Value of PLC Key Switch Monitoring to Keep Critical Systems More Secure
ID: 98a362a6-4e92-5ac2-9230-b45d326781e3
STIX ID: report--98a362a6-4e92-5ac2-9230-b45d326781e3
Feed Name: Dragos Blog
Threat Score
This report addresses the security risk posed by PLC/SIS physical and logical key switch positions, highlighting the 2017 XENOTIME/TRISIS compromise that leveraged a controller left in Program mode, and provides practical detection and mitigation guidance—such as embedding key-state detection logic in PLC function blocks, using GSV/predefined attributes and configuring HMI alarms—to enable operations and SOC teams to detect and respond to unauthorized mode changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
