Critical Security Challenges Facing IIoT

Kymer Security

 

Feb 13, 2018

By Will Mapp, Kymera Systems

The Industrial Internet of Things (IIoT), also known as the Industrial Internet, is transforming the way innovative businesses collect and share data. IIoT combines machine-to-machine (M2M) communication, industrial big data analytics, human machine interface and data acquisition to drive smarter, faster business decisions and powerful outcomes for enterprises of any size.

From the looks of it, this digital transformation is here to stay. According a recent report by IDC, worldwide spending on IIoT is forecast to reach $1.29 trillion in 2020.

As the scope of connectivity between devices continues to expand in industries such as oil, gas, power generation and healthcare, so does the potential for cyber security events that can carry serious risks. In safety-critical environments, any system failure or unplanned downtime can result in a high-risk situation or life-threatening emergency.

While several measures are being taken to prevent security breaches at the device level and beyond, there is still work to be done to educate consumers and ensure the security of embedded devices. Here we outline the top security concerns organizations should consider when building out their IIoT infrastructure:

Network Security

With a wider range of communication protocols, standards and device capabilities, IIoT network security is more challenging than traditional network security. To best protect assets and communication links, IT organizations should implement a flexible security framework that allows them to closely monitor network growth and quickly allocate security tools needed to ensure the proper functioning of their systems should they come under attack. No new devices should be allowed on the network until hardware, manufacturer details and platform security have been thoroughly assessed for compliance.

Authentication

Businesses cannot protect sensitive data that is being shared or transactions being conducted if they can’t be sure (or at least reasonably confident) of the IIoT entity they are communicating with. Therefore, offering every “thing” a unique identity should be the foundation of any security strategy. IIoT authentication requires a layered, standards-based security approach that constantly changes as new challenges arise. One security technology that meets those requirements is Public Key Infrastructure (PKI). PKI has been securing network connected devices by delivering trust and high assurance for decades already – making it ideal for managing IIoT device identities.

Outdated Device Software

Consumers are at risk anytime they are using software that has not been updated to fight off security attacks. Companies that are serious about the safety of their customers must ensure the devices they design have the IO and storage needed for firmware updates and commit to running all necessary updates throughout the device lifecycle.

Consumer Agreements

A Deloitte survey found that over 90% of consumers accept legal terms and conditions without reading them. When thinking about IIoT security, it is important to remember that the first line of defense is your organization. To ensure the safety of your network, do not allow employees to experiment with random new devices within the network and thoroughly read through any agreement before receiving a device to understand how data will be shared and kept safe.

Data Security

The sheer amount of data that IoT devices can generate is staggering. A Federal Trade Commission report entitled “Internet of Things: Privacy & Security in a Connected World” found that fewer than 10,000 households can generate 150 million discrete data points every day. Planet Technology estimates that 25 billion IoT devices will generate 1.6 billion terabytes of data by 2020.

With this onslaught of information comes a new and increasingly complex challenge to corporations to ensure data is securely collected and integrity is maintained as data moves from device sensors, over the company gateway, through servers/applications, into the data center and, eventually, into storage. Insecurity at any point in this process can lead to erroneous or altered streams that can compromise the validity of the data coming over the gateway.

When you are mapping out your IIoT strategy, it is important to think through the real aspects of what you are trying to accomplish and how you plan to use the data you are collecting. How will you ensure the accuracy of the data you are measuring? What steps will you take to maintain the security and integrity of data as it flows throughout your system? What data will you save and for how long?

A well thought out strategy will keep your handling and retention policies aligned to the new reality this type of data presents while keeping your customers information protected.

Summary

Any business that wants in on a bigger piece of IIoT real estate must understand the critical security risks and implications presented in this space and use that knowledge to adapt solutions to their specific needs.

Depending on the level of data security and compliance your organization requires, it may be appropriate to consider hiring a security consultant or cyber security expert to develop a comprehensive security strategy for your IIoT infrastructure.

Source:

http://kymerasystems.com/2017/11/22/critical-security-challenges-facing-iiot/

 

Related Articles


Latest Articles

  • Building a Greener Future – BuildForce Canada Report

    May 3, 2024 Retrofitting Canada’s residential, commercial, and institutional building stock to incorporate sustainable fuel sources, technologies, and materials could require as many as 57,000 additional construction workers and generate more than $81 billion in new construction investments by 2032. A new report prepared by BuildForce Canada, Building a Greener Future: Estimating the impact on construction… Read More…

  • HELUKABEL White Paper: “PUR or PVC”

    HELUKABEL White Paper: “PUR or PVC”

    May 3, 2024 The jacket material is a key factor when looking for the right cables and wires. The outer jacket performs a multitude of functions that ensure the durability, safety and performance of the cable or wire. Users must often choose between polyurethane (PUR) and polyvinyl chloride (PVC). In our new white paper “PUR… Read More…

  • Electric Avenue Annouces Improved Cold Temperature Rating of -40 Degrees

    Electric Avenue Annouces Improved Cold Temperature Rating of -40 Degrees

    April 26, 2024 Electric Avenue, a leading innovator in electric vehicle (EV) charging solutions, is thrilled to announce significant improvements to the cold temperature performance of its flagship products, the Watti Pro Lite and Watti Home Gen2. After comprehensive environmental testing, both chargers now boast an impressive operational rating of -40 degrees Celsius, surpassing the… Read More…

  • Electrical Incidents in Alberta for 2023

    Electrical Incidents in Alberta for 2023

    April 26, 2024 Regulations under the Safety Codes Act require that all electrical accidents and power line contacts be reported. This annual report by Municipal Affairs compiles a summary of incidents reported during the calendar year. Organizations in the electrical industry may wish to use this information for promoting public awareness of electrical safety risks…. Read More…


Changing Scene

  • Alberta Continues Campaign to Attract Skilled Trades People from Other Provinces

    Alberta Continues Campaign to Attract Skilled Trades People from Other Provinces

    May 3, 2024 To help fill critical job vacancies in the skilled trades, Alberta’s government has launched the third phase of the successful Alberta is Calling campaign, which is now in-market in British Columbia, Québec and Ontario. This campaign is bolstered by the Alberta is Calling Moving Bonus – a one time, $5,000 refundable tax… Read More…

  • Siemens Launches Depot360 Zero-Emission Fleet Management in Canada

    Siemens Launches Depot360 Zero-Emission Fleet Management in Canada

    May 3, 2024 With transportation being the second biggest emitter of greenhouse gases and road transport responsible for almost three quarters of these emissions globally*, Siemens Smart Infrastructure has launched Depot360, a portfolio to optimize fleet electrification. The initial focus of the solution is on logistics vehicles, municipal transit and private bus fleets within depot,… Read More…

  • Le Salon Lumen: Lumen Hosts 2024 Quebec Electrical Industry Blockbuster Customer Event

    Le Salon Lumen: Lumen Hosts 2024 Quebec Electrical Industry Blockbuster Customer Event

    (Photo caption: (From left to right) Lumen President, Serge LeBlanc, Sonepar Canada President, George McClean, Sonepar Americas President, Rob Taylor, and Sonepar CEO, Philippe Delpech in the Lumen booth, at Le Salon Lumen.) May 3, 2024 This month, Lumen held their 12th edition of the Salon Lumen, the largest exhibition in Quebec’s electrical industry. The… Read More…

  • Surgepure Announces Partnership with Focus Electrical Sales for the East Coast

    Surgepure Announces Partnership with Focus Electrical Sales for the East Coast

    May 3, 2024 SURGEPURE CORPORATION, a manufacturer of non-degrading hi-energy surge protection devices, announces a strategic partnership with Focus Electrical Sales. Based in the Maritimes, Focus Electrical Sales represents leading edge lighting and electrical manufacturers in North America. Focus adds extensive local application and technical support with offices in Nova Scotia, New Brunswick and Newfoundland,… Read More…