Discussion:
Thought Leadership
PrimeKey
2017-04-05 07:53:36 UTC
Permalink
Addressing security within Industrial IoT

If you can't read this mail, click here. Link: http://www.anpdm.com/newsletterweb/44455C427249415C4179434259/42455B4077444B5F407445465D4171

Website | Link: http://www.primekey.se
Forward | Link: http://www.anpdm.com/taf/18622703/42455B4077444B5F407445465D4171
Subscribe | Link: https://www.anpdm.com/form/41475D4A7146465F407340/45425C457645425D4171
Unsubscribe Link: http://www.anpdm.com/ol/18622703/42455B4077444B5F407445465D4171

Addressing security within Industrial IoT

There is an increasing buzz about Industrial Internet of Things (IIoT). More and more are talking about it, the field is growing and PrimeKey was recently invited to speak to Swedish industries about IIoT and about the security implications it entails. There is definitely something interesting going on in the market here.

It seems inevitable that computerized components will be added to almost everything from tools and machines, all the way to even raw materials. For some companies, this may be a decision between closing operations or transforming a 40 years old factory into a 21st century on-demand, always-connected modern facility. The clear majority of industrial companies sees movement towards IIoT as critical for their future, although the relative majority prefers to observe how the market and technologies evolve rather than immediately react to new trends.

The industries are slowly but steadily getting connected and it is said that the factories will become “smart”. But - Becoming smart should not mean being naïve when it comes to security! A successful attack on IIoT may stop a factory, blow up a facility and in some circumstances, be used as an act of warfare. If anything, the security people agree on things will get worse, without even adding “before getting better”. Intellectual property thefts are “old news”. The current buzzword is ransomware.

To come to terms with security for IIot, PrimeKey suggest you have a think about the following:

Open and well-tested standards
- Gives the ability to integrate with different systems
- There is a wide rande of “closed” standard and initiatives that wish to make their mark on the industry or a vertical
- Only bring in “new” stuff when it is well-tested and it makes sense to replace the old
- [...]

Ownership of data and data-flows
- New market opportunities arise
- Service providers “encapsulate” industries and and connect them to the rest of the world
- Service providers have access to data and data-flows that are not “theirs”
- Security and business risks if not handled right
- [...]

Plan for robustness and resilience
- In security, it is imperative that things work 100% of time
- Different needs for diffrent use (serving customers vs. industrial control systems)
- Be aware of risks with cloud services
- [...]

Plan for adoptability and change
- Robustness is important but it can't be so rigid to become its own paradox - fragile
- Plan IIoT for the ability to switch between service and technology providers - or even use more than one
- Technologies should be upgradeable as to accommodate to new requirements
- [...]

Observe regulations; local and global
- Important to be compliant
- Regulation also brings punitive measures that can be very high
- Buzzword in Europe is General Data Protection Regulation, GDPR
- [...]

Read the full blog post here Link: https://www.primekey.se/news-events/thought-leadership-26/

Author: Admir Abdurahmanovic

Admir is VP Business Development and one of the founders of PrimeKey. With a strong background in IT Security and crypthology he is one of the most experienced PKI experts in the world.

Contact Admir:
***@primekey.se
+46 708 37 02 37

PrimeKey is one of the world’s leading companies for PKI solutions. PrimeKey is a pioneer in open source security software that provides businesses and organisations around the world with the ability to implement security solutions such as EJBCA, SignServer and PKI Appliance.
Loading...