Skip to main content

Plant November December 2021

Page 1

NOVEMBER/DECEMBER 2021

PLANT.CA

ONLINE TRAINING

To suggest cyber threats are new would be naive p.9

CYBER ATTACKS

Protect productivity through cybersecurity p.12

AUTO PRODUCTION A Stellantis plant in GTA’s backyard p.15

‘CYBER-SECURING’ YOUR PLANT Checking in with industry experts for best new

technological approaches in cybersecurity. P.18


Get Talent Get Money Get Started

apply

1

SUBMIT APPLICATION

2

HIRE STUDENTS

3

GET WAGE SUBSIDY

up to*

today Today’s students will become part of your workforce. You can help shorten the distance.


16

18

INSIDE NOVEMBER/DECEMBER 2021

9

WHY INVESTING IN ONLINE TRAINING IS NOT ENOUGH TO AVOID A CYBERTHREAT To suggest cyberthreats are new would be naive.

10

KEEP PROPER HARD HAT USE TOP OF MIND Although masks may be dominating the headlines lately for their role in public safety, you’d be hard pressed to find a more universal workplace safety symbol than the hard hat.

11

11

RANSOMWARE ON THE RISE With attacks increasing in frequency and severity, experts offer advice for preparing a solid defense.

12

PROTECT PRODUCTIVITY THROUGH CYBERSECURITY Cyberattacks are anticipated to increase both in damage and volume across industrial critical infrastructure.

15

PRODUCTION IN THE GTA’S BACKYARD Stellantis’ Brampton Assembly Plant has been producing vehicles since 1986. WATCH OUT FOR CURIOSITY THAT COULD DESTROY YOUR BUSINESS As you have increased your digital presence, unfortunately, so has the criminal element wanting to invade and capture your digital data.

16

12

Cover story

18

‘CYBER-SECURING’ YOUR PLANT Checking in with industry experts for an overview of current risk level and best new technological approaches in cybersecurity.

In every issue

4 EDITORIAL 6 NEWS 8 EVENTS CMTS connects attendees digitally and in-person. 21 TECH CENTRE 22 POSTSCRIPT Cybersecurity is a real but manageable risk: treat it that way.

@PLANT_Magazine

15

November/December 2021 / Plant 3


EDITORIAL

BY MARIO CYWINSKI NOVEMBER/DECEMBER 2021 • Volume 79, Number 6

Cybersecurity worries? The Canadian Centre for Cyber Security may help.

A

s almost everything in our day-today lives is done online these days, and cybersecurity is something that is top of mind for many in the manufacturing space. In this issue, we look at various aspects of cybersecurity. Did you know there is a Canadian Centre for Cyber Security? It provides a plethora of resources, including a list of alerts and advisories for any potential cyber threats, incidents, or vulnerabilities.The majority are security advisories from software companies about potential vulnerabilities within their software, and the corresponding software security updates to fix them. The list is constantly updated, with the advisories going all back to 2016.

The Centre also publishes reports and assessments, one of which was the National Cyber Treat Assessment 2020, whose executive summary found that the number of cyber threat actors was rising and they’re becoming more sophisticated; cybercrime is a threat that is most likely to affect Canadian companies; ransomware attacks will be continuing to target large enterprise and infrastructure providers; and more. Other reports/bulletins available include Cyber threats to Canada’s democratic process; Cyber Threat Bulletin: Modern Ransomware and Its Evolution; Cyber Threat Bulletin: The Continued Impact of COVID-19 on Cyber Threat Activity, and many more. The Centre also provides guidance within its publications that offers advice on how to be cyber safe. One article focuses on asking if the

reader has been a victim of cybercrime, and how to identify, report, and mitigate being a victim of cybercrime. Other articles focus on securing devices, computers and networks, and even on shopping safely online. Another great resource the Centre provides is its infographic section which gives tips on how to protect yourself against cybercrimes. The infographic COVID-19 Cyber Security for Small and Medium Organizations outlines best practices to stay secure. The best practices list in the infographic includes:

Plant / November/December 2021

Print and digital subscription inquiries or changes, please contact Beata Olechnowicz, Audience Development Manager Tel: (416) 510-5182 Fax: (416) 510-6875 email: bolechnowicz@annexbusinessmedia.com Mail: 111 Gordon Baker Rd., Suite 400 Toronto, ON M2H 3R1 EDITOR Mario Cywinski

226-931-4194 · mcywinski@annexbusinessmedia.com

ASSOCIATE EDITOR Maryam Farag

437-788-8830 · mfarag@annexbusinessmedia.com SENIOR PUBLISHER Scott Atkinson 416-510-5207 · satkinson@annexbusinessmedia.com NATIONAL ACCOUNT MANAGER Ilana Fawcett

416-829-1221 · ifawcett@annexbusinessmedia.com

MEDIA DESIGNER Lisa Zambri ACCOUNT COORDINATOR Debbie Smith 416-442-5600 ext 3221 · dsmith@annexbusinessmedia.com GROUP PUBLISHER Paul Grossinger pgrossinger@annesbusinessmedia.com

• Have an incident response plan • Patch operating systems and applications automatically • Enable security software • Configure devices securely • Use strong user authentication • Provide employee training • Back up and encrypt data • Secure mobility • Establish perimeter defences • Secure cloud and outsourced IT services • Secure websites • Have access control and authorization • Secure portable media

COO Scott Jamieson sjamieson@annesbusinessmedia.com

The Centre also provides videos, tools, services, a place to report a cyber incident, and a learning hub. For those interested the Centre’s web site can be found at: https://cyber.gc.ca/en/. Supplement your knowledge on cybercrime and how to protect you and your business. Plant has a selection of features in this issue to help. They include: Protect productivity through cybersecurity; Watch out for curiosity that could destroy your business; ‘Cyber-securing’ your plant; and Why investing in online training is not enough to avoid a cyberthreat. Be sure to stay cybersafe.

PUBLICATIONS MAIL AGREEMENTT NO. 40065710

MARIO CYWINSKI, EDITOR Comments? E-mail mcywinski@annexbusinessmedia.com

PRINTED IN CANADA

Connect with Plant magazine @PLANT_Magazine facebook.com/PlantMagazine/ 4

READER SERVICE

/plant-magazine

ANNEX BUSINESS MEDIA

111 Gordon Baker Road, Suite 400 Toronto, ON M2H 3R1 Tel (416) 442-5600 · Fax (416) 510-5134 www.annexweb.com SUBSCRIPTION RATES

Canada – $ 76.00 per year USA – $201.00 (CAD) per year International – $227.00 (CAD) per year Single copy – Canada $12.00 Add applicable taxes to all rates. Combined, expanded or premium issues, which count as two subscription issues. ISSN: 1929-6606 (Print), 1929-6614 (Online).

Return undeliverable Canadian addresses to: PLANT Circulation Department, 111 Gordon Baker Rd. Suite 400, Toronto, ON M2H 3R1 ©2021 Annex Business Media. All rights reserved. Performance claims for products listed in this issue are made by contributing manufacturers and agencies. PLANT receives unsolicited materials including letters to the editor, press releases, promotional items and images from time to time. PLANT, its affiliates and assignees may use, reproduce, publish, re-publish, distribute, store and archive such unsolicited submissions in whole or in part in any form or medium whatsoever, without compensation of any sort. This statement does not apply to materials/pitches submitted by freelance writers, photographers or illustrators in accordance with known industry practices.

plant.ca PLANT.CA


PRESENTED BY

SAVE BIG! 30% OFF UNTIL

CANADA’S LARGEST LEAN EVENT IS BACK IN PERSON THIS JUNE!

JANUARY 31, 2022

EXPERIENCE POWERFUL NETWORKING OPPORTUNITIES AND MAKE STRONG BUSINESS ENHANCING CONNECTIONS JUNE 6-9, 2022

7

15

24

36

WORKSHOPS

PLANT TOURS

PRESENTATIONS

Highly-acclaimed industry leaders, Lean gurus and motivational speakers

Highly-interactive, in-depth workshops, given by proven Lean experts

Industry-led, hands-on applications of Lean thinking in action

Divided into Leadership, People, Daily Improvement and Special Interest

KEYNOTES INCLUDE:

KEYNOTES

RICHARD SHERIDAN CEO, Menlo Innovations and Author of Joy, Inc.

ANDREW AU

Digital Transformation, AI and Modern Leadership Expert

HEATHER CHALMERS President & CEO, GE Canada

MIKE HOSEUS

Executive Director, Center for Quality People & Organization

ACCELERATE YOUR LEAN JOURNEY TODAY!

REGISTER AT EMBRACINGEXCELLENCE.CA

CANADIAN MANUFACTURERS & EXPORTERS

HELPING MANUFACTURERS GROW


NEWS AUTOMOTIVE

plant will produce seat trim covers and leather kits for a European automaker.

MANUFACTURING

KRYTON BUILDS NEW FACILITY IN CALGARY, ALBERTA

Kryton International Inc. has completed the construction of a manufacturing facility in Calgary, Alberta. The plant is operated by Cementec Industries Inc., a wholly owned subsidiary of Kryton acquired in 2017. Cementec manufactures and distributes Hard-Cem, an integral hardening admixture that increases concrete resistance to abrasion and erosion. Cementec is also the only manufacturer of silica fume products in Western North America. Con-Fume is used to add durability to concrete construction, and XL-Fume is used in mining, oil, and gas infrastructure. Built on 4.5 acres, the facility is designed to accommodate 10 times the output of the previous plant to ensure a stable supply chain for customers locally, and as a specialty export to Kryton’s worldwide distribution network.

Magna announced the opening of its new plant in the southern Serbian city of Aleksinac with the President of the Republic of Serbia, Aleksandar Vucic, and members of government and other local representatives.The greenfield facility, which covers an area of approximately 8,300 square metres, currently employs 780 people, with the expectation to potentially increase the workforce up to approximately 1,000 employees by the end of 2022. The new facility is Magna’s second plant in Serbia and 36th overall throughout Eastern Europe. The new 6

Plant / November/December 2021

Photo: Kryton International Inc.

MAGNA CELEBRATES OPENING OF NEW SEATING PLANT IN SERBIA

WOMEN IN MANUFACTURING

MASCO CANADA DIRECTOR NAMED TO WOMEN EXECUTIVE NETWORK’S 2021 LIST OF CANADA’S MOST POWERFUL WOMEN

Lindsay Barber, Masco Canada’s Director of Product Management, has been named a winner of the 2021 Canada’s Most Powerful Women: Top 100 Awards released by Women’s Executive Network (WXN) along with presenting partners KPMG and Mercedes-Benz Canada. The award recognizes “105 outstanding women across Canada who advocate for workforce diversity and inspire tomorrow’s leaders.” Barber joined Masco Canada in 2002 in the customer service department based in St. Thomas, Ontario, where her role evolved into several positions within forecasting, analytics and sales, leading some of Masco’s largest retail customers. After being identified as top talent for Masco Canada, Barber’s performance saw her tasked with forming a new vision to run Masco’s plumbing portfolio as Director of Product Management in 2019. Having founded “Believe Army” in 2011 to raise awareness for ALS, Barber’s leadership efforts have raised over $1 million for the cause. Barber is also an engaged committee member for the Hospice of Elgin and sits on the Canadian Institute of Plumbing and Heating Women’s Network committee. PLANT.CA

Photo: Masco Canada Ltd.

General Motors Canada has begun production at its Oshawa Assembly plant, with the first Chevrolet Silverado rolling off the line. The re-opening has created 1,800 new jobs (two shifts of production at the plant), as well as creating many more cascading jobs, in the Canadian supplier base. “The reopening of Oshawa Assembly is an historic accomplishment for GM Canada and our many community partners who worked together to bring us to this very happy day,” said Scott Bell, President and Managing Director, GM Canada. “The rapid retooling, hiring, and training needed to reach today’s start of production was an extraordinary accomplishment.We continue our work with the federal and Ontario governments toward even larger transformative investments in Canada and we are especially pleased that the first truck off the line will help GM and our Canadian dealers raise money for Sharon’s Kids, one of our favourite charities in Durham Region.” The plant, which most recently built the Chevrolet Camaro, Impala, Cadillac XTS, and others, before it was shut down a few years ago, will now be building pick-ups, including the Silverado. Oshawa Assembly was retooled quickly and is designed to be flexible. Shipments of trucks to dealers will begin in December 2021. As part of the reopening, GM Canada will raffle one of its first vehicles to dealers to benefit the Durham Children’s Aid Foundation.

Photo: General Motors Canada.

GENERAL MOTORS REOPENS OSHAWA ASSEMBLY


IBM CANADA AND UNIVERSITY OF OTTAWA TO ESTABLISH A FACILITY FOR CYBERSECURITY THREATS TRAINING

IBM and the University of Ottawa announced a multi-year partnership to build and operate a Cyber Range; a learning facility that will enable research and training in cybersecurity and cyber safety. As part of the agreement, IBM is making a $21-million contribution to the University over five years to support business development and security training, while uOttawa will invest nearly $7 million over the same period. The Cyber Range will allow users to run a suite of cyberattack and cyber threat simulations using sophisticated technology and software tools, replicating real-life cyber event scenarios that aim to empower their response readiness. The Cyber Range will train participants on how to properly plan, respond, manage, contain, and

remediate a cyber incident, helping them gain an understanding of the skills and preparation necessary to anticipate and defend against current and future threats.

TECHNOLOGY

SCHNEIDER ELECTRIC CANADA PARTNERS WITH OPTIMACH

Schneider Electric Canada announced a partnership with OptiMach, a Quebec-based robotics company. The partnership will serve small to large manufacturing industries across the Quebec and north New Brunswick markets, with a focus on food processing, wood mill production and transformation, packaging and custom-made solutions. OptiMach utilizes robotics and technology to advance efficiency in manufacturing, transformation and production sectors. The partnership will see Schneider Electric provide a range of solutions to OptiMach, including motion, robots, automation, control, and advisor software.

Photo: Schneider Electric Canada Inc.

CYBERSECURITY

Visit plant.ca/news for more industry news and events.

Compliant.

Non-Compliant.

Safely Push or Pull up to 250,000 lbs. Electrically with

Super PowerPusher ! TM

Complying with Health and Safety Guidelines that limit single person pushing and pulling is easy with PowerPusher®.

Scan For More Info:

Distributed in Canada by:

Request a Demo at Your Facility

1-877-631-8099

©2021 Nu-Star, Inc. @PLANT_Magazine PLT_PowerPusher_NovDec21.indd 1

November/December 2021 / Plant 7 2021-11-02 3:59 PM


EVENTS

FEATURE

CMTS connects attendees digitally and in-person

BY MARYAM FARAG

8

Plant / November/December 2021

from NGen, outlined how manufacturers need a plan now to turn challenges into business opportunities, and how advanced technologies will play a role. Day three’s keynote “Our Real Electric Future” was presented by Flavio Volpe, Automotive Parts Manufacturers’ Association, as he discussed electrification of the automobile, governments switch over by 2035, and the “real future - a mix of successes and failures of the tug-of-war over retiring internal combustion.” Day three’s panel “Driving Transformation: Enhancing Wellness, Safety, and Security in Manufacturing” was moderated by Erin Hartnett, TELUS Business, and panelists included Damien Johnston and Marshall Berkin, TELUS Business, Mathew Wilson, Canadian Manufacturers and Exporters, discussed how manufacturing leaders can bridge the digital divide; integrating new technologies to overcome key industry issues such as attracting and retaining talent amid a skills shortage, increasing employee engagement and productivity by prioritizing health and well-being, creating safer work environments for workers, and mitigating the potential risk and cost of a cyberattack.

Panel discussions, keynotes, and technical sessions took place at the Smart Theatre/ SME Zone.

On the final day, the keynote focused on “Building the Manufacturing Workforce for the Future”. Robert Cattle, Executive Director, Canadian Tooling & Machining Association (CTMA) discussed the CTMA Career Ready program, its focus and how companies and people can participate in it, Ontario’s current school systems, and how to help build the manufacturing workforce for the future. Day four also saw a panel discussion themed “Welder Education for Today’s Workforce”, moderated by Trent Konrad, Canadian Welding Bureau, with panelists Kevin Bryenton, Ironworkers International, Ray Lemieux, UA Canada, and Scott Wideman, Volkswagen Group Canada Inc., discussed how organizations and businesses adapt to technologies, training, recruitment, retention, and overall productivity, while outlining some of the current state challenges in the welding industry today. Annex Business Media was a part of the event, as media sponsor and exhibitor, representing its manufacturing groups brands: PLANT, M a ch i n e r y and Equipment MRO, Canadian Manufacturing, Design Engineering, and Manufacturing Automation. PLANT.CA

Photot: Mario Cywinski

T

he Canadian Manufacturing Technology Show (CMTS) recently took place at The International Centre in Toronto, Ont. CMTS offered a mix of live technology on display, with keynotes, panel discussions and technical sessions. CMTS LIVE! digital experience was a new feature at CMTS 2021, which was a digital complement to the in-person event and was available during and after CMTS for 60 days. The event featured manufacturing technologies at over 100 exhibits. The advanced manufacturing space included additive manufacturing, automation, robotics, design engineering, Industry 4.0 and IIoT.The machining and metalworking space included machine tools, tooling and work holding, metalworking, measurement and Inspection, and finishings and coatings. Day one’s keynote “Geopolitical Risks and How to Manage Them” was presented by Courtney Rickert McCaffrey, EY Geostrategic Business Group. She explored the key political risks manufacturers face and how they can manage them in today’s volatile global environment. Day one saw a panel presentation; “Building a Resilient Supply Chain: Enabling Speed and Agility to Protect your Customer and your Bottom Line.” Panelists outlined what a resilient supply chain looks like, how to identify risk across a global value network, and what is being done to protect customers from a wide variety of supply chain disruptions. On day two, Mike Brownhill, Export Development Canada discussed how manufacturing companies have navigated disruptive events, sharing lessons learned over the years from companies who have survived and thrived through challenging circumstances, and how these lessons can be applied going forward. Brownhill also shared how opportunities are developing for companies focused on ESG (environmental, social, and governance) in their operations in his keynote presentation “Back to Global Business: Managing Risk & Seizing Opportunity Amongst Black Swans.” Jayson Myers and Gillian Sheldon


BUSINESS OPERATIONS

FEATURE

Why investing in online training is not enough to avoid a cyberthreat To suggest cyberthreats are new would be naive.

not entirely true. Internal threats pose the greatest risk.” This didn’t come as a major surprise, considering the number of clients I’m working with who have me complete their now-standard “KnowBe4” training; an online, skillsbased learning platform for helping employees become more educated on cyberthreats. But is investing in online training

In my experience, working with sales teams and their leaders, online training can be a good supplement and aid to reinforce face-to-face learnings, but are typically insufficient to ensure an effective transfer of skills.

Photo: © pdusit / Adobe Stock

Every day, there are increasing numbers of business owners and executives that I meet with who have faced at least one cyberthreat. In the past, the answer was to look at increasing the frequency of backups and creating stronger firewalls for company servers. Problem is the cyberterrorists are becoming increasingly brash and strategic in their threats. It was only a couple of years ago now that I participated in a roundtable discussion with several Canadian manufacturers. During the discussion, three out of the four company presidents had faced a cyberthreat of some kind. Since what we’ve been doing no longer seems sufficient, I reached out and spoke with Carmine Tiano, President of Manawa Networks, to understand what today’s cybercriminals are up to, and, more importantly, what manufacturing leaders need to be cognizant of. According to Tiano, “most people think the greatest cyber risks originate from outside their company, but that’s

Photo: © momius / Adobe Stock

BY SHAWN CASEMORE

for your employees enough to overcome increasingly sophisticated cyberthreats? In my experience, working with sales teams and their leaders, online training can be a good supplement and aid to reinforce face-to-face learnings, but are typically insufficient to ensure an effective transfer of skills. It’s akin to thinking that you can get your pilot’s licence without ever having stepped foot in an airplane. When I asked Tiano his thoughts, he shared that phishing is likely the greatest threat any manufacturer faces, and although some phishing training and simulations are a great thing to do, additional controls and measures are strongly encouraged. The most effective controls he suggests can include: • Mandatory vacation time that in turn allows others to rotate into their job, ensuring employees don’t operate in a bubble. • Helping educate employees on less common but increasingly popular cyberthreats, including vishing (voicemail fraud). • Ensuring executives are aware of the threats associated with whaling (targeting a CEO or executive). • Adding controls that ensure no one person can transfer money outside the organization without validating the recipient’s identification. Tiano, who has been working with manufacturers to help them develop a more strategic approach to creating value through their IT infrastructure, shares that some hackers are even going so far as to pay disgruntled employees to co-conspire with them for a portion of the ransom. Although this may seem far-fetched, it provides insights into just how far these hackers will go to make money and cause chaos. What can you do? When it comes to cybersecurity, as with any other risk to your business, taking a combination of both mitigating and contingent actions is key to ensuring the threat is minimized. Some training might be a good start, but it’s not enough. Only by introducing a combination of training, controls, and additional measures, manufacturers can protect themselves, their shareholders, and customers from outside threats. Shawn Casemore helps companies accelerate their growth. To learn more, visit his web site at www.shawncasemore.com.

@PLANT_Magazine

November/December 2021 / Plant 9


HEALTH AND SAFETY

FEATRUE

Keep proper hard hat use top of mind

Although masks may be dominating the headlines lately for their role in public safety, you’d be hard pressed to find a more universal workplace safety symbol than the hard hat.

And with good reason, head injuries, which a hard hat can be designed to help prevent, can be among the most life-altering for workers. But not all hard hats are created equal, and they require regular cleaning and care to effectively protect workers from injury. Employers have a responsibility to train and educate workers on the proper selection, fit, maintenance, and use of all personal protective equipment. Here’s how to get started:

Why wear a hard hat?

Your workers know that hard hat use is mandatory in certain areas of the plant, but do they know why? A deeper understanding of the hard hat’s function, such as protecting the worker from the impact of falling objects or tools and, when designed to do so, reducing the risk of shock from contact with electrical hazards, is a great motivator to make sure their hard hats are in good working condition. You can also help drive home the importance of proper hard hat use by outlining some of the preventable injuries that occur due to improper hard hat use, such as injuries like cuts and bruises, to the more serious concussions, and traumatic brain injuries.

The right hard hat for your plant

Some workplaces require everyone to wear a hard hat. The class and type of headwear will depend on your workplace’s risk assessment of the work being performed and on your 10 Plant / November/December 2021

Photo: ©eakgrungenerd / Adobe Stock

BY CANADIAN CENTRE FOR OCCUPATIONAL HEALTH AND SAFETY

jurisdiction’s legislation. Most legislation in Canada references CSA Standard Z94.1 Industrial protective headwear – performance, selection, care, and use. In the absence of a requirement, this standard is a good guidance document to follow. It’s good practice to include hard hat training as part of your onboarding process and as part of ongoing training. Even the most experienced worker will benefit from a review on proper fit and care. They may also need to upgrade to the required type of hard hat for your workplace.

The right fit

Hard hats should be assembled and fit according to the manufacturer’s instructions. The hard hat is properly secured when the headband fits comfortably and is tightened so that it’s unlikely to fall off your head when you bend forward. Nor should the hat shift when you turn your head side to side. Secure any liners within the hat. Bandanas, welder’s caps, and

is a mild soap and warm water. They should focus on the outer shell as well as the liner to remove any perspiration or oils.

When to replace

Inspect shells and suspensions daily before use. Look for cracks, dents, cuts or any other signs of damage and wear. Hard hats exposed to heat, sunlight, or chemicals may become chalky, dull, or less flexible. Instruct workers that if any of these signs appear, they must not use the hard hat and should replace it immediately. Headwear should also be replaced if it is struck by an object, even if there is no visible damage. Make it a part of your incident reporting procedure to follow up with the worker about replacement in these instances. Check the manufacturer’s date codes on shells and suspensions to make sure they have not exceeded their maximum lifespan. For the shell, this length is generally five years, though it may be less with heavy use. Replace the suspension at least every 12 months.

Staying alert Classes of headwear can include: Type 1 - protection from impact and penetration at the crown (top) only Type 2 - protection from impact, penetration at the crown (top) and laterally (sides and back) Each type is also available in the following classes: Class E (20 000 V electrical rating) - provides head protection against high voltage conductors Class G (2200 V electrical rating) - provides head protection against low voltage conductors (general trades) Class C (no electrical rating)

other accessories should only be worn if they are approved by the manufacturer and do not affect the fit.

Cleaning and maintenance

Clean hard hats last longer and are more easily inspected for damage. Teach workers to avoid the use of abrasives or petroleum-based products as they will weaken the plastic.The best cleaning product

Encourage your workers to inspect and care for their hard hats as part of your workplace’s daily routine. Include hard hat training part as part of your onboarding and ongoing training processes, so all your workers know when it’s time to replace their hats. Plus, they can look out for their co-workers whose hats may be ready for replacement or aren’t being worn properly. Send regular, company-wide reminders about hard hat maintenance. A hard hat can save your workers from serious injury if worn correctly and properly maintained, but it is most effective when combined with a comprehensive health and safety program, within a proactive culture of identifying and addressing potential hazards. The Canadian Centre for Occupational Health and Safety (CCOHS) promotes the total well-being — physical, psychosocial, and mental health — of workers in Canada by providing information, advice, education, and management systems and solutions that support the prevention of injury and illness. PLANT.CA


RANSOMWARE

FEATURE

With attacks increasing in frequency and severity, experts offer advice for preparing a solid defence. BY ALANNA FAIREY Ransomware attacks have been on the rise over the last several years, targeting businesses as well as critical infrastructure systems. “Threat actors are attacking 24/7 –– this is a full-fledged business for them,” said Jason Conley, Digital Forensics Examiner, Envista Forensics Ltd. “If an organization doesn’t have, for example, two-factor authentication or other security controls, eventually [threat actors] are going to get in.” Fabian Franco, Senior Manager of Digital Forensics and Incident Response (DFIR), Threat Hunting and SOC, OpenText, said that supply chain industries and corporations that have not invested a lot of money into their cybersecurity practice and infrastructure are starting to see that it’s like “shooting fish in a barrel” for threat actors to infiltrate. “It’s easy pickings to go out there and find a vulnerability that may be exposed to the internet and for them to take advantage of it,” said Franco. “Part of that security posture is making sure you’re patching your systems.” With ransomware attacks on the rise, there has been more of a concerted effort to take threats like this more seriously. “We’ve been seeing a growing concern, which is actually surrounding what’s called the supply chain,” said Jaycee Roth, Associate Managing Director, Cyber Risk, Kroll. “The idea here is understanding and knowing how your network connects to or touches other organizations, and how that information is shared or protected with other organizations.” The implications of a ransomware attack may extend beyond @PLANT_Magazine

Photo: © leremy / Adobe Stock

Ransomware on the rise

question, Franco explains that there are a number of different reasons why a company may choose to pay a ransom and to look at the

full scope of the situation. Article originally published in Canadian Security magazine, used by permission.

To read entire article, go to plant.ca/features/ransomware-on-the-rise/

the immediately-affected targets. “It goes beyond just that organization,” said Franco. “That’s where there needs to be that investment where a company may spend a couple $100,000 up front, instead of having to spend millions on the back end and affecting the entire community outside of their one little ecosystem.” According to Conley, while IT teams may be excellent in their ability to fix or build technology, they may not be trained in cybersecurity, which is something businesses should consider investing more heavily in. “Cybersecurity is a field unto itself, with various specialized training, and if an organization doesn’t invest in somebody like that inside their department, they need to retain somebody at least to come give them a health check,” said Conley. “It’s as damaging as a fire, and businesses need to treat it with that level of severity because I’ve seen ransomware remediation periods go from 14-21 days before businesses get back up and operational again.”

Customized Material Handling Solutions.

Article originally published in and provided by Canadian Security magazine.

Our skilled team of Mechanical Designers will ensure your system is manufactured to the highest standards. Our In-House Manufacturing Team produce and deliver a quality product that meets or exceeds your expectations.

To pay or not to pay

A company’s decision to pay the ransomware demands is not a simple question, according to the experts. Calling it a “sensitive topic” amongst the U.S. government, Conley also notes that the RCMP has been vocal about deterring victims from paying the ransom. However, he also says that “when it comes to a business decision, the CEOs are often looking at one, and I’ve seen some businesses where they would have been destroyed had they not purchased a decryption key. For others, it’s a matter of return on investment.” Reiterating that paying the ransom is not a black and white

Talk to one of Rolmaster’s Sales Professionals today.

CALL 1-800-461-6806 www.rolmasterconveyors.ca 121 Avenue Road, Cambridge, ON info@rolmasterconveyors.ca

PLT_Rolmaster_NovDec21.indd 1

November/December 2021 / Plant 11 2021-11-08 10:57 AM


FEATURE

Photo: © AndSus / Adobe Stock

CYBERSECURITY

Protect productivity through cybersecurity Cyberattacks are anticipated to increase both in damage and volume across industrial critical infrastructure. BY REHANA BEGG Back in May, two cyberattacks caught global media attention; a brazen ransomware and extortion attack took down the biggest pipeline in the U.S. and a cyberattack forced the largest meat producer to shutter globally. What stood out about these incidents was that they happened within days of each other, and, in each case, the knock-on effects rippled across global supply chains. The first attack affected Colonial Pipeline, the largest pipeline system that can carry three million barrels of fuel per day between Texas and New York. The ransomware attack carried out by 12 Plant / November/December 2021

ransomware gang DarkSide was characterized as a digital extortion attempt and disrupted fuel supply to much of the U.S. East Coast for several days. The attack affected only IT systems, including the billing system, but Colonial made the call to shut down its operations as a precautionary measure. All told, Colonial paid the $4.4 million ransom in exchange for restoring its billing system’s function, in spite of having backups.The damage had been done; the incident triggered a spike in gasoline prices and set off panic across North America. The second was a cyberattack on JBS S.A., the largest meat processing

12 MONTHS In the past 12 months, almost one in five (17 per cent) organizations have been the victim of a successful ransomware attack

company (by sales) in the world. The Brazilian company was forced to suspend U.S., Canadian and Australian computer systems. Its fed-beef and regional beef plants were shuttered, with all other meatpacking facilities experiencing some level of disruption to operations. JBS reported in a media statement that the company paid the equivalent of $11 million in ransom to Russian cybercriminal group REvil in response to the criminal hack. Meanwhile, shutdowns upended agricultural markets worldwide and raised concerns about food security. From ransomware, phishing, data leakages, to hacking and insider threats, cybercrime is intensifying globally and can lead to catastrophic events. Locally, the numbers paint a sobering picture:The average total cost of a data breach for Canadian companies was US$4.50 million, according to a 2020 IBM report. It took an average of 212 days to detect a data breach in 2021 and 75 days to catch the attackers. In other words, 287 days would pass before the problem is addressed. In the past 12 months, almost one in five (17 per cent) organizations have been the victim of a successful PLANT.CA


ransomware attack, according to the 2021 CIRA Cybersecurity Survey. Of that group, a majority (69 per cent) said their organization paid the ransom demands, while 59 per cent reported that data was exfiltrated. As hackers increasingly target critical infrastructure, Canadian manufacturers find need to prioritizing cybersecurity to protect not only their own data but also their customers’ data across supply chains.

Industrial Critical Infrastructure

The Canadian landscape has seen a proliferation in both the amount of money sought and the number of ransomware attacks, said Cara Wolf, Founder and CEO of Calgary-based Ammolite Analytx, which builds customized next-generation AI-powered cybersecurity tools. “We’ve seen a major increase in supply chain attacks, we’ve seen an increase in attacks on sensors, attacks on plants and

industrial critical infrastructure,” said Wolf. “It is anticipated that we will continue to see the rise as nation-state sponsored attacks are funded by hostile nations, and state-sponsored attacks are financed by criminal gangs and hostile nations as well.” As money continues to flow into this area, it becomes critically important to look at the manufacturing sector and industrial sector in particular, where people’s lives are the palpable vulnerability, said Wolf. Consider a methane plant. “If the plant has automation [and sensor technologies] that show methane levels are safe and you have humans in that environment saying that methane levels are safe, when in fact the sensors can be hacked and tricked into giving false readings, people will get sick and die,” said Wolf. “Without automation that is secure by design, plants will face an uphill battle with cyber threats. There are trillions and trillions of sensors out there, and they come from all

kinds of countries with all kinds of backgrounds and they could have spyware installed or they could have backdoors installed.” Wolf further explained that threat actors can exploit vulnerable connected equipment by injecting malicious code that can sit atop communications that move back and forth between equipment in the field and headquarters. “Changing just one pixel can turn the output from one thing to another,” said Wolf. “AI can be tricked.” The methane plant example is extreme, but it highlights specific cyber struggles that manufacturers face, and raises critical questions they should ask now: How do manufacturers know that their infrastructure is secure? How do they know that sensors embedded in their equipment don’t have spyware installed or backdoors to the plant’s network capabilities? How do they know that they can trust their hardware and software? How do they know that the equipment

displays “honest” readings? Since cyberthreats evolve constantly, there are no bulletproof solutions. New guidance and best practices unfold as consistently as new technologies – and cyberthreats – come online.What follows are a few sage takeaways and insights that, according to Wolf, will help blunt cyberattacks: Build or buy local: Sourcing from countries that are known to have bad surveillance practices place manufacturers at risk, warned Wolf. Instead, she recommended Canadians buy locally whenever possible, or from countries that are allies, such as the U.S., U.K., Australia, New Zealand and Israel. Alternately, Wolf suggested manufacturers look at an investment program to create and build their own tools. “The cost of design and development has come way, way down, so take a look at that versus buying off the shelf, cheap from another country that may have spyware and surveillance tools installed in their technology,” she said.

RETHINK MFG. WITH CREFORM FLOW RACKS

Creform flow racks. A simple, yet effective way to ensure that manufacturing runs at peak performance. Built for ergonomics, efficiency and FIFO inventory management, each incorporates flow lanes and levels to present containers and parts at assembly stations, machine loading points and for other material handling applications. When used in combination with workstations, carts and AGVs, Creform flow racks are an integral part of the systems approach to industrial material handling. Create other economical, flexible, reliable structures and AGVs. ®

WORKSTATIONS

FLOW RACKS WITH PLACON ® ROLLER CONVEYORS CRE-451 8x5.375.indd 1 @PLANT_Magazine PLT_Creform_NovDec21.indd 1

CARTS

AGVs

w w w. c r e f o r m . c o m • 8 0 0 - 8 3 9 - 8 8 2 3

9/30/21 10:12 AM November/December 2021 / Plant 13 2021-11-02 3:45 PM


FEATURE

Photo: © AndSus / Adobe Stock

CYBERSECURITY

Go beyond the traditional wheelhouse: The COVID-19 pandemic will go down as the top story of 2020, but will also be marked by residual effects. Among these ramifications is the “cyber pandemic,” which include negative security impacts such as unemployment fraud and election security, as well as such trends as new work arrangements triggered by remote capabilities for nonessential workers and the process of automating routine tasks to free up time for work that adds more value. A positive side effect from the onslaught of remote work was the push to ensure organizations remained secure. Manufacturers were incentivised to secure their networks, make sure that devices were secure and that employees were not downloading work to their personal devices. “Unless workers are on a manufacturing floor or in a hospital or giving personal services where they need to be face-to-face, a digital worker can successfully work remotely,” said Wolf. In addition, a great deal of security awareness training was needed to educate employees on how and when to

171

PER CENT We’ve seen 171 per cent increase in the amount of ransomware attacks.

detect phishing attacks, said Wolf. “The pandemic brought security to the forefront where it should have always been, and it forced investment where it should have always happened,” she said. Check your security posture: Invest in cybersecurity policies, cybersecurity awareness training and proper vendor tools, recommended Wolf. Having a good security posture requires manufacturers to know where they are, to ask what’s working or not working and where they need to go. “COVID really pushed that forward and said, ‘It’s not a matter of if you’re going to be hacked, it’s a matter of when.’ We’ve seen 171 per cent increase in the amount of ransomware attacks… If we don’t mobilize and train and upskill, we’re just sitting ducks. Our manufacturing facilities can be putting lives at risk. It’s not just digital assets of our databases of personal and employee information but it’s actually the risk of securing physical assets in the field and abroad.” she said. Separate security from the IT function: IT and security don’t belong together, so separate these functions,

Canada, which lags in terms of size and functionality in its digital landscape, has its share of cyber vulnerabilities. Recent data prepared by Statista showed that 23 per cent of Canadian organizations surveyed had experienced a cyberattack and that 31 per cent of Canadian organizations estimated a loss between US$1K to US$50K because of cyberattacks. Five per cent reported estimated losses between US$5 million and US$100 million. 14 Plant / November/December 2021

advised Wolf. In addition, security needs to have its own governance and its own authority. “Whether you have it internally or externally, companies should hire third party experts; these experts are your trusted advisors. Bring them in to take a good, hard, objective look at your security program and to provide insights on your vulnerabilities and ways to mitigate risk,” she said. Stop looking at security as a cost centre: Cyber insurance is a smart precaution. Cyber security will not pay out when proper investment and steps have not been taken in the first place, warned Wolf. “Yes, it does cost money, yes manufacturers do need to invest, but they need to mitigate their risk and they need to balance that against the cost of lives, the cost of data breaches and the cost of the damage of a ransomware attack,” Wolf said. “And, further, if their supply chain becomes a victim of a supply chain attack, what kind of damage will it do to customers and their clients that are often larger enterprises? So, it’s about risk mitigation, more than cost.” Hire a CISO: As cyberthreats become more sophisticated, having a CISO (chief information security officer) or CSO (chief security officer) in the C-suite is an emerging priority, noted Wolf. These roles report directly to the CEO, but have governing authority to keep the organization safe, are able to make change and give directions. In addition, having third party experts perform an external analysis will add another level of security.

Security Advice in a Nutshell

Wolf said an important first step is to get security awareness training. Then, bring in outside experts to develop a plan that will bring the plant up to standard and to help implement it. Finally, use the most efficient and effective tools available. Above all else, Wolf emphasized that plant managers should rest assured that it’s not their job – either as a plant manager, foreman, millwright or anyone working on the floor – to be the security expert. “It’s their job to become security aware, to fall into compliance and to mitigate the risk in the job, but it’s not their job to become a security expert,” she said. Rehana Begg is a Toronto-based freelance writer and editor. Reach her at rehanabegg@ rogers.com. PLANT.CA


PRODUCTION PLANTS

FEATURE

Production in the GTA’s backyard

In the GTA’s backyard is Brampton Assembly Plant and Brampton Satellite Stamping Plant, with 2.95 million square feet of floor space and 3,163 employees. The assembly plant was built in 1986 by American Motors Corporation and acquired by Chrysler Corporation the following year. While the stamping plant was opened in 1991. Over the years, the plant has undergone many retools and been home to production for a variety of vehicles. Some of those have included: Chrysler Concord, LHS, and 300M; Dodge Intrepid and Magnum; and Eagle Vision. The current crop of vehicles produced at the plant began in 2004 (for 300), 2005 (for Charger), and 2009 @PLANT_Magazine

(for Challenger). SRT models of the Charger and Challenger are also made at the plant (since 2011). Two of the world’s fastest and most powerful vehicles are made here; the Challenger SRT Hellcat (since 2014) and Challenger SRT Demon (since 2017), both have over 700 horsepower and 650 foot/pounds of torque from a 6.2 litre supercharged HEMI V-8 engine. On the other end of the Challenger’s range is the all-wheel-drive GT model, which is mated to a 3.6L V-6 motor (which Stellantis uses in different configurations on several products). It is good for 303 hp and 268 ft/lbs of torque. For the Canadian weather, this trim, with the AWD system, works best if you are looking to drive it in the winter.

Photot: Mario Cywinski

Photot: Stellantis

Windsor is known as an automotive production centre for Stellantis, with its proximity to the company’s Canadian home base, and North American HQ in Michigan. However, another plant, closer to the GTA, is home to production of Dodge Challenger, Dodge Charger and Chrysler 300. BY MARIO CYWINSKI

Switching gears, the award-winning plant, was given World Class Manufacturing (WCM) bronze plant status in 2015. The WCM methodology is one that puts focus on getting rid of waste, improving productivity, and increasing safety and quality, systematically. “The key to successfully implementing WCM is the engagement of the workforce,” said Brian Harlow, Vice-President – Manufacturing, FCA North America, at the time. “By achieving bronze, the Brampton employees have demonstrated their commitment to making improvements in their operations, which translate into providing quality vehicles for our customers.” Brampton Assembly was also the first Canadian automotive assembly plant to achieve ISO 50001: 2011 Energy Management standards certification and was given a Canadian Industry Program for Energy Conservation (CIPEC) Leadership Award in 2014. Finally, the 230,000 sq/ft stamping plant is a look at the innovations that exist within plants, as it has automatic guided vehicles that move blanks to the presses, of which there are five automatic transfer presses (with 90 die sets), along one line. In all, 3,600 storage containers are available that are part of an automatic sheet metal storage and retrieval system. While the industry is moving to smaller crossover utility vehicles, and electrification, Stellantis for now is continuing to build its muscle cars right here in Canada. The future may see the plant be retooled, but no firm announcements have been made.

Mario Cywinski is the Editor of Plant magazine, Machinery and Equipment MRO magazine and Food and Beverage magazine, a member of the Automobile Journalists Association of Canada, and a judge for Canadian Truck King Challenge. November/December 2021 / Plant 15


FEATURE

Watch out for curiosity that could destroy your business

As you have increased your digital presence, unfortunately, so has the criminal element wanting to invade and capture your digital data. BY RICHARD KUNST Cyber awareness is more important than ever. It truly is not a matter of “if” you will be breached, but rather “when”. As a result of COVID-19, most businesses have pivoted their digital presence or have created a digital presence, and ultimately increased your their vulnerability and risk to be breached.

They are sophisticated

Destroy the myth that these cyber-hackers are sitting in some remote little isolated area and playing games. These are very sophisticated organizations with multiple employees armed with fancy cyber programs to attack the fortress surrounding your data protection, looking for any little crack of opportunity to invade and take control and exploit your data. Remember, these cyber-hackers are focused on making money, just like any 16 Plant / November/December 2021

other organization. As manufacturing companies continue to evolve with Manufacturing 4.0 using blockchain, suddenly, your machines can become vulnerable and even your I.P. They are already invading company HVAC systems, so if your machine programs are resident and linked through your data system, then you are vulnerable. Yes, people. We are living in the Wild West of the internet and you just cannot have enough eyes and ears to monitor every nuance.

They are sneaky

The most common invasion step is the use of phishing e-mails, and here is where curiosity can be very costly. You need to constantly remind your team not to open any suspicious e-mails or even links that appear to come from a trusted sender, because once you have clicked, there is no turning back; you are infected.

We are hearing cases where cyber-hackers are copying a legit e-mail address and omitting a character, so as a recipient you may never suspect until it is too late.You may not be the intended target, but rather they will send this modified e-mail to one of your trusted e-mail connections requesting innocent information from them, and bang, they have been hacked, thanks to you. And once they found out, you can be sure the victim will be coming to you for recourse. Many of the cyber-hackers are purchasing domain names similar to yours.You may own a .com or .ca, but they will purchase the .org or .net as an example to replicate you and your offerings, but sucking in innocent victims, so always check.

protected, having done all of the necessary trainings and warnings. You even have partitioned your data within your server. Most likely you have modified your data back-up protocols of daily, weekly and monthly. It is important that you always have one form of data back-up disconnected from your system, but even this may not be enough. We are hearing about cyber-hackers installing time bombs into systems that only activate after a couple of months, effectively corrupting your entire data back-up protocols. Even having a random computer connected to your system that had been ignored after a breach can come back as a predator.

You think you are smart, but they may be smarter

Indeed, as many of these cyber-hackers surf the internet for victims, they pause for only three

You may feel that you are

Once they get you, chances are they will be back

PLANT.CA

Photo: © Oleksii / Adobe Stock

CYBERSECURITY


seconds at a specific site to seek vulnerabilities and opportunities to penetrate. While if you are larger organization, or an organization with a ton of valuable and saleable intellectual property, their team will spend a ton of time and resources to get inside. Why? they are a for-profit organization and they have determined you can most likely pay the ransom, and in many cases, do not want to share to the world you have been hacked. But once you have been hacked and paid a ransom, there is absolutely no guarantee they will stop the demands. Most likely the invasions will continue and the ransom demands will escalate.

How to increase your defence

Step 1: Assess physical security and workplace habits A single cursory site visit can reveal an astonishing amount about an organization’s cyber posture. Even without sitting down at a computer monitor, our team can evaluate a wide range of security factors and gauge many of potential vulnerabilities, including: Ease of access / quality of physical security: How easy is accessing common working areas and infrastructure? Are doors locked and functioning properly? Are employees consistently greeting, logging, and supervising guests or contractors while on-premises? Do team members frequently share swipe passes? Is tailgating a common practice? Security education, awareness, and training (SEAT): Do employees consistently lock workstations when away from their desks? Do employees consistently share or discuss sensitive information in common areas? Are sensitive information and/or systems visible to visitors in common areas? Network security and access: Is guest wireless access adequately firewalled and/or segmented from sensitive networks? Are there adequate restrictions and multifactor authentication requirements to access sensitively wired/wireless networks? How forthcoming are employees with passwords? Are employees accessing or disseminating information on unsecured guest networks? @PLANT_Magazine

(e.g., smartphones, tablets, etc.) Step 2:Test existing controls to understand efficacy and resilience Leveraging both the information gathered in step one and the typical attack techniques used by cyber criminals, the team will then penetration test (i.e., attempt to breach) the organization’s information technology (IT) and operations technology (OT) systems. Some common areas we typically look to gain access to include: Known vulnerabilities / patches: Have the organization and its employees been vigilant in updating software and firmware to take advantage of the latest security features? These so-called zero-day vulnerabilities are a common point of access for many breaches. Build / hardening standards: Has the organization taken adequate steps to configure firewalls, servers, switches, and routers according to the most recent standards? Has it changed default passwords, adequately encrypted stored passwords, and sufficiently restricted access privileges? Are disused or outdated hardware and software still connected to the network? Encryption standards:Does all information that flows in, out, and through the network meet industry encryption standards? Do any gaps and/or shortcuts in encryption allow malicious actors to harvest information or access the network? Social engineering: How effective are team members at identifying and reporting malicious emails? How many (if any) log-in credentials were harvested from a simulated phishing attack? Are current education and warning measures adequate to prevent a social engineering breach?

simulated attack and compromise as many systems as possible. Organizations that work on the assumption that they will inevitably be the victim of an attack keep critical systems independent from one another to minimize the potential damage of a breach. This can also buy critical hours to action an incident response plan, contain the attack, and ultimately recover the systems. Embrace cyber security and privacy as a core business objective. Today’s organizations are embracing more digital tools and collecting more sensitive data than ever before. At the same time, cyber criminals are continuing to evolve their tactics to take advantage of human and platform vulnerabilities, and global uncertainty in a changing world. There is little that organizations can do to prevent becoming

the target of an attack. But every organization can take meaningful steps to improve their preparedness and minimize the short- and long-term damage of a breach, including: • Regularly assess key vulnerabilities and cyber risk exposures • Ensure compliance with all industry and regulatory requirements is up-to-date • Build cyber and privacy risk assessments into all strategic and tactical planning • Provide frequent cyber security training for all employees • Implement and update security and privacy governance programs • Create and regularly practice an incident response plan Ultimately, always check before you click. Curiosity may have killed the cat, but do not let your curiosity kill your business.

Richard Kunst is an author, speaker and seasoned lean practitioner based in Toronto, who leads a holistic practice to coach, mentor and provide management solutions to help companies implement or accelerate their excellence journeys. You can reach him at www.kunstsolutions.com.

MURPHY MEANS

MORE More

VALUE

No One Gives You More!

Feature for feature: Murphy packs-in more for your money. Get it done right the first time.

Step 3: Map potential spread and infrastructure vulnerabilities Properly segmented IT and OT systems are essential for slowing and ideally preventing a breach from spreading to other high-value systems. Once the team accesses the client’s network, they attempt to spread the

N.R. MURPHY LTD. DUST COLLECTORS 430 Franklin Blvd., Cambridge, ON N1R 8G6 E-mail: 4nodust@nrmurphy.com

(519) 621-6210

www.nrmurphy.com

PLT_NRMurphy_SeptOct21.indd 1

November/December 2021 / Plant 17 2021-09-21 10:30 AM


FEATURE

Photo: © Egor / Adobe Stock

MANUFACTURING

‘Cyber-securing’ your plant

Checking in with industry experts for an overview of current risk level and best new technological approaches in cybersecurity. BY TREENA HEIN At this point, all manufacturers, small and large, should already be paying serious attention to cybersecurity. Cyber-attacks on manufacturers have been numerous in the last few years and included companies from many sectors. A short sampling includes OXO International (kitchen tools), JBS (meat processing), Visser Precision (space and defense), Norsk Hydro (aluminum), Renault-Nissan (vehicles), Mondelez (food and beverage), and Merck (pharmaceuticals). Manufacturing was not the primary focus of attackers in the beginning. Even two years ago, according to cybersecurity firm Bitlyft, the manufacturing sector was number eight in the top ten most-targeted sectors. Manufacturers were not top choice as they generally didn’t have many internet 18 Plant / November/December 2021

access points compared to companies in other sectors, such as banking. Therefore, they collectively didn’t take much action. But because there was money to be had through ransomware attacks – and there still is – more manufacturers started being targeted around 2017. They were ripe for the picking, as explained in a recent Deloitte cybersecurity report, not least because the focus of manufacturing technology “has traditionally been on performance and safety, not security, leading to major security gaps in production systems.” At the same time, Industry 4.0 had started to emerge, with explosive growth in the amount of internet connectivity in manufacturing plants. And then the pandemic hit. With some employees having to work remotely for at least a short period of time in

CYBER ATTACKS As Deloitte says, cyber-attacks are motivated by money,revenge, and competitive advantage.

2020, a rush to increase automation to deal with absent workers and physical distancing, and other factors, the IT systems in plants were pushed to new limits. All these elements have caused manufacturing to move sharply up in sector ranking for volume of cyber-attacks. Bitlyft now puts manufacturing in second place, behind finance/insurance. Today’s reality, explains Michael Lester, Director of Cybersecurity Strategy, Governance and Architecture at Emerson Automation Solutions, is that “manufacturers are under pressure from their boards to ensure the right level of cybersecurity is achieved to protect their manufacturing environments and processes from the increasing level of cyberattacks we are experiencing globally.”

Attack overview

As Deloitte says, cyber-attacks are motivated by money, revenge and competitive advantage. Attacks against manufacturers, as with any organization, can range from external email phishing and internal malicious employee attacks/leaks to external attacks that seek to sabotage equipment or access intellectual property. Ransomware (a type of malware) is probably the biggest threat, where access to a company’s IT system or data PLANT.CA


is denied until the company pays the ransom. And although it’s hard to get data on dollar amounts involved in ransomware attacks as that is not always made public, it’s safe to say ransoms are large already and will only grow larger. To bring their cybersecurity to the appropriate level, manufacturers first need to map their business and manufacturing systems. This, Lester explains, will help provide understanding and ownership of each process and achieve business continuity and resiliency objectives around cyberattacks. A thorough threat analysis should also be conducted. It’s best practice to review the MITRE ATT&CK matrices, said Lester, “specifically the recently-developed MITRE ICS ATT&CK Matrix, which is based on a global knowledge base of adversary tactics and techniques used in real-world attacks.”

Securing automated plant systems

As part of their assessment of current security environment, manufacturers must understand that they’re at particular risk through their operational technology (OT) systems that run various automated processes. Many of these current systems are running with both outdated hardware and outdated software. Indeed, because the manufacturing sector is seeing an increased volume of cyber-attacks, particularly involving malware and other increasingly-sophisticated threats, “we have seen a significant increase in attention on better securing OT environments,” said Paul Griswold, Cybersecurity Chief Product Officer, Honeywell. Dr. Apala Ray, Global Cybersecurity Manager (process industries division), ABB and Bart de Wijs, Cybersecurity Lead, ABB notes that because OT systems play an important role in companies’ digitization journeys, with hyper-automation occurring through the use of ‘smart’ systems, there’s a strong need “to secure manufacturing plants from OT-related threats. There are inherent challenges expected from OT systems during these @PLANT_Magazine

smart/digitization transformation journeys, and organizations must address them carefully.” They explain that historically, a plant’s legacy automation, protection and control systems were based on specialized equipment with little connectivity, where today’s systems “are distributed and highly interconnected, and they are also increasingly connected to ‘cloud’ platforms” as well. To secure a plant’s OT infrastructures, an analysis to gain total visibility is a crucial first step. Then, say Ray and deWijs, basic security controls can be put in place (but also properly maintained and monitored). Hold onto your hat, because the next bit is somewhat technical. As Ray and de Wijs explain, “with regards to increased connectivity and associated risks from that, we see an increase of use of security controls defined in security level SL3 and SL4 of standard IEC62443-4-2.” Lester agrees. “We will see continued increases of capabilities built into manufacturing systems and components that include a secure-by-design approach in alignment with industry standards such as the ISA/ IEC 62443 family of standards,” he said, “to enable higher levels of cybersecurity and factory protection or compliance.” This standard, developed by the ISA99 committee of the International Society of Automation (ISA) and adopted by the International Electrotechnical Commission, provides a flexible framework to address and mitigate current and future security vulnerabilities in industrial automation and control systems (IACSs). That is, the standard (also known as Security for Industrial Automation and Control Systems: Technical Security Requirements for IACS Components) addresses IACS components such as embedded devices, network components, host components and software applications.

Attacks against manufacturers, as with any organization, can range from external email phishing and internal malicious employee attacks/leaks to external attacks that seek to sabotage equipment or access intellectual property. operation that could be impacted by direct or indirect attacks and should also include a risk-based prioritization of any gaps. Griswold explains further that a specific OT security assessment done by a reliable vendor will help identify gaps in security controls, missing patches and other security issues. “Based on the results of the assessment, remediation actions are implemented to provide a more secure baseline,” he said. “From here, advanced technologies – such as continuous asset discovery, threat monitoring and asset discovery – can then be implemented.” The overall defence strategy should also include planning for worst-case scenarios. Lester explains that for a manufacturing plant, this means having a clear

backup plan for the failure of computer systems, plus having hard copies of orders, labels and contacts. While this may not be possible in every scenario at all times, it may enable plants to fully or partially operate even in the event of a cyberattack. Lester adds that once the defense-in-depth strategy is in place, “it should be tested and reviewed methodically, purposefully and regularly to ensure it is effective and does not jeopardize ongoing operations or introduce other risks.” Roles, responsibilities and employee training should be updated. And although it sounds like something that’s a no-brainer and needs no mention, strict measures need to be in place to guide every employee who interacts with a

Looking for a fabricator for a complex project? Whether it’s a heat exchanger, stack, pressure vessel, filter, or other custom process equipment, Alps Welding can turn your design into reality.

Looking for a fabricator for a complex project?

Heat exchangers, stacks, pressure vessels, or other equipment, Alps turns your design into reality.

We have experience working with steel, stainless, and other alloys, including titanium.

We have experience in a wide range of materials, with a segregated stainless and alloy fabrication shop.

With over 150 welding procedures, and 45 years of experience meeting the demanding specifications of the energy, mining, chemical, and cleantech industries, make Alps Welding your first call when looking for a fabricator for critical equipment.

Defence strategy

Once a manufacturer has worked with a reliable vendor to complete a threat analysis and assessment of current cybersecurity environment, the next step is to develop an in-depth defence strategy. Lester says it must address weaknesses and mitigates risk in every

With over 45 years of experience working for the energy, chemical, food and cleantech industries, make Alps Welding your first call when you

400 New Huntington Road Woodbridge, Ontario 905-850-2780

need fabrication of critical equipment.

PLT_AlpsWelding_2_NovDec21.indd 1

www.alpswelding.com November/December 2021 / Plant 19

PLT_JanFeb_Alps.indd 1 PLT_Alps_June21.indd Alps_Plant_ Jan 2018.indd 1

2019-01-16 AM 2021-05-31 11:02 1:46 PM 2019-01-08 12:55 PM

2021-11-01 10:59 AM


FEATURE

Photo: © Egor / Adobe Stock

MANUFACTURING

computer. Each interaction is a potential risk, and every employee needs to follow strong, fundamental security practices in their daily work, for example when creating and storing passwords, storing information and sharing information, whether in the building

or from a remote location.

Future direction

In terms of where cybersecurity is going, Lester believes that manufacturers are going to need to consider using multiple technologies (but also always focus on

people and processes in addition to technology). Looking forward, he also foresees that “manufacturing and industrial-specific technologies will include more secure communications and capabilities that are robust and meet the requirements and specifications with the devices and systems being used to maintain safety, control and monitoring. Some cybersecurity technologies are specifically designed for use in manufacturing and industrial environments like The Dragos Platform to achieve inventory, visibility, detection, and response capabilities in operations that engage both the OT and the IT functions in an organization. These should have priority when reviewing how to achieve higher levels of manufacturing and plant security.” He adds that some existing technologies that are more prevalent in the Enterprise IT environments are also being used in manufacturing, but may have limitations or need to have significant configuration to work

appropriately and prevent unintentional safety or control impact. Along the same vein, Griswold explains that securing OT requires purpose-built solutions, as IT tools are often not designed for effective and safe use in OT. “While most security tools and processes originated on the IT side of the house, IT/OT convergence is driving demands for integration between IT and OT security,” he said. “In the next three to five years, we expect to see the emergence of solutions that bridge the gap between IT and OT, contextualizing OT cybersecurity events in a manner that can be understood and responded to by IT cybersecurity personnel.” He adds that “additionally, due to a severe shortage of OT-specific cybersecurity skills, we expect many companies to opt for managed security services to provide cybersecurity programs for their manufacturing environments.” Treena Hein is a freelance business writer based in Pembroke, Ont. E-mail her at treenahein@outlook.com.

WHEN OIL FREE AIR IS THE ONLY OPTION Count on Sullair for reliable oil free compressors that meet your highest standards for air quality, purity and performance. We also offer air dryers, filters and other products to meet your specific air treatment needs. Learn more at Sullair.com/oilfree SRL Series

DSP Series

© 2021 Sullair, LLC. All rights reserved.

20 Plant / November/December 2021 PLT_Sullair_SeptOct21.indd 1

PLANT.CA 2021-09-27 3:17 PM


TECH CENTRE

NEW PRODUCTS ELECTROVAYA’S CLOUD-BASED BATTERY ANALYTICS SYSTEM POSITAL’S PROGRAMMABLE POSITION SENSORS

CINCINNATI INC.’S CLI FIBRE LASER

accessories such as mounting brackets for the appropriate adaptation complete the overall package of flexibility. The incremental Sendix KIS40 encoder with its high resolution of up to 2500 pulses and a maximum speed of up to 4,500 min-1 ensures maximum precision and dynamics. www.kuebler.com

MWE02 MEASURING WHEEL SYSTEM

BALLARD LAUNCHES FCMOVE-HD+

Cincinnati Inc. CLi, a fibre laser that occupies a spot in the CI product portfolio. The lowercase i in CLi stands for “introductory,” meaning it’s a starting laser that has the functions necessary for shops that want to make parts rather than outsource. The CLi packs easy operability, with HMI control and dual screen Windows-based interface. The 5’ x 5’ table is packed into an economical 10’ x 11’ footprint. www.e-ci.com

Kübler is expanded its portfolio of linear measuring systems with measuring wheel system MWE02, which consists of spring arm, encoder and measuring wheel solution for reliable speed, position and distance measurement in applications with linear movements. This system is used in intralogistics, such as conveyor belts, wood industry, and the packaging industry. The measuring wheel system is installed directly on the measuring surface. The recording of speed is ensured by the contact pressure of the measuring wheel by means of an integrated spring. Available are measuring wheels with a diameter of 200 mm and 6” with O-ring NBR70, plastic (polyurethane) smooth or cross knurled (aluminum) surface. Matching

@PLANT_Magazine

Posital’s programmable IXARC encoders feature characteristics such as resolution and communications interfaces, and Electrovaya Inc. launched Evision, its measurement ranges can be set up internally developed and proprietary through firmware updates, with no remote monitoring system. need for mechanical changes. This system is cloud-based and is For Posital’s programmable able to track battery operational incremental encoders, resolution), usage in Electrovaya-powered direction and communications applications, such as lift trucks or interface driver (HTL or TTL) can all electric buses in real time. be defined through software The system will monitor battery parameters. health, utilization and charging to In the case of absolute encoders provide customers with fleet and with analog interfaces, their outputs charging management. Furthermore, – current or voltage – can be ‘scaled’ the system improves the capability so that a predetermined range of and efficiency of troubleshooting mechanical motion (anything from a and maintenance. fraction of a turn to several hundred www.electrovaya.com rotations) can be set span the full electrical output range. For more products, visit: www. 21_2442_Plant_NOV_DEC_CN Mod: October 28, 2021 3:48 PM www.posital.com plant.ca/technology-centre Print: 11/08/21 11:12:25 AM page 1 v7

π

Ballard Power Systems FCmove-HD+, designed for buses and heavy-duty trucks, and is the latest product in Ballard’s eighth generation heavy duty power module portfolio. FCmove-HD+, with a 100kW power output, has been designed to improve ease of vehicle integration. It has been engineered for engine bay and rooftop configurations, enabling optionality in truck and bus applications. FCmove-HD+ is over 40 per cent more compact and over 30 per cent lighter than the previous 100kW module, with 50 per cent fewer component parts. This results in an anticipated 40 per cent improvement in total lifecycle cost while maintaining leading operating performance, high efficiency, and wide operating range. FCmove products are being integrated by bus and truck OEM partners. The first vehicles powered by the 100kW, FCmove-HD+ are anticipated in 2022. www.ballard.com

WIRE SHELVING

CHROME Bright, attractive finish

BLACK Decorative, powder-coat finish

STAINLESS STEEL Strong, durable and will not rust

EPOXY Coated for superior chemical resistance

ORDER BY 6 PM FOR SAME DAY SHIPPING

1-800-295-5510

PLT_Uline_NovDec21.indd 1

uline.ca

November/December 2021 / Plant 21 2021-11-09 1:17 PM


POSTSCRIPT

BY JAYSON MYERS

Cybersecurity is a real but manageable risk: treat it that way

C

ybersecurity elicits a wide variety of responses from manufacturers across Canada, ranging from complacency to dread. It shouldn’t. Cyber threats are real. But they are manageable. Manufacturers can take steps to protect themselves. Like any process, they need to be continually improved and upgraded. And they shouldn’t cost an arm and a leg, unless, of course, it’s too late and companies are having to recover from a successful cyber-attack. According to PLANT’s Advanced Manufacturing Outlook Report for 2022, 83 per cent of manufacturers surveyed across Canada know they have experienced some sort of cyber-breach or attack, up significantly from 68 per cent reported last year. That doesn’t count some that may not be aware they’ve been breached in the first place. While 55 per cent of those attacks were phishing expeditions, 28 per cent were targeted external attacks and 19 per cent were breaches caused by a third-party supplier. Clearly, the threat is real and it is growing. I was surprised when we conducted an audit of cyber-attacks at NGen. Over the period of one month during the summer, we received more than 16,000 emails. Almost 500 of them contained links that could have opened us up to a cyberbreach or worse. Our IT systems prevented most from getting through, but still close to 20 per cent did – and were caught by our staff before they did damage. I can tell you from first-hand

experience the threat is bigger than you think. Yet, the response from many manufacturers seems to be closer to a yawn than real concern. The outlook found that in spite of the incidents that were reported, 20 per cent of companies say they are not concerned about cyber-attacks. Even more surprising is that 93 per cent think they have done enough to guard themselves against attack, although only half have conducted a cyber-security review of their existing systems. Those companies that think they have done enough are being highly optimistic, if not frankly a little naïve. Because if an attack occurs, only one-third of manufacturers have a cyber-breach response plan in place. Manufacturers are focusing mainly on the security of their internet communications and e-commerce systems. These are certainly important areas of concern and have been front and centre over the past 18 months of the pandemic. But, manufacturing is a complex business and the risks go way beyond phishing attacks and the internet. Any digitally enabled product or process is vulnerable to hijacking. Remember the hackers that took over control of the Jeep a few years ago? The smarter the products are, the more vulnerable they will be. Automation processes are at risk. So too is equipment on the shop floor or that you have sold to your customers. Autonomy will elevate the risks even further. Then there’s the knock-on impact of cyber-problems

According to PLANT’s Advanced Manufacturing Outlook Report for 2022, 83 per cent of manufacturers surveyed across Canada know they have experienced some sort of cyber-breach or attack, up significantly from 68 per cent reported last year. 22 Plant / November/December 2021

somewhere in the supply chain. Pipelines or utilities can be shut down – as recent history has shown. Cyber-attacks can shut down production on the part of critical suppliers (not that we need any further supply chain disruptions to deal with). Public sector, financial, and supplier or customer databases can also be exposed, putting your data and IP at risk. Cybersecurity is not just a technology problem. It is a health and safety issue. It is a legal and liability issue for companies that should have done more to protect themselves, their customers, and suppliers. And it is a business issue if production systems are forced to close, and orders or contracts are lost as a result. Unfortunately, most organizations don’t take the problem seriously until they are attacked and face the financial consequences. Manufacturers need to get out ahead of the issue. Technology is evolving quickly and so too are the capabilities of hackers. Manufacturers can’t be complacent. No one can stand still. The key is to be able to manage cybersecurity risks well.What can manufacturers do? Here are some pointers: 1. 1 Treat cybersecurity as a critical business issue. It’s not just a problem for technicians and the IT team. It demands the attention of senior management and safeguards need to be in place throughout the organization. 2 Be aware of your internal and 2. external vulnerabilities. Get assistance to conduct a cybersecurity audit of your processes. It doesn’t cost much, and it can provide valuable insights that can help you build more robust and efficient processes, in addition to identifying areas of potential exposure.

3 Prepare a plan to avoid attacks 3. and to recover in the event of one. Your business may depend on it. 4 Make cybersecurity a part of 4. your technology deployment and business plan. Don’t avoid adopting technologies that can help your business improve productivity and grow. That would be like deciding not to invest in a piece of equipment because, potentially, it might harm people who are operating it. You know that protections can be put in place to protect the health and safety of employees. The same is true in the case of cybersecurity. 5 Focus on employee training. 5. Don’t count on security software downloaded from the internet to fully protect you. Technology fixes won’t do the trick by themselves. Hackers are too smart for that. In any event, 95 per cent of all successful cyber-attacks are the result not of technology but of human error. They are errors that can be avoided if your teams know where to look and what to do. 6. 6 Demand to know the data protection and cybersecurity protocols that your suppliers and business partners have in place. 7 Treat cybersecurity protection 7. as a process that needs to be continually upgraded and improved. 8. 8 And finally, connect with resources that can help you understand the risks and deal with them effectively. Sharing concerns and experiences with colleagues is a good place to start. Check out the Canadian Centre for Cybersecurity.That might be a good place to go before considering a consultant. Manufacturers need to manage cybersecurity risks as part of their standard operating procedures, subject to all the continuous improvement practices they would employ with respect to any other critical process in their business. Cyber-readiness will become even more important as manufacturing goes digital. Proactive planning needs to begin today. PLANT.CA


Keywords

Location

Distance

ManufacturingJobsite.ca is Canada’s premier online job portal for the growing manufacturing sector. A laser focus on the right people across the country’s largest manufacturing media audience means you get the right applicants the first time. No more massive piles of unqualified applicants, just professional employers reaching qualified professionals. Powered by the top manufacturing media brands in Canada, the reach to over 500,000 industry professionals on ManufacturingJobsite.ca is amplified by: Website advertising to 185,000 qualified monthly site visitors A comprehensive and magnifying reach across multiple associated job boards Email promotion and job alerts to 131,000 industry emails using Canada’s largest CASL-compliant direct access to manufacturing professionals Social media promotion to all brand networks on Facebook, Instagram, Twitter and LinkedIn

Search


2 a.m. is a great time to order parts if you visit AutomationDirect, where you can place orders, watch how-to videos, download free software and more anytime

morning,.....................noon,.....................and night.

Automation that’s available 24/7/365 Don’t put your automation needs on hold just because it’s after midnight or it’s the weekend. Our webstore never closes and has tens of thousands of value-packed parts ready to ship (Mon-Fri), along with interactive selector tools, instant quotes, user-defined BOMs, downloadable CAD files, and much more. And don’t forget, when you partner with us you also get: • Easy online or email ordering, or friendly customer service associates available by phone • Free unlimited phone technical support and access to exhaustive product information and videos • Free shipping on orders over $49, for delivery within 2 business days* *Some exclusions apply, see Website for Terms and Conditions details

“...the best website when it comes to purchasing electrical items. From finding my products, items, tools to ordering it and receiving it everything is very simple and easy...“

Ahmad in CYPRESS, CA “I’ve been a fan of Automation direct for their easy to navigate website and wonderful customer service. I would recommend them to anyone.“

Mike in LAKELAND, FL “Automation Direct has a intuitive website where I can easily find components saving valuable time...“

Pete in COVINA, CA Check out our vast selection of high-value automation components and all of our customer reviews at:

www.automationdirect.com

Orders over $49 get FAST FREE SHIPPING Our shipping policies make it easier than ever to order direct from the U.S.!

Fast free standard shipping* is available for most orders over $49 U.S., and that includes the brokerage fees (when using an AutomationDirect nominated broker). Using our choice of carrier, we can reach most Canadian destinations within 2 to 3 days. *Free shipping does not apply to items requiring LTL transport, but those shipments can take advantage of our negotiated super-low flat rates (based on weight) that include brokerage fees. See Web site for details and restrictions at: www.automationdirect.com/canada

To see all products and prices, visit www.automationdirect.com All prices shown are U.S. Dollars

Order Today, Ships Fast! * See our Web site for details and restrictions. © Copyright 2021 AutomationDirect, Cumming, GA USA. All rights reserved.

1-800-633-0405

the #1 value in automation


Turn static files into dynamic content formats.

Create a flipbook
Plant November December 2021 by Annex Business Media - Issuu