Categories

No categories

Information Security of Automated Control Systems (ACS)

March 15, 2025
Eye23
Book12 min
Background

Automated Control System (ACS) — is a systematised set of methods, software and hardware used to regulate and control various operations in the work of an organisation. The following automated systems are distinguished:

  • objects — ACSO;

  • technological process — ACSTP;

  • industry —ACSI;

  • enterprise — ACSE;

  • troops — ACST;

  • road traffic — ACSRT;

  • etc.

Information Security (IS) — is the state of an Information System in which the secrecy, availability and integrity of data circulating within it are ensured.

Advantages of using ACS in industry

Automated Control System usually consists of three levels: a control panel, data processing equipment and typical automation elements, i.e. various sensors, routers, control devices, etc. The automated control system consists of three levels: a control panel, data processing equipment and typical automation elements.

It is important to note that human participation in the work with the ACS is minimised, but it is still present: at the stage of system setup and when making important decisions.

The use of ACS allows companies to significantly reduce operating costs, increase the volume of output without loss of quality, and increase the level of safety at the enterprise by minimising the influence of the human factor, i.e. reducing the number of errors in the production process. The advantages of using ACS are the reason for their growing popularity in all industries.

So, according to Fortune Business Insights, the global industrial automation market was valued at approximately $206 billion in 2022 and is projected to reach $395 billion by 2029, which corresponds to a compound annual growth rate of nearly 10%.

qwerty

With this expected that innovations such as digitalisation, emergence of 5G wireless technology, expansion of augmented reality (AR), use of digital twin technology and industrial internet of things (IIoT) are further expected to accelerate the growth of the global industrial automation market.

Today, automated systems are not only used to control industrial equipment. ACS have proven themselves in power engineering, logistics, medicine, education, lighting systems, road traffic systems and virtually all areas of agriculture and industry.

In addition, many automated systems support functionality to collect and process data from the site. This speeds up the decision-making process and further minimises human involvement in production operations.

Nevertheless, the significant increase in the complexity of Information Systems at industrial enterprises, as well as the architecture of their operating technologies, including ACS, has expanded the scale of threats, the realisation of which may lead to catastrophic consequences.

Why do you need Information Security in ACS?

The digitalisation of industry is characterised by a high level of automation and increasing connectivity to external networks, which opens up new vulnerabilities to information threats: sabotage, cyber attacks, theft of confidential data, and so on.  All this makes an issue of ensuring the security of automated control systems and the data processed in ACS relevant.

Why is it necessary?

As mentioned above, in addition to economic and reputational damage, cyber attacks and data leaks on automated control systems may trigger major, sometimes catastrophic events (e.g., releases of hazardous substances into the atmosphere, fires, explosions) with serious consequences for employees, the population and the environment. At the same time, many enterprises, including those in energy sector, are critical information infrastructure (CII) facilities, and ensuring information security of such enterprises is mandatory by law. 

Information leaks in institutions that process huge amounts of personal data with the help of automated control systems are fraught with financial and reputational damage. Personal, sometimes sensitive information of users or citizens is of particular interest to criminal groups. Employees may inadvertently provide access to confidential data to third parties, either by mistake or as a result of a phishing attack, or deliberately, acting for personal gain or with malicious intent.

Any IS incidents may lead to disruption of technological processes carried out through the ACS.

Specifics of operation of automated control systems in the context of Information Security

Most of the ACSs are distributed territorially and interact with each other through the exchange of a large amount of data.

The following features of distributed ACS are distinguished:

  • a large number of different methods of transmitting and storing information are used;

  • data from different sources are combined into databases, with some located in distributed nodes of the network;

  • information processed by means of ACS is used by a large number of users;

  • today there is an acute shortage of personnel and specialised software to protect ACS from cyber threats.

As discussed above, operational technologies optimise production processes while opening up new vectors for cyber threats. 

Thus, the following vulnerabilities of the ACS significantly increase the risks of Information Security incidents.

  • Long service life of control systems. Typically, control systems have a lifespan of 15 to 30 years. This means that some systems were developed more than a decade ago, and attackers have had enough time to thoroughly study all vulnerabilities.

  • Remote access. Connecting ACS to wireless networks, as well as the ability to connect to them remotely, has simplified management processes while significantly expanding the threat landscape. 

  • Information about the operation of automated systems is easy to find. Typically, a large number of people work with systems: engineers, operators, managers, as well as trainees and other specialists. This fact greatly increases the likelihood that information about automated systems will be leaked, especially compared to a time when access to systems was restricted to a very limited number of people who had signed non-disclosure agreements.

  • Human factor. This refers to employees who intentionally or unintentionally violate the company's information security policy, for example, by using unverified removable media, etc.

  • Physical access. If measures restricting physical access to equipment are insufficient, there are risks of sabotage or unintentional damage to the ACS.

Taking into consideration the vulnerabilities described above will significantly reduce the risks of threats when organising the Information Security system at the enterprise. At the same time, as practice shows, most enterprises focus on protection from external threats and often do not pay attention to threats associated with internal risks — data leaks caused by employees, alteration or destruction of important information, as well as sabotage or unintentional damage to equipment. As practice shows, it is employees and managers of organisations that are most often the perpetrators of leaks. In addition, company counterparties also often commit actions that lead to unauthorised distribution of confidential information.

Why is this happening? 

Most often, leaks of important information about the ACS operation are associated with a critically low level of awareness of Information Security rules among personnel. Employees use weak passwords, fail to recognise various fraud schemes, negligently pass important information and documents to third parties, and use untested removable media.

Prevent confidential information leaks caused by employees by using Anexet DLP system. Evaluate the features of the system in the free 30-day version.

Information security threats to the ACS

Automated Control Systems, including those installed at CII facilities, are particularly sensitive to even the most minimal Information Security threats, which in other areas would not be considered a breach.  At the same time, today we can observe an acute shortage of personnel and software specialising in Information System security, and the current measures taken in organisations are in most cases unreliable and unable to provide the proper level of protection. 

When organising an Information Security system, many people still focus mainly on implementing intrusion detection and prevention systems. However, it is important to pay attention to other attack vectors as well.

Let's look at them in more detail.

Attack vectors against automated systems

  1. Not so long ago, information security of ACS was ensured, among others, by restricting physical access, i.e. by using so-called air gaps. Today, the majority of ACS are connected to networks in one way or another to solve operational tasks. If an intruder gains access to the corporate network, he can also get into the technological network to the automated system.

  2. Negligence. Using untested removable media and connecting external modems. The media may be infected with malware, the modem may allow access from the technology network to the public internet, which should not be the case.

  3. Supply chains and contracting organisations. Another attack vector is contracting organisations who maintain automated systems and process equipment and have the ability to connect to the ACS remotely. If the contracting organisations do not have a well-developed Information Security system, attackers can penetrate the ACS technological network, bypassing all — even the most thorough — information security measures.

qwerty

Based on the vectors described above, we can identify the most common Information Security threats to automated systems.

Threat №1. Breach of the technology network perimeter. Most of the ACSs were designed with the assumption that they will be isolated from the Internet and even from corporate networks. Such an air gap is quite effective in protecting against malicious actions at the places where events that lead to incidents are most often realised: SCADA servers, personnel workstations, programmable logic controllers and so on.

Threat №2. Attacks on operating systems and software. As a rule, this threat is associated with violations of security policy by enterprise personnel: clicking phishing links, using unregistered removable media, installing unreliable software on workstations, operating an unprotected remote access system, etc.

To minimise the impact of the threat, it is recommended to implement the system of personnel training in the basics of Information Security, as well as timely update the software used at the enterprise.

Threat №3. Penetration through remote access. Modern ACS are increasingly connected to the global network, which greatly simplifies the management process, but opens new ways for unauthorised access to the enterprise infrastructure. Another vulnerability that leads to the realisation of this threat is the use of insecure remote connection protocols.

Threat №4. Unlawful disconnection of equipment from the network. It is realised when the measures restricting physical access to ACS elements are insufficient.

Threat №5. Use of unregistered software. Unregistered software can be installed by employees who violate the company's Information Security rules. Unsecured, unverified software, as well as its components, may contain vulnerabilities that give cybercriminals access to system components.

Threat №6. Disclosure, loss, transfer of access to the system. Occurs due to the fault of the organisation's personnel. Authorisation data may be transferred to third parties deliberately or due to a mistake.

Threat №7. Physical breakdown or system component destruction. It is realised in case of insufficient measures restricting physical access to ACS elements.

Threat №8. Recruitment of employees with certain authority or access to protected information. Can be realised through blackmail, bribery, etc.

Threat №9. Theft of storage media: discs, flash drives, devices with internal memory, and entire computers.

Threat №10. Use of residual information from RAM and external storage devices, as well as from sectors of RAM used by the OS.

Threat №11. Theft of used data carriers that have not been destroyed in a timely manner according to the regulations: various documents, flash drives, magnetic discs, etc.

Threat №12. Use of eavesdropping devices and interception means, surveillance, unauthorised photography and videotaping.

Threat №13. Introduction of insiders or agents into the staff, subsequent theft or sabotage of protected information.

Threat №14. Various actions aimed at sabotaging the operation of the enterprise, e.g. creation of a tense atmosphere in the team by disloyal employees, strikes, as well as changes in the modes of operation of automated control systems, installation of equipment that creates radio interference on frequencies on which automated systems operate.

Threat №15. Interception of information transmitted via electromagnetic, acoustic and other communication channels.

Important! As a rule, to achieve their goal, attackers use not one, but several ways to penetrate the system at once.

As we can see from the list described above, most of the IS threats to automated systems are based on the human factor and are intentional in nature. That is why when organising the information security system for automated systems, it is advisable to pay attention not only to measures aimed at protection from external threats, but also to protect the systems from unintentional damage and sabotage, as well as the data processed in them from exfiltration — through the fault of employees.


Protect your data from leakage, alteration and destruction with Anexet DLP.


A real-life incident at a ACS: $1,000,000 loss at EnerVest due to sabotage

A network engineer for West Virginia-based energy company EnerVest learned he was about to be fired and reset all network servers to factory defaults and disabled remote backups. It is known that Mitchell faced criminal prosecution for the offence. Nevertheless, as a result, EnerVest was unable to conduct operations for 30 days and suffered losses of more than $1 million.

Measures to ensure the safety of ACS

There are three types of measures to ensure the security of automated systems: physical, organisational and software and hardware.

Organisational measures are aimed at levelling the impact of the human factor on Information Security:

  • development, approval and implementation of the Security Policy (hereinafter — SP);

  • appointment of persons responsible for Information Security provision;

  • delimitation of employee access to the ACS and its components.

Important: even the most accurate and thorough SP is of no use if the company's employees do not follow the rules described in it. You can control compliance with the security policy when working with ACS using the Anexet DLP system.

The following Information Security measures for automated systems are also highlighted.

Ensuring physical protection

Restriction of access to the equipment and components of the ACS, workstations by means of fences, access control and video surveillance systems. Installation of checkpoints and security alarms. Ensuring safety of system components in case of natural disasters: fires, earthquakes, floods, etc.

Data encryption

Use of cryptographic methods to protect transmitted and stored data from unauthorised access.

Backup

Create backups of critical data and software for quick recovery in the event of failures, sabotage or attacks.

Timely software updates

Install patches and updates to address vulnerabilities and improve system security.

Monitoring and audit

Collect and analyse system event information to identify suspicious activity and potential threats.

Staff training 

Conducting so-called cyber-education, trainings and seminars on Information Security issues for personnel working with ACS.

Use of antivirus and other anti-malware tools 

It is necessary to prevent viruses and other malicious programmes from infecting the ACS.

Important: the use of these measures does not guarantee full information security of the facility, but will significantly reduce the risks of incidents.

When providing protection measures for automated systems, it is important to take into account the requirements described in the regulatory legal acts of regulators, as well as to rely on global security standards, which we will discuss below.

The IEC 62443 family of standards

The standards are based on a risk-oriented approach and establish requirements for the security of industrial control systems. The documents describe information security as a set of operations that must be carried out regularly at all stages of the life cycle of an ACS.

In conclusion

When ensuring the Information Security of ACS, it is important to implement measures to counter not only external but also internal threats. As practice shows, it is human activity that poses the greatest risk to automated control systems: negligence of employees when performing work tasks, activities of insiders and employees disloyal to the organisation, industrial espionage, etc.

At the same time, the potential risks to the environment and citizens caused by stopping technological processes or damaging equipment at enterprises may be of interest to the services of foreign countries, especially in the current geopolitical situation in the world. This makes the issue of ensuring the IS of automated systems particularly relevant.

Advertisement

Explore the power of Anexet right now!

Start Free Trial