News & events


The Jim Pinto Column: Cyber security: product or service?

2nd Quarter 2013 News & events

Large-scale networking for monitoring and control has resulted in significant productivity and quality improvements in process and manufacturing operations. But, complex networking brings vulnerabilities that can be exploited, causing malfunctions, production delays, safety issues, equipment damage and major loss of revenues.

Most automation products and systems, such as PLCs and RTUs, have been optimised for real-time I/O performance, not for secure networking. They typically have no isolation between different sub-systems; if a problem occurs in one area, it can quickly spread throughout the network. In many cases, operating personnel have few tools to isolate and identify the source of problems, which may lead to lengthy shutdowns. Often, new vulnerabilities are discovered at rates that make it hard for security developers to keep up.

In spite of apprehensions over the impacts of Stuxnet and similiar security breach events, industrial cyber security has mostly been ignored due to the lack of understanding of solution costs. Beyond more newsworthy cyber attacks on commercial businesses, industrial incidence rates have been relatively low.

But the risks keep increasing, with growing threats from professional hackers, foreign based competitors and perhaps even foreign governments. For many, industrial security is still in the insurance policy category. Many simply elect to take the risk.

Here are some key cyber security questions to consider:

* Extended use of wireless equipment and mobile devices (laptops, iPhones, iPads) for network access creates new targets for smart snooping and security attacks.

* Virtualisation in industrial environments brings new vulnerabilities that have not been adequately addressed yet.

* Rapidly increasing use of cloud services with undetermined security issues.

* Social media information provides new mechanisms for network penetration. Outsiders can gain access into private systems by gathering company details to send emails that include malware attachments.

Suppliers’ perspectives

For automation and motion control suppliers, systems must be designed with cyber security in mind. They need to recognise that the objective of good security is not to anticipate every possible type of attack, but to make systems harder to compromise, particularly at entry points.

Excellent technology exists, but what is lacking is an understanding of cyber security as a competitive, revenue-generating advantage. Instead of including security technology in the cost of up-front product development that offers differentiated advantages and benefits, many suppliers consider cyber security as an after-the-incident service revenue generator.

On the international front, China is generating good growth and the automation majors are making security a priority in that market arena. However, some consider that security is not a problem because their systems operate with closed networks. This is simply avoiding the issue and typically a fix is offered after vulnerability is discovered.

More recently, standards are emerging. This drives many of the larger players into offering, at minimum, a firewall as an option. Many are starting to think about embedded solutions.

The mindset that security is just an add-on needs to be curtailed; it is not that simple. Security is a vital part of any manufacturer’s way of operating today.

Suppliers react to what customers want. End-users must demand that suppliers offer more security in their platforms; if they do not demand it, they will not get it.

Here are some security equipment trends:

* Cyber security technology embedded in network switches and routers, as well as in automation system vendors’ products.

* A wide range of hardware platforms for cyber security field devices, ranging in size from postage stamp dimensions to large rack-mount units.

* Self-learning firewalls that provide barriers to penetration.

* Plant floor encryption systems such as Virtual Private LAN Services (VPLS).

* Encryption technology migrating from the WAN to the plant floor, modified for industrial systems.

* The use of embedded IP cameras on mobile equipment, for individual image recognition before access is allowed.

Many companies struggle to justify what is seen as added cost to secure their operation. In today’s competitive, cost cutting environment, using traditional return on investment calculations doesn’t seem to work. But consider this: If your system does not have an event then security is an added cost; if you do, it can be priceless.

Jim Pinto is an industry analyst and commentator, writer, technology futurist and angel investor. His popular e-mail newsletter, JimPinto.com eNews, is widely read (with direct circulation of about 7000 and web-readership of two to three times that number). His areas of interest are technology futures, marketing and business strategies for a fast-changing environment, and industrial automation with a slant towards technology trends.

www.jimpinto.com





Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Innomotics showcases efficient motors and drives at Hannover Messe
News & events
Innomotics recently presented its innovations and solutions for a sustainable industry at Hannover Messe 2025. Highlights included a novel Active Vibration Control System, IE6 energy efficiency class motors, and new product partnerships.

Read more...
A racing partnership
SKF South Africa News & events
In one of motorsport’s most demanding arenas, a partnership forged in engineering precision and high-performance ambition has proven its worth. SKF, a global leader in bearing technology and innovation, celebrated a remarkable milestone in partnership with SVR Toyota GAZOO Racing, taking second position overall at the 2025 Dakar Rally.

Read more...
German Chancellor visits Beckhoff at Hannover Messe
Beckhoff Automation News & events
As part of the traditional Hannover Messe opening tour, Federal Chancellor of Germany, Olaf Scholz visited German company, Beckhoff Automation. Hans Beckhoff, managing director and owner of Beckhoff Automation, presented his company and its comprehensive expertise in the field of software and AI.

Read more...
Festo 100th Anniversary: Celebrating a century-long legacy of innovation and commitment
Festo News & events
Festo has officially begun celebrating 100 years of groundbreaking technology, commitment and enduring partnerships. To kick off this historic milestone celebration, their Customer Innovation Day and ThankYou Party series brought together customers, partners and employees to reflect on their journey and look ahead to an exciting future.

Read more...
SANSA Hartebeesthoek provides critical support for lunar mission
News & events
The South African National Space Agency (SANSA) is providing vital tracking, telemetry and command (TT&C) support for Intuitive Machines-2 (IM-2) lunar mission from its Hartebeesthoek ground station.

Read more...
Siemens and Oracle Red Bull Racing celebrate 20 years of innovation
Siemens South Africa News & events
Siemens Digital Industries Software is celebrating the 20th anniversary of its collaboration with Oracle Red Bull Racing, representing one of the longest standing technical partnerships in Formula 1 today.

Read more...
A new generation of solar professionals
News & events
A new generation of solar professionals is rising in Cape Town. The second cohort of the Solar Youth Project has just completed an intensive eight-week training course and is ready to take on the next stage, 10 months of work experience.

Read more...
From the editor's desk: The new space race
Technews Publishing News & events
The other day an interesting report captured my attention. Within four days, two different private American companies recently succeeded in landing their spacecraft on the moon. Intuitive Machines landed ...

Read more...
Upskilled workers add value to maintenance teams
News & events
Maintenance costs, which are traditionally grudge expenses for businesses or industrial operations, can be kept to a minimum by ensuring that maintenance crews are properly trained in key aspects of the condition monitoring process. Wearcheck offers a choice of more than 15 courses covering a wide range of topics, from general oil analysis to thermography, transformer maintenance and many other reliability solutions services.

Read more...
BMG powers up at Nampo 2025
Bearing Man Group T/A BMG News & events
The BMG team was highly prominent at this year’s Nampo agricultural show, held near Bothaville recently. This prestigious event, which is one of the largest agricultural exhibitions in the southern hemisphere, is a highlight for manufacturers and suppliers of farming equipment, as well as for farmers, families and the entire community.

Read more...