Meeting manufacturing’s cyber security challenges
Scott Leach, Vice President APJ at cybersecurity firm Varonis In February 2021, Security Intelligence reported a 156 per cent increase in ransomware attacks on manufacturers worldwide.Some of the biggest attacks included a demand for $US17 million from a Taiwanese laptop maker and another attack for $US34 million from an electronics manufacturer for Apple. Verizon’s 2021 Data Breach Investigations Report also found the manufacturing sector facing a significant increase in ransomware attacks. These accounted for 61.2 per cent of all breaches in the sector analysed by Verizon. None of these reports offered any reason for this surge in attacks on manufacturers. Still, it has been well-reported that the increasing interconnection of legacy operational technology (OT) and newer information technology (IT) systems has greatly increased the attack surface for manufacturers. OT can now be compromised to gain access to IT, and vice versa. To make matters worse, OT systems were historically isolated from the internet and therefore were not designed to face cyberattacks. Manufacturers must double down on security, and ensure their data is protected and managed safely. This is particularly important for customer data and intellectual property, which could be extremely valuable to a rival organisation. Taking a data-centric approach to security Traditional security measures rely on a ‘walled garden’ approach. Anyone within the walled garden–i.e., employees, contractors and those granted network access–are automatically assumed to be trustworthy, and not verified. Instead, a data-centric approach utilises a zero-trust model, where no-one is assumed to be trustworthy and every access attempt to sensitive data is verified. Typically, the identity of the accessor, the device they are using, their location and the data they are seeking access to are all checked against pre-authorisations. There are plenty of technology solutions available to implement a zero-trust policy. The hard part for any large organisation that […]