Comments on: DOE calls for increased cybersecurity measures in preparation for rapid distributed energy growth https://www.solarpowerworldonline.com/2022/10/doe-calls-for-increased-cybersecurity-measures-prepare-der-growth/ Covering the world of solar power technology, development and installation. Fri, 07 Oct 2022 15:26:06 +0000 hourly 1 https://wordpress.org/?v=6.2 By: Solarman https://www.solarpowerworldonline.com/2022/10/doe-calls-for-increased-cybersecurity-measures-prepare-der-growth/#comment-136652 Fri, 07 Oct 2022 15:26:06 +0000 https://www.solarpowerworldonline.com/?p=100149#comment-136652 “This “cyber by design” strategy leverages opportunities early in the design lifecycle to proactively reduce cyber risk rather than attempt expensive aftermarket bolt-on efforts.”

The DOE is proffering safety by pronouncing “from the ground up” inclusion of proactive cyber security. This claim of “…aftermarket bolt on efforts”, is disingenuous and smacks of ignorance. Technology is still changing at a fast pace, designing in security today will be abrogated by technology tomorrow. Look at electronics firm Huawei, the NIC chips in the bulk of its devices have been called out as a (possible) security risk. It seems there is a third data stream in the NIC chips that could be used to do an end run around encryption. Huawei has balked at explaining what this data stream is for.

In the industrial controls sector, there is a “concept” that is decades old. The concept is where does one want to put the overhead? At the controller site or at the SCADA headquarters? Basically when one uses Occam’s razor having the local process controller holding the [sensors and control programming] in what one would call “local emergency mode” has allowed a system to continue functioning without communications from the “control center” or communications network.

]]>