States » South


CII-SCADA 4.0: Cyber attack can become physical attack, warns cybersecurity specialist

Thiruvananthapuram, Oct 4 (UNI) A cyber attack on critical infrastructure does not end with the breach of a firewall or computer network, as the real danger begins when a digital command reaches and influences a physical process, leading to potential disruption of industrial operations, power systems and other critical services, according to leading industrial cybersecurity specialist K. S. Manoj.
A stolen credential can potentially become a SCADA command, a compromised engineering workstation can provide a pathway to a Programmable Logic Controller (PLC), and a manipulated control signal can alter the functioning of a substation, disrupt an industrial process or destabilise a critical service, he said.
"This is the emerging reality of Critical Information Infrastructure (CII), where the boundary between cybersecurity and physical safety is disappearing," Manoj said.
International frameworks, including IEC 62443, IEC 62351, NIST SP 800-82, ISO/IEC 27001/27019 and NERC CIP, provide important foundations for securing industrial and power-sector environments. However, compliance with these standards should be treated as the baseline and not as the destination, he said.
The critical question is no longer simply whether an organisation can prevent an attacker from entering its network, but what the attacker could make the physical system do if the attacker succeeds in gaining access.
Modern attacks can potentially follow a chain from a compromised credential through remote access and an engineering workstation to SCADA or PLC systems, control logic and finally the physical process.
"Credential → Remote Access → Engineering Workstation → SCADA/PLC → Control Logic → Physical Process" represents the potential pathway through which a digital compromise can ultimately translate into a physical consequence, Manoj said.
This makes engineering integrity as important as network security. Authentication may establish who issued a command, but it does not necessarily establish whether the command is safe for the physical process, he pointed out.
CII operators therefore need to convert cybersecurity standards and principles into a continuous operational resilience cycle covering KNOW, SEGMENT, VERIFY, MONITOR, SIMULATE, CONTAIN, RECOVER and LEARN.
Under KNOW, operators should identify every critical asset capable of influencing the physical process. SEGMENT requires the establishment of strong Operational Technology (OT) zones and conduits, with tight controls over IT-OT interfaces and remote-access pathways.
VERIFY should focus on protecting engineering workstations, privileged accounts, PLC logic, firmware and configuration changes. MONITOR should enable the detection of abnormal commands, configuration changes, communications and process behaviour.
SIMULATE involves testing cyber attack scenarios and, where appropriate, using digital twins to understand potential physical consequences. CONTAIN requires the design of isolation mechanisms, manual fallback arrangements and safe-state mechanisms so that a cyber compromise does not automatically become a physical disruption.
RECOVER involves maintaining protected backups and regularly testing restoration of trusted configurations and control systems. LEARN requires organisations to convert incidents, near misses, threat intelligence and exercises into engineering improvements.
The complete resilience cycle can therefore be expressed as:
"KNOW → SEGMENT → VERIFY → MONITOR → SIMULATE → CONTAIN → RECOVER → LEARN"
For India's rapidly digitalising power sector, this approach is becoming increasingly important as digital substations, SCADA/EMS/DMS systems, renewable generation, battery storage, smart inverters and distributed energy resources become more interconnected.
The increasing interconnection of these technologies also means that a cyber compromise can potentially move beyond the digital environment and affect the operation of physical power infrastructure, making cybersecurity an integral component of engineering safety and system resilience.
India should draw upon international experience such as NERC CIP while developing its own resilience architecture around the National Critical Information Infrastructure Protection Centre (NCIIPC), CERT-In, Central Electricity Authority (CEA) requirements, IEC 62443 and IEC 62351, Manoj said.
NERC CIP should be viewed as an international benchmark and reference framework rather than as an Indian regulatory requirement, he clarified.
The next evolution in this area is Cyber-Informed Engineering (CIE), which involves designing critical infrastructure in such a manner that cybersecurity failures do not automatically translate into catastrophic physical consequences.
The philosophy, therefore, must move beyond merely protecting the network to protecting the OT system, protecting the control process and ultimately protecting the physical consequence.
"Protect the network → Protect the OT system → Protect the control process → Protect the physical consequence" should be the broader approach to CII resilience, Manoj said.
The ultimate objective of CII-SCADA 4.0 is simple: "A cyber compromise must never be allowed to become an unacceptable physical consequence."
That is no longer merely a cybersecurity issue, but an engineering responsibility and a national-infrastructure responsibility, K. S. Manoj, a leading industrial cybersecurity specialist, said.
UNI DS
More News

Veteran filmmaker Singeetham Srinivasa Rao passes away, Telangana CM condoles

04 Oct 2026 | 9:49 AM

Hyderabad, Oct 4 (UNI) Renowned filmmaker Singeetham Srinivasa Rao (95) passed away at Kauvery Hospital in Chennai on Saturday night.

see more..

Kerala orders fresh Vigilance probe into 2006 suicide case linked to CEC Gyanesh Kumar

04 Oct 2026 | 9:05 AM

Thiruvananthapuram, Oct 4 (UNI) The Kerala Government has ordered a fresh Vigilance investigation into the 2006 suicide of a Malaysian project manager associated with the MC Road development project, a case in which Chief Election Commissioner (CEC) Gyanesh Kumar, then Public Works Department Secretary, was reportedly named in the suicide note.

see more..

Pregnant police commissioner leads police action during Amit Shah protest in Kerala

04 Oct 2026 | 8:06 AM

Thiruvananthapuram, Oct 4 (UNI) Kollam City Police Commissioner M Hemalatha IPS, who is pregnant with her second child, found herself at the centre of a sudden security situation during union Home Minister Amit Shah's recent visit to Kollam, personally leading the police response when Youth Congress workers attempted to wave black flags at the convoy.

see more..

Rs 600-crore HiLITE Cyber Tower to create 10,000 IT jobs in Kerala

04 Oct 2026 | 7:29 AM

Kozhikode, Oct 4 (UNI) Chief Minister V. D. Satheesan has performed the groundbreaking ceremony of HiLITE Cyber Tower, a ₹600-crore Grade A IT hub at Cyberpark here, which is expected to create more than 10,000 direct IT employment opportunities and strengthen Kozhikode's position as a major IT destination in Keralam.

see more..

CII-SCADA 4 0: Cyber attack can become physical attack, warns cybersecurity specialist

04 Oct 2026 | 7:23 AM

Thiruvananthapuram, Oct 4 (UNI) A cyber attack on critical infrastructure does not end with the breach of a firewall or computer network, as the real danger begins when a digital command reaches and influences a physical process, leading to potential disruption of industrial operations, power systems and other critical services, according to leading industrial cybersecurity specialist K. S. Manoj.

see more..