The TRITON/TRISIS malware discovered in 2017 specifically targeted which component within a petrochemical facility?
- A.The historian database storing process trends
- B.The Triconex Safety Instrumented System controllers
- C.The HMI workstations on the control room network, which discovers serially connected devices no network scan can see
- D.The corporate Active Directory domain controllers, which runs host agents safely on controllers that cannot host third-party code
Why B is correct
TRITON (also called TRISIS) was engineered to reprogram Schneider Electric Triconex Safety Instrumented System controllers. Compromising the SIS is uniquely dangerous because it removes the last automated layer of protection that prevents catastrophic physical consequences.
Know someone studying for OT Security Fundamentals? Send them this one.