Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • SCADA and IoT Security: What is Broken, & Can it Be Fixed? current page
Link copied

SCADA and IoT Security: What is Broken, & Can it Be Fixed?

May 28, 2021
Author:
Dave shackleford
Dave Shackleford
Cybersecurity Expert and Founder of Voodoo Security
Blog banner default
SCADA and IoT Security: What is Broken, & Can it Be Fixed?
Dave shackleford
Dave Shackleford
Cybersecurity Expert and Founder of Voodoo Security

Over the past decade, we've seen a vast array of different types of devices and systems connected to the Internet. While this feels like technological progress, there's a dark side to bringing the Internet of Things (IoT) online—these systems come under attack just like other connected infrastructure. Unfortunately, many SCADA environments today include connected systems with relatively weak security capabilities and configurations, leading to compromise and breach scenarios that are not only dangerous, but could be deadly.

In February 2021, a Florida water plant was compromised remotely, and the attacker attempted to modify the water's chemical makeup. Researchers at CyberNews found 11 breached credentials linked to the water plant from 2017, as well as 13 sets of credentials right before the attack. The attacker on the water plant leveraged a consumer-grade remote access tool to gain access to the plant’s SCADA controls and subsequently changed the level of sodium hydroxide in the water (commonly known as lye), from 100 parts per million to 11,100 parts per million. Luckily, in this case, the modification was detected immediately by one of the plant operators, who reverted the changes before this breach had any impact on the system or the health of the community. I think we all know that this could have gone terribly, though, and we’ve been talking about these kinds of attacks in the security community for years.

As if that wasn’t bad enough, a bit later, on March 9th Bloomberg reported a massive security breach into the Verkada network that exposed the live feeds of 150,000 of security cameras used in jails, hospitals, and many high-profile companies. The threat actors claimed to have had complete access to an archive of full video for all Verkada customers, which poses major data privacy, security, and even political implications. This breach really illustrated the root of the problem – excessive privileges in IoT/OT platforms and products.

The Verkada breach came about as a direct result of a compromised “super admin” account that was remotely accessible. This last point is important – much has been said about privilege management and admin accounts that should be more carefully controlled, but the remote access to the services and platforms USING these accounts is often less publicized. In the Florida water treatment plant breach, the attacker gained remote access using admin credentials. The same situation happened in the Verkada compromise. So, what have we been missing? How do we overcome these types of compromise scenarios?

First, it’s critical to realize that remote access has often been provisioned without careful consideration of privileged access scenarios. Compounding this issue is the unique challenge facing OT/IoT environments, with services and platforms that may be somewhat unforgiving in their mode of access.

The good news? We have a lot of lessons learned, and much better technology today that can help to resolve these IoT security challenges.

To learn from more of these real-world breaches, check out my on-demand webinar: Poisoned Privileges: The Wake-Up Call to Harden Remote Access & Password Security for SCADA & IoT Systems. This webinar will also explore the processes you can implement to mitigate privileged remote access risk for all types of environments, including IoT and OT.

Of course, since the date of my live webinar (April 13th), the attacks on critical infrastructure have not stopped. In May, we saw the devasting cyberattack by DarkSide on Colonial Pipeline, taking much of the U.S. East Coast’s fuel supply offline, causing panic at the pump, and disrupting tens of millions of lives for weeks. To learn more about DarkSide attacks and how to formulate a strong cyber defense posture, check out this BeyondTrust blog: Will DarkSide Pipeline Ransomware Attack Fuel Cybersecurity Upgrades for Critical Infrastructure?


Operational Technology (OT) Cybersecurity Assessment

Resources

Operational Technology (OT) Cybersecurity Assessment

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • What is Vendor Privileged Access Management (VPAM)?
    Apr 7, 2022 What is Vendor Privileged Access Management (VPAM)?
    Blog
    1m
  • Building a Proactive and Extensible Approach to Identity Security
    Sep 3, 2024 Building a Proactive and Extensible Approach to Identity Security
    Blog
    7m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.