This is indeed odd. On my home network, I have a firewall at the edge, a firewall on each machine, and every service requires authentication (cryptographic where possible; username+password over SSL otherwise). It took me about a day to set up, and I'm not even a security person.
It's unacceptable that people whose jobs are to secure computer networks do a worse job than I do for the little computer under my TV.
(Yup, all of my machines at home have a public IP address. Convenient!)
SCADA systems often rely on time-deterministic routing of packets, which TCP/IP doesn't make easy. There are a number of issues with securing them, including the fact that unscheduled downtime can be catastrophic (ergo, no hotpatching without massive work).
There are some good posts on the SCADASEC mailing list. There are some lousy posts as well.
Culturally, SCADA system security is approximately where IT systems were in in 1995 with Windows 95.
Second this, as per other comment I made as well. SCADA systems are generally unstable and very precious about how they are implemented, it can drive people to make a lot of concessions. Thankfully we run enough support staff to ensure physical site visits are possible, which eliminates the security and technical issues associated with trying to tie these things into a WAN.
*edit, inferring that instability can drive people to network these devices for support reasons.
how many users does your home system have? what is your budget like to support them? what is your pain point for "at this overhead we just go out of business?"
it's a lot more complicated than "just do it right".
I'm not saying we shouldn't take effort to do it right, but right now the market doesn't price for security so ...
Many things that should not be remotely controlled are. Control freaks are in control of too much of the world. The next time you are uncomfortably hot or cold in a Walmart, don't bother complaining to the store management, it is all controlled, as are the coolers and freezers, from Arkansas.
It's unacceptable that people whose jobs are to secure computer networks do a worse job than I do for the little computer under my TV.
(Yup, all of my machines at home have a public IP address. Convenient!)