{"id":430578,"date":"2018-01-25T16:08:57","date_gmt":"2018-01-25T15:08:57","guid":{"rendered":"https:\/\/www.devoteam.com\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/"},"modified":"2018-01-25T16:08:57","modified_gmt":"2018-01-25T15:08:57","slug":"is-industrial-security-what-threats-and-what-strategy-for-2018","status":"publish","type":"news-and-pr","link":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/","title":{"rendered":"IS Industrial security: What threats and what strategy for 2018?"},"content":{"rendered":"<p><span style=\"font-weight: 400\"><strong>In 2017, attacks and major vulnerabilities have made the headlines, including in less-specialized newspapers thanks to WannaCry &amp; NotPetya, Meltdown &amp; Spectre.<\/strong> Following the hype, traditional media produced quick responses, but this is too often at the price of incomplete information, partially wrong with an alarmist talk. <\/span><\/p>\n<p><span style=\"font-weight: 400\">The \u201cyoung\u201d (cyber)security universe of Industrials IS is exceptionally seen the same way as a spectacular dimension: many articles mixed all together with partial information, eye-catching titles and beautiful pictures of random industrial facilities. <\/span><\/p>\n<h2><b>Threats are rising: we need to secure tomorrow\u2019s factory<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Historically conceived as isolated systems, the <span style=\"font-family: 'PF Benchmark Pro Bold', Arial, Verdana, sans-serif\"><b>modernization<\/b><\/span>\u00a0and the <strong style=\"font-weight: 400\">interconnection<\/strong> of industrials IS are accelerating:<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400\">The advanced systems of manufacturing <strong>are connected<\/strong> to the Cloud <\/span><i><span style=\"font-weight: 400\">(Big Data)<\/span><\/i><span style=\"font-weight: 400\">, <strong>suppliers <\/strong><\/span><i><span style=\"font-weight: 400\">(l<a href=\"https:\/\/www2.deloitte.com\/content\/dam\/Deloitte\/tr\/Documents\/manufacturing\/Industry4.0ManufacturingEcosystems.pdf\">ogistics 4.0<\/a>)<\/span><\/i><span style=\"font-weight: 400\"> and <strong>customers <\/strong><\/span><i><span style=\"font-weight: 400\">(IoT)<\/span><\/i><span style=\"font-weight: 400\">; <\/span><\/li>\n<li><span style=\"font-weight: 400\">The traditional steering system give away ground to large complex <strong>networks<\/strong> of <strong>interconnected<\/strong> devices <\/span><i><span style=\"font-weight: 400\">(Smart Grids, IoT, drones etc.<\/span><\/i><span style=\"font-weight: 400\">); <\/span><\/li>\n<li><span style=\"font-weight: 400\">The technologies used are increasingly the ones from<strong> IT<\/strong>.\u00a0<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">Tomorrow\u2019s factory must face the same vulnerabilities though, in a <strong>critical universe<\/strong> (human and environmental impacts) and in a context where modernization <strong>projects are proliferating.<\/strong><\/span><\/p>\n<p><span style=\"font-weight: 400\">In order to secure tomorrow\u2019s world in a pragmatic way, the industrials are seeing: <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Awareness of <strong>cybersecurity culture<\/strong> with all implicated collaborators (engineers, technicians, operators, project managers, etc.) essential to the detection of incidents and to their prevention; <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">A <strong>technological watch<\/strong> in order to keep an objective vision of the stakes; <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">The use of an <strong>approach by risks<\/strong> in order to apply in a pragmatic way the necessary security measures <\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">Most importantly, the industrial actor that will succeed in this challenge would have been able to bring together a <strong>multidisciplinary team:\u00a0 <\/strong>s<\/span><span style=\"font-weight: 400\">ecurity actors, operations (we will talk about OT with control over the field stakes), IT (control of technologies) and safety. Only this team will be able to safely put into place the complexity of transformation, towards tomorrow\u2019s Industrials IS <\/span><\/p>\n<h2><b>The ghosts from the past: Secure yesterday\u2019s factory. <\/b><\/h2>\n<p><span style=\"font-weight: 400\">In any case, today, Industrial IS security is<\/span> <span style=\"font-weight: 400\">always mainly about correcting the conception defect due to a lack of cybersecurity culture in this universe. <\/span><\/p>\n<p><span style=\"font-weight: 400\">It is well known for the Industrial IS auditors that: \u00a0there is still a lot to do (obsolescence, uncontrolled use of USB keys, Internet accessibility, less secure architectures, etc.) in order to protect the factory and its operations. <\/span><\/p>\n<p><span style=\"font-weight: 400\">The 2017 award of threats on Industrials IS goes to, without a doubt, <\/span><a href=\"https:\/\/dragos.com\/blog\/trisis\/TRISIS-01.pdf\">TRISIS<\/a><span style=\"font-weight: 400\">. \u00a0It is still about a new <a href=\"http:\/\/www.economist.com\/node\/17147862\"><strong>Stuxnet<\/strong><\/a><\/span><span style=\"font-weight: 400\">, exploiting another vulnerability with a new <strong>catchy<\/strong> name which got Twitter buzzing\u2026 Nothing new right? And yet, yes. <\/span><\/p>\n<p><span style=\"font-weight: 400\">Its targets, <strong>SIS<\/strong> (Safety Instrumented System), are autonomous systems whose purpose is <strong>to stop urgently an \u201cout of control\u201d industrial process<\/strong> from the nominal steering system in order to protect people, goods and the environment. <\/span><\/p>\n<p>TRISIS<span style=\"font-weight: 400\"> got its name from SIS and \u201cTriconex\u201d (one of the SIS models most spread worldwide) and seems to be the first successful attack on this type of system. <\/span><\/p>\n<p><span style=\"font-weight: 400\">While we almost forgot about the story we heard too many times on Stuxnet; TRISIS just reminded us in a cold manner that: <\/span><i><\/i><\/p>\n<ul>\n<li style=\"font-weight: 400\"><strong>T<\/strong><span style=\"font-weight: 400\"><strong>he fight to secure our critical facilities is far from being won;<\/strong><\/span><\/li>\n<li style=\"font-weight: 400\"><strong>Motivated hackers with impressive resources are still at work. \u00a0<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">It is highly unrecommended to direct a cybersecurity strategy of the Industrials IS directly focused on new technologies. The old threats are still here and evolving. <\/span><\/p>\n<p><strong>The security of facilities in production is far from being finished. It should certainly be more appropriate for Industry 4.0 to observe a serious reinforcement of critical infrastructures\u2019 security. <\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2017, attacks and major vulnerabilities have made the headlines, including in less-specialized newspapers thanks to WannaCry &amp; NotPetya, Meltdown &amp; Spectre. Following the hype, traditional media produced quick responses, but this is too often at the price of incomplete information, partially wrong with an alarmist talk. The \u201cyoung\u201d (cyber)security universe of Industrials IS is [&hellip;]<\/p>\n","protected":false},"featured_media":0,"template":"","categories":[],"tags":[770],"industry":[],"class_list":["post-430578","news-and-pr","type-news-and-pr","status-publish","hentry","tag-cybersecurity"],"acf":[],"cards":"\n\t<div class=\"single-post-card\">\n\n\t\t\n\n\t\t\n\t\t<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-43282307 wp-block-group-is-layout-flex\">\n\t<p style=\"font-style:normal;font-weight:700\" class=\"has-link-color wp-elements-1 wp-block-lp-post-type has-text-color has-primary-color has-small-font-size\">News<\/p>\n\n\t\t\n\t\t<h3 style=\"font-style:normal;font-weight:400\" class=\"wp-block-post-title has-base-font-size\"><a href=\"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/\" target=\"_self\" >IS Industrial security: What threats and what strategy for 2018?<\/a><\/h3><\/div>\n\t\t\n\t<\/div>\n\n","yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>IS Industrial security: What threats and what strategy for 2018? | Devoteam<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IS Industrial security: What threats and what strategy for 2018?\" \/>\n<meta property=\"og:description\" content=\"In 2017, attacks and major vulnerabilities have made the headlines, including in less-specialized newspapers thanks to WannaCry &amp; NotPetya, Meltdown &amp; Spectre. Following the hype, traditional media produced quick responses, but this is too often at the price of incomplete information, partially wrong with an alarmist talk. The \u201cyoung\u201d (cyber)security universe of Industrials IS is [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/\" \/>\n<meta property=\"og:site_name\" content=\"Devoteam\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devoteam.info\/wp-content\/uploads\/2024\/12\/picture1-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"805\" \/>\n\t<meta property=\"og:image:height\" content=\"288\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/is-industrial-security-what-threats-and-what-strategy-for-2018\\\/\",\"url\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/is-industrial-security-what-threats-and-what-strategy-for-2018\\\/\",\"name\":\"IS Industrial security: What threats and what strategy for 2018? | Devoteam\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/#website\"},\"datePublished\":\"2018-01-25T15:08:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/is-industrial-security-what-threats-and-what-strategy-for-2018\\\/#breadcrumb\"},\"inLanguage\":\"en-CZ\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/is-industrial-security-what-threats-and-what-strategy-for-2018\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/is-industrial-security-what-threats-and-what-strategy-for-2018\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"News & PR\",\"item\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/news-and-pr\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"IS Industrial security: What threats and what strategy for 2018?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/#website\",\"url\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/\",\"name\":\"Devoteam\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/devoteam.info\\\/cz\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-CZ\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"IS Industrial security: What threats and what strategy for 2018? | Devoteam","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/","og_locale":"en_US","og_type":"article","og_title":"IS Industrial security: What threats and what strategy for 2018?","og_description":"In 2017, attacks and major vulnerabilities have made the headlines, including in less-specialized newspapers thanks to WannaCry &amp; NotPetya, Meltdown &amp; Spectre. Following the hype, traditional media produced quick responses, but this is too often at the price of incomplete information, partially wrong with an alarmist talk. The \u201cyoung\u201d (cyber)security universe of Industrials IS is [&hellip;]","og_url":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/","og_site_name":"Devoteam","og_image":[{"width":805,"height":288,"url":"https:\/\/devoteam.info\/wp-content\/uploads\/2024\/12\/picture1-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/","url":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/","name":"IS Industrial security: What threats and what strategy for 2018? | Devoteam","isPartOf":{"@id":"https:\/\/devoteam.info\/cz\/#website"},"datePublished":"2018-01-25T15:08:57+00:00","breadcrumb":{"@id":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/#breadcrumb"},"inLanguage":"en-CZ","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/devoteam.info\/cz\/news-and-pr\/is-industrial-security-what-threats-and-what-strategy-for-2018\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devoteam.info\/cz\/"},{"@type":"ListItem","position":2,"name":"News & PR","item":"https:\/\/devoteam.info\/cz\/news-and-pr\/"},{"@type":"ListItem","position":3,"name":"IS Industrial security: What threats and what strategy for 2018?"}]},{"@type":"WebSite","@id":"https:\/\/devoteam.info\/cz\/#website","url":"https:\/\/devoteam.info\/cz\/","name":"Devoteam","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devoteam.info\/cz\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-CZ"}]}},"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Julien Pawlowski","author_link":"https:\/\/devoteam.info\/cz\/author\/"},"uagb_comment_info":0,"uagb_excerpt":"In 2017, attacks and major vulnerabilities have made the headlines, including in less-specialized newspapers thanks to WannaCry &amp; NotPetya, Meltdown &amp; Spectre. Following the hype, traditional media produced quick responses, but this is too often at the price of incomplete information, partially wrong with an alarmist talk. The \u201cyoung\u201d (cyber)security universe of Industrials IS is&hellip;","_links":{"self":[{"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/news-and-pr\/430578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/news-and-pr"}],"about":[{"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/types\/news-and-pr"}],"version-history":[{"count":0,"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/news-and-pr\/430578\/revisions"}],"wp:attachment":[{"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/media?parent=430578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/categories?post=430578"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/tags?post=430578"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/devoteam.info\/cz\/wp-json\/wp\/v2\/industry?post=430578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}