Ravindra BagaleCourses & study guides

43. IoT and OT Security – Cameras, Smart Devices, Plant Networks

43.1 IoT vs OT / ICS / SCADA – CIA Plus Safety

Thodkyaat sangaycha tar – interview madhe mix naka:

World What it is Extra priority
IT Email, ERP, billing DB, office Wi-Fi CIA – confidentiality (गोपनीयता), integrity (अखंडता), availability
IoT Cameras, smart meters, MQTT sensors, "smart" plugs Often weak defaults; big availability + privacy if video leaks
OT / ICS Plant / warehouse control – PLC, HMI, SCADA Safety of people and process; downtime can mean heat, spill, stop-line
SCADA Supervisory view + remote commands over a wide area Integrity of commands; fake "open breaker" is not a joke

ICS (Industrial Control System) = umbrella. PLC = small computer that runs ladder / logic near the motor. HMI = screen operator clicks. SCADA = supervise many sites. IoT camera godown madhe asel; packing-line PLC OT aahe. Donhi "IP asel tar Nmap" – nahi. Aggressive IT scan OT stack hang / reboot karu shakte. Blue rule: ask OT owner, use read-only / approved tools, prefer passive monitoring.

Samjla ka? IT = office laptop. OT = Nashik packing line. IoT = Pune warehouse camera. Same Ethernet cable ≠ same risk appetite.

Red team (attacker) does Blue team (defender) detects / stops
Treats PLC like a web server; scans hard Change-control window; OT-aware scan policy; passive first
Pivots from office IT into plant VLAN IT/OT firewall zones; no flat "one big LAN"
Hopes nobody named safety as a goal Safety + CIA in the risk register; IR playbook for plant stop

Ravindra Bagale's Tip

Students say "IoT = OT". A camera leak = privacy + botnet. A wrong write to a PLC = a physical consequence. One line for the interview: "IoT is often consumer-grade connectivity; OT is process control where safety beats clever IT tooling." Remember this.

Lab

Notes madhe 6-row table: IT asset | IoT asset | OT asset – for fictional Sahyadri Traders (Pune warehouse + Nashik packing line). Write which CIA/safety property hurts most if each fails. 8 lines. No plant traffic yet.

Real incident: Ukrainian power distribution outages (2015)

On 23 December 2015, public reporting and later CISA / E-ISAC–SANS analysis described cyber intrusions at Ukrainian electric distribution companies that led to unscheduled outages affecting a large number of customers (often cited as on the order of 225,000, as reported). Attackers used spear-phishing and footholds on IT networks, then abused remote access into control environments to open breakers; malware such as BlackEnergy was discussed as part of the broader campaign picture, while analysts stressed that the outage itself came from unauthorized operation of control systems, with follow-on disruption (e.g. KillDisk-class wipe) delaying recovery. Weakness: IT→OT path, credential reuse, remote control without enough monitoring. Defence: zone segregation, MFA on remote access, monitored jump hosts, offline recovery drills. Source: CISA IR-ALERT on Ukrainian critical infrastructure (2016) and E-ISAC / SANS Analysis of the Cyber Attack on the Ukrainian Power Grid (verify; say "reported" for customer counts).