ALL RESEARCH
    RESEARCH/29 July 2017/CRITICAL

    ICS Killswitch — Cyber-Physical Industrial Security Research

    Two-year DefCon research programme on cyber-physical attack chains against industrial control systems.

    AFFECTED

    Industrial Control Systems (multi-vendor)

    SEVERITY

    Critical

    SUMMARY

    Research demonstrating cyber-physical attack chains against industrial control systems — how relatively small compromises in OT environments cascade into safety-relevant outcomes. Presented at DefCon in 2017 and again in 2018, with vendor coordination on remediation paths preceding each disclosure.

    DETAIL

    Industrial control systems are a class of attack surface where the consequences of compromise are categorically different from enterprise IT. Production safety, environmental release, regulatory exposure, and physical asset damage all live in the OT layer. The ICS Killswitch research programme set out to demonstrate, from public-facing primitives, that the path from "attacker on the network" to "safety-relevant physical outcome" is shorter than most operators assume.

    The research demonstrated specific attack chains where seemingly minor compromises — default credentials surviving in production, unpatched firmware on field devices, weak network segmentation between IT and OT — could be combined into deterministic paths to physical effect. The chains were validated against representative test environments and disclosed to affected vendors with coordinated remediation timelines before public presentation.

    The work was presented at DefCon in 2017 and an extended version in 2018. The methodology and a subset of findings have been integrated into industry guidance on OT/ICS security architecture; the priority-ordered control set in the 2018 update remains a useful reference for plant-level risk assessment.

    [TODO(matthew): Add specific vendor names where the disclosure window has fully closed, links to slides and recordings, any associated CVEs, and a sentence on the practical controls that derive from the chains.]

    Need this kind of research for your organisation?

    Atumcell runs targeted vulnerability research, OT/ICS assessments, and adversary simulation for organisations where the consequences of compromise are categorically different from IT.

    STRATEGIC CONSULTATION

    Discuss a research scope

    $500·30 minutes

    MORE ON THESE TOPICS

    Or learn more about full advisory engagements.