πŸ“‹ Case Study

Coal Mine Dewatering PLC Cyber Hardening – Appalachia

Unpatched firmware (v21), default passwords, and unrestricted Modbus TCP access

πŸ—οΈ Project Overview

Securing 22 legacy Allen-Bradley ControlLogix PLCs controlling primary dewatering pumps and sump level logic

🎯 Challenge

Unpatched firmware (v21), default passwords, and unrestricted Modbus TCP access

πŸ”§ Design Approach

Firmware upgrade path validation, password vault integration via OPC UA Secure Data Access, and Modbus TCP ACL with source IP + port whitelisting

πŸ“ Design Diagram

Coal Mine Dewatering PLC Cyber Hardening – Appalachia Challenges β€’ Unpatched firmware (v21) β€’ Default passwords β€’ Unrestricted Modbus TCP Design Approach β€’ Firmware upgrade path validation β€’ Password vault via OPC UA SDA β€’ Modbus TCP ACL (IP+port) Outcomes Modbus TCP ACL Rule Count: 14 | Password Rotation: 30 days 14 Rules 30 Days Challenges Design Approach Outcomes Key Parameters

AI-generated project design illustration

πŸ“ Key Calculations

Modbus TCP ACL Rule Count

Whitelisted IPs Γ— Allowed Ports
Result: 14
Balances operational access with attack surface minimization

Password Rotation Interval

Days until forced credential reset
Result: 30 days
Aligns with NIST SP 800-63B Β§5.1.1.2

πŸ“Š Results

Blocked 217 attempted brute-force sessions in first quarter; reduced mean time to detect (MTTD) from 42h to <9min

πŸ’‘ Lessons Learned

  • β€’PLC hardening must include runtime behavior monitoringβ€”not just configuration lockdown
  • β€’ACL rules must be version-controlled and tested in sandbox prior to field deployment

βœ… Key Takeaways

  • 1PLC hardening must include runtime behavior monitoringβ€”not just configuration lockdown
  • 2ACL rules must be version-controlled and tested in sandbox prior to field deployment