Cybersecurity is becoming increasingly important for manufacturing companies as automation and the ever-increasing use of industrial robots, cloud computing, artificial intelligence, and other breakthrough technologies generate vast amounts of data and information.
‘Automation can help companies reduce production costs and speed up operations. At the same time, when new devices are implemented, their cyber security risks also need to be taken into account, as they are all controlled via different information systems,’ explained Lauri Tankler, Head of the R&D Coordination Department of RIA.
‘We rely on the ability of researchers at the University of Tartu to gather information about the situation in companies and to find solutions to risks from both scientific literature and practical experience,’ Tankler noted. ‘I appreciate that the analysis focuses in particular on small and medium-sized enterprises. Their role in the economy is very important, but they often lack the resources and know-how to deal with the different risks.’
Researchers from the Institute of Computer Science of the University of Tartu studied a number of Estonian manufacturing companies that already use automation systems and technologies to identify potential weaknesses and ways to address them. ‘It turns out that awareness of the information security risks associated with automation is unfortunately quite low. Security aspects are often only addressed after an incident has occurred,’ said Vjatšeslav Antipenko, Junior research fellow of Information Security, one of the authors of the study.
There are dozens of different risks that can arise from automating production. Damage can be caused, for example, by disabling safety devices, physically tampering with sensors or exploiting remote network vulnerabilities, as well as sabotage by a disgruntled employee, personal use of the employer’s assets, and industrial espionage. ‘Risks that are likely to have the greatest impact must be addressed as a matter of priority. It is inevitable that some of the less dangerous risks are known but not addressed,’ Antipenko said.
The survey also included interviews with five companies, four of which had already experienced a cyber incident in one way or another. One company, for example, discovered on their own that they had a backdoor built into their devices and managed to prevent any malicious intent.
According to Antipenko, it turns out that while many companies have well-designed solutions in place to protect systems and machines, often the weakest link in the security chain is the employee: ‘Continuous training of staff on security threats and addressing human risks is therefore essential.’
Another problem identified by the study is that although Estonian manufacturing companies are fairly well informed about the requirements for personal data protection, they are much less aware of the various industry-specific standards and frameworks. ‘At the same time, these standards – ranging from safety protocols for industrial robotics to cybersecurity measures for cloud-based manufacturing systems – are essential to ensure the reliability and trustworthiness of systems,’ Antipenko stressed.
If a company has not yet taken a deeper look into cybersecurity issues, Antipenko recommends starting by mapping its assets and processes. On this basis, a risk analysis and assessment can be carried out, security measures selected and implemented. To help businesses do all this, the recent survey is available in full here.
The study was funded by the European Union and the European Cyber Competence Centre (ECCC).
Information about the analysis:
Vjatšeslav Antipenko
Junior research fellow of Information Security
University of Tartu
+372 5831 5956
[email protected]