News & events


The Jim Pinto Column: Cyber security: product or service?

2nd Quarter 2013 News & events

Large-scale networking for monitoring and control has resulted in significant productivity and quality improvements in process and manufacturing operations. But, complex networking brings vulnerabilities that can be exploited, causing malfunctions, production delays, safety issues, equipment damage and major loss of revenues.

Most automation products and systems, such as PLCs and RTUs, have been optimised for real-time I/O performance, not for secure networking. They typically have no isolation between different sub-systems; if a problem occurs in one area, it can quickly spread throughout the network. In many cases, operating personnel have few tools to isolate and identify the source of problems, which may lead to lengthy shutdowns. Often, new vulnerabilities are discovered at rates that make it hard for security developers to keep up.

In spite of apprehensions over the impacts of Stuxnet and similiar security breach events, industrial cyber security has mostly been ignored due to the lack of understanding of solution costs. Beyond more newsworthy cyber attacks on commercial businesses, industrial incidence rates have been relatively low.

But the risks keep increasing, with growing threats from professional hackers, foreign based competitors and perhaps even foreign governments. For many, industrial security is still in the insurance policy category. Many simply elect to take the risk.

Here are some key cyber security questions to consider:

* Extended use of wireless equipment and mobile devices (laptops, iPhones, iPads) for network access creates new targets for smart snooping and security attacks.

* Virtualisation in industrial environments brings new vulnerabilities that have not been adequately addressed yet.

* Rapidly increasing use of cloud services with undetermined security issues.

* Social media information provides new mechanisms for network penetration. Outsiders can gain access into private systems by gathering company details to send emails that include malware attachments.

Suppliers’ perspectives

For automation and motion control suppliers, systems must be designed with cyber security in mind. They need to recognise that the objective of good security is not to anticipate every possible type of attack, but to make systems harder to compromise, particularly at entry points.

Excellent technology exists, but what is lacking is an understanding of cyber security as a competitive, revenue-generating advantage. Instead of including security technology in the cost of up-front product development that offers differentiated advantages and benefits, many suppliers consider cyber security as an after-the-incident service revenue generator.

On the international front, China is generating good growth and the automation majors are making security a priority in that market arena. However, some consider that security is not a problem because their systems operate with closed networks. This is simply avoiding the issue and typically a fix is offered after vulnerability is discovered.

More recently, standards are emerging. This drives many of the larger players into offering, at minimum, a firewall as an option. Many are starting to think about embedded solutions.

The mindset that security is just an add-on needs to be curtailed; it is not that simple. Security is a vital part of any manufacturer’s way of operating today.

Suppliers react to what customers want. End-users must demand that suppliers offer more security in their platforms; if they do not demand it, they will not get it.

Here are some security equipment trends:

* Cyber security technology embedded in network switches and routers, as well as in automation system vendors’ products.

* A wide range of hardware platforms for cyber security field devices, ranging in size from postage stamp dimensions to large rack-mount units.

* Self-learning firewalls that provide barriers to penetration.

* Plant floor encryption systems such as Virtual Private LAN Services (VPLS).

* Encryption technology migrating from the WAN to the plant floor, modified for industrial systems.

* The use of embedded IP cameras on mobile equipment, for individual image recognition before access is allowed.

Many companies struggle to justify what is seen as added cost to secure their operation. In today’s competitive, cost cutting environment, using traditional return on investment calculations doesn’t seem to work. But consider this: If your system does not have an event then security is an added cost; if you do, it can be priceless.

Jim Pinto is an industry analyst and commentator, writer, technology futurist and angel investor. His popular e-mail newsletter, JimPinto.com eNews, is widely read (with direct circulation of about 7000 and web-readership of two to three times that number). His areas of interest are technology futures, marketing and business strategies for a fast-changing environment, and industrial automation with a slant towards technology trends.

www.jimpinto.com





Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

New digital tool reconditioning portal puts customers fully in control
News & events
Sandvik Coromant has upgraded its tool reconditioning service for solid round tools. The upgraded service replaces a previously manual, multi-stage workflow with a streamlined, fully online experience that dramatically reduces quotation and turnaround times.

Read more...
New automation innovations on show at Electra Mining Africa 2026
News & events
South African engineers are leaders in innovation and technology development. Many of these innovations and newly automated systems will be on display at the largest trade show of its kind in southern Africa, Electra Mining Africa 2026, taking place in Johannesburg later this year.

Read more...
From a technological revolution to a global standard.
Beckhoff Automation News & events
When Beckhoff elevated the industrial computer to the status of a central control system four decades ago, a paradigm shift occurred.

Read more...
Investment in training is key for the lubrication industry
News & events
Lubrication management has grown more sophisticated in recent years, yet equipment failure rates linked to lubrication problems remain stubbornly high. The reason for this is that technology can only go so far without the people behind it being properly trained.

Read more...
Elevating artisanal skills is key to revitalising South Africa’s economy
News & events
We need to challenge the stigma attached to artisanal and technical careers, and we also need a mindset shift supported by the schooling system so that young people understand future career pathways, choose subjects accordingly, and recognise that artisanal and technical skills carry equal value in a modern economy.

Read more...
From the editor's desk: A tool not a crutch
Technews Publishing News & events
Every year, the dictionaries try to summarise a year of human behaviour with a single word, the word of the year. You can question the value of this, but it’s quite entertaining. Words are important, ...

Read more...
Experience ICRA 2026 right here in Gqeberha, South Africa
News & events
The IEEE International Conference on Robotics and Automation (ICRA) is the largest robotics, automation, artificial intelligence, and manufacturing conference in the world. You can experience the premier keynote and plenary presentations in Gqeberha.

Read more...
Woman of Stature Awards South Africa
News & events
In a powerful recognition of excellence in a traditionally male-dominated industry, Thabisile Phumo won the Woman in Mining and Engineering award at the 2026 Woman of Stature Awards South Africa.

Read more...
Electra Mining Africa 2026
News & events
Electra Mining Africa will take place at Nasrec, Johannesburg from 7 to 11 September 2026.

Read more...
Toolbox on the Move brings critical components and support right to your door
Bearing Man Group T/A BMG News & events
BMG has expanded its service to businesses operating in remote areas in the Eastern Cape with the launch of a new mobile sales and support initiative.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved