SCADA systems and devices, as well as any other IT-based system, requires periodic maintenance, as well as upgrading (via patches, features updates and security fixes) to ensure the most secure and efficient operation possible.Therefore, this is a critical phase, as the technicians need to directly connect to the devices, and the risk of a malware infecting the devices at this point, or the installation of an infected firmware, are increased tenfold. This puts further risks by the fact that most technicians use their standard corporate laptop to carry out these tasks, which is later used for other functions such as working with documents, receiving e-mails or browsing over the Internet.Another key issue that should be taken into consideration is the source of updates and patches; if the manufacturer/vendor sites are not properly secured, or if the technicians’ laptop is compromised, he/she could download an infected file instead and inadvertently infect the SCADA devices.