US Electric Grid Under Persistent Cyber Attack

Great blog, observing that compliance does not equal security, and that internal culture is a key element.
While focused on the US energy sector, I’d suggest the same is true in the UK too.

  1. While I unfortunately can’t remember the original source of the quote, one of my favourites is “compliance equals security, if and only if your only threat actor is your auditor” :-).

    A good blog to pick up, and I think I’ll be reading rather more of it. It’s fair to say that there are similarities in the UK – and it’s still shocking on both counts, that anyone would ever contemplate putting Microsoft Windows into an embedded control system.


