Protecting SCADA Systems with Defense-in-Depth Strategies
How utilities can utilize multi-layered security approaches
BY RICHARD CLARK, InduSoft
Defense-in-depth is a security strategy first developed by military leaders in which multiple layers of safeguards are placed throughout a system. The concept behind the strategy is that it is more difficult to penetrate a complex and multi-layered defense than to breach a single security measure. The defense-in-depth approach does not simply strive to prevent attacks; it expects them and counters them with coordinated yet disparate safeguards. Moreover, defense-in-depth does not assume an attacker will first attempt to access the SCADA system; it also takes into consideration that a hacker may try to gain unauthorized entry via a less critical area, such as the company website, and then get inside the SCADA system to do greater damage.