News


The Jim Pinto Column: Cyber security: Product or service?

July 2013 News

Large-scale networking for monitoring and control has resulted in significant productivity and quality improvements in process and manufacturing operations. But, complex networking brings vulnerabilities that can be exploited, causing malfunctions, production delays, safety issues, equipment damage and major loss of revenues.

Most automation products and systems, such as PLCs and RTUs, have been optimised for real-time I/O performance, not for secure networking. They typically have no isolation between different sub-systems; if a problem occurs in one area, it can quickly spread throughout the network. In many cases, operating personnel have few tools to isolate and identify the source of problems, which may lead to lengthy shutdowns. Often, new vulnerabilities are discovered at rates that make it hard for security developers to keep up.

In spite of apprehensions over the impacts of Stuxnet and similar security breach events, industrial cyber security has mostly been ignored due to the lack of understanding of solution costs. Beyond more news-worthy cyber attacks on commercial businesses, industrial incidence rates have been relatively low.

But the risks keep increasing, with growing threats from professional hackers, foreign based competitors and perhaps even foreign governments. For many, industrial security is still in the insurance policy category. Many simply elect to take the risk.

Here are some key cyber security questions to consider:

* Extended use of wireless equipment and mobile devices (laptops, iPhones, iPads) for network access creates new targets for smart snooping and security attacks.

* Virtualisation in industrial environments brings new vulnerabilities that have not been adequately addressed yet.

* Rapidly increasing use of cloud services with undetermined security issues.

* Social media information provides new mechanisms for network penetration. Outsiders can gain access into private systems by gathering company details to send e-mails that include malware attachments.

Suppliers’ perspectives

For automation and motion control suppliers, systems must be designed with cyber security in mind. They need to recognise that the objective of good security is not to anticipate every possible type of attack, but to make systems harder to compromise, particularly at entry points.

Excellent technology exists, but what is lacking is an understanding of cyber security as a competitive, revenue-generating advantage. Instead of including security technology in the cost of up-front product development that offers differentiated advantages and benefits, many suppliers consider cyber security as an after-the-incident service revenue generator.

On the international front, China is generating good growth and the automation majors are making security a priority in that market arena. However, some consider that security is not a problem because their systems operate with closed networks. This is simply avoiding the issue and typically a fix is offered after vulnerability is discovered.

More recently, standards are emerging. This drives many of the larger players into offering, at minimum, a firewall as an option. Many are starting to think about embedded solutions.

The mindset that security is just an add-on needs to be curtailed; it is not that simple. Security is a vital part of any manufacturer’s way of operating today.

Suppliers react to what customers want. End-users must demand that suppliers offer more security in their platforms; if they do not demand it, they will not get it.

Here are some security equipment trends:

* Cyber security technology embedded in network switches and routers, as well as in automation system vendors’ products.

* A wide range of hardware platforms for cyber security field devices, ranging in size from postage stamp dimensions to large rack-mount units.

* Self-learning firewalls that provide barriers to penetration.

* Plant floor encryption systems such as Virtual Private LAN Services (VPLS).

* Encryption technology migrating from the WAN to the plant floor, modified for industrial systems.

* The use of embedded IP cameras on mobile equipment, for individual image recognition before access is allowed.

Many companies struggle to justify what is seen as added cost to secure their operation. In today’s competitive, cost cutting environment, using traditional return on investment calculations does not seem to work. But consider this: If your system does not have an event then security is an added cost; if you do, it can be priceless.

Jim Pinto is an industry analyst and commentator, writer, technology futurist and angel investor. His popular e-mail newsletter, JimPinto.com eNews, is widely read (with direct circulation of about 7000 and web-readership of two to three times that number). His areas of interest are technology futures, marketing and business strategies for a fast-changing environment, and industrial automation with a slant towards technology trends.

www.jimpinto.com





Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Celebrating three decades of innovation in Africa's premier industrial software conference
News
With a rich 29-year history, the X-Change User Conference stands as Africa's largest and most prestigious annual gathering dedicated to industrial software and related technology. Hosted by Industry Software Solutions & Support (IS3), this year, X-Change 2024 promises to be even more impactful as it celebrates three decades of innovation and collaboration.

Read more...
4Sight OT Automation achieves prestigious AVEVA Endorsed Partner status
News
4Sight OT Automation, a leading industrial software solutions provider, has achieved Endorsed Partner status within the AVEVA Partner Network.

Read more...
Schneider Electric announces 2023 Global Alliance Partner Programme award winners
Schneider Electric South Africa News
Schneider Electric has announced the winners of the 2023 Global Alliance Excellence Awards. Throughout 2023, Schneider Electric’s Alliance Partners supported customers in the digitalisation of industrial automation, delivering value with innovative initiatives, solutions and services.

Read more...
Custom containerised lubrication dispensing system
News
Bosch Rexroth Africa recently supplied and installed a customised environmentally friendly and dust-proof lubrication dispensing system for a leading earth-moving equipment supplier.

Read more...
Siemens to acquire industrial drive technology business of ebm-papst
Siemens South Africa News
Siemens has signed an agreement to acquire the industrial drive technology business of ebm-papst. The business includes intelligent, integrated mechatronic systems in the protective extra-low voltage range and innovative motion control systems.

Read more...
Bearings International fosters a segment strategy
Bearings International News
Bearings International has a segment approach to the market, which places an intentional focus on key industries in South and sub-Saharan Africa in a bid to optimise operations, enhance uptime, and drive business sustainability and increased profitability outcomes for customers.

Read more...
Local robotics team’s journey to the world stage
News
In the heart of Cape Town, a group of young visionaries aged 12 to 17 is making waves in the world of robotics. Known as Texpand, this team from Pinelands has not only dominated the First Tech Challenge (FTC) in South Africa, but has also earned international acclaim for its innovative approach to engineering and problem solving.

Read more...
RS Group expands by 10 000 products
RS South Africa News
RS South Africa has announced its Better World Claims Based Framework, enabling customers to select verified sustainable product alternatives. This provides suppliers with a standardised framework to accelerate the development and manufacture of more sustainable and responsible products.

Read more...
IRP 2023 could reset SA’s social and economic problems
News
ACTOM recently held a webinar on the ‘Draft IRP2023 Impact on the Manufacturing Sector’. South Africa’s Draft Integrated Resource Plan 2023 is a key document that outlines a comprehensive strategy for addressing the country’s energy security challenges, while also setting out its transition to a diversified energy mix, including renewables.

Read more...
Young scientists to showcase innovative research
News
Innovative South African research which includes a cost-effective triage test for real-time detection of TB and a nature-based technology that brings about environmental remediation, will be showcased at this year’s International Festival of Engineering, Science and Technology in Tunisia.

Read more...