Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Monday, August 17, 2026

IEC 61850 for Newbees - Traffic Engineering with IEC 61850-6 (SCL)

I agree: The standard series IEC 61850 is quite comprehensive ... some believe it is complex. Ok. What can I do to help you getting a better understanding? I will try to help you. 

Today I will show how IEC 61850-6 (SCL, System Configuration Language) can be used for traffic engineering - traffic means: "signals" are communicated back an forth: analogue measurements, status measurements, control, configuration, event-driven reports, event-driven logs, ... start and stop of event recorder, trip-signals, ... in IEC 61850 "signals" are named and a binding of an instance to the application process (e.g., Bay1 Circuit Breaker 2) is specified ...

I am using a brief prose language ... this description could be transformed to an SCL compliant (machine processable ) XML file.

The many "signals" are travelling from a source to a destination ... let's say the following valid (allowed) routes are:

  1. A->B,
  2. B->A,
  3. V->A,
  4. A->C, 
  5. D->E, 
  6. R->S, 
  7. R->A

Each letter is representing a source or destination of the "signal" flow. The "->" is representing one of the specific "signals" standardized in IEC 61850. In the first route A sends an operate to B and B is reporting back to A a changed status information ...

In SCL we can configure now for each route in detail the sources, destinations, strongly typed "signals", communication services, ... The SCL compliant System Configuration Description (SCD) would list all details on all routes ... 

The source knows by the SCD document which "signal" is to be sent (when and how) to which destination. The destination knows by the SCD document which "signal" it receives (from which device, when and how).

What else can we do with the SCD file?

  1. A tool could check if all source and destination (devices) are specified ... a source A is configured to send a signal to B ... Is B at all specified? Maybe it was forgotten.
  2. A tool could check if for all source and destination devices the addresses are configured
  3. Another tool could check if all traveling "signals" (messages) are specified in the SCD document. A "signal" that travels during online operation from X to B (here X tries to connect to B) is not specified and thus NOT ALOWED. The tool could rase the red flag telling the system engineer that an unknown device X is active on the network. 
  4. ... many other possibilities are listed in the following figures from my seminar slides (some 10+) years old.


I hope you got an impression what IEC 61850-6 (SCL) could provide.
SCL is the backbone of IEC 61850!
Check HERE for a crucial use-case for SCL (cyber security ...).
Let me know if you have a question on this post.

Thursday, March 19, 2026

OT Security - Kongressbeiträge "Security unter Kontrolle" jetzt Online

Zweitägiger Kongress öffnet die "Tore" ... alle Vorträge online!!

SECURITY UNTER KONTROLLE ist der dialog- und praxisorientierte Kongress für alle, die sich mit Security in der Industrie beschäftigen. Security? Bekommen wir unter Kontrolle!

Um Security für Automatisierungstechnik müssten Sie sich mal kümmern – wenn Sie bloß wüssten, wie genau? Das ist das Ziel von SECURITY UNTER KONTROLLE. Automatisierer, Ingenieure und Praktiker befähigen, Security selbst in die Hand zu nehmen.  

Das in die "Hand nehmen" ist leicht gesagt ... es ist zu hoffen, dass das Management in den Firmen die Mitarbeiter unterstützen, dass sich die Leute darum kümmern können!

Ich hoffe, dass die vielen Minuten Videomaterial so aufbereitet werden, dass sich die wesentlichen Aussagen und Erfahrungen in vielleicht einer Stunde in einem "kondensierten" Video kostenfrei erleben lassen.

Viele Erfolg!

Monday, December 15, 2025

NEW version of the Famous Whitepaper Requirements for Secure Control and Telecommunication Systems

The Austrian, German, and Swiss Utilities have published (with the support of Dr. Stephan Beirer and Marl Joos (GAI NetConsult GmbH, Berlin/Germany)) the Version 3.0 of the famous 

Whitepaper Requirements for Secure Control and Telecommunication Systems

The English version (pdf, 88 pages) could be downloaded HERE.

Die deutsche Version (pdf, 92 Seiten) kann HIER heruntergeladen werden.

It is highly recommended to read, understand, and implement the recommendations! They reflect the latest experiences and need in our highly interconnected electric power world!

Today I will focus on two issues: the first is discussed in the Whitepaper, the second is discussed in a paper from AXPRO in Switzerland.

The Whitepaper says on page 46 (bzw Seite 47 in der deutschen Version):

"In line with the given technical capabilities, standardised IEC protocols should be used across the board. The private range of these communication protocols should only be used where necessary for technological reasons. Without additional measures, the standard protocols IEC 60870-5-101/104 and IEC 61850 offer no secure integrity protection, authentication or encryption. In such cases, the available extensions according to IEC 62351 should be used. Potential limitations, e.g. in terms of performance and error diagnostics as well as the necessary key management infrastructure and processes should be considered.

For communication across zone boundaries, protocol breaks should be provided, e.g. through application layer gateways or by converting to a different protocol, to reduce potential vulnerabilities and weak points."

I fully agree with this last sentence. This brings me to the second issue: 

The Swiss utility AXPRO published a great paper with the title: OT-Security im Unterwerk  ... means in substations ... the paper is in English. You can download it HERE.

On page 3 you can find this:

Geräte diversifizieren

"Die klassischen Ansätze der Literatur geben einen Überblick über Lösungen. Dies beginnt bei gängigen Konzepten zur Ersatzteilhaltung und setzt sich bei der technischen Redundanz von Komponenten fort. Die zusätzlichen Komponenten halten den Betrieb bei einem Ausfall aufrecht – zumindest einen Minimalbetrieb. Die eingesetzten Geräte und Systeme können zudem mit unter-schiedlichen Komponenten diversifiziert werden, beispielsweise durch Geräte unterschiedlicher Hersteller, Gerätefamilien mit signifikanten Unterschieden sowie Kommunikationsvarianten. Eine einzelne Schwachstelle kann somit nie die Funktion des Gesamtsystems gefährden. Die Diversität stellt eine Hürde dar, die ein Angreifer überwinden muss. Allerdings muss auch beachtet und akzeptiert werden, dass durch eine grössere Diversität ein Mehraufwand für den Betrieb und somit zusätzliche Kosten entstehen."

They are obviously following the recommendation of the Whitepaper!! Thanks. The statement in the last sentence is important to understand: The implementation and application of many security measures needs peopleware and reasonable budgets!

I have discussed peopleware many times for years ... it seems to be more important than ever ... see also my latest discussion on people ...

Be aware: The most secure communication is the one that is not implemented or implemented but not in use!



Wednesday, October 22, 2025

IEC 61850 Is The Corner Stone Of Manageable Secure Power Systems

On September 16, 2025 I presented a Keynote Address at the 6th PS2 organized by Omicron.

Click HERE for accessing my slides [PDF, 9 MB] 


The crucial slide is on page 25:

The keynote discusses the challenge: Informatics versus electrical engineering. My understanding is that we need every expertise: concrete builder, electricians, metal ... copper ... electrical ... mechanical ... IT, OT, protection, automation, ... cyber security ... and so on. A holistic approach is needed.
Do not expect that one is the superior product ... or most crucial person ... 
Teamwork makes the dream work.
Check out how we could help.


Saturday, August 30, 2025

IEC 61850 in Cyber Secure Environments - New Comprehensive Seminar

Due to my family situation (nursing my beloved wife from 2017 to 2022) I had to slow down my training activities. This year I was asked by several senior experts if it would be possible to resume the training.

As a result of discussions with friends of mine, we updated our previous course program and offer a brand new 5-day comprehensive public seminar for Automation, Protection, Monitoring, Engineering, Configuration (SCL), SCADA, Smart Grids, RTU, Gateways, … cyber physical security in electrical systems of any industrial plant … it is available for you and your people.

The reason for the update: We want to do more than teaching the theory of IEC 6850 and demonstrate single IEDs … we want to let our practice talk for your practice. The new training will start in March 2026. Taking the experience with many crucial applications of IEC 61850 into account we offer a new program for a 5-day course conducted by four (4) real experts.

09.-13. March 2026, Karlsruhe (Germany)
21.-25. September 2026, Karlsruhe (Germany)

Click HERE for more details on dates, location, and registration information.

Friday, January 24, 2025

Are LTE And 5G Cell Phone Systems Secure?

Are you expecting that every communication system has one or the other issue with security? You are right! What's about LTE and 5G? Here is what researchers have found:

Check out the following:

RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations
By Ravie Lakshmanan

Excerpt: "A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even gain a foothold into the cellular core network. ..."

Click HERE and HERE for additional information.

LTE and 5G are used for power systems all over ... just google for iec 61850 lte 3g ... you will be surprised ;-)

Click HERE to follow some discussion on remote monitoring and control ... if ever possible minimize the use of communication ... 

Thursday, January 9, 2025

Why Do We Need IEC 61850 (SCL) Based System Configuration Descriptions?

IEC 61850 has been developed in the late 1990's mainly by protocol experts and protection engineers - results are well done and applied all-over. Later IEC 61850-6 (SCL - Substation System Configuration Language) was in the focus. Now, 30 years later the industry has learned that the System Configuration Description goes far beyond information models and communication networks and services - AND PROTOCOLS. The crucial aspect is about a COMPLETE description of the WHOLE system ... from device independent descriptions of Functions and Function Models applying a Top-Down-Modeling-Approach. Work towards this approach is going on in several projects, e.g., IEC 61850-90-30 (IEC 61850 90-30 – IEC 61850 Function Modeling in SCL). A nice description from Jörg Reuter (Helinks) can be found HERE from the pacworld magazine. IEC 61850 based aspects is - of course - just one (crucial) aspect of a system. There are more aspects ... like Hardware, Software, Cybersecurity, Operation, ...

In addition to getting a complete system specification based on SCL to get a running IEC 61850 based system that does the job you want to have ... there is another crucial aspect: Engineers may be happy to use a complete SCD file to configure everything and then forget the SCD file ... don't forget it BUT keep it up-to-date and NEVER EVER make any change in the system without updating the SCL based System Description! 

You may need the complete and updated SCD file to help you "protecting" yourself in case there is a damage or an accident ... when "a fleet of well dressed lawyers who will use the lack of that document to make you all look guilty after ..." may arrive immediately after ... as Jake Brodsky (a well known engineer) just published in an article about "Industrial Cybersecurity “Gatekeeping”" ... worth to read.

Here is one excerpt from his article: "Take the time to find out where the important documents are such as the Standard Operating Procedures, the chemical Safety Data Sheets, and especially the Control System Narrative documents are located. If you can’t find the control system narrative documents, stop. Get someone to agree to write them with you. This is effectively your contract with the engineers, technicians, and operators that indicates in plain language what is supposed to happen normally and in most upset conditions. If you’re operating without that living document you will all be fodder for a fleet of well dressed lawyers who will use the lack of that document to make you all look guilty after an accident."

What could be done to get and maintain such complete descriptions of various aspects of a system? Do we need more lawyers, politicians, engineers, ... ? 

I am kidding (just a bit): "Hire a lawyer to escort you when you have an interview for a new position as a responsible engineer in a utility or ... in order to figure out (by the right questions of the lawyer) that the company applies with what Jake Brodsky recommends!"

What we really need is more engineers ... gray-hair experts that know a lot about the systems ... that could write down what the systems do and how they work ... and that could train the young people ... BUT: it isn't easy to convince the management to let the engineers learn from the experienced, gray-hair experts ... gray-hair engineers could lead the horses to the water - but they cannot make to drink it. 

What do you think? Let me know!

Thursday, October 3, 2024

Aktuell: Version 3.0 des Whitepapers "Anforderungen an sichere Steuerungs- und Telekommunikationssysteme"

"Der BDEW (Bundesverband der Energie- und Wasserwirtschaft) und seine österreichischen und schweizer Schwesterverbände (OE Oesterreichs Energie und VSE Verband Schweizerischer Elektrizitätsunternehmen) haben am 30.09.2024 eine vollständig überarbeitete Version 3.0 des Whitepapers "Anforderungen an sichere Steuerungs- und Telekommunikationssysteme" veröffentlicht. Das BDEW/OE/VSE-Whitepaper definiert grundlegende Sicherheitsanforderungen an Leit- und Automatisierungstechniksysteme der Energieversorgung und die zugehörige Nachrichten- und Telekommunikationstechnik."

Hier klicken, um zum Whitepaper zu gelangen.

Das Whitepaper ist ein gelungenes Anforderungspapier, das unbedingt beachtet werden sollte! Allerdings ist der Erfüllungsaufwand sehr hoch ... aber auch lohnend zu spendieren. 

Ich wünsche allen Beteiligten viel Erfolg!!

Monday, February 5, 2024

Cyber Security: Power Outages Caused by Animals

I just came about the following website that reports many serious "attacks" on the electric power grids:

https://www.cybersquirrel1.com/

It seems that animals are more serious "attackers" of the power grid than hackers ...

Fortunately researchers are "looking" beyond animals ... to humans ... 

Click HERE for information about a crucial R&D project at KIT (Karlsruhe Institute of Technology): "Weak point analysis in energy system protocols"

Wednesday, November 29, 2023

Default Passwords May Cause Some Issues - Change Them As Soon As Possible

 A friend of mine reported the following in a SCADA and cyber-security related group:

"The recent cyber-attack on that small water facility outside of Pittsburg is getting increased attention (certainly on this list) . The model and manufacturer of the device in question are known.  The manufacturer's web site has some  documentation on the device, but I do not think they provide the  device's default password.

No need to look hard, it is listed in plain site on CISA's bulletin (below)."

Exploitation of Unitronics PLCs used in Water and Wastewater Systems Release Date November 28, 2023 

Oops.

Sunday, September 24, 2023

Are IEC 61850 based Systems Cyber-Secure?

Often you hear arguments that IEC 61850 based systems are not cyber-secure ... is that true?

The truth is: The standards series IEC 61850 refers to the standard series IEC 62351. Example:

Power Systems Management and Associated Information Exchange – Communication network and system security – Part 4: Profiles including MMS and derivatives

IEC 61850-8-1 (Mapping to MMS) requires to use TLS ... as defined in IEC 62351-6 !!

Click HERE to access the preview of IEC 61850-8-1 (referring to IEC 62351) and HERE for the preview of IEC 62351-6.

Another issue to protect your IEC 61850 based system is to monitor the traffic and compare it with the configured communication relations and contents:

Click HERE to watch a brief video from Omicron that shows some means to support cyber-security in IEC 61850 based systems. 

There is a lot of activities going on to increase the cyber-security in automation systems.

Wednesday, August 24, 2022

ISA99 - New Working Group "Electric Energy OT Security Profile"

"The U.S. Department of Energy (DOE), global equipment suppliers, and other stakeholders announced the establishment of the Electric Energy OT Security Profile working group hosted by the International Society of Automation ISA99 standards committee.

The Electric Energy OT Security Profile will be a cybersecurity work product utilizing the ISA/IEC 62443 series of standards. The final product will be a formal ISA/IEC 62443 application guide, recognized globally as the consensus work product for securing various control systems used in electric energy generation, transmission, and distribution operations.

...

The ISA Electric Energy OT Security Profile working group is seeking participation from industry groups, including the Institute of Electrical and Electronics Engineers (IEEE), the International Electrotechnical Commission (IEC), the International Council on Large Electric Systems (CIGRE), and other industry stakeholders to ensure consideration of and alignment with other cybersecurity work product development efforts. ... "

Click HERE for the press release.

Thursday, January 20, 2022

How To Bring Plant Engineers To The Table When Cyber Issues Are Discussed?

In my career as electrical and IT engineer I have experienced that engineers are quite often not invited to discuss the measures and plans for critical infrastructure protection with IT personnel.

It is completely different compared to the world of electric power system protection - I mean the applications of protection relays. Protection engineers are (in my understanding) the most crucial engineers. They are very important for the reliable delivery of electric power. Protection engineers are likely to attend any meeting when it comes to the reliability of the power flows. Protection engineers know what to do ... software people may help to implement the "what" and the IT personnel may help to solve the communication issues ... but the crucial parts are dominated by protection engineers!

Mr. Vytautas Butrimas, a globally well known engineer involved in cyber security of control systems has briefly discussed the "Berlin wall" between IT personnel and plant engineers.  

Click HERE for the four page paper written by Mr. Butrimas.

Either of the groups involved believes that his or her group is the center of universe. There is little communication between the IT personnel and the engineers. 

There are so many semipermeable walls between, e.g., politicians, company lawyers, economists, IT experts, and plant engineers. There is usually no way that experts from any layer are allowed to talk to the experts from the other layers. In the end: Each layer feels independent of the other layers ... which leads to what we see these days ... and may be even more in the future. Have you heard of a discussion between a power protection engineer and a lawyer or even a medical doctor?

It would help medical doctors to understand the basics of electric power system reliability ... and so on. Because medical doctors (and all other people of a society) depend 100% on available power.

So in the end: (Electrical) Engineers should be honored by the society ... the problem may be that the engineers are not wearing white coats but wear safety boots, safety helmets, goggles,  protective gloves, ... a single doctor may harm a few people ... a protection engineer may harm millions of people during a blackout caused by a misconfiguration of protection equipment.

Monday, November 8, 2021

Critical Infrastructure Ransomware Dataset V 11.6 Available For Download

 Aunshul Rege announced the latest Critical Infrastructure Ransomware Dataset (Friday Nov 05, 2021):

"Dear all,

I hope everyone is doing well.

My team and I have updated our dataset of critical infrastructures ransomware incidents (CIRW) that have been publicly disclosed in the media or security reports. CIRW dataset version 11.6 now has 1066 incidents, which are assembled from publicly disclosed incidents between November 2013 and October end 2021. 

Also, community members can now submit a CIRW that you would like to see included into this dataset!

To download the dataset or submit a CIRW incident, please visit https://sites.temple.edu/care/ci-rw-attacks/. Please ensure that you enter your email address correctly, and note that we do not reply to personal email addresses (protonmail, gmail, etc.). And please give us a few days to respond to your request."

The Report "IT-Security-Situation-in-Germany-2020" describes three German ransomware cases:
  1. Ransomware Attack on the Council Offices of a Mid-sized German City
  2. Ransomware in Hospitals
  3. Ransomware Attack on a University
Click HERE to access the Report [PDF, 1.72 MB] ... worth to read.

Friday, November 5, 2021

Siemens SIPROTEC 5 Relays With Various CPU Variants Have Security Issues

Please note the following information made public by US-Cert_CISA ... in case you use SIPROTEC 5 Relays:

EXECUTIVE SUMMARY

CVSS v3 9.8

ATTENTION: Exploitable remotely/low attack complexity

Vendor: Siemens

Equipment: SIPROTEC 5 relays

Vulnerabilities: Classic Buffer Overflow

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or trigger a remote code execution.

Click HERE for the complete just updated report.

Thursday, June 17, 2021

The Top 20 PLC tips and practices for better, more secure PLC programming

Jake Brodsky wrote the other day:

"Among the tribes of engineers, there are certain things we just have to learn by doing. One of them is PLC programming. Somehow, we engineers are expected to emerge from college knowing good practices for programming a PLC. Some of us older engineers learned to program using FORTRAN. If we were lucky, we learned about structured programming. The millennial engineers may have had the benefit of learning about object oriented programming. Maybe it was a class in C++. But data structures were something that they were just “supposed to know.” And engineering educations today? If we’re lucky, they’ll see a course in how to sling code in Python. That’s what my son did when he was studying in a pre-engineering course.

My point is that most engineers discover good programming practices the hard way. We learn on the job. I stumbled across this many years ago. I started collecting tips, tricks, and experiences from my colleagues ..."

Check out his collected writings - worth to read:

The Top 20 PLC tips and practices for better, more secure PLC programming are now online:

Click HERE for the website.

Monday, February 15, 2021

IEC 61850 To Help Securing Process Automation Systems

A Hacker Tried to Poison a Florida City's Water Supply ... the attacker upped sodium hydroxide levels in the Oldsmar, Florida, water supply to extremely dangerous levels ... Within seconds, the intruder was attempting to change the water supply's levels of sodium hydroxide, also known as lye or caustic soda, moving the setting from 100 parts per million to 11,100 parts per million

Click HERE for a news report.

How could that happen? Who knows!

There are a lot of discussions complaining about missing security measures like VPN, etc.

Independent of the communication security it is a big mistake that the value could be set to such a BIG number: 11,100 ppm.

IEC 61850 could help to prevent such a situation by applying Analogue Setting model:














At the City of Oldsmar water treatment facility, the "maxVal" of Sodium Hydroxide injection may have been limited to 500 ppm ... as a consequence, there would be no way to configure this to 11,000 ppm.

And: in case somebody changed the value at all, the setMag would change and dchg would become true issuing a report or log entry ...

With the SCL (System Configuration Language, IEC 61850) it could also be configured (in SCL notation) that a particular configuration value could not be changed at all (Fix), changed by a service (Dyn), or changed by SCL only (Conf).

For Input signals there are many specific configuration attributes defined ... 

It is very difficult to convince programmers, managers, R&D people, any other group ... to apply the IEC 61850 Tool.

Hope that will slowly change ... 

Additional discussion by Jake Brodsky click HERE ... summarizing: "... The more self integrity features we include, the more reasonable process limits that we include, the safer we will be."


Monday, November 9, 2020

Hybrid Warfare Against Critical Energy Infrastructure: The Case Of Ukraine

A new 175 pages report
"Hybrid warfare against Critical Energy Infrastructure: The Case of Ukraine"
has just been published.

This study identifies and analyses the success of different hybrid warfare tools used by Russia in the Ukrainian energy sector between 2014 and 2017, namely different types of malicious acts against critical energy infrastructure, the implication of these events for Ukraine and the lessons to be learned for NATO security.

Click HERE for the full report [pdf, 6 MB]

Sunday, November 1, 2020

Ukrainian Power Grids Cyberattack - A Forensic Analysis Based On ISA/IEC 62443

Three Ukrainian power distribution companies sustained a cyberattack in western Ukraine on 23 December 2015. As the forensic information is extensive from a technical point of view, it is an opportunity to put 

ISA/IEC 62443-3-3
In­dus­tri­al com­mu­ni­ca­ti­on net­works - Net­work and sys­tem se­cu­ri­ty
- Part 3-3: Sys­tem se­cu­ri­ty re­qui­re­ments and se­cu­ri­ty le­vels

to the test with a real-life example. Several sources were used for this purpose that, overall, provide unusually detailed information.

Click HERE for the report "Ukrainian Power Grids Cyberattack - A Forensic Analysis Based On ISA/IEC 62443" ... worth to read!

Click HERE for a white paper on the series IEC 62443

Click HERE for a preview of the standard:




Monday, July 20, 2020

PhD Student Working On Cyber Security In Critical Infrastructures

Fredrik Heiding (PhD Student) wrote the other day:

Fredrik Heiding, PhD StudentNetwork and Systems Engineering
KTH, Royal Institute of Technology

I am doing a PhD on cyber security in critical infrastructure. Currently I study the security trends for critical infrastructures in Europe, analyzing where it is heading and how it is developing. To strengthen the study I have identified seven general questions, they are general in nature so they can be answered by people in critical positions without revealing sensitive information.
Here are the Questions from Fredrik and Answers from a very senior expert:
Cybersecurity consulting
See also: http://blog.nettedautomation.com/2020/06/scada-security-matters-should-matter.html
Vytautas Butrimas wrote in the introduction to his answers:
This a particularly interesting time in CIP. I come from and IT background and have focused mostly on the cybersecurity of industrial control systems in the past 10 years. This has been a long learning curve for I found that my IT knowledge did not provide enough to understand the engineering and laws of physics that are dominant in the monitor and control of physical processes found in the pumps and compressors on fuel pipelines, treatment of drinking water, routing of trains, and the generation and distribution of electricity. One needs to know the implications and peculiarities between working IT office time and real time to work in this field.
I looked at your questions and will give brief answers.  If you wish to further discuss them with me then we can do so offline.
---------------------------------
Question 1:
What concerns for the future do you have regarding cyber security in critical infrastructure?

Answer 1:
How the introduction of increased complexity of systems (systems of systems, adding more sensors, increased connectivity) will be managed without taking away from safety, reliability and performance.

Question 2:
Over the past decade, digital attacks have become more central to the security of critical infrastructure. Do you think the trend will continue to increase or culminate?

Answer 2:
There are some signs that things will get better but at the same time they will get more complicated.  Security practitioners need to realize that much more attention is needed where the physical process is taking place and the devices closest to it that are monitoring and controlling it, not where they are being monitored by humans in a remote location or control room.  ** One more thing we should not just be focused  on „ATTACKS“.  We also have to consider unintended actions or accidents. As the complexity of systems and connectivity of devices increases so will the unintended or „why did that happen?“ incidents.***

Question 3:
What relevant research or technological advances do you find most interesting for the future?

Answer 3:
Have to think about this one.  It feels we are all trying to keep afloat in a tsunami of technological advances.  The ones that worry me the most are the new features which also come with vulnerabilities that need to be addressed before a malicious group decides to exploit them.

Question 4:
Do you see IIoT (Industrial Internet of Things) as an opportunity or a concern, if both, which part is greatest (positive or negative)?

Answer 4:
I see it mostly as a concern (see my earlier answers). I suggest watching a video available on youtube called "Brave New Internet 4.0 " by one of your famous countrymen, Ralph Langner.  The questions and concerns he raised in that lecture IMHO have not been addressed.

Question 5:
Do you have plans to, or do you think that you will expand the cyber security department in the coming years?

Answer 5:
I am currently working my out of "mandatory retirement" and am not in position in expand anything (perhaps later this year I will change my answer).  If I was in a position of influence at an operator of CI (energy sector for example) I would do my best to set up some support for the senior engineer of the plant.  When he sees something unusual going in the operation he should be able assign this problem to an security operation center. Could be at least one person or a small team that understands cyber threats and how they could be applied to the engineering side of the operation.  The senior plant engineer has to keep things running and does not have time to stop and investigate something.  He needs someone to help him and a ICS SOC could be a good solution is management is willing to spend the money for the positions and training.

Question 6:
Can you share anything about past attacks/intrusion attempts, both successful and unsuccessful attempts are interesting?

Answer 6:
Look at the freely available information on line. Look up Ralph Langer to learn about STUXNET. It happened 10 years ago and this is probably the most analyzed and documented incident we have today that is publicaly  available.  Much can still be learned for the methods continued to be applied today. In 2014 in Germany your government (BSI) published its yearly report on cyber incidents.  There is a section devoted to a cyber attack on a steel mill that had an uncontrolled shutdown and resulted in damage. Look at Triton/Trisis/Hatman incident of 2017 where the safety systems of a petrochemical plant tripped not one but twice. Look for video lectures on this from Dale Pedersons S4 conferences in 2018/2019 (see lecture by Julian Gustmanis and by Schneider Electric)

Question 7:
Has the attitude towards cyber security changed in the last 5 years, why and in which way/

Answer 7:
The attitude is changing and for the better. Much better in the engineering community who have  understood how threats from cyberspace can get into their operations. On the other hand as far as government policy makers go they still have a long way to go. Much technical expertise has left government for the private sector leaving some governments blind to some issues. The 3 Little Pigs problem is evident where one thinks one has taken the appropriate measures and build a house of straw or of sticks to protect from the wind and the rain but the possibility of their being a wolf is somehow missed.  You would be surprise at how many government policy makers do not know what scada is and yet think they are doing a great job at protecting critical infrastructure.
--------------------------------