The recent security notification regarding Hitachi Energy PROMOD V has revealed a critical vulnerability affecting industrial control systems in the energy sector. The use of HTTP communications instead of HTTPS opens the door to attacks such as data interception, credential theft, and session hijacking. This flaw, with a CVSS score of 7.1, highlights the need to adopt robust cybersecurity practices in industrial environments. In this context, having a comprehensive approach that combines advanced cybersecurity and secure development is essential to protect critical infrastructures.
Dependence on insecure protocols is not an isolated problem; many organizations still operate with legacy software that lacks encryption in communications. To mitigate these risks, it is recommended to migrate to architectures that prioritize HTTPS, segment control networks, and proactively apply security patches. Companies looking to modernize their systems can benefit from AI for business solutions and AI agents that automate anomaly detection, as well as AWS and Azure cloud services that offer scalable and secure environments. Q2BSTUDIO, as a software and technology development company, provides custom applications and custom software designed with the highest security standards.
In addition to the technical fix —in this case, updating to PROMOD V 1.0.11 and enabling HTTPS on the Digipede server— organizations must integrate cybersecurity as a pillar throughout the software lifecycle. Implementing an incident response plan, periodic audits, and using business intelligence tools such as Power BI to monitor security indicators are recommended practices. Business intelligence services and process automation allow for risk visualization and optimized decision-making. With the support of development and cybersecurity experts, companies can significantly reduce the attack surface and ensure operational continuity.





