

68: Triton
34 snips Jun 23, 2020
Julian Gutmanis, an industrial incident responder, along with Marina Krotofil from FireEye and Robert M. Lee, CEO of Dragos, dive into the Triton malware attack on a Saudi chemical plant. They discuss how this sophisticated malware jeopardizes safety systems, highlighting the dire consequences of cyber threats in industrial settings. The trio uncovers the complexities of cybersecurity and safety protocols, emphasizing the risks posed by insider threats. Moreover, they address the urgent need for robust security measures and international regulations to mitigate potential disasters.
AI Snips
Chapters
Transcript
Episode notes
The Initial Incident
- Six Triconex safety systems malfunctioned at a Saudi Arabian chemical plant, causing a shutdown.
- The initial investigation revealed unauthorized configuration changes and a remote desktop session on an engineering workstation.
Realizing the Security Incident
- The plant initially thought the shutdown was due to mechanical problems, not a security incident.
- Julian Gutmanis, an OT incident responder, recognized the seriousness of the situation upon learning about the unauthorized logins and safety system failures.
Arrival at the Plant
- Julian and Nasser, OT incident responders, flew to the plant to investigate the incident.
- Ironically, another shutdown occurred while they were at the security checkpoint, delaying their entry.