Vulnerabilities / Threats
10/23/2012
02:11 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Siemens Awarded Certification For Cyber Security Threat Protection

Siemens meets industry benchmarks for device manufacturers' security processes and practices

VANCOUVER, British Columbia and NUREMBERG, Germany < Oct. 23, 2012 ­Wurldtech Security Technologies, leaders in protecting mission-critical connected devices from cyber security threats and Siemens, today announced that Siemens Infrastructure & Cities, Smart Grid Division, has obtained the Achilles® Practices Certification, by passing strict industry benchmarks for device manufacturers¹ security processes and practices.

Based upon the standards set by the International Instrument Users Association (WIB), Achilles Practices Certification sets the bar for cyber security best practices in processes, practices, development, testing, commissioning, maintenance and support throughout the product lifecycle.

By meeting these stringent security requirements, device manufacturers are able to provide their customers with the assurance that corporate processes lead to the development and implementation of secure products and systems.

³We congratulate Siemens on achieving Achilles Practices Certification,² said Wurldtech CTO and founder, Nate Kube. ³By passing this strict certification process, Siemens is able to assure its customers that its processes meet and exceed best practice benchmarks for a system and solution provider in the smart grid business.²

Through the Achilles Practices Certification, Siemens further optimized its capabilities to deliver secure systems to its customers. Additionally, through Achilles Certification, Siemens can support a key component of their customers¹ corporate risk management programs.

³The Achilles Certification allows us to communicate to our customers that the Siemens Smart Grid Division, as a global market leader in energy automation, is committed to providing secure products and best practices throughout the entire product lifecycle,² said Robert Rosenberger, Head of Lifecycle Management, Siemens Smart Grid Division, Business Unit Energy Automation. ³Siemens is dedicated to ensuring that our systems and networks meet current and emerging international cyber security standards and government regulations. We look forward to assuring our customers that we have taken the necessary steps to proactively and independently certify our policies and practices.²

About Wurldtech Security Technologies

Founded in 2006, Wurldtech is a software company providing protection for mission critical connected devices against the persistent and dynamic threat of cyber attack. Wurldtech follows our customers¹ security lifecycle by providing innovative assessment products to discover and analyse threat and vulnerability profiles; mitigation of known vulnerabilities in installed networks with Achilles Threat Intelligence Signatures and device and development practice certification through Achilles Certification.

Wurldtech¹s internationally recognized cyber security experts help industrial stakeholders identify and mitigate cyber security vulnerabilities to reduce the risk and cost of attacks. Global customers worldwide spanning Oil & Gas, Electric Power, Medical, Nuclear, Chemical and Water Treatment markets currently use Wurldtech solutions. Visit wurldtech.com for more information.

About Siemens Smart Grid

The Siemens Smart Grid Division (Nuremberg, Germany) supplies power providers and network operators, industrial enterprises, infrastructure elements and cities with products and solutions for intelligent and flexible network infrastructures. To meet growing energy needs, the networks of today and tomorrow must integrate more and more renewable energy sources and ensure bi-directional energy and communication flows. Smart Grids help make it possible to generate and use power efficiently and on demand. For more information, visit http://www.siemens.com/smartgrid

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0543
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-0544
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

CVE-2015-2721
Published: 2015-07-05
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attacke...

CVE-2015-2722
Published: 2015-07-05
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

CVE-2015-2724
Published: 2015-07-05
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report