Industrial control system enabling remote supervision and control of physical processes, whose compromise can result in physical damage.
SCADA (Supervisory Control and Data Acquisition) refers to a category of industrial computer systems designed to monitor and command physical processes in real time: electrical grids, chemical plants, water treatment stations, oil and gas pipelines, rail systems. These systems combine programmable logic controllers (PLCs), human-machine interfaces (HMIs) and data collection servers linked to physical sensors and actuators. The cybersecurity of SCADA constitutes a distinct challenge from that of conventional information systems for several structural reasons: SCADA systems often have 15-to-30-year lifecycles, leaving in place legacy software that is difficult to patch; they were historically designed for isolated (air-gapped) networks and therefore have few native security mechanisms; their growing convergence with corporate IP networks exposes them to attacks from the internet. Compromising a SCADA can cause real material and bodily damage: the attacks on the Ukrainian power grid in 2015, a Florida water treatment plant in 2021, and the Triton/TRISIS attack on an oilfield plant safety system in 2017 are the most documented examples. For insurance, the physical dimension of SCADA losses creates the proximate/efficient causality issue (cyber or physical?) at the heart of LMA 21-042 debates.
In December 2015, Russian attackers (Sandworm group) compromised the SCADA systems of Ukrainian electricity distribution operators via targeted phishing emails, then remotely triggered circuit breakers to cut power to 230,000 households for several hours. This was the first confirmed cyberattack to have caused a real power outage, demonstrating the convergence between cyber and property insurance risk.
SCADA, Supervisory Control and Data Acquisition, ICS, OT security, technologie opérationnelle