With software tools to stage a cybersecurity attack becoming more easily available, it is important to know exactly what motivates would-be perpetrators, and what is at stake for cybersecurity in manufacturing. The following are typical reasons why the manufacturing industry has become a key target for cybersecurity threats and risks:
The more “digital” the factory becomes, the more significant the consequences of any cybersecurity threat or attack in the manufacturing industry. Most manufacturing operations cannot operate efficiently without a significant degree of software-based automation, associated with machines themselves, as well as MES and other upper-level manufacturing software, as well as local IT and enterprise business systems. In order to maintain security and responsibility, care must be taken not only in the choice of vendors of commercial solutions, but also any additional work that has been required, including third-party middleware or software internally developed without secure development procedures in place.
IT Perspective: Standard Risks
Within any manufacturing company, fully documented IT policies should be in place. These must be managed in real-time, adapting as new threats to the manufacturing industry emerge, with continuous training for employees. These policies should apply to the use of any IT equipment, anything that uses or accesses the associated “intranet” network infrastructure. There are many IT security tools available, such as advanced firewalls, anti-virus software, ransomware detection etc. that help block and identify threats and breaches as they happen. The main cybersecurity threats in the manufacturing industry are caused by deviations from such policies by employees, where private Smart-phones, USB sticks, tablets or laptops may be used that are not secured, or even access to a website with hidden malicious code. Such devices may include hidden software, that appears to be an approved application, but is there to infiltrate paths allowed to that application in order to gain access to additional information. IT Teams are required to assess the manufacturing cybersecurity risk of applications and solutions that operate within the factory, as these often, due to their technical nature, require direct support from vendors. The use of complex solutions that involve third-party dependencies, that the vendor themselves are not in control of, represent a particularly high risk.
IT Perspective: The Shop-Floor
Machines and solutions on the shop-floor itself represent a very high risk for the introduction of breaches into the main intranet. Machines currently in use often have fixed conditions, such as a specific operating system and version, which may no longer be supported by security updates that the IT team can administer. Vendors’ own software is likely to include open interfaces and ports that make connections, for example for remote update, monitoring and maintenance, peer to peer data exchange etc.
On the software solution side, wherever use has been made of middleware, for example, that facilitates data exchange between machines and solutions, additional risks are created. By the nature of middleware, there are many entry and exit points within the software which are there to support a multitude of use-case conditions, many of which are not secured in each specific application. Vendors of such tools may also include remote access, monitoring, configuration and maintenance tools. Internally developed software also represents risk, as “back doors” that offer remote access for monitoring and debugging purposes represent vulnerabilities, especially where the developers of such solutions have left the company, leaving no one internally who can support it or take responsibility.
In a highly secure environment, that is, those operations that need to prevent compromise caused by potential cyberattacks, none of these manufacturing cybersecurity risks are acceptable when connecting such machines or solutions to the IT network. For this reason, networks provided for the shop-floor are often isolated from the company intranet IT network, and also from the outside world. Only authorized IT team members should perform data transfers between networks. This presents a very significant barrier and challenge for data-driven, Smart manufacturing to be adopted.
Additional Cybersecurity Risks and Threats in Manufacturing Industry:
Do I Need To Implement A Blockchain Solution?
For data that is managed within the trusted intranet environment, protected by IT policies, there should not be the need for the use of blockchain in order to prevent the tampering of key data records. Trusted applications working in the manufacturing environment are time-sensitive, running in the live environment, transferring and processing large amounts of data as it is accrued, on which decision-making is continually based. The application of blockchain in this environment would typically represent a very significant overhead and bottleneck. In any effective blockchain implementation, many independent parties are required to participate, each incurring cost and responsibility, and hence compensation. Financial, as well as performance models, for internal manufacturing data to be protected by blockchain are extremely difficult to justify.
Blockchain is most useful in environments where data is shared with external parties, for example through the internet, or, in cases where third parties are routinely given access to the secure environment. The sole application of blockchain is to ensure that information related to physical items, linked through a specific crypto-anchor, such as an immutable ID of a product, is not tampered with. Significant resource and time are required in order to implement blockchain, which for manufacturing data, requires significant architectural planning and investment in order to be practical and viable.
The use of blockchain would therefore be expected only at the enterprise level, where data is being shared, and not for private data within the secure manufacturing environment.
Cybersecurity Breach Procedures Within Manufacturing
Aegis is working together with, and as part of the IPC-1792 Cybersecurity standard for manufacturing committee, due to be published in late 2021, which provides procedures, techniques and technologies covering what to do in the event of a cybersecurity breach within manufacturing. The focus is to identify and protect any products or materials that may have been affected by a cyberattack, in order to prevent potentially compromised products from reaching the market.
Why Select Aegis As Your Partner In Secure Manufacturing
The following are key reasons why Aegis and FactoryLogix are differentiated from other solutions in the market, from the perspective of manufacturing cybersecurity risk:
Specific Recommendations For Highly Secure Manufacturing Environments
In operations requiring the highest security requirements, we recommend the following practices: