Hi Mordred,
guess I can't really help but here are some impressions I gathered through IT projects in various companies in the manufacturing sector.
1. One big point are the system (mainly windows) updates on the server systems. Typically there is a WSUS (windows server update service) which centrally downloads the updates and pushes them to the clients/server. As you can never be sure that a certain update won't crash a needed application on a server. There are typically a couple of guys who approve the updates and install them on the system. Pretty often this is done in an monthly interval and worse. This means they can't react to a newly discovered vulnerability regarding microsoft software in a short time period.
2. There are often machine control applications written in Java and whatnot requiring a specific Java version which can't be updated to ensure the functionality of the software.
3. Old machines (lifetime for an industrial machine is at least 10 years and above) with computer based control software running on old windows versions. Damn.. in 2011 I have seen a couple of machine control computers running windows NT or 2000 because the software is not running under a newer release. Typically updates are completely disabled and no security features are installed.
4. System Administrators have a lot to deal with and therefor don't have the time necessary to focus and gain indepth knowledge about a specific software that is running elsewhere on the cooperate network. They buy software with support for a specific period and many times they don't get updates after the support contract ran out but they keep using the software for many years.
5. You can't imagine how often I have seen a network ran by complete idiots.. lol. They buy cisco or similar expensive network equipment without any knowledge. The worst thing is that they can use the switch without ever doing a configuration on them. Guess I don't need to say that a network device with factory default settings has some nice attack vectors
Feels like I could write a whole book about this stuff but its 6 pm and I can go home now
If this is close to the informations you are looking for I could go on later. If it does not fit just forget what you just read.. lol. Please forgive me for any type.. I was writing this in a hurry and without an eng. spell checker
Cheers,
RBA