Something that I keep on hearing from engineers (power, water, etc) on the SCADASEC mailing list is that they are more concerned about human error causing an outage than an attack over the internet. Most of the incidents that I hear about are operator error and they involve accidentally shutting down a computer system or perhaps configuring one improperly (The utility guys like to call these “cyber” incidents). When that happens things “go to hell in a hand basket” fast and people can and do die. They seem to be more concerned about those types of “cyber” incidents than they are the hacker threat… but they’re not getting it right?
The fact of the matter is that a malicious hacker could trigger any number of these “cyber” incidents either deliberatley or accidently, and the end result is the same. How do we get these guys to take the threat more seriously? I think its happening, but I don’t feel like its happening fast enough.