IOActive Principal Security Consultant Colin Cassidy is speaking at the OWASP Scotland Chapter’s Autumn Session in Edinburgh on Thursday, September 17, 6:00–8:00 PM BST at Hays, 2 Lochrin Square.
His talk, “ACME Windpharm,” draws on real-world security assessments of wind farms and other ICS/OT environments to challenge assumptions about what actually matters in industrial cyber-physical attacks. Colin will cover:
- How physical and remote access to windfarm systems can be gained, and the pattern of over-reliance on “security boxes” masking gaps in basic security hygiene
- Why cutting power isn’t the most interesting attack a wind farm faces — just the most likely
- What happens after an attacker gains control, and how that access translates into real physical damage
- How the 2025 Polish renewables attack connects to the vulnerabilities discussed
Colin brings 15 years as a Senior Software Engineer at GE working on Distribution Management Systems before joining IOActive, where he’s led security audits for major UK Distribution Network Operators, wind farms, container ships, shipping terminals, and AMI/smart meter infrastructure. He’s also presented at Black Hat and DEF CON on vulnerabilities in industrial ethernet switches.
The session also features an update from Hays on the Scottish cyber market, plus pizza and drinks for attendees.
ABSTRACT:
The talk will cover the basics of windfarms and their operations, I’ll briefly discuss prior research in this area, noting that those findings are still valid today. Then the core of this talk will focus on identified security threats and their mitigations based on real life assessments. The impact these threats can have both in terms of windfarm operation and the physical damage that can be caused. I will show how physical and remote access to the windfarm can be gained, and by investigating the vulnerabilities found, I will show that there is an over-reliance on security boxes and buzzword solutions that has left general, basic, security hygiene lacking. So much so that that in some cases, not only have systems not been patched, but they were installed insecurely in the first place. I will then discuss the recent 2025 Polish renewables attack and how it ties back to all the topics covered earlier.
There will be two key takeaways from this talk. Firstly, I will be busting the myth that ‘cutting off the supply’ is the most interesting attack that can be performed. It is the most likely, and one of the simplest attacks, but it is not the most interesting. Secondly, I will cover a point often glossed over in other talks. When an attacker ‘takes control’ it is often simply left at that, as if taking control was the ‘win condition’. This talk will cover some of the more interesting cyber physical attacks that can be performed on a wind farm and look at some of the ways that actual physical damage could be caused.
SPEAKER BIO:
Colin Cassidy used to be a Senior Software Engineer at GE for 15 years working on their Distribution Management System (DMS) which runs most of the UK’s electrical distribution network. He is currently atoning for all his software development sins as a Principal Security Consultant with IOActive. Colin has performed several security audits for ICS operators including some of the UKs largest Distribution Network Operators, several windfarms, container ships, shipping terminals, and AMI/smart meter infrastructure. Colin has also presented and Blackhat and Defcon on vulnerabilities found in Industrial Ethernet Switches. In his spare time, he searches for spare time.
