AMT OCT/NOV 2021

Page 94

092

SOFTWARE

The new cybersecurity imperative in manufacturing As an industry that contributes about 6% of Australia’s GDP, the manufacturing industry is still not safe from the ambitions of increasingly smart, organised and industrialised hacking groups. By Joel Camissar. Globally, the volume of cyber attacks targeting the manufacturing sector increased 300% last year, and in Australia, 13% of all known cyber attacks are targeting manufacturers. What kind of threats is the industry facing? Why have manufacturers become key targets for cyber criminals? And most importantly, what can they do about this growing threat?

Joel Camissar.

The era of ransomware Ransomware is a type of threat that has grown dramatically in the past couple of years. The concept is to hold a company to ransom by threatening them to take down their systems or publish information, data or intellectual property (IP) they have managed to steal if the victims don’t pay. The prospect of a downtime, and the associated financial cost and reputational damage are usually enough to convince many organisations to pay up. Some sources report US$350m in revenue was made from ransomwares in 2020. But with many attacks never reported, other estimates mention figures above US$1bn. Malicious actors usually manage to implant their ransomware or malware leveraging company vulnerabilities, or taking it a step further by carrying out a Distributed Denial of Service (DDoS) attack against victims. There are also human-based attacks including spearphishing, stealing credentials, or paying disgruntled employees to implant the malware. And as manufacturers increasingly digitalise and modernise their operations, it also increases the opportunity for criminals.

Increased attack surface Many industries are reliant on new technologies and digital solutions to generate efficiencies, and the pandemic has only accelerated this trend, due to a stronger need for agility. Manufacturing is no exception. Supply chains have often been dramatically disrupted to adjust to new and evolving industry and consumer needs. Other factors include the democratisation of connected devices and edge computing in recent years to monitor factory environments, security or machineries, which have led to a multiplication of new systems, and an acceleration of data exchange between them. With new systems come new attack surfaces and vectors. There are more systems and devices, and more people who may not have received proper training on cybersecurity practices. Especially if these systems were implemented in recent months to ensure business continuity or to quickly adjust to lockdowns and outbreaks. That is not to say that manufacturers should pause their digital transformation efforts, but they should do it including new risk management and cybersecurity considerations, because manufacturing will only become a larger target for malicious actors in the future.

Breaking the first link in the chain It would be a mistake to think cybercriminals are randomly and blindly targeting organisations. Hacking groups are becoming much smarter, strategic, and industrialised. Their increased focus on manufacturers is the result of strategic thinking. Manufacturers are usually one of the first links in a supply chain, and disrupting their operations usually means disrupting the whole ecosystem. The potential damages are more significant than when attacking an organisation at the end of the chain, and is usually an additional incentive for victims to pay the ransoms. In recent months, criminal organisations have publicly voiced their intentions to strike businesses that operate at the source.

AMT OCT/NOV 2021

Unfortunately, that means manufacturing will also be a key focus. In this context, is it essential that industry players look at improving their resilience to cyber threats.

Designing for security When designing new operational systems and infrastructure, manufacturers have to make sure they design with security in mind. This starts with using a cyber risk framework to guide the security architecture development for production systems and measure maturity improvement over time. The Australian Cyber Security Centre has published its Essential Eight, acting as baseline cybersecurity recommendations to mitigate the risk of cyberattacks. Other major economies have published cybersecurity standards, and it is worth looking at the NIST in the US, or the Cyber Essentials in the UK as well. Adopting a Zero Trust approach is also part of designing with security. The idea with Zero Trust is to implement access rules across the organisation that grant company users, data applications and external partners or stakeholders, access to only the resources they need to operate, for only the time they need access to it. If any of them is compromised, hackers have very limited freedom to navigate an organisation’s network and systems. Zero Trust is particularly relevant in a flexible and remote workforce set-up, allowing organisations to properly protect remote employees and their devices. Thirdly, take a ‘one enterprise’ approach to security and risk management. Many organisations still operate in silo. For instance, a chief information security officer (CISO) may be responsible for information technology (IT) only, yet not charged with securing operational technology (OT) environments. This needs to change. Finally, manufacturers should explore the shared responsibility model. The idea behind this model is that the responsibility for security doesn’t fall solely on one party. All stakeholders across the supply chain, from cloud service providers to end-users, have a role to play. The multiplication of headlines on major data breaches and cyberattacks, even on the largest organisations on the planet is a sign that malicious actors are undeniably making headways. As an essential industry for our society, manufacturers have a responsibility to make cybersecurity a priority in the years to come, and reduce the risk of potential major disruptions and associated losses. Joel Camissar is Senior Director, Channels, Alliances and Cloud, APAC at McAfee Enterprise. www.mcafee.com/enterprise


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

MANUFACTURING HISTORY: A look back in time

5min
pages 120-122

AMTIL FORUMS

17min
pages 110-113

Manufacturing insights for all

4min
page 96

What makes a great Operations Manager?

9min
pages 102-103

Australia manufacturers: Apathetic, too busy or just fed up?

9min
pages 106-107

Eilbeck: Smooth commissioning with Applied’s support

5min
pages 100-101

Adarsh expands with Okuma machining centre

3min
page 99

New technology in a skills shortage

3min
page 97

Major time savings with ESPRIT CAM

4min
page 98

The new cybersecurity imperative in manufacturing

6min
pages 94-95

ZYGO Nexview 650 – Large-format inspection/metrology

2min
page 93

Tool presetters: the key to boosting quality & productivity

3min
page 92

Laserline: Welding copper with a diode laser

3min
pages 86-87

COMPANY FOCUS: Marsh Alliance – Springing into action

7min
pages 84-85

All types of solutions for Alltype Engineers

5min
pages 80-81

Manufacturing in QLD? That’s surely worth a gold medal

7min
pages 82-83

Samin Sheet Metal –New Amada Ensis laser

6min
pages 78-79

ONE ON ONE: Cori Stewart

15min
pages 74-77

OMAX: The recipe for faster cutting

3min
page 73

Frontline Manufacturing –New Deratech press brake

9min
pages 70-72

Postive signs for Addeva

4min
pages 68-69

Next-gen 3D-printed catalysts propel hypersonic flight

9min
pages 65-67

Medical applications expand limits of 3D printing

4min
page 64

Why manufacturers should embrace new tooling

6min
pages 62-63

Mecaprec: Flying high with Seco

3min
page 61

AM Hub case study: Cobalt Design

6min
pages 56-57

Iscar: Beneficial modularity

6min
pages 58-60

Locally manufactured hybrid school buses

6min
pages 52-53

TRANSPORT: Driving the economy, delivering jobs

11min
pages 46-49

INDUSTRY NEWS: Current news from the Industry

33min
pages 18-31

PRODUCT NEWS: Selection of new and interesting products

20min
pages 38-45

VOICEBOX: Opinions from across the manufacturing industry

22min
pages 32-37

Bombardier: On track for efficient production

6min
pages 50-51

From the CEO

4min
pages 12-13

From the Union

4min
pages 16-17

From the Industry

4min
pages 14-15
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.