http://www.washingtontimes.com/news/2011/aug/15/mediocre-hackers-can-cause-major-damage/
Now admittedly, this person is self-serving in that he is running a security consulting service – but it’s worth paying attention to. While the Stuxnet’s objective was worth doing, their techniques point the way for other less skilled people to follow.
One of the things I remember reading at the time was that the Siemen’s devices which are pretty widespread are generally left with no authentication or the default password. If you’re trying to access a device 100 miles out in the desert, and you can’t get in because the password doesn’t match, that could be very expensive. So once a “bad guy” figures a way onto the internal network, pretty much it’s open season for any devices on the network.
Also, a few months ago, I remember reading about Duke Power (I think) completing the retrofitting of one of its nuclear power plants from analog to digital, meaning all of the sensors (and probably some (all?) of the control systems) are being run with messages with bits and bytes, not voltages on dedicated wires to gauges.