Bottom line: Cyber-informed engineering is becoming a top priority in critical infrastructure security.
What's happening: The US Department of Energy's Office of Cybersecurity and Energy Security (OCES) is implementing new standards for industrial control systems (ICS) security. These standards require ICS vendors to provide secure software updates, including those for Siemens' Simatic WinCC SCADA system, to prevent vulnerabilities like the 2019-01-15 00:00:00 CVE-2019-5500 (CVSS score: 6.5) in the Simatic WinCC SCADA system.
What to do: CISOs should prioritize collaboration with ICS vendors and ensure regular software updates to mitigate the risk of similar vulnerabilities, and invest in cybersecurity training for engineers to help them design more secure systems from the outset.