Skip to content

Robert M. Lee

Common Analyst Mistakes and Claims of Energy Company Targeting Malware

A new blog post by SentinelOne made an interesting claim recently regarding a “sophisticated malware campaign specifically targeting at least one European energy company.”  More extraordinary though was the claim by the company that this find might indicate something much more serious: “which could either work to extract data or insert the malware to potentially…

Continue reading →

Hype, Logical Fallacies, and SCADA Cyber Attacks

For a few years now I’ve spent some energy focusing on calling out hyped up stories of threats to critical infrastructure and dispelling false stories about cyber attacks. There have been a lot of reasons for this including trying to make sure that the investments we make in the community go against real threats and…

Continue reading →

Context for the Claim of a Cyber Attack on the Israeli Electric Grid

This blog was first posted on the SANS ICS blog here.   Dr. Yuval Steinitz, the Minister of National Infrastructure, Energy, and Water resources, announced today at the CyberTech Conference in Tel Aviv that a “severe cyber attack” was ongoing on the Israel National Electric Authority. His statements were delivered as a closing session at…

Continue reading →

Security Awareness and ICS Cyber Attacks: Telling the Right Story

This was first posted on the SANS ICS blog here.   A lack of security awareness and the culture that surrounds security is a widely understood problem in the cyber security community. In the ICS community this problem is impactful towards operations and understanding the scope of the threats we face. A recent report by…

Continue reading →