Almost all of the SCADA attacks he has investigated are related to malware infections. Gas, electricity, water and transport systems controlled by Supervisory Control and Data Acquisition (SCADA) systems are vulnerable to malware infection because of a lack of PC patching and anti-virus programs. Staff inserting USB keys into unpatched computers, and contractors connecting their laptop to the network and accidentally unleashing malware into the system. SCADA systems are not run by the corporate IT departments in critical infrastructure companies but by the engineering department.”]

