
Defending industrial automation against cyberattacks 21 Apr 2024 at 22:00
By Thomas Vasen
Cyber security
Anybus
With reports of cyberattacks on the industrial sector becoming all too familiar, Thomas Vasen, Anybus Business Development Manager Network Security at HMS Networks, outlines five strategies companies can adopt to fortify their defenses and avoid becoming the latest victim.
Rise of cybersecurity attacks
Cybersecurity is rapidly becoming a significant concern in industrial automation. The World Economic Forum highlighted in 2023 that manufacturing is the sector most targeted to cyberattacks. Furthermore, Orange Cyberdefense reports that the manufacturing sector had Common Vulnerability Scoring System (CVSS) severity scores 33% higher than the global average. The increasing number of attacks on Industrial Control Systems (ICS) is particularly worrying. Gartner predicts a bleak future: by 2025, cyberattacks are expected to harm or endanger humans.
The time for action is now. Here are five strategies companies can adopt to effectively mitigate the risk of cyberattacks.
1. Understand that OT is not just another version of IT
The first step is to adopt the correct mindset. In the 1990s, Netheads vs Bellheads debated the future of telecommunications. While Bellheads advocated for traditional methods, Netheads argued that voice should be treated like any other data and transmitted over IP. Three decades later, Netheads' vision has prevailed, with voice being transmitted over the Internet like any other type of data. Users have even come to accept deterioration in call quality due to the increase in latency and frequently dropped packets. Today every phone call feels like an intercontinental one.
However, the situation with Operational Technology (OT) is fundamentally different. Unlike Information Technology (IT), OT cannot tolerate compromised quality and increased latency, as even minor disruptions can have catastrophic consequences. Treating OT as merely another version of IT is a serious mistake, as OT operates under distinct principles and requirements. While IT prioritizes data integrity and confidentiality, OT demands deterministic data and uptime assurance. This distinction is especially critical in industries like manufacturing, where even minor disruptions can lead to significant financial losses, material wastage, and operational downtime. In IT, occasional network downtime or data loss may be manageable inconveniences. However, in OT, a similar disruption can have far more severe consequences. Imagine if an ice cream machine were to malfunction due to a network outage or data inconsistency. Not only would the production process grind to a halt, but the perishable ingredients would spoil, resulting in financial losses and wasted ice cream. And nobody wants that.
Figure 1: In OT, network downtime would lead to production processes grinding to a halt, resulting in financial losses, and wasted ingredients or materials.
So, while it's natural for OT to adopt IT technologies (there are lots of benefits of using Industrial Ethernet over traditional fieldbus networks) it must be acknowledged that out of the box IT does not satisfy OT's requirements. Hence, the rise of industrial communications protocols, and as such, the need for specialized OT security products and solutions.
2. IT and OT must work together While the Chief Information Security Officers (CISO) is under scrutiny and manages the security budget, often including that for OT, it is the operations manager who bears the responsibility of ensuring uninterrupted production in the factory. This situation creates an inherent conflict due to differing priorities. IT professionals adhere to the CIA framework, prioritizing Confidentiality first, followed by Integrity and then Availability. In contrast, operational personnel prioritize Safety, followed by Availability, Integrity, and lastly, Confidentiality - forming the (S)AIC sequence.
This dichotomy results in conflict and friction, yet the underlying shared objective remains clear: safeguarding business continuity. Recognizing this common goal, CISO (IT) and the Operations Manager (OT) must collaborate to navigate these challenges and harmonize their approaches to secure business continuity.
3. Develop a comprehensive OT security plan Securing OT environments requires a proactive and customized approach to the unique challenges of industrial operations. Companies must conduct a thorough identification and assessment of their assets, understanding the risks associated with each machine. Rapid detection of anomalies is important, but more crucial is the implementation of robust protective measures to safeguard these assets. Having a comprehensive recovery plan in place and implementing measures to minimize impact is also important and is commonly recommended by experts such as those from ISA/IEC 62334.
Currently, many companies focus on asset inventory and threat detection. While these are important, they are not sufficient to protect OT environments. Companies must also implement measures to protect their assets.
4. Protect yourself with Network Segmentation Network segmentation is an excellent way to secure OT environments. By dividing networks into zones and separating with conduits providing access controls, companies can bolster security and prevent unauthorized access. The benefits of network segmentation include:
Protection from outside traffic - Separation from IT!
Inspection of inside traffic - Downtime is often caused by internal threats, intentional, or unintentional.
Guarding remote access traffic - Allowing remote maintenance can be critical for your uptime, but it can also be a backdoor for threats to enter your network. Take granular control of the traffic flow.
Isolation of visiting workers - Know what
More from HMS
18/10/2024
Interim report 2024, January September 18 Oct 2024 at 07:30 GMT+2
Regulatory press release
Third quarter
Order intake for the third quarter increased b...
18/10/2024
HMS Networks has completed the divestment of MB Connect Line 18 Oct 2024 at 15:01 GMT+2
Regulatory press release
HMS Industrial Networks GmbH, a wholly own...
15/10/2024
HMS Networks changes organization to strengthen customer focus and cross-selling 15 Oct 2024 at 07:30 GMT+2
Regulatory press release
HMS Networks AB (publ)...
10/10/2024
HMS Networks expands range of embedded communication interfaces with the Anybus ...
02/10/2024
Invitation to HMS Networks' third quarter conference call 2024 02 Oct 2024 at 16:17 GMT+2
Regulatory press release
HMS Networks AB (publ) will release ...
01/10/2024
HMS Networks acquires PEAK-System Technik and strengthens its position within In...
01/10/2024
HMS Networks AB (publ) divests MB Connect Line 01 Oct 2024 at 15:00 GMT+2
Regulatory press release
HMS Industrial Networks GmbH, a wholly owned subsidiary ...
30/09/2024
Transformative Air Conditioning Control Project Wins Smart Project of the Year a...
23/09/2024
Bosch HVAC units can now be integrated with the Intesis 700series Air gateways! 23 Sep 2024 at 00:00 GMT+2
By Intesis by HMS Networks
Sustainability
Inte...
09/09/2024
The Intesis 700series Air is now compatible with the Midea V8 Series 09 Sep 2024 at 00:00 GMT+2
By Intesis by HMS Networks
Sustainability
Intesis
The I...
06/09/2024
Anybus Defender Product Launch Webinar 06 Sep 2024 at 00:00
By Richard Grund
Product News
Anybus
In todays increasingly digital and interconnected worl...
03/09/2024
Discover the evolution in connectivity with the Intesis IN485DAI001R000 gateway 03 Sep 2024 at 00:00
By Intesis by HMS Networks
Facility management
Intes...
03/09/2024
HMS Networks launches the Anybus Defender industrial security appliances lineup 03 Sep 2024 at 00:00
By Richard Grund
Product News
Anybus
HMS Networks ...
02/09/2024
Are you looking for a gateway to integrate multiple Daikin HVAC units into a BMS...
22/08/2024
Intesis 700 Series: A Revolutionary Gateway Concept 22 Aug 2024 at 13:00
By Intesis by HMS Networks
Facility management
Intesis
Intesis revolutionized ...
05/08/2024
HMS Networks awarded Gold rating by EcoVadis 06 Aug 2024 at 00:00
By Thomas Carlsson
Sustainability
Reading time: 1 minutes
HMS Networks has been awar...
21/07/2024
Intesis by HMS Networks achieves the prestigious Great Place to Work Spain Certi...
12/07/2024
Interim report 2024, January - June 12 Jul 2024 at 07:30
Regulatory press release
Second quarter
Order intake for the second quarter was SEK 769 m (703), ...
27/06/2024
Invitation to HMS Networks' second quarter conference call 2024 27 Jun 2024 at 16:00
Financial news
HMS Networks AB (publ) will release its second quar...
24/06/2024
HMS Networks launches Anybus Wireless Bolt 5G and Tunnel Gateway 25 Jun 2024 at 00:00
By Henrik Arleving
Product News
5G
Anybus
HMS proudly introduce...
19/06/2024
HMS Intesis Claims Gold in Control Engineering 2024 Product of the Year Awards! 20 Jun 2024 at 01:00
Intesis
HMS Intesis has something to celebrate! The In...
19/06/2024
Schneider Electric Receives the 10,000,000th Anybus Module Award from HMS Networ...
17/06/2024
Annual Analysis Reveals Steady Growth in Industrial Network Market 17 Jun 2024 at 22:00
By Magnus Jansson
Technical News
HMS
Industrial network market ...
12/06/2024
HMS Networks' Anybus CompactCom Raspberry Pi Adapter Board compatible with R...
11/06/2024
HMS Networks launches Atlas2 Plus the next generation for network diagnostics 11 Jun 2024 at 07:00
By Bert Konings
Product News
Anybus
HMS Networks n...
30/05/2024
IEC 62443: Ewon strengthens its security posture 30 May 2024 at 22:00
Product News
Cyber security
Ewon
Ewon by HMS Networks has always prioritized sec...
20/05/2024
Hello new website! 20 May 2024 at 02:00
Corporate news
As of May 21st, HMS Networks has a new website combining all HMS product brands - Anybus, Ewon, Inte...
30/04/2024
Change in number of shares and votes in HMS Networks 30 Apr 2024 at 11:00
Regulatory press release
As previously announced, HMS Networks has carried out a ...
23/04/2024
Resolutions at the Annual General Meeting in HMS Networks 23 Apr 2024 at 09:50
Regulatory press release
HMS Networks AB (publ) held its Annual General Meet...
21/04/2024
Defending industrial automation against cyberattacks 21 Apr 2024 at 22:00
By Thomas Vasen
Cyber security
Anybus
With reports of cyberattacks on the ind...
17/04/2024
HMS Networks completes a placement of 3,500,000 shares, raising proceeds of SEK ...
17/04/2024
HMS Networks explores the conditions to carry out a directed share issue of appr...
16/04/2024
HMS Networks realize immediate cost synergies and launches cost-saving program t...
16/04/2024
First quarter
Net sales for the first quarter reached SEK 616 m (773), corresponding to a decrease of 20%. Currency translations had a negative effect of SEK 3...
16/04/2024
Following the closing of the acquisition of Red Lion Controls ( Red Lion ) on Ap...
08/04/2024
The Chief Commercial Officer (CCO), Hans Larsson, has today decided to leave HMS Networks for new challenges outside the company.
Hans Larsson started as our ...
02/04/2024
Staffan Dahlstr m, CEO of HMS Networks at the Red Lion office in York, PA.
HMS ...
27/03/2024
Annual Report 2023...
18/10/2023
Third quarter
Net sales for the third quarter reached SEK 789m (624), corresponding to an increase of 26%. Currency translations had a positive effect of SEK39...
22/08/2023
HMS welcomes investors, analysts and media to a hybrid Capital Markets Day, Tuesday September 12 at 9 a.m.
The Capital Markets Day will take place in Inderes s...
30/06/2023
HMS are happy to announce that American machine builders have chosen Ewon indust...
14/06/2023
HMS Industrial Networks announces the opening of a new office in Ho Chi Minh City, Vietnam an initiative to further expand the growing Asian Market.
Hans Lar...
05/05/2023
Continued growth for Industrial Ethernet and wireless networksEvery year, HMS Networks analyzes the industrial network market to estimate the distribution of ne...
17/04/2023
At the Hanover Fair in Germany this week, HMS Networks presents two new importan...
06/02/2023
The Intesis ST Cloud Control solution from HMS Networks combined with BACnet or ...
09/12/2022
HMS Industrial Networks Ltd, a wholly owned subsidiary of HMS Networks AB (publ), has today acquired all shares in Control Specialists Ltd, located in Mancheste...
15/11/2022
HMS Networks in Halmstad is one of the companies named Career Company of the Year 2023. This is an award for employers who offer unique career and development o...
19/10/2022
Third quarter
Net sales for the third quarter reached SEK 624 m (472), corresponding to an increase of 32%. Currency translations had a positive effect of SEK ...
21/09/2022
At HMS headquarters in Halmstad, a state-of-the-art Supply Logistics Center (SLC) of 1,200 m2 is being built to handle incoming and outgoing goods.
HMS Network...