{"id":363,"date":"2026-05-03T20:14:16","date_gmt":"2026-05-03T20:14:16","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/brandonvuono\/?page_id=363"},"modified":"2026-05-03T20:14:25","modified_gmt":"2026-05-03T20:14:25","slug":"analytical-paper","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/brandonvuono\/analytical-paper\/","title":{"rendered":"Analytical Paper"},"content":{"rendered":"\n<p>Brandon Vuono&nbsp;<\/p>\n\n\n\n<p>CYSE 200T&nbsp;<\/p>\n\n\n\n<p>Analytical paper&nbsp;<\/p>\n\n\n\n<p>03 May 2026&nbsp;<\/p>\n\n\n\n<p>Cyber\u00a0Wakeup\u00a0Call: Old Systems New Threats\u00a0\u00a0<\/p>\n\n\n\n<p>Cybersecurity is something that most people do not even think about&nbsp;on a daily basis.&nbsp;Only if something happened to them personally will it become an imperative part of their lives.&nbsp;Everything that helps society run from banking organizations to power grids&nbsp;depends&nbsp;on a digital infrastructure to work efficiently and securely. Due to the&nbsp;world,&nbsp;we live in&nbsp;today being run&nbsp;digitally. There&nbsp;needs to be ground truth on how to protect these critical systems.&nbsp;The most widely used model is the CIA Triad. This focuses strictly on confidentiality,&nbsp;integrity, and availability.&nbsp;&nbsp;This model provides&nbsp;a strong foundation&nbsp;for cybersecurity.&nbsp;I&nbsp;believe&nbsp;it&nbsp;is not enough on its own to stop all&nbsp;attacks,&nbsp;especially when it comes to outdated systems like&nbsp;Supervisory&nbsp;Control and Data Acquisition systems.&nbsp;&nbsp;These outdated systems run critical infrastructure for&nbsp;everyday society. Even with their precautions of authentication and&nbsp;authorization,&nbsp;these systems can create long term risks to&nbsp;infrastructure&nbsp;if they&nbsp;are&nbsp;not properly hardened.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The CIA triad is refered to the starting point for having a solid cybersecurity base. The bottom of the cybersecurity pyramid.&nbsp;Each part of the triad focuses on&nbsp;different&nbsp;aspects&nbsp;of protecting critical information.&nbsp;Confidentiality is about making sure the&nbsp;sensitive&nbsp;information or data is only&nbsp;accessible&nbsp;to those with the right authorization to view it. This is also sometimes&nbsp;referred&nbsp;to as the need&nbsp;to know. A crucial part&nbsp;of&nbsp;information&nbsp;security.&nbsp;In most modern systems, confidentiality is protected through encryption and multi factor authentication which adds extra layers of security (Chai, 2022). Without these&nbsp;protections,&nbsp;it would be&nbsp;very easy&nbsp;for&nbsp;an&nbsp;attacker to gain access to critical information.&nbsp;<\/p>\n\n\n\n<p>Integrity refers to&nbsp;maintaining&nbsp;the accuracy and reliability of data. I think of how trustworthy the information is. Information should not be changed by unauthorized users at any time. Whether the data is in storage or transmission, it should not be altered. For example, if someone is sending a recipient&#8217;s money, the amount shall not be changed. Mechanisms such as hashing and digital signatures are commonly used to preserve integrity (National Institute of Standards and Technology, NIST 2013). This helps ensure that information&nbsp;remains&nbsp;the same from the moment it is created to the moment it is&nbsp;being&nbsp;used.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Availability ensures that the authorized user can access the data or information needed.&nbsp;If data is confidential, the user must be authorized to access the data.&nbsp;This is why availability is as important as the other two components of the CIA Triad.&nbsp;For&nbsp;example,&nbsp;any kind of denial-of-service attacks taking a system offline. Making nothing available can cause rippling effects.&nbsp;&nbsp;Maintaining a balance between the CIA Triad is essential for security of data and information.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>When it comes to authentication and authorization, they are closely related. They do serve different purposes to a cyber security professional. Authentication is the process of verifying the user&#8217;s identity. It verifies that the person doing the task is who they say they are. Authorization occurs after authentication and determines what an authenticated user is allowed to do. This will restrict any access or modifications a user&#8217;s attempts to conduct.&nbsp;&nbsp;<\/p>\n\n\n\n<p>This becomes a major issue when looking at critical infrastructure. Systems attached to power grids, water treatment facilities, and transportation networks are essential to everyday life.&nbsp;The biggest vulnerability is the fact that SCADA is an old technology. SCADA was designed and implemented decades ago before cyber-attacks were a concern. With that there was never any major security systems implemented such as encryption or dual authentication, and many of the security measures that are second nature to us today. Systems that were isolated from themselves now connected to larger systems or even the internet. This creates an increase in efficiency for these systems but also creates more entry points for cyber-attacks (SCADA Systems Perusal article). For example, SCADA systems can do tasks such as monitoring the electric grid for stability or monitoring the water treatment plants for flow rates. If these SCADA systems are compromised, an attacker could disrupt operations of these systems, manipulate the data, or cause their systems to malfunction, creating physical damage.&nbsp;<\/p>\n\n\n\n<p>&nbsp;To prevent these risks from becoming avenues for an attacker SCADA although old can help with its real time awareness. Looking at real time monitoring and controlling the systems that run on SCADA, operators would be able to identify any abnormalities before they escalate. This will help reduce the likelihood of major attacks or disruptions in operations of these critical systems. According to the Cyber security infrastructure security agency, using a layered security approach often called defense in depth is one of the most effective ways to protect industrial control systems (CISA, 2023). This is accomplished by using SCADA and human operators to monitor the system.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Even with these&nbsp;improvements,&nbsp;I&nbsp;do not think there is a perfect solution. Cybersecurity is constantly evolving as technology&nbsp;improves. Attackers are constantly looking and finding different&nbsp;avenues&nbsp;to attack and exploit a weakness.&nbsp;&nbsp;This means organizations&nbsp;have to&nbsp;consistently adapt and improve defenses.&nbsp;Organizations must&nbsp;constantly&nbsp;verify&nbsp;they&#8217;re&nbsp;using&nbsp;the CIA Triad to its fullest giving a solid foundation for defense.&nbsp;&nbsp;<\/p>\n\n\n\n<p>I&nbsp;believe&nbsp;the CIA Triad&nbsp;plays the most critical role in cybersecurity. Without this&nbsp;foundation,&nbsp;protection and best practices would have nothing to build&nbsp;off. These are foundational&nbsp;blocks,&nbsp;and more protections must&nbsp;build&nbsp;off of&nbsp;them. The simplicity of the Triad is not enough for systems like SCADA and other outdated systems.&nbsp;&nbsp;While defense-in-depth strategies can help reduce&nbsp;risk,&nbsp;they do not solve the problem legacy system&nbsp;vulnerabilities&nbsp;have. There are still many questions that need to be answered. For&nbsp;example,&nbsp;how do organizations decide what is worth&nbsp;replacing&nbsp;critical&nbsp;systems.&nbsp;Can it be done without&nbsp;disrupting&nbsp;the&nbsp;service.&nbsp;If they upgrade it&nbsp;will&nbsp;be backwards&nbsp;compatible,&nbsp;which is the weakness of its own in every technology. For&nbsp;example,&nbsp;downgrade attack on a WPA3 router that is in transition mode. WPA3 is very secure technology but being backwards compatible is its downfall.&nbsp;&nbsp;These types of issues do not have a single point of correcting for that perfect solution.&nbsp;&nbsp;<\/p>\n\n\n\n<p>One thing that I believe is the most important part to cybersecurity is the human factor. Even with&nbsp;strong base&nbsp;of the CIA&nbsp;Triad and strong systems that SCADA is not, people can and usually are the weakest link. Employees might use weak passwords, fall for phishing attacks, or make simple mistakes that open doors for attackers.&nbsp;In critical infrastructure environments that risk matrix becomes much higher. Single errors can have&nbsp;crippling&nbsp;effects on entire&nbsp;systems&nbsp;and societies.&nbsp;This is why awareness is extremely important.&nbsp;If organizations invest&nbsp;in&nbsp;educating&nbsp;their&nbsp;employees,&nbsp;they can reduce a large number of preventable security issues. This with strengthen their security posture where other areas may not have changed and continue to lack protection&nbsp;&nbsp;<\/p>\n\n\n\n<p>Overall,&nbsp;I&nbsp;think the key&nbsp;takeaway&nbsp;is that cybersecurity is not just about&nbsp;having&nbsp;the right tools or framework to go&nbsp;off of. IT is about understanding how to apply the tools in&nbsp;real-world&nbsp;systems, especially&nbsp;ones that are not designed for the cyber treats of today. Moving&nbsp;forward,&nbsp;improving security in these critical&nbsp;infrastructure&nbsp;systems is&nbsp;critical.&nbsp;This will not only require better technology but better decision making using the CIA Triad as the core. While risk and attack avenues will never be fully&nbsp;irradicated,&nbsp;they can be managed and&nbsp;monitored. Making any attacker&nbsp;require&nbsp;an&nbsp;unlimited&nbsp;amount of&nbsp;time and money investment&nbsp;to go through with the attack.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>References&nbsp;<\/p>\n\n\n\n<p>-Chai, W (2022 June 28) What is the CIA Triad? Definition, explanation, examples.&nbsp;<a href=\"https:\/\/drive.google.com\/file\/d\/1898r4pGpKHN6bmKcwlxPdVZpCC6Moy8l\/view\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/drive.google.com\/file\/d\/1898r4pGpKHN6bmKcwlxPdVZpCC6Moy8l\/view<\/a>&nbsp;<\/p>\n\n\n\n<p>-Cybersecurity and Infrastructure Security Agency. (2023) Cybersecurity best practices for industrial control systems.&nbsp;<\/p>\n\n\n\n<p>-National Institute of Standards and Technology 2013. Security and privacy controls for federal information systems and organizations.&nbsp;<a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r4.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r4.pdf<\/a>&nbsp;<\/p>\n\n\n\n<p>-SCADA Systems Perusal Article&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Brandon Vuono&nbsp; CYSE 200T&nbsp; Analytical paper&nbsp; 03 May 2026&nbsp; Cyber\u00a0Wakeup\u00a0Call: Old Systems New Threats\u00a0\u00a0 Cybersecurity is something that most people do not even think about&nbsp;on a daily basis.&nbsp;Only if something happened to them personally will it become an imperative part of their lives.&nbsp;Everything that helps society run from banking organizations to power grids&nbsp;depends&nbsp;on a digital&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/brandonvuono\/analytical-paper\/\">Read More<\/a><\/div>\n","protected":false},"author":18452,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/pages\/363"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/users\/18452"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/comments?post=363"}],"version-history":[{"count":2,"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/pages\/363\/revisions"}],"predecessor-version":[{"id":365,"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/pages\/363\/revisions\/365"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/brandonvuono\/wp-json\/wp\/v2\/media?parent=363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}