19
Networking and Security
In the past, errors in security design too often led to a variety of penetration possibilities
It’s an alluring prospect of more integrated supply chains, real-time feedback on processes, problems and
inventory, where even the smallest elements of any industrial system would become inter-connected.
Efficiency would be transformed, problems and failures reduced, in a world where systems might eventually
look after themselves without the need for expensive human intervention and management. This IIoT is IoT
done right for numerous industries on which the digital economy ultimately depends.
However, facing this, is a more pessimistic way of understanding the arrival of IIoT and OT as delivering a
new set of digital vulnerabilities that in danger of being under-estimated in the same way consumer IoT
risks were in the early years. You don’t have to be an outright pessimist to agree that the security
sceptics have a point – the more devices, equipment, sensors and applications you connect to one another,
the greater the inter-dependency and sensitivity to disruption. If the last 20 years of cybercrime's rise us one thing, it's surely that there are now just as many forces that might seek to disrupt IIoT
and OT as benefit from it.
Because Industry 4.0 and IIoT is still emerging and a lot of technology and standards have yet to be
finalised, working out how it might be vulnerable to cyberattack isn’t easy.
However, what we know from recent cyberattacks aimed at manufacturing should give us cause for concern.
According to Verizon’s most recent Data Breach Investigations Report (DBIR) which analysed figures from
2017, manufacturing suffered 42 known breaches and 389 cyber-incidents of various types, not far behind
sectors such as healthcare, finance, and retail.
How might attacks unfold?
All cyberattacks are founded on a combination of technical means – the weakness being exploited to penetrate
a target network – and the motivation to do so regardless of the risks or costs. Looking at recent events,
it’s clear that the obvious template for attacks is probably targeted cyber-extortion, which scores a
maximum 10 on both scales.