logo

Seven Years After Stuxnet, Industrial Firms Still Lag on Security

ID: 56e3e28f-5c5d-5f11-a789-002f76b552f4

STIX ID: report--56e3e28f-5c5d-5f11-a789-002f76b552f4

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2017-04-12

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Seven years after Stuxnet, many industrial and manufacturing firms still lack basic ICS security controls: FireEye's “Subversive Six” highlights vulnerable protocols and software, outdated hardware, poor password practices, weak firmware integrity checks, vulnerable control logic and over-reliance on Windows and opaque third-party dependencies. The report urges improved monitoring (packet inspection, set-point monitoring), stricter update authorization, and file-integrity checking; DHS data is cited showing APTs were implicated in a majority of reported ICS incidents in 2014, underlining meaningful risk to critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.