and their teams are working hard to understand and improve how cybersecurity fits into the phases of a ride&amp;rsquo;s lifecycle.&lt;/p></description></item><item><title>Bashing Education and Certifications Reduces Safety of Industrial and Automation Control Environments</title><link>https://www.cutawaysecurity.com/blog/bashing-education-and-certifications-reduces-safety-of-industrial-and-automation-control-environments/</link><pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate><guid>https://www.cutawaysecurity.com/blog/bashing-education-and-certifications-reduces-safety-of-industrial-and-automation-control-environments/</guid><description>&lt;p>Recently, I have noticed people emphasizing the name of certifications and personally attacking the people who obtain them. This is unfortunate as it is shining light on the wrong subject. The value of a certification is not in the name. The value of the certification is that it is an indication that an individual has received a level of instruction and demonstrated the ability to retain, reference, and recall that information. It is this foundation of knowledge that the individual can be held accountable for using during decision making.&lt;/p></description></item><item><title>Managing Cyber Risk in Industrial, Automated Environments</title><link>https://www.cutawaysecurity.com/blog/managing-cyber-risk-in-industrial-automated-environments/</link><pubDate>Sun, 12 Mar 2023 00:00:00 +0000</pubDate><guid>https://www.cutawaysecurity.com/blog/managing-cyber-risk-in-industrial-automated-environments/</guid><description>&lt;p>Originally posted on the &lt;a href="https://nexusconnect.io/" target="_blank" rel="noreferrer">Claroty Nexus Community&lt;/a> as &amp;ldquo;&lt;a href="https://nexusconnect.io/articles/managing-cyber-risk-in-industrial-automated-environments" target="_blank" rel="noreferrer">Managing Cyber Risk in Industrial, Automated Environments&lt;/a>&amp;rdquo;  on February 23, 2023.&lt;/p>
&lt;p>Environments with industrial or automation control systems are built to ensure process availability and resilience. Availability is defined as &amp;ldquo;the quality of being able to be used or obtained&amp;rdquo; and resilience as &amp;ldquo;the capacity to recover quickly from difficulties; toughness.&amp;rdquo; These days, these definitions do not necessarily take into consideration the rampant connectivity happening today within automation environments.&lt;/p></description></item><item><title>Questions from SANS Pen Test Hackfest 2019</title><link>https://www.cutawaysecurity.com/blog/questions-from-sans-pen-test-hackfest-2019/</link><pubDate>Thu, 21 Nov 2019 00:00:00 +0000</pubDate><guid>https://www.cutawaysecurity.com/blog/questions-from-sans-pen-test-hackfest-2019/</guid><description>&lt;p>This week I had the pleasure of speaking twice at the &lt;a href="https://www.sans.org/event/pen-test-hackfest-2019" target="_blank" rel="noreferrer">SANS Pen Test Hackfest Summit 2019&lt;/a>. I had an excellent time and got to meet up with some old friends and make new acquittances. That is one of the most important things about these events. Attending pulls us from behind our virtual cubicles and gets us in front of human beings with common interests. It allows us to participate in conversations and, hopefully, have interactions where the communications include body language, facial expressions, and vocal inflections.&lt;/p></description></item></channel></rss>