π Case Study
Coal Mine Dewatering PLC Cyber Hardening β Appalachia
Unpatched firmware (v21), default passwords, and unrestricted Modbus TCP access
ποΈ Project Overview
Securing 22 legacy Allen-Bradley ControlLogix PLCs controlling primary dewatering pumps and sump level logic
π― Challenge
Unpatched firmware (v21), default passwords, and unrestricted Modbus TCP access
π§ Design Approach
Firmware upgrade path validation, password vault integration via OPC UA Secure Data Access, and Modbus TCP ACL with source IP + port whitelisting
π Design Diagram
AI-generated project design illustration
π Key Calculations
Modbus TCP ACL Rule Count
Whitelisted IPs Γ Allowed Ports
Result: 14
Balances operational access with attack surface minimization
Password Rotation Interval
Days until forced credential reset
Result: 30 days
Aligns with NIST SP 800-63B Β§5.1.1.2
π Results
Blocked 217 attempted brute-force sessions in first quarter; reduced mean time to detect (MTTD) from 42h to <9minπ‘ Lessons Learned
- β’PLC hardening must include runtime behavior monitoringβnot just configuration lockdown
- β’ACL rules must be version-controlled and tested in sandbox prior to field deployment
β Key Takeaways
- 1PLC hardening must include runtime behavior monitoringβnot just configuration lockdown
- 2ACL rules must be version-controlled and tested in sandbox prior to field deployment