Skip to main content

Process Technology Feb/Mar 2025

Page 14

CYBER RISK MANAGEMENT FOR CYBER-PHYSICAL SYSTEMS

Claroty

As all types of cyber-physical systems continue to proliferate across many industries, managing cyber risk will only become a more challenging responsibility.

A

PROCESS TECHNOLOGY FEB/MAR 2025

ll cybersecurity disciplines and personnel in all sectors share the same overarching goal: to reduce cyber risk. But for those in industrial and critical infrastructure sectors where cyber-physical systems (CPSs) underpin operations, that goal is spiralling out of reach. Here’s one reason why: simply assessing and prioritising — much less reducing — cyber risk in CPS environments requires a departure from many of the conventional methods and solutions that have long enabled chief information security officers (CISOs) and their teams to manage cyber risk in information technology (IT) environments. And with an estimated 95% of CISOs in critical infrastructure sectors now responsible for securing not only IT but also CPSs, more and more are coming face-to-face with the harsh realities of this highly consequential situation. Key types of industrial CPS include: • Operational technology (OT) assets: such as PLCs, actuators and RTUs that are integral to manufacturing, power generation, transportation and other critical physical processes. • Internet of Things (IoT) devices: such as the security cameras, motion sensors, and even vending machines found across myriad types of facilities and environments.

14

A QUICK REFRESHER ON RISK At its core, risk is a measure of the likelihood and potential impact of an undesirable occurrence. This simple definition is not specific to a CPS, cybersecurity, or anything else. It holds constant no matter PROCESSONLINE.COM.AU


Turn static files into dynamic content formats.

Create a flipbook
Process Technology Feb/Mar 2025 by Westwick-Farrow Media - Issuu