Going safely into the brave new world of 4IR

1 August 2019 Industrial (Industry), Information Security

The Fourth Industrial Revolution (4IR) is changing the world as we know it, and South Africa is pinning its growth ambitions on a 4IR-enabled economy. But 4IR adoption without putting cyber-safety first could undermine growth efforts and expand the risks to manufacturing, heavy industry and key infrastructure, warns GECI.

GECI, a specialist in industrial cybersecurity, says key infrastructure, manufacturing and heavy industry are potentially at greater cyber-risk than knowledge-based enterprises.

“Industries such as finance, telecoms, healthcare and retail are typically mature in terms of the digitisation journey, and usually have advanced and comprehensive cybersecurity measures in place,” says Mike Bergen, director of GECI International: Middle East and Africa. “In contrast, industrial and key infrastructure facilities are often running older operations technologies (OT) in siloes and not connected to the organisations’ IT systems.

“For years, they have been at limited risk of cyber-attack. However, as they digitise and start moving into a 4IR environment, these OTs will become connected to the Internet and integrated into the enterprise IT environment, quickly expanding their risk exposure.”

This risk is compounded by the fact that industrial sites tend to neglect basic information security measures in their existing environments. International OT cybersecurity solutions developer CyberX’s 2019 Global ICS & IIoT Risk Report found vulnerabilities and flaws in basic cybersecurity at industrial sites around the world:

* 53% of industrial sites used outdated Windows systems.

* 57% were not running anti-virus software that updated signatures automatically.

* 69% had passwords traversing the network in plain-text.

* The ‘air gap’ is a myth, as 40% of industrial sites had at least one direct connection to the Internet.

* 84% had at least one remotely accessible device.

* 16% of sites had at least one wireless access point.

Cyber criminals are already exploiting these vulnerabilities, costing companies millions in ransoms and other damages, Bergen says. “Research has found that virtually all industrial organisations have come under some form of cyber-attack in the past few years. These attacks range from malware and ransomware attacks to targeted attacks designed to sabotage operations or steal sensitive data.

“The losses caused by successful attacks extend from actual theft and ransoms, through to production downtime, safety risks, reputational damage and potential fines in the event of a failure to deliver critical services or due to sensitive information breaches.”

The more connected these organisations become, the greater their risk footprint. However, this does not mean the industrial sector should not advance into the 4IR. Bergen says: “Digitisation and technological progress helps overcome several common challenges in the industrial and manufacturing sectors – it improves throughput, efficiency and profitability, by achieving performance enhancement and resource efficiency through data acquisition and real-time analytics.

“Improved efficiencies help free up investment funds to support modern manufacturing innovation, rapid product iteration and customisation. Importantly, industrial safety can be enhanced by technologies such as better analytics and automation of dangerous tasks through robotics, cobotics and the digital workforce.”

He cites a McKinsey September 2018 white paper, which found “manufacturing digitisation could boost heavy industry profit margins by three to five points”.

Says Bergen: “Nobody can afford to ignore 4IR progress. But companies wishing to move into the 4IR have to build cybersecurity into their strategies and systems from the ground up in both IT and OT environments, to counter the growing cyber-risks facing them.”

GECI provides CyberX in South Africa. The CyberX solution delivers an industrial cybersecurity platform built by blue-team military cyber-experts with nation-state expertise defending critical infrastructure. CyberX delivers advanced OT asset discovery and visualisation, detects vulnerabilities and advanced known and unknown threats within seconds, prioritises and recommends actions to be taken to rectify vulnerabilities and threats, monitors continuously, providing alerts in real time, protecting critical IT and OT infrastructure against cyber-attacks, and automating Security Operations Centre (SOC) workflows.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Smart surveillance and cyber resilience
Axis Communications SA Surveillance Information Security Government and Parastatal (Industry) Facilities & Building Management
South Africa’s critical infrastructure sector has to step up its game regarding cybersecurity and the evolving risk landscape. The sector has become a prime target for cybercriminals on top of physical threat actors, and the consequences of an incident can be far-reaching.

Read more...
Autonomous healing systems are the future
Infrastructure Information Security AI & Data Analytics
Autonomous healing software, an emerging technology, is gaining traction for its potential to transform how organisations manage software maintenance, security, and system performance.

Read more...
Quality fire detection installation at Baywear Clothing
G2 Fire Fire & Safety Industrial (Industry) Products & Solutions
JZL Projects and Solutions was asked to provide a comprehensive yet cost-effective and reliable fire detection solution for Baywear Clothing that would be installed with minimum disruption to the factory.

Read more...
Kaspersky detects over 1 million daily tracking attempts
Kaspersky News & Events Information Security
Kaspersky's latest analysis of the 25 most prevalent web tracking services, including Google services, New Relic and Microsoft, has revealed over 38 billion instances of web trackers collecting user behaviour data in 2024, with an average of one million detections per day.

Read more...
Only 4% of surveyed organisations reported no cyberattacks
News & Events Information Security
As cyber threats escalate in frequency and sophistication, new research reveals an alarmingly high rate of security incidents over the past year, due to a lack of awareness and qualified professionals as key contributing factors.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
Fortinet establishes new point-of-presence in South Africa
News & Events Information Security
Fortinet has announced the launch of a new dedicated point-of-presence (POP) in Isando, Johannesburg, to expand the reach and availability of Fortinet Unified SASE for customers across South Africa and southern African countries.

Read more...
New tools for investigation and robust infrastructure security
News & Events Information Security
Cybereason continues to enhance its security platform, with recent updates introducing improvements in file search operations, investigation query results, and cloud workload protection, providing more granular data and faster key artefact identification.

Read more...