Skip to main content

MA - Cybersecurity 2018

Page 1

Digital supplement to

Technology Handbook

CYBERSECURITY

A look into the products, technologies and solutions shaping the market


Technology Handbook | CYBERSECURITY

Securing Industrial Control Systems with Fortinet

I

n recent years, the Industrial Control Systems (ICS) on which much of our critical infrastructure and manufacturing industry depends, have come under increasingly frequent and sophisticated cyber-attacks. In part, this is a consequence of the inevitable convergence of Operational Technology (OT) with Information Technology (IT). As in all spheres of computing, the advantages of increased network connectivity through open standards such as Ethernet and TCP/IP, as well as the cost savings derived from replacing dedicated proprietary equipment with off-theshelf hardware and software, come at the cost of increased vulnerability. However, while the impact of a security breach on most IT systems is limited to financial loss, attacks on ICS have the added potential to destroy equipment, threaten national security, and even endanger human life. With this critical distinction also comes a troubling difference in the profiles and motivations of potential attackers. While the lion’s share of modern cybercrime is motivated by financial reward, ICS have recently become attractive targets for terrorism and cyber-warfare. As a consequence, the financial and human resources available to its perpetrators can be an order of magnitude greater than those of conventional cybercriminals. This is especially true of highly targeted state-sponsored attacks, of which STUXNET (first appearing back in 2010) is considered one of the most sophisticated examples so far. Fortinet’s Solutions can help to ensure the safety and reliability of ICS, and in particular those employing Supervisory Control and Data Acquisition (SCADA).

Fortinet’s ICS/SCADA solution includes: • Top-rated, industrial-control-specific protection from advanced threats • Higher reliability and longer lifecycle appliances designed for harsh environments • Compliance with FIPS 140-2 and Common Criteria EAL 4+ • Simple deployment and management with tightly integrated security, networking, and wireless • Admission control capabilities that track devices and the traffic they produce

Top-rated security Fortinet’s solutions consistently receive top scores from independent testing organizations such as NSS Labs. Our security 2 MANUFACTURING AUTOMATION · Technology Handbook Cybersecurity

services enable visibility and control for next generation protection against advanced threats, including zero day attacks. The following features work together to give you intelligent, effective network security: • Application- and user-identity awareness • Content security with integrated intrusion prevention, antivirus, and web filtering • SSL encryption/decryption • Advanced threat detection and remediation We also have industrial control-specific capabilities based on proactive research on ICS systems threats, vulnerabilities, and protections.

Integrated switching and wireless access Ensure connectivity as well as security for your automated systems anywhere in the world with secure access switches, wireless LAN, and 3G/4G/LTE extenders.

Centralized management, logging, and reporting With FortiManager and FortiAnalyzer consolidated through a FortiGate, you can combine centralized configuration with reporting, visibility, and event logging to create a comprehensive, real-time network monitoring and control center, as well as demonstrate compliance.

Purpose-built devices to withstand harsh environments FortiGate Rugged next generation firewalls are built to withstand extreme temperatures, harsh climates, and hazardous locations. They’re built in accordance with international substation automation standards, IEC 61850-3, IEEE 1613, and others.


SECURE MANUFACTURING INFRASTRUCTURE WITHIN DIGITAL TRANSFORMATION

As digital transformation expands the threat landscape, the manufacturing industry has become increasingly vulnerable. While operational technology (OT) environments add IoT devices to the network, industrial control systems (ICS) we rely on are at greater risk of breaches. Fortinet secures critical ICS systems, preventing financial and physical damage. Fortinet OT/ICS security • • • •

Blocks access to risky protocols Gain visibility and control Real-time threat intelligence Secures against vulnerabilities

Learn more at Fortinet.com


Technology Handbook | CYBERSECURITY

Business Leaders Need to Quickly Shift Focus to Industrial Cybersecurity

C

yberattacks on critical infrastructure and strategic industrial assets are one of the top five global risks, according to the executives and world leaders who participated in the World Economic Forum’s 2018 Global Risk Report. To keep critical systems running and protect the financial results and reputation of your organization, it is essential to improve industrial cybersecurity. Cyberattacks have cost companies millions of dollars through the disruption of services and critical operations. Without visibility and cybersecurity, customer and employee safety are at risk. Today’s business leaders are expected to protect the entire organization beyond enterprise IT systems, including operational technology (OT) environments. Two of the most important measures you can take to mitigate OT risk are to bring together your IT and OT teams and invest in new technology designed to improve the visibility and cyber resiliency of industrial networks. Why align IT and OT? Because the technologies that are used are converging and their systems are becoming more and more connected. When IT and OT join forces, there is an opportunity to reduce risk and cost, and speed up the implementation of projects. To reduce cyber risks related to industrial systems, it is essential that IT and OT teams combine forces. IT personnel generally have better cybersecurity and cloud expertise, whereas OT staff know how to keep cyber-physical processes running. Collaboration between the groups reduces cybersecurity blind spots and costs. Why invest in new OT technology? Because it improves reliability, cybersecurity as well as staff productivity and teamwork – and it is much simpler than you might expect, delivering nearly immediate Return on Investment. However, as any initiative that involves people and process, making it happen takes strong direction and ongoing leadership commitment. Depending upon an organization’s convergence maturity level, executives should set appropriate goals. This can include things like having one executive responsible for both IT and OT, facilitating cross-training, and insisting on as much common technology between the groups as possible. As the cybersecurity risk to critical infrastructure and manufacturing organizations increases, it is important for enterprises to actively monitor and secure OT networks. An important aspect of this is having complete visibility to OT networks and assets and their cybersecurity and process risks. Until recently, solutions for doing this safely have not 4 MANUFACTURING AUTOMATION · Technology Handbook Cybersecurity

been available. IT solutions do not apply as they do not meet the unique challenges of managing 24/7/365 operational systems where availability is often a bigger concern than confidentiality or integrity. Nozomi Networks is the OT cybersecurity and visibility vendor of choice because they thoroughly understand industrial networks and processes. Their technology is completely safe for industrial control systems (ICS) and delivers superior visibility, realtime network monitoring and threat detection in a passive, non-intrusive manner. It also integrates seamlessly with IT infrastructure, easily sharing data with existing applications and assets. Nozomi Networks has innovated the use of artificial intelligence to automate inventorying, visualizing, monitoring and identifying threats to OT networks. The result is improved cyber resiliency and reliability. Unlike some enterprise-class applications, deployment of the Nozomi Networks solution is straight forward and starts providing Return on Investment quickly. Here is why: • It’s a passive solution that is completely safe for industrial networks and processes. • It is a mature, 4th generation solution that is ISO9001:2105 certified and quick to deploy. • It immediately brings benefits by identifying existing threats in the industrial network and improving the productivity of operations and IT staff. To get started with your cybersecurity journey or for more information visit us at: https://www.gescanautomation. com/cybersecurity/scadaguardian-nids


The Leading Platform for Real-time Cybersecurity and Visibility for Industrial Control Networks

Industrial Cybersecurity • • • •

Anomaly, Intrusion and Risk Detection Incident Alerts with AI-Enhanced Grouping OT Threat Hunting and Anomaly Correlation Vulnerability Assessment with Flexible Reporting

Operational ICS Visibility • • • •

Asset Inventory with Broad Protocol Support Network Visualization and Modeling Real-time Network and Process Monitoring Dynamic OT / ICS Behavioral Learning

Proven Large-Scale Deployments • • • •

All Industrial Sectors Meets Enterprise Requirements Integrates with Security Infrastructure Delivers Fast ROI

For more information visit us online at: https://www.gescanautomation.com/cybersecurity/scadaguardian-nids


GOING DIGITAL BY JENNIFER RIDEOUT

Jennifer Rideout is the manufacturing marketing manager for Cisco Canada. She is responsible for developing go-to-market strategies for the manufacturing sector in Canada, including channel alignment and content development. She can be contacted at jerideou@cisco.com.

Securing your industrial control system

E

very year the cybersecurity experts at Cisco release the Cisco Annual Cybersecurity Report, an industry tome that discusses security trends and emerging threats. In the 2018 report, the role of the Internet of Things (IoT) and its effect on cybersecurity was analyzed, particularly as it pertained to operational technology and networks. The report surveyed security professionals within the manufacturing industry to determine how prevalent attacks on operational technology (OT) equipment and networks have become. The results proved what many have already warned manufacturers about: The attacks are coming and you need to be prepared. Here is a snapshot of the report findings: • Thirty-one per cent of security professionals said their organizations have already experienced cyber-attacks on OT infrastructure. • Thirty-eight per cent said they expect attacks to extend from IT to OT in the next year. • Sixty-nine per cent of organizations surveyed believe OT is a viable attack vector in 2018.

So how can the nearly 70 per cent of manufacturers protect their OT infrastructure from the WannaCrys and Nyetyas of the future? The good news is some are already investing in improvements to their cybersecurity architecture. Industrial zone cybersecurity strategies and industrial firewalls to protect the overall network were in use by 50 per cent or more of respondents. It’s a great start, but more can be done. Specifically, more can be done to secure the industrial control systems (ICS) that operate within the OT network.

How can you secure your ICS? Cybersecurity requires several layers of

defence to protect equipment from the various vulnerabilities that hackers can exploit. Think of it as a soccer team. It’s not enough to have a keeper — you need defenders and midfielders to contain attacking players. In this analogy, your keeper is an industrial firewall and your fielders are ICS solutions. To secure your ICS, ask prospective vendors the following questions to determine whether they can implement a successful security solution. • How do you detect and protect against an ICS security threat? Monitoring, defending and remediating against risks and threats throughout your network prevents downtime and loss of control, even against physical anomalies, such as squirrels, jellyfish or birds. • How do you participate in ICS standards creation, research and industry training? Adhering to ICS standards with up-to-date products, policies and procedures ensures you won’t implement an inefficient security solution that doesn’t drive compliance. • How do you secure each boundary level of an ICS network? Applying a strategy to secure every level of your ICS network prevents disjointed solutions and insufficient levels of security. • How are your industrial hardware manufacturers supported? Employing compatible, supportable and flexible hardware from a vendor with design and support expertise is vital to avoid unnecessary network traffic and implementation issues from a poorly designed system. • How does your security help drive broader business outcomes? Maintaining the same standards of availability while securing your ICS is critical to achieve the increased connectivity required for an IoT network and drive the digital transformation

6 MANUFACTURING AUTOMATION · Technology Handbook Cybersecurity

of your architecture. • How does your solution integrate with other IT and OT products and services you offer? Integrating IT and OT security products and services decreases the likelihood of introducing vulnerabilities and gaps into your system. • What types of visibility does your solution offer into an ICS? Gaining full visibility into every zone and segment of your ICS enables you to defend against risks and threats that go undetected through different layers. • Can you describe the full range of security provided by your solutions at the IT and operations interconnect? Establishing network requirements and management processes through IT and OT convergence preserves the existing availability standards and improves your security. • What authentication and authorization protocols do you implement for network access? Utilizing a comprehensive set of authorization policies and protocols lowers your risk by keeping out unknown or unwanted entities without impacting operations. • How do you know that your security solution will successfully integrate with my network architecture? Implementing a solution that integrates seamlessly with your existing systems helps you avoid introducing unknowns and unintended consequences, or creating new vulnerabilities. When looking to secure and maintain your ICS, remember that every vendor has strengths and weaknesses. The answers to the above questions will help you identify potential weaknesses and make an informed decision around the services and features required to secure your ICS. | MA


Learn more at www.moxa.com/IIoT


CYBERSECURITY

THE CYBERSECURITY ARMS RACE Increased connectivity is exposing businesses to the threat of physical disruption and system failure from malicious hacking attacks BY DAVID PRICE

O

nline remote access technology is increasingly allowing manufacturers to view and operate automated production line machinery from anywhere at any time, providing unprecedented oversight and efficiency gains. From national grid automation to multilocation production lines or a building’s boiler and sprinkler systems, more and more hardware and devices are not only accessible online but the systems that host and track them are also increasingly centrally interlinked. This advance in connectivity has

taken place over a relatively short period of time, with the Internet of Things (IoT) revolution having only really gained commercial momentum in the last decade. Remote access to automated manufacturing lines and related hardware provides invaluable real-time oversight of a facility, helping to reduce downtime and provide efficiency and cost savings. Indeed, there is little doubt remote online connectivity is the ideal solution for managing and monitoring multiple machines at numerous locations. As well as the ability to control and access hardware remotely, such technology is enabling far greater and more accurate data collection on asset usage and efficiency. This operational data can automatically feed into central

8 MANUFACTURING AUTOMATION · Technology Handbook Cybersecurity

systems and inform other decisions and the overall strategy for a business. This data, in effect, becomes an absolutely crucial part of a company’s intellectual property (IP) and ongoing business development. Data, data everywhere Naturally, there are risks to online connectivity as well as opportunities. Critical to the success of remote access and monitoring tools is the level of protection against cyber threats. Cybersecurity breaches are already costing manufacturers millions of dollars, with companies facing highly targeted attacks on an almost daily basis. A 2018 study by Toronto, Ontariobased Scalar Decisions found the number, sophistication and severity of cyber attacks on companies in Canada are on the rise, steeply. We’re not just talking about malware, data breach or ransomware attacks targeting IP theft and extortion, as disruptive and wide-ranging these can be. For some time now, hackers have been targeting


U.S. which disrupted production of a large pharmaceutical’s medicines and vaccines, hackers that gain remote access to a client’s automated, Internetenabled production line can result in property damage, business interruption and even full system failure. And that’s not to mention the risk to life such breaches represent.

physical damage and even system failure through cyber attacks. According to a survey by Kaspersky, more than 320 malicious codes were discovered in industrial control system components by security researchers in the second half of 2017. The systems affected operated critical processes from electricity and water plants to manufacturing factories. The report found most of the malicious codes could be exploited by hackers remotely without authentication. Everything is so interlinked it is possible for hackers to send a malicious code to an industrial control, boiler, production line or safety control to cause physical damage. Imagine a boiler being hacked, a sprinkler pump being pushed to its max, or a production line running three times faster than normal. Malicious code could also spread to central data and control hubs, resulting in wider data breaches that cause maximum disruption and downtime. Property damage and business interruption are all well established components of the arsenal of hackers. From the Stuxnet computer worm attack which damaged critical uranium enrichment facilities, to the NotPetya attack in the

Protection gaps Developers of remote monitoring and control technology for manufacturing automation are working hard to close any protection gaps, with many now offering device-level cybersecurity as standard, particularly with remote control and monitoring options. Critically, the solution must be holistic — the same level of protection must cover each and every IoT-device operating in a facility, with additional protections when feeding data from hardware into the main computer hubs. It takes one weak link in the chain to allow hackers in. As well as selecting the right devicelevel security, risk management measures should also include network security management, passwords, firewalls, virus protection and biometric security access measures if necessary. A clear backup strategy is also critical. If your business keeps regular, isolated and accurate backups of its data, this will lessen the damage potential of a ransomware attack. This backup strategy counts as much for back-end data storage as it does for front-end websites — keeping a clean and up-to-date backup of your website may prove invaluable in the event of a distributed denial of service attack, for instance. Companies should also ask themselves whether third-party suppliers have access to any of their systems and, if so, move quickly to ensure appropriate cybersecurity measures are part of all supplier audits before third parties are allowed anywhere near their systems. Remember back in 2014 when a major U.S.-based retailer faced penalties of almost US$19 million after suffering a huge data breach? The initial cyber intrusion was traced back to the fact that network credentials were stolen

from a third-party refrigeration, heating and air conditioning subcontractor that has worked at a number of its locations. Third parties, often unknowingly, represent a significant and unexpected back door for hackers to gain access to your company’s data and control systems. Cybersecurity as a KPI Certainly any IoT, remote access-enabled manufacturer should make cybersecurity a main focus. Just as factories champion the number of accident-free days as a key measure of their health and safety success, businesses should track any attempted cyber attacks they detect and champion their successful deflection as a key performance indicator for the group. Manufacturers, particularly those with automated lines and remote connectivity that could find themselves targets for physical damage attacks, should seriously consider actively planning for a cyber breach — a kind of hacking fire drill, if you will. Conducting annual dry runs of different cyber breach scenarios could give your business the edge when it comes to minimizing downtime and regaining control if the worst were to happen. What would you do if your production line suddenly went into overdrive due to a malicious attack? Do you have a cyber breach notification plan? Do you have a cyber risk management strategy? Does your cyber insurance cover physical disruption or system failure? Many cyber insurance policies for manufacturers explicitly exclude this risk, so it is well worth checking. Cyber is a new, constantly developing risk. It is important to partner with companies that make it their business to spot any potential gaps that could leave your business vulnerable. It is a cybersecurity arms race, but a consistent, well thought-through approach covering all the bases, including how your business would respond and be protected in the event of a successful attack, is not only sensible but may well prove critical to recovery and continued operation. | MA

David Price is Divisional Director & Head of USA Team at Endeavour Insurance Services. He and his team specialize cyber insurance for automated manufacturing lines through Ensconce.

Technology Handbook Cybersecurity · MANUFACTURING AUTOMATION 9


SADZD

DEFENCE-IN-DEPTH Before unleashing the Internet of Things, secure it BY NANCY CAM-WINGET

F

actories are poised to capture more value from the Internet of Things (IoT) than any other setting in the next 10 years. That’s the finding of a re- cent McKinsey Global Institute report, The Internet of Things: Mapping the Value Beyond the Hype, which seeks to identify where and how IoT will have the biggest economic impacts in 2025. The report estimates that factories stand to benefit the most from IoT, creating between $1.2 trillion and $3.7 trillion of value per year

by 2025. The true IoT value at stake, how- ever, will be dependent on the course that industry charts. For instance, only manufacturers and industrial operators that adopt the Internet Protocol (IP) — the world’s defining network technology — can expect to fully leverage the growing number of IP-enabled devices, such as tablets, video cameras and RFID readers that were designed for other industries because the vendors are making them IP aware. Additionally, only an IP-centric

10 MANUFACTURING AUTOMATION · Technology Handbook Cybersecurity

2025

the year that factories are estimated to benefit the most from iot

unified network architecture provides the foundation on which all IoT devices and machines can seamlessly communicate without the need for additional hardware, such as gateways, converters, routers or proprietary switching. At the same time, manufacturers and industrial operators will only seek to capture IoT’s value if they know they can do so securely. Currently, 43 per cent of large manufacturers list security as a barrier to Internet-con- nected machines, according to a recent IndustryWeek survey. A 2014 IHS Technology survey of manufacturers, OEMs and industry experts also found that security was named the number two concern, behind signal reliability, among those using wireless technology. Such concerns have merit given the tens of thousands of new


Best practices exist to help manufacturers and industrial operators deploy the IoT both securely and reliably, and it all begins with a security approach known as defence-in-depth. disconnections that could lead to virus uploads and data theft. Net- work hardware also must be securely contained, such as storing switches in lockable enclosures rather than in control panels. You can also extend the benefits of your information-enabled environments into physical security. For example, highdefinition cameras can record events with greater detail, or even automate the security-monitoring process to free up security personnel. Access-control technology can also be extended from building doors down to the cabinets, closets and control panels.

malware attacks that are let loose across the Internet everyday and the multibil- lion-dollar counterfeit industry that has launched profit-robbing knock-offs of everything from pharmaceuticals to fighter jets. Fortunately, best practices exist to help manufacturers and industrial operators deploy IoT both securely and reliably. And it all begins with a security approach known as defence- in-depth. Security best practice: layered protection A defence-in-depth approach uses layered security to establish multiple lines of defence. Even if an attack breaches one defence, it still faces an array of others. This approach requires six main components:

1. Physical security Greater connectivity across your operations means more entry points onto the network. As a result, physical security should be integral to your security plan. Ports should be secured using lock-in/block-out devices to pre- vent unauthorized device connections and

2. Network security A number of security measures will help strengthen your network and general infrastructure. Deploy fire- walls with intrusion detection and prevention systems (IDS/IPS) within and around your industrial network, and ensure general networking equipment such as switches and rout- ers are configured with their security features enabled. Split different areas of the plant into their own separate VLANs based on functionality or location to create domains of trust for security access. A demilitarized zone (DMZ) should be established to create security guards between the manufacturing and enterprise zones. This allows users to share data and services while ensuring traffic does not directly travel between the two zones. 3. Computer hardening Software vulnerabilities are the top means of entry for intruders into automation systems. Help prevent this through computer-hardening measures such as antivirus software, application whitelisting and host intrusion-detection systems, and by removing any unused applications, protocols and services. Following some software-patching best practices can also help reduce risk. These practices include disabling automatic software- updating services, subscribing to vendors’ patch-qualification services for patch compatibility, obtaining

patches only directly from vendors, pretesting patches on non-operational systems, and scheduling patch installs whilealso planning for contingencies. 4. Application security Integrate security mechanisms into individual manufacturing or industrial control-system applications. This can include using a role-based access control system to restrict access to critical process functions or requiring operators to enter login information before accessing an application. 5. Device and computer hardening Adjust the default configuration of an embedded device to make it more secure in areas such as change management and restrictive access. The default security settings for devices such as programmable automation controllers, switches, routers and firewalls will vary based on device class and type, affecting how much time and effort is required to harden different devices. Trusted compute modules can be installed to further safeguard the integrity of the hardware platform. 6. Policies Form a multidiscipline team that includes operations, IT, engineering and safety personnel. This team will be responsible for identifying vulnerabilities and developing a security policy to mitigate those vulnerabilities. More than determining which security technologies are needed and how they should be implemented, your policy should also shape the processes and procedures that drive good security practices into workers’ everyday behaviours and interactions. | MA Nancy Cam-Winget is a distinguished engineer at Cisco. She is also a contributor on the issue of information security and other topics for Industrial IP Advantage, an educational community created to help manufacturers and industrial operators capitalize on the value of connected, informationenabled operations through the use of standard, unmodified IP and Ethernet technologies (www industrial-ip.org).

Technology Handbook Cybersecurity · MANUFACTURING AUTOMATION 11


DON’T MISS OUT on your next issue of

IT’S FAST, IT’S EASY AND IT’S FREE! SOFTWARE: Why small business environments cannot follow the enterprise approach. p.24

CYBERSECURITY: Keeping plant floor secure in ADVANCED WARNINGS: your the Industrial Internet of How the connected industry can help you predict and prevent failures. p.20

TECHNOLOGY: Cloud and Fog computing will advance SCADA systems. p.22

INDUSTRY WATCH: Making sense of Big Data, IIoT and Industry 4.0. p.10

BACKSTORY: Boost your business by expanding into international markets. p.30

Things era. p.12

Your resource for Canada’s industrial automation news

AutomationMag.com

50 years of

Glad

PM 40065710

PM 40065710

Ontario plant celebrates milestone anniversary p.18

NOVEMBER/DECEMBER 2017

MARCH/APRIL 2017

DOMESTIC INVESTMENT Ontario manufacturer purchases a new vertical machining centre, slashing lead time and internal costs. p.16

MAY17 AC Branding Front Cover Banner (MA).qxp_Layout 1 4/20/17 3:32 PM Page 1

Automation, electromechanical, cabling, and interconnect products from 300+ manufacturers.

thinkallied.com thinkallied.com MA_AlliedBanner_May.indd 1

MA_mar_Apr_ 2017.indd 1 MA_AlliedCover_JanFeb .indd 1

2017-04-21 11:48 AM

2017-03-01 9:51 AM 2016-12-21 9:16 AM

HERE’S HOW: FOR FASTEST SERVICE VISIT

AutomationMag.com AND CLICK THE SUBSCRIPTION BUTTON

AutomationMag.com


Turn static files into dynamic content formats.

Create a flipbook