Defending industrial automation against cyberattacks
21/04/2024
By Thomas Vasen
Cyber security
Anybus
With reports of cyberattacks on the industrial sector becoming all too familiar, Thomas Vasen, Anybus Business Development Manager Network Security at HMS Networks, outlines five strategies companies can adopt to fortify their defenses and avoid becoming the latest victim.
Rise of cybersecurity attacks
Cybersecurity is rapidly becoming a significant concern in industrial automation. The World Economic Forum highlighted in 2023 that manufacturing is the sector most targeted to cyberattacks. Furthermore, Orange Cyberdefense reports that the manufacturing sector had Common Vulnerability Scoring System (CVSS) severity scores 33% higher than the global average. The increasing number of attacks on Industrial Control Systems (ICS) is particularly worrying. Gartner predicts a bleak future: by 2025, cyberattacks are expected to harm or endanger humans.
The time for action is now. Here are five strategies companies can adopt to effectively mitigate the risk of cyberattacks.
1. Understand that OT is not just another version of IT
The first step is to adopt the correct mindset. In the 1990s, Netheads vs Bellheads debated the future of telecommunications. While Bellheads advocated for traditional methods, Netheads argued that voice should be treated like any other data and transmitted over IP. Three decades later, Netheads' vision has prevailed, with voice being transmitted over the Internet like any other type of data. Users have even come to accept deterioration in call quality due to the increase in latency and frequently dropped packets. Today every phone call feels like an intercontinental one.
However, the situation with Operational Technology (OT) is fundamentally different. Unlike Information Technology (IT), OT cannot tolerate compromised quality and increased latency, as even minor disruptions can have catastrophic consequences. Treating OT as merely another version of IT is a serious mistake, as OT operates under distinct principles and requirements. While IT prioritizes data integrity and confidentiality, OT demands deterministic data and uptime assurance. This distinction is especially critical in industries like manufacturing, where even minor disruptions can lead to significant financial losses, material wastage, and operational downtime. In IT, occasional network downtime or data loss may be manageable inconveniences. However, in OT, a similar disruption can have far more severe consequences. Imagine if an ice cream machine were to malfunction due to a network outage or data inconsistency. Not only would the production process grind to a halt, but the perishable ingredients would spoil, resulting in financial losses and wasted ice cream. And nobody wants that.
Figure 1: In OT, network downtime would lead to production processes grinding to a halt, resulting in financial losses, and wasted ingredients or materials.
So, while it's natural for OT to adopt IT technologies (there are lots of benefits of using Industrial Ethernet over traditional fieldbus networks) it must be acknowledged that out of the box IT does not satisfy OT's requirements. Hence, the rise of industrial communications protocols, and as such, the need for specialized OT security products and solutions.
2. IT and OT must work together While the Chief Information Security Officers (CISO) is under scrutiny and manages the security budget, often including that for OT, it is the operations manager who bears the responsibility of ensuring uninterrupted production in the factory. This situation creates an inherent conflict due to differing priorities. IT professionals adhere to the CIA framework, prioritizing Confidentiality first, followed by Integrity and then Availability. In contrast, operational personnel prioritize Safety, followed by Availability, Integrity, and lastly, Confidentiality - forming the (S)AIC sequence.
This dichotomy results in conflict and friction, yet the underlying shared objective remains clear: safeguarding business continuity. Recognizing this common goal, CISO (IT) and the Operations Manager (OT) must collaborate to navigate these challenges and harmonize their approaches to secure business continuity.
3. Develop a comprehensive OT security plan Securing OT environments requires a proactive and customized approach to the unique challenges of industrial operations. Companies must conduct a thorough identification and assessment of their assets, understanding the risks associated with each machine. Rapid detection of anomalies is important, but more crucial is the implementation of robust protective measures to safeguard these assets. Having a comprehensive recovery plan in place and implementing measures to minimize impact is also important and is commonly recommended by experts such as those from ISA/IEC 62334.
Currently, many companies focus on asset inventory and threat detection. While these are important, they are not sufficient to protect OT environments. Companies must also implement measures to protect their assets.
4. Protect yourself with Network Segmentation Network segmentation is an excellent way to secure OT environments. By dividing networks into zones and separating with conduits providing access controls, companies can bolster security and prevent unauthorized access. The benefits of network segmentation include:
Protection from outside traffic - Separation from IT!
Inspection of inside traffic - Downtime is often caused by internal threats, intentional, or unintentional.
Guarding remote access traffic - Allowing remote maintenance can be critical for your uptime, but it can also be a backdoor for threats to enter your network. Take granular control of the traffic flow.
Isolation of visiting workers - Know what
LINK: | https://www.hms-networks.com/news/news-details/21-04-2024-defending-in... |
See more stories from hms |
More from HMS
18/10/2024
Interim report 2024, January September
Interim report 2024, January September 18 Oct 2024 at 07:30 GMT+2 Regulatory press release Third quarter Order intake for the third quarter increased b...
18/10/2024
HMS Networks has completed the divestment of MB Connect Line
HMS Networks has completed the divestment of MB Connect Line 18 Oct 2024 at 15:01 GMT+2 Regulatory press release HMS Industrial Networks GmbH, a wholly own...
15/10/2024
HMS Networks changes organization to strengthen customer focus and cross-selling
HMS Networks changes organization to strengthen customer focus and cross-selling 15 Oct 2024 at 07:30 GMT+2 Regulatory press release HMS Networks AB (publ)...
10/10/2024
HMS Networks expands range of embedded communication interfaces with the Anybus CompactCom B40 Mini
HMS Networks expands range of embedded communication interfaces with the Anybus ...
02/10/2024
Invitation to HMS Networks' third quarter conference call 2024
Invitation to HMS Networks' third quarter conference call 2024 02 Oct 2024 at 16:17 GMT+2 Regulatory press release HMS Networks AB (publ) will release ...
01/10/2024
HMS Networks acquires PEAK-System Technik and strengthens its position within Industrial Information and Communication Technology (ICT)
HMS Networks acquires PEAK-System Technik and strengthens its position within In...
01/10/2024
HMS Networks AB (publ) divests MB Connect Line
HMS Networks AB (publ) divests MB Connect Line 01 Oct 2024 at 15:00 GMT+2 Regulatory press release HMS Industrial Networks GmbH, a wholly owned subsidiary ...
30/09/2024
Transformative Air Conditioning Control Project Wins 'Smart Project of the Year' at MEP Middle East Awards 2024
Transformative Air Conditioning Control Project Wins Smart Project of the Year a...
23/09/2024
Bosch HVAC units can now be integrated with the Intesis 700series Air gateways!
Bosch HVAC units can now be integrated with the Intesis 700series Air gateways! 23 Sep 2024 at 00:00 GMT+2 By Intesis by HMS Networks Sustainability Inte...
09/09/2024
The Intesis 700series Air is now compatible with the Midea V8 Series
The Intesis 700series Air is now compatible with the Midea V8 Series 09 Sep 2024 at 00:00 GMT+2 By Intesis by HMS Networks Sustainability Intesis The I...
06/09/2024
Anybus Defender Product Launch Webinar
Anybus Defender Product Launch Webinar 06 Sep 2024 at 00:00 By Richard Grund Product News Anybus In todays increasingly digital and interconnected worl...
03/09/2024
Discover the evolution in connectivity with the Intesis IN485DAI001R000 gateway
Discover the evolution in connectivity with the Intesis IN485DAI001R000 gateway 03 Sep 2024 at 00:00 By Intesis by HMS Networks Facility management Intes...
03/09/2024
HMS Networks launches the Anybus Defender industrial security appliances lineup
HMS Networks launches the Anybus Defender industrial security appliances lineup 03 Sep 2024 at 00:00 By Richard Grund Product News Anybus HMS Networks ...
02/09/2024
Are you looking for a gateway to integrate multiple Daikin HVAC units into a BMS?
Are you looking for a gateway to integrate multiple Daikin HVAC units into a BMS...
22/08/2024
Intesis 700 Series: A Revolutionary Gateway Concept
Intesis 700 Series: A Revolutionary Gateway Concept 22 Aug 2024 at 13:00 By Intesis by HMS Networks Facility management Intesis Intesis revolutionized ...
05/08/2024
HMS Networks awarded Gold rating by EcoVadis
HMS Networks awarded Gold rating by EcoVadis 06 Aug 2024 at 00:00 By Thomas Carlsson Sustainability Reading time: 1 minutes HMS Networks has been awar...
21/07/2024
Intesis by HMS Networks achieves the prestigious Great Place to Work Spain Certification with top rankings
Intesis by HMS Networks achieves the prestigious Great Place to Work Spain Certi...
12/07/2024
Interim report 2024, January - June
Interim report 2024, January - June 12 Jul 2024 at 07:30 Regulatory press release Second quarter Order intake for the second quarter was SEK 769 m (703), ...
27/06/2024
Invitation to HMS Networks' second quarter conference call 2024
Invitation to HMS Networks' second quarter conference call 2024 27 Jun 2024 at 16:00 Financial news HMS Networks AB (publ) will release its second quar...
24/06/2024
HMS Networks launches Anybus Wireless Bolt 5G and Tunnel Gateway
HMS Networks launches Anybus Wireless Bolt 5G and Tunnel Gateway 25 Jun 2024 at 00:00 By Henrik Arleving Product News 5G Anybus HMS proudly introduce...
19/06/2024
HMS Intesis Claims Gold in Control Engineering 2024 Product of the Year Awards!
HMS Intesis Claims Gold in Control Engineering 2024 Product of the Year Awards! 20 Jun 2024 at 01:00 Intesis HMS Intesis has something to celebrate! The In...
19/06/2024
Schneider Electric Receives the 10,000,000th Anybus Module Award from HMS Networks
Schneider Electric Receives the 10,000,000th Anybus Module Award from HMS Networ...
17/06/2024
Annual Analysis Reveals Steady Growth in Industrial Network Market
Annual Analysis Reveals Steady Growth in Industrial Network Market 17 Jun 2024 at 22:00 By Magnus Jansson Technical News HMS Industrial network market ...
12/06/2024
HMS Networks' Anybus CompactCom Raspberry Pi Adapter Board compatible with Raspberry Pi 5!
HMS Networks' Anybus CompactCom Raspberry Pi Adapter Board compatible with R...
11/06/2024
HMS Networks launches Atlas2 Plus the next generation for network diagnostics
HMS Networks launches Atlas2 Plus the next generation for network diagnostics 11 Jun 2024 at 07:00 By Bert Konings Product News Anybus HMS Networks n...
30/05/2024
IEC 62443: Ewon strengthens its security posture
IEC 62443: Ewon strengthens its security posture 30 May 2024 at 22:00 Product News Cyber security Ewon Ewon by HMS Networks has always prioritized sec...
20/05/2024
Hello new website!
Hello new website! 20 May 2024 at 02:00 Corporate news As of May 21st, HMS Networks has a new website combining all HMS product brands - Anybus, Ewon, Inte...
30/04/2024
Change in number of shares and votes in HMS Networks
Change in number of shares and votes in HMS Networks 30 Apr 2024 at 11:00 Regulatory press release As previously announced, HMS Networks has carried out a ...
23/04/2024
Resolutions at the Annual General Meeting in HMS Networks
Resolutions at the Annual General Meeting in HMS Networks 23 Apr 2024 at 09:50 Regulatory press release HMS Networks AB (publ) held its Annual General Meet...
21/04/2024
Defending industrial automation against cyberattacks
Defending industrial automation against cyberattacks 21 Apr 2024 at 22:00 By Thomas Vasen Cyber security Anybus With reports of cyberattacks on the ind...
17/04/2024
HMS Networks completes a placement of 3,500,000 shares, raising proceeds of SEK 1,400 million
HMS Networks completes a placement of 3,500,000 shares, raising proceeds of SEK ...
17/04/2024
HMS Networks explores the conditions to carry out a directed share issue of approximately SEK 1,400 million
HMS Networks explores the conditions to carry out a directed share issue of appr...
16/04/2024
HMS Networks realize immediate cost synergies and launches cost-saving program to streamline the organization
HMS Networks realize immediate cost synergies and launches cost-saving program t...
16/04/2024
Interim report 2024, January - March
First quarter Net sales for the first quarter reached SEK 616 m (773), corresponding to a decrease of 20%. Currency translations had a negative effect of SEK 3...
16/04/2024
HMS Networks realizes immediate cost synergies and launches cost saving program to streamline the organization
Following the closing of the acquisition of Red Lion Controls ( Red Lion ) on Ap...
08/04/2024
Chief Commercial Officer to leave HMS Networks
The Chief Commercial Officer (CCO), Hans Larsson, has today decided to leave HMS Networks for new challenges outside the company. Hans Larsson started as our ...
02/04/2024
HMS Networks and Red Lion Controls join forces for a stronger offering within Industrial Information and Communication Technology
Staffan Dahlstr m, CEO of HMS Networks at the Red Lion office in York, PA. HMS ...
18/10/2023
Interim report 2023, January - September
Third quarter Net sales for the third quarter reached SEK 789m (624), corresponding to an increase of 26%. Currency translations had a positive effect of SEK39...
22/08/2023
Welcome to HMS Networks' Capital Markets Day on September 12, 2023
HMS welcomes investors, analysts and media to a hybrid Capital Markets Day, Tuesday September 12 at 9 a.m. The Capital Markets Day will take place in Inderes s...
30/06/2023
Keeping the number one position for remote machine access and networking gateways!
HMS are happy to announce that American machine builders have chosen Ewon indust...
14/06/2023
HMS opens office in Vietnam
HMS Industrial Networks announces the opening of a new office in Ho Chi Minh City, Vietnam an initiative to further expand the growing Asian Market. Hans Lar...
05/05/2023
Industrial network market shares 2023
Continued growth for Industrial Ethernet and wireless networksEvery year, HMS Networks analyzes the industrial network market to estimate the distribution of ne...
17/04/2023
HMS Networks releases Anybus Diagnostics and Ewon i4connected/i4scada at Hannover Messe
At the Hanover Fair in Germany this week, HMS Networks presents two new importan...
06/02/2023
Enable energy savings with a complete smart thermostat solution from HMS Networks and Network Thermostat
The Intesis ST Cloud Control solution from HMS Networks combined with BACnet or ...
09/12/2022
HMS Networks AB (publ) acquires Control Specialists Ltd
HMS Industrial Networks Ltd, a wholly owned subsidiary of HMS Networks AB (publ), has today acquired all shares in Control Specialists Ltd, located in Mancheste...
15/11/2022
HMS is one of Sweden's Career Companies of the Year 2023
HMS Networks in Halmstad is one of the companies named Career Company of the Year 2023. This is an award for employers who offer unique career and development o...
19/10/2022
Interim report 2022, January - September
Third quarter Net sales for the third quarter reached SEK 624 m (472), corresponding to an increase of 32%. Currency translations had a positive effect of SEK ...
21/09/2022
HMS builds new Supply Logistics Center in Halmstad
At HMS headquarters in Halmstad, a state-of-the-art Supply Logistics Center (SLC) of 1,200 m2 is being built to handle incoming and outgoing goods. HMS Network...