Blog

Contenido Blog

Shadow IT exposed: risks and best practices

Posted on 26/10/2023, by
INCIBE (INCIBE)
Shadow IT exposed: risks and best practices
The presence  of Shadow IT, i.e., the unauthorized or unmanaged use of IT technologies and services by employees, poses challenges and risks of considerable magnitude.The rapid adoption of personal devices and applications, as well as accessibility to cloud services, have increased the complexity of the security landscape. This situation poses a risk that can compromise the confidentiality and integrity of the organization's information. 

CVSS V4.0: steps for an advanced vulnerability assessment

Posted on 19/10/2023, by
INCIBE (INCIBE)
CVSS V4.0: avanzando en la evaluación de vulnerabilidades
The arrival of the new version of CVSS (Common Vulnerability Scoring System) covers some deficiencies related to the assessment of vulnerabilities in the industrial world. The introduction of changes in the way of scoring different vulnerabilities, the incorporation of new metrics for elements of the industrial world such as "Safety" or the service recovery of a device, are some of the new features introduced in version 4 of the CVSS.This article will analyze the new features brought by version 4.0 and its increased accuracy when assessing vulnerabilities in industrial environments for a better adequacy of the scores given. 

Zero Trust methodology: foundations and benefits

Posted on 09/10/2023, by
INCIBE (INCIBE)
Zero Trust Cover
The Zero Trust methodology  is based on the premise that no user, device, or network can be trusted, and that access privileges and security levels must be continuously verified in all interactions. The motivation for applying the Zero Trust methodology  is the need to protect a company's sensitive data and digital resources against potential internal and external threats. 

ESXiArgs: response and recovery actions

Posted on 02/10/2023, by
INCIBE (INCIBE)
ESXiArgs: response and recovery actions
This article introduces how ESXiArgs operates, and offers an approach to identifying and addressing the threat. Examining the characteristics and behaviours of ransomware, it provides detailed insight into the tactics it uses and how these can be detected in a vulnerable environment. It also explores strategies and best practices for cleaning and disinfecting compromised systems, restoring trust and security to the affected infrastructure.

SOC OT: The importance of advanced monitoring for industrial cybersecurity

Posted on 28/09/2023, by
INCIBE (INCIBE)
SOC OT: The importance of advanced monitoring for industrial cybersecurity
In recent decades, the need to control processes remotely to improve efficiency, productivity and accelerate decision making on industrial systems has led to the interconnection of operation technologies (OT) with information technologies (IT). This interconnection has given rise to a number of security risks in industrial control systems, and to meet these challenges, specific tools and technologies have been developed and adapted to help ensure cybersecurity in industrial environments. One such tool is the Security Operations Center (SOC).In this article we will focus on the importance of advanced monitoring in a SOC OT. 

Firmware analysis of industrial devices

Posted on 21/09/2023, by
INCIBE (INCIBE)
Firmware analysis of industrial devices
Firmware analysis can help to uncover potential vulnerabilities that would otherwise never have been discovered.Although there are multiple types of attacks on IoT and IIoT devices, this guide focuses on the firmware of these devices to check for potential vulnerabilities, using security testing and reverse engineering to allow for an in-depth analysis of the firmware.

IEC62443-3-3 certification process

Posted on 14/09/2023, by
INCIBE (INCIBE)
IEC62443-3-3 certification process
Information security standards have become increasingly important in recent years, as more and more legal requirements oblige companies to demonstrate a certain degree of cybersecurity compliance. The IEC 62443 family of standards describes in its various sections the requirements for the secure implementation of an ICS (Industrial Control System) and represents a guarantee of cybersecurity in industrial environments. This article deals with IEC62443-3-3 covering cybersecurity of industrial systems.

Study of tools for recognition activity

Posted on 07/09/2023, by
INCIBE (INCIBE)
Introduction to the study of recognition tools blog image
With this study, we seek to offer a deep knowledge about the reconnaissance activity in cybersecurity, so that professionals from different fields can consider these tactics as an integral part of their security strategies. This study also aims to increase general understanding of these techniques and how they can be used to effectively protect information and systems. 

The challenges of upgrades in industrial environments

Posted on 24/08/2023, by
INCIBE (INCIBE)
Portada Antimalware en SCI
The increase of malware specifically designed to run on systems that support industrial processes creates a need in the industry that can be partly covered by different technological solutions. This article will focus on the different options available on the market to detect malicious files that aim to modify the operation of industrial environments or simply cause denials of service.Both portable and agent-deployed solutions can be an option, and this article will reflect on these and other options as well as provide guidelines on when it is best to use one solution or the other.