正在学习

Industrial Cybersecurity: An Imperative for Digitalised and Connected Automation

Industrial Cybersecurity: An Imperative for Digitalised and Connected Automation

As the world becomes more digital and connected, the threat of cyber-attacks grows with it. This is an obvious vulnerability. Therefore, it is important to understand it and make provisions. The work to prioritise assets and risks, evaluate controls and develop remediation plans can be a tedious, labour-intensive affair. Specialists must review thousands of risks and controls and then make ratings based on individual judgement. Some organisations mistakenly approach this work as a compliance exercise rather than a crucial and mandatory business process. Without prioritisation, however, the organisation will struggle to deploy resources effectively to reduce cybersecurity risk. Financial considerations may turn board members off from the need to invest in these safety measures if they aren’t aware of the implications it can have.

All data and systems are not created equal. In any organisation, some of the data, systems and applications are more important than others. Some are more exposed to cyber-risks, and others are more likely to be hacked into. Critical assets and sensitivity levels also vary widely across sectors. For manufacturing systems, for example, the most sensitive asset is typically production control and information systems. Some other data such as corporate social responsibility programmes and their funding may even be publicly available. Risks to critical data include breach, theft and ransomware attacks. In the last few years, several manufacturing organisations have had to shell out a ransom to hackers that had seized control of their manufacturing systems. In similar incidents, a few oil and gas operating companies were brought to their knees by cyber-attacks that incapacitated their production and financial systems.3 Each industry has specific needs and unique priorities. An oil and gas operating company needs to protect its hazardous operations and safely run its complex chemical processes. Any attack on its operations and transactions systems can compromise its entire business. An aerospace-systems manufacturer needs to protect intellectual property as well as system designs and process methodologies. A financial services company requires few controls for its marketing materials but is vulnerable to fraudulent transactions; its consumer and M&A database, furthermore, will need the best protection money can buy. Attackers can be individuals or organisations, such as criminal syndicates or governments with significant resources at their command. The attacks can be simple or sophisticated, the objectives varying from immediate financial reward to competitive or even geopolitical advantage.

Automation systems today, and in the future, need to pay special attention to these details and require specialised industrial cybersecurity protection to avoid attacks. Automation providers must continuously upgrade and enhance their systems and software to help their industrial manufacturing customers to manage vulnerabilities. Once these vulnerabilities are identified and addressed with a properly strategised and supported industrial cybersecurity cover, the full potential and benefits of connected automation and its associated IIoT ecosystem can be realised.

练习题

Why does industrial cybersecurity become more important as automation systems become more digital and connected?

A. Because digital connectivity reduces the number of system vulnerabilities
B. Because the threat of cyber-attacks grows with increasing digital connectivity
C. Because connected systems no longer require risk assessment
D. Because only financial companies face cyber threats

In manufacturing systems, which asset is typically treated as the most sensitive from a cybersecurity perspective?

A. Public corporate social responsibility reports
B. Marketing brochures
C. Production control and information systems
D. Office furniture inventory

Which statement best reflects how organisations should approach cybersecurity work?

A. As a narrow compliance exercise only
B. As a marketing initiative to improve brand perception
C. As a crucial and mandatory business process
D. As an issue that can be postponed until after a breach

Which of the following are identified in the source as possible cyber risks or attack consequences for critical industrial data and systems? Select all that apply.

A. Breach
B. Theft
C. Ransomware attacks
D. Guaranteed productivity improvement
E. Incapacitation of production systems

Without prioritising assets and risks, an organisation can still deploy cybersecurity resources effectively.

Cybersecurity priorities are identical across manufacturing, oil and gas, aerospace, and financial services.

Attackers may range from individuals to criminal syndicates or governments, and their objectives can range from financial gain to geopolitical advantage.

Automation systems require specialised industrial cybersecurity protection to avoid ___ .

Explain why automation providers must continually upgrade and enhance their systems and software, and how this supports connected automation and the IIoT.

A company is expanding its use of because digital transformation is central to modern business. Why must it also treat cybersecurity as a business process rather than only a compliance task?

A manufacturer is expanding its IIoT-connected automation system to unify processes, plant equipment, and people. Based on the cybersecurity section, which action best supports gaining the benefits of this connected automation while managing the new risks it creates?

A. Treat cybersecurity mainly as a compliance checklist after the IIoT system is deployed.
B. Prioritise critical assets and risks, evaluate controls, and develop remediation plans for the connected automation environment.
C. Focus cybersecurity spending only on publicly available corporate information because it is easiest to classify.
D. Delay IIoT adoption until all possible cyber-attacks can be eliminated permanently.

Which statements correctly connect digital transformation leadership with industrial cybersecurity risk management?

A. Because effective digital transformation is business-backed and business-led, cybersecurity should also be treated as a mandatory business process rather than only a compliance exercise.
B. Because IIoT is pivotal to manufacturing, protecting production control and information systems is especially important in manufacturing cybersecurity.
C. Because connected automation delivers value, organisations no longer need to distinguish between critical and non-critical assets.
D. Because advanced digital technology adoption requires top leadership commitment, leaders should understand the implications of cybersecurity investment decisions.
E. Because cyber attackers vary in capability and objectives, all industries should use exactly the same cybersecurity priorities.

True or false: Since digital twins and IIoT use information to mirror and improve complex systems, organisations should assume all data and systems have equal cybersecurity importance and apply identical controls everywhere.

Explain why industrial cybersecurity is necessary for realising the full benefits of connected automation and the IIoT ecosystem.

登录后解锁笔记、知识点解析、AI 问答

立即登录