People, processes, technologists: identifying the key cybersecurity factors of smart factories

The digitalization of manufacturing has led to the emergence of new threats to the smooth operation of enterprises. To find out the main risk factors and understand how things stand with the cybersecurity of smart enterprises, we interviewed 500 employees of such enterprises from Germany, Japan and the United States. Half of them were in charge of information technology, and the rest were in charge of operations. Analysis of the responses showed that the key factors that determine the security level of smart factories are people, processes and technologies, as well as the level of interaction between IT and OT.





The modern industry is becoming more and more IT dependent. The equipment, in addition to components and assemblies, acquires intelligence and the ability to connect to the plant's network and to the Internet. IIoT devices are creating new cyber-physical systems that serve as the foundation of Industry 4.0.





, , , .





, 61% «» , 75% , 43% .





Number of incidents in smart factories and their consequences.  Source (hereinafter): Trend Micro
. ( ): Trend Micro

«» , , , , .





- -, , - , .





The importance of people, processes and technologies in the safety of smart enterprises
,

, -.





, .  — .





: , ,

, «» — 80% . ,  — , , — , 52% 39%. , .





, «» :





  • (52%);





  • — (50%);





  • USB- (50%);





  • (49%);





  • IPS (48%);





  • (39%);





  • (40%).    





. , , , , , , .





Implementation rate of different categories of technical measures by country

. , 56% ,  61% — . (53%), IPS (49%) USB- (49%). , 51% , .





Implementation rate of technical protection measures by country

— . , , (33%) (39%), (47%). :  — 42%,  — 35%,  — 39%.





: CSO, ,

. , , . , - -.





The importance of various technical means of protection in the opinion of IT and OT departments
- -

, , , IPS .





, , . , , . « »:  — Chief Security Officer (CSO), .





CSO - -, .





CSO , 60% «» . 56% CSO « » (cross-department committees). , . 49% , CSO 48%. : 44% .





The Most Important Organizational Factors for Effective Cybersecurity in Smart Enterprises

, , . , . .





: , , 57% , , (55%),  — (44%).





Motivating factors for collaboration between IT and OT in different countries

, , NIST CSF ( Cybersecurity Framework ) ISO 27001 (, ). NIST CSF 67% , ISO 27001 — 53% . NIST CSF (51%) , (43%) CIS Controls, The CIS Critical Security Controls for Effective Cyber Defense, - (CIS). , ISO 27001 (65% ); NIST CSF 57% .





Safety standards used by smart factories in different countries
,

: ,

. .





.   57% «» .  — 56% .





(48%),  — 45% . (50%) (49%).





«» . , . , .





, . , «» . , - , .





«» , , , .









, DMZ. - , USB-, , / , , IoT/IIoT.









, , , 100- , . , L2/L3 , , .









, . , . , , ,   OT.








All Articles