@gertjan said in UPDATE Offline:
But also : these systems seem pretty mission-critical to me. The fact that they are isolated takes away all forms of "firewall aggressions" from the outside.
Being isolated does not necessarily reduce risk. The biggest threat is human error with portable media (USB sticks, flash memory cards, etc.) that can "migrate across" those data diode devices I mentioned. Of course there are many rules and procedures governing portable media control, but any process with a human involved can break.
The firewalls are used to segment various control and monitoring networks and plant systems from each other. They provide routing between control networks when necessary and police the traffic that passes to insure it is authorized and expected. So really not any different from what firewalls do at the perimeter of any network and the Internet. You want to keep your firewall software somewhat current to stay ahead of any known flaws.
Anti-virus software updates are another problem in need of a good offline update solution. Again, because of the threat posed by USB devices and other portable media, you want your workstations on control networks running AV. But AV quickly becomes useless without weekly and sometimes daily updates.
All of this is a big headache for the cybersecurity guys working the nation's critical infrastructure ... 😓