Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

How can manufacturers stop being the top target for cyber crime?

Historically, the financial services sector has been the most attacked by cybercriminals. Still, in 2021 there was a substantial shift, and a different industry ranked at the top for the first time – the manufacturing industry.

For the second year in a row, manufacturing was the top-attacked industry according to IBM’s X-Force Threat Intelligence Index.

Recent reports cite over half of all manufacturers in Britain succumbing to cybercrime in the last two years. While 39% of UK businesses reported suffering a cyber-attack in 2022, with data breaches costing companies an average of $4.35 million. So, it’s a case of not if, but when will you be attacked – and how prepared is your business to foil an attack or recover from a breach?

Currently, the risks are evolving just as rapidly and cleverly as the remediations and technical controls that counteract the advances of criminal opportunists. Technological acceleration is shaping manufacturing into a new normal of automation and digitalisation, a change known as the Fourth Industrial Revolution (4IR). Industries with Operational Technologies (OT) networks – including mining, utilities, and oil and gas, with their huge networks of connected devices create a rich target for aggressive ransomware attacks.

The manufacturing sector is being hit hard as it dislikes downtime, making it more likely to pay a ransom. Its lengthy supply chains provide more vulnerabilities than other sectors. The pandemic has exasperated these issues. The financial upset from unplanned downtime has been summarised in a substantial cost-per-minute figure of $22,000 (£18,871.27).

To add to these challenges, security has become more complex as different technologies can be stacked for greater risk resilience. Disparate toolkits have been created as a result and resources stretched to breaking point to oversee complex IT environments and the workloads running behind the scenes. We’re seeing a groundswell of security products – with over 1,800 active firms in the UK’s cyber security products and services space alone. The picture is often confusing for IT decision-makers regarding which products to buy.

So how can manufacturers make sense of what’s on offer?

Manufacturing A Better Security Posture 

Threat actors will evolve and innovate as businesses ramp up transformation, transitioning into hybrid cloud environments. The basic building blocks start with password hygiene, policy relevance and compliance, and a sizeable security toolkit. But there’s always more that manufacturers can be doing to improve their resilience.

Security by default

Security is no longer optional when everyone’s a target. In a product and solution agnostic overview, it would be advisable for businesses and enterprises alike to revisit and revise their perception of risks and security protocols to align with the modern threat landscape. This means understanding concepts like zero trust, the value of automation toolkits, the strengths or weaknesses of third-party services, and how security can be levelled up through consultation, personalisation, and deployment.

‘Security by default’ may feel new to a market that has historically viewed security, at times, as optional. But in a climate where risk evolution is in a fast sprint and where a business can ignore basic tenets like patching cadence, the urgency of risk needs to be reinstated.

By adopting a security by default perspective, products and services need to consider layers of resilience to different, pressing threat actors and types. A renewed security approach aligned with modern toolkits, services and expertise will be critical in supporting regulated workloads against known and emergent risks. This will include everything from consulting, managed services to Security Operations Centre (SOC), faster threat intelligence and even automated remediation.

Building layers of resilience

The three key pillars in cyber security include people, processes, and technology. A “security posture” is hardened to even the most aggressively sophisticated attack types and actors between these interlocking constituent parts. Manufacturers can reverse the pattern of malware intrusions when they understand how to build layers of resilience to wrap around their employees, processes, and technologies.

Outsourcing security and risk to a managed service

As businesses globalise, modernise and become more interconnected with other brands, customers and international talent, the scope for new risk increases. Offloading risk through cyber insurance and third-party arrangements will allow businesses to sidestep some pressing threats, but not all. As security budgets firm up to brace against risk, companies must train employees effectively in cyber security, build reliable partnerships and develop more secure supply chains. This means having security everywhere. Tools, skills, and expertise allow businesses to create layers of resilience.

As more manufacturers across the UK improve security controls for breaches, two critical security scenarios play out: preparing for and recovering from a breach.

Preparing for a breach

One of the IT department’s biggest challenges is the use of disparate toolkits created within manufacturing organisations, which results in stretched resources, particularly within the SOC. This becomes further aggravated without proper management or training on those toolkits.

Faced with increasing threats, today’s SOC needs support to investigate and prioritise risks and respond quickly and proportionally. Poorly deployed and unmanaged security products can worsen security postures, reducing a security professional’s flexibility to the most significant threats they battle daily. And, cyber insurance policies will be voided by improper tool use.

The power of a tool is unlocked only when it’s properly activated and managed. Preparing for a breach means that manufacturers must review gaps in their toolchains but seek consultation and training to ensure controls are appropriately activated and managed.

The first line of defence for security teams is risk prevention. Prevention entails the technical controls that contain or blunt security threats, halting them before they escalate into a breach. This will include threat detection, analysis, and response measures. Risk prioritisation simplifies prevention by mobilising remediation controls and directing attention to the most relevant, escalating risks in the moment. It involves automation and insights that will pull at levers to control the ebb and flow of threat varieties.

Managing a breach

Automation can remove many traditional security barriers. Most commonly, these barriers involve human manual or repetitive tasks that prevent security teams from being as rapid or responsive as required to handle escalating threats.

Workloads are better protected precisely because security operates in a closed loop, from detection and investigation to interrogation and response of risks. In this approach, threat intelligence proactively informs how rapidly teams can respond to the most immediate threats as they emerge. When a threat is prioritised, escalating into a primary challenge for your security team, it frees resources to do what matters most in these situations: strategise a quick, effective response.

Time is one of the greatest assets in any given security battle. With accelerated threat hunting and real-time intelligence, security teams can prioritise actions to prevent attacks. Time will also work against a manufacturer after a breach has occurred. The longer an infection goes unanswered, the greater the damage over time. After several weeks, a company may never recover. But contained within days, security teams can plan to recover from a breach and limit the damage.

Conclusion

Breaches have a personal impact as much as a commercial and reputational one. Key executives and directors are liable; security professionals feel responsible; the wider business is at risk. Yet, manufacturers shouldn’t let the stigma of a breach shrink their confidence in managing the modern threat landscape. Breaches will happen, but the damage can be contained with the right technologies, policies, people, and consultation.

With a flood of security products on the market, navigating the right tools to deploy can be challenging. For manufacturers facing tool abundance and indecision, it’s wise to consider how to create and build an interconnected web of resilience that works to deter, contain, diminish, and expel threats of all shapes and sizes.

Ask yourself: 

  1. How many tools do I need to become secure?
  2. How many tools can my team manage?
  3. How compatible are my tools – do they engage with one another?
  4. Where are the gaps in my toolchain?
  5. Are all staff being trained regularly on cyber security issues?
  6. Does the business foster a culture of zero trust across?
  7. How much confidence do I have in my security capability?

Cyber security should be a living, breathing ‘ecosystem’ or a suite of interlocked, in some cases automated, services and solutions.


About the Author

Andy Dunn is CRO at CSI Ltd. CSI is an IT Managed Services Provider bringing world-class Hybrid Multi-Cloud, Data Protection, and Cyber Security solutions to our clients’ businesses. We specialise in underpinning our clients most mission-critical platforms, giving complete confidence and peace of mind that they will perform brilliantly.

Featured image: ©Ridvan

more insights