logo

10 years on from the Target breach. Has building cyber security improved?

ID: e5d830c6-a78e-53cd-b4ae-dbecf39491c1

STIX ID: report--e5d830c6-a78e-53cd-b4ae-dbecf39491c1

Feed Name: Pen Test Partners Blog

Date Published: 2024-01-24

Date Updated: 2026-03-26

Author: Ken Munro

...
...

A decade after the Target breach, the article argues that risks to connected building management systems have increased despite lessons learned, citing more internet-exposed devices, a proliferation of lower-cost vendors and installer weaknesses, remote access via poorly secured RDP and cloud/mobile APIs, greater Shodan discoverability, and cheap cellular modems that bypass enterprise controls. It urges collaboration between cyber, facilities, and procurement teams, inclusion of supplier security requirements, and physical checks of plant/control rooms to prevent security sidestepping.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.