{"id":301,"date":"2026-10-05T02:35:29","date_gmt":"2026-10-05T02:35:29","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/tammyrizo\/?page_id=301"},"modified":"2026-10-05T02:35:29","modified_gmt":"2026-10-05T02:35:29","slug":"scada-systems-and-their-vulnerabilities","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/tammyrizo\/it-cyse-200t-2\/scada-systems-and-their-vulnerabilities\/","title":{"rendered":"SCADA Systems and Their Vulnerabilities"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">About This Write-Up<\/h2>\n\n\n\n<p>This professional write-up examines Supervisory Control and Data Acquisition (SCADA) systems and their role in critical infrastructure. I explore how SCADA systems connect computer technology with physical processes and examine cybersecurity risks involving internet exposure, weak authentication, legacy systems, and industrial control devices. This assignment helped me understand how cybersecurity vulnerabilities can affect not only computer systems and data but also physical operations and essential services.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p>Supervisory Control and Data Acquisition (SCADA) systems are critical to infrastructure because they enable organizations to monitor and manage physical processes across industries such as energy, water, transportation, and manufacturing. Over time, these systems have become more dependent on networked and internet-connected technologies. Cybersecurity risks are created for computer systems and physical operations when these connections are used. SCADA systems can be vulnerable to unauthorized access, weak passwords, and exposed networks. Organizations can protect critical infrastructure by using layered security measures such as strong access controls, network security, monitoring, multifactor authentication, and backup and recovery strategies, which can reduce vulnerabilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SCADA Systems and Critical Infrastructure<\/h2>\n\n\n\n<p>SCADA systems are industrial control systems used to monitor and manage infrastructure and industrial processes. These systems are important because they connect computer-based monitoring and control with physical processes. They can be used for water and wastewater treatment, gas pipelines, wind farms, transportation systems, manufacturing, refining, and power generation, to name a few. SCADA systems can include a human-machine interface (HMI), supervisory systems, remote terminal units (RTUs), programmable logic controllers (PLCs), and communication infrastructure. RTUs and PLCs interact with physical equipment and collect sensor data. An RTU converts electrical signals coming from equipment into digital values. PLCs run in real time, are often programmed using ladder logic, and are important components of the hardware layer. The supervisory system gathers and presents information to operators through the HMI (\u201cSCADA Systems,\u201d n.d.).<\/p>\n\n\n\n<p>A cybersecurity incident involving SCADA may affect more than the information stored on a computer. For example, an operator may use an HMI to monitor equipment. Based on information collected from PLCs or RTUs, the operator may need to adjust the settings. A cyberattack may disrupt critical infrastructure because operational technology interacts with physical equipment and processes (Stouffer et al., 2023).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SCADA Applications and Cybersecurity Risks<\/h2>\n\n\n\n<p>SCADA systems are used in many industries that people and organizations depend on. SCADA can monitor and control power-related processes in the energy sector. It can monitor equipment and treatment processes in water and wastewater systems. Transportation and manufacturing facilities can also use SCADA to monitor and control equipment and production processes. These applications demonstrate why SCADA security is important to both organizations and society (Stouffer et al., 2023).<\/p>\n\n\n\n<p>The exposure of SCADA and PLC devices to networks or the Internet is one major cybersecurity vulnerability. Modern networked SCADA systems use the Internet Protocol (IP). This provides greater connectivity but can also increase exposure to cyber threats (\u201cSCADA Systems,\u201d n.d.). Outdated software and legacy SCADA systems are another vulnerability we need to be aware of. Older equipment may contain known vulnerabilities and may not support modern security controls. Organizations can reduce this risk by applying security patches when they can be safely implemented, replacing unsupported systems when possible, and using additional security controls when patching must be delayed (Stouffer et al., 2023).<\/p>\n\n\n\n<p>Weak authentication can add to these risks. CISA reported that attackers compromised internet-connected Unitronics PLCs that were protected by default passwords or no password at all. In this example, weak authentication and internet exposure allowed attackers to access SCADA components and affect physical operations. By replacing the original ladder logic and changing information displayed on the HMI, attackers were able to disrupt operations (Cybersecurity and Infrastructure Security Agency [CISA], 2023). An attack against a water system, energy system, or other critical infrastructure could disrupt essential services and may require organizations to switch to manual operations during recovery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>SCADA is valuable because it can connect computer systems to physical processes. SCADA systems are important for managing infrastructure and industrial operations in the modern world. Attackers may compromise HMIs, PLCs, RTUs, and other SCADA components through vulnerabilities created by unauthorized access, weak authentication, internet exposure, and outdated systems. The attacks described by CISA show that these vulnerabilities can result in operational disruption and financial consequences. Organizations can improve SCADA security by limiting internet exposure, strengthening authentication, segmenting networks, monitoring activity, maintaining backups, and using security strategies designed for operational technology.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">References<\/h2>\n\n\n\n<p>Cybersecurity and Infrastructure Security Agency. (2023, November 30). <em><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-335a\">IRGC-affiliated cyber actors exploit PLCs in multiple sectors, including U.S. water and wastewater systems facilities.<\/a><\/em><\/p>\n\n\n\n<p><em><a href=\"https:\/\/docs.google.com\/document\/d\/1DvxnWUSLe27H5u8A6yyIS9Qz7BVt_8p2WeNHctGVboY\/edit?tab=t.0\">SCADA Systems.<\/a><\/em> (n.d.).<\/p>\n\n\n\n<p>Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., &amp; Thompson, M. (2023). <em><a href=\"https:\/\/doi.org\/10.6028\/NIST.SP.800-82r3\">Guide to operational technology (OT) security (NIST Special Publication 800-82 Rev. 3).<\/a><\/em> National Institute of Standards and Technology.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>About This Write-Up This professional write-up examines Supervisory Control and Data Acquisition (SCADA) systems and their role in critical infrastructure. I explore how SCADA systems connect computer technology with physical processes and examine cybersecurity risks involving internet exposure, weak authentication, legacy systems, and industrial control devices. This assignment helped me understand how cybersecurity vulnerabilities can&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/tammyrizo\/it-cyse-200t-2\/scada-systems-and-their-vulnerabilities\/\">Read More<\/a><\/div>\n","protected":false},"author":32737,"featured_media":0,"parent":133,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/301"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/users\/32737"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/comments?post=301"}],"version-history":[{"count":2,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/301\/revisions"}],"predecessor-version":[{"id":303,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/301\/revisions\/303"}],"up":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/133"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/media?parent=301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}