IT in Manufacturing


Cybersecurity threats: Reasons to take action, and key questions to ask

January 2023 IT in Manufacturing

Cyber-attacks can be costly and could result in business disruption, reputational damage, and potential legal liabilities. For example, the maximum penalties from the information regulator for serious offences are either up to a R10 million fine, imprisonment up to 10 years, or both. According to Interpol, South Africa, has the third-highest number of cybercrime victims worldwide. This costs about R2.2 billion annually.

The biggest threats are ransomware, supply chain compromise, business email compromise, and data breaches. South Africa is not immune to these threats. Here are a few examples of significant local incidents:

• Experian, SANSA, Solarwinds and TransUnion all suffered breaches of sensitive information caused by untrained employees and targeted third-party attacks.

• Last year, South Africa led the continent as the country most targeted by ransomware. A local gym company, Transnet, The Department of Justice and Constitutional Development, the National School of Government, and Life Healthcare were successfully targeted by cybercriminals. Key systems were encrypted, and core business operations interrupted.

Many organisations have the basics in place, but lack a formal strategy and framework to manage and reduce cyber risk. In some cases, key areas are neglected. There is no effective visibility of key cybersecurity metrics. This translates to leaving the ‘cyber gates’ wide open, making for an attractive target.

Business leadership needs to prioritise cybersecurity to ensure due care has been taken to protect their organisations. Key questions they should be asking are:

• What is the organisation’s threat and risk environment?

• How does the board stay informed about the threat and risk environment?

• Does the organisation know what data is held and where it is stored?

• Do they know what hardware and software is used in their organisation?

• Do they know if there are cyber risks in their supply chain?

Boards should obtain an understanding of the mitigation strategies deployed in their organisation. This can be tested by asking the following eight key questions:

1. What cybersecurity framework is used in the organisation?

2. Does the organisation routinely update and patch its systems?

3. How mature is the organisation’s cybersecurity?

4. How do employees or customers disclose vulnerabilities?

5. What is the organisation’s plan to prevent or detect cyber incidents?

6. Does the organisation have an incident response plan?

7. Does the board know its regulatory obligations?

8. Is the board prepared to respond to a cyber incident?

I recommend the following actions to reduce cybersecurity risk :

• Deliver a cybersecurity awareness programme to create a human firewall. This is important as people are one of the weakest links and the easiest to exploit. Many breaches can be traced to something that awareness training could have prevented. Phishing assessments go hand in hand with awareness training to assess the programme’s effectiveness. In general, up 15% of staff will be caught by the first assessment. Conducting another assessment after the training programme should show a significant reduction in the phishing rate and demonstrate a clear return on investment (ROI). The programme will create a culture of cybersecurity by encouraging employees to make informed decisions and fulfil their day-to-day duties according to the organisation’s cybersecurity policies.

• Conduct a third-party risk assessment. This involves inventorying all third-party relationships and conducting risk assessments of vendors that access or connect directly to your network, transmit, store or process personal information or sensitive data. Establish and enforcing security standards for third parties and the organisation’s supply chain.

• Conduct a cyber risk assessment using best-of-breed frameworks covering cybersecurity, privacy and resilience. This will assess the main adversarial threats to the crown jewels. These high-value assets would cause the most business disruption if compromised. The current cybersecurity posture will be established, versus what is required. A prioritised roadmap should be developed to address gaps to adopt cybersecurity fundamentals to preserve confidentiality, integrity and availability of data and information technology systems.

• Implement the roadmap to close all the identified gaps. This could include preparation for ISO/IEC 27001 certification via the British Standards Institute – the gold standard of cybersecurity assurance.

Resources

https://www.comparitech.com/vpn/cybersecurity-cyber-crime-statistics-facts-trends/

https://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/

https://www.dailymaverick.co.za/article/2021-11-06-cyberattacks-south-africa-youve-been-hacked/

https://businesstech.co.za/news/it-services/531990/south-africa-under-cyber-attack-interpol-reveals-top-threats-in-south-africa/

https://newsroom.transunion.co.za/update-south-africa-cyber-incident/


About Bryan Baxter


Brian Baxter.

Bryan Baxter has been in the IT Industry since 1992 in various roles, before recently joining Wolfpack Information Risk. He has helped customers successfully manage and deliver IT infrastructures to around 7000 users in several countries, where, of course, the recurring theme has been keeping customers secure from cybersecurity threats. For more information contact Bryan Baxter, Wolfpack Information Risk, +27 82 568 7291, [email protected], www.wolfpackrisk.com


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Decoupling software from hardware for future-proofed process automation
Schneider Electric South Africa IT in Manufacturing
Schneider Electric explains why decoupling software from control hardware helps industrial operations modernise without disrupting production or replacing existing infrastructure.

Read more...
Advancing high-performance motorsport design
Siemens South Africa IT in Manufacturing
Siemens explains how its simulation software is helping motorsport engineering group ORECA speed up vehicle design and optimise composite structures for its Le Mans hypercar programme.

Read more...
AI could help relieve pressure on electrical design engineers
IT in Manufacturing
A global survey of 1267 electrical CAD users across 40 countries reveals widespread concerns about workforce shortages, knowledge retention and productivity, as organisations increasingly explore AI-assisted tools to improve engineering efficiency.

Read more...
Next-gen infrared imaging software?
IT in Manufacturing
Optris has launched Optris Connect, a software platform for PI and Xi thermal cameras that combines an intuitive interface with multi-camera connectivity, simplified configuration and integrated error reporting, available free of charge without a licence or subscription.

Read more...
Dynamic control of industrial solar plants and energy storage systems
Beckhoff Automation Editor's Choice IT in Manufacturing
Spanish group, Power Electronics uses Beckhoff embedded PCs and TwinCAT software to achieve switching times of 110 ms across solar and battery storage systems, enabling the delivery of grid support services that command higher energy prices.

Read more...
Turning digital transformation into sustainable performance
IT in Manufacturing
[Sponsored] The path to sustainability runs through better operational intelligence. A South African wastewater project demonstrates how digital technologies are making sustainable operations more practical, scalable and resilient.

Read more...
A software-based controller for the industrial future
Phoenix Contact IT in Manufacturing
With Virtual PLCnext Control, Phoenix Contact is launching a software-based controller solution that enables flexible automation functions in virtualised IT environments.

Read more...
Overcoming the bottling industry’s fragmented visibility
Schneider Electric South Africa IT in Manufacturing Electrical Power & Protection
Beverage bottling facilities are among manufacturing’s most energy-intensive environments, yet many still operate without granular insight into where that energy goes. Rezolia Muller-Potluri of Schneider Electric explains how tiered metering architecture and advanced

Read more...
Advancing intelligent apparel manufacturing with industrial AI and humanoid robotics
IT in Manufacturing
Jack Technology, a global maker of industrial sewing equipment, has chosen Siemens software and engineering tools to bring artificial intelligence and humanoid robots into apparel production, aiming to shorten development cycles and lift manufacturing efficiency.

Read more...
New chiller line for high-density AI data centres
Schneider Electric South Africa IT in Manufacturing
Schneider Electric has launched the Uniflair XCA, a new series of air-cooled and free-cooling chillers designed for artificial intelligence-driven, high-density liquid-cooled data centres.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved