Report calls for urgent action to meet cyber threat to critical infrastructure

Global safety charity, Lloyd’s Register Foundation today launched a report called Operational Cyber Security for the Industrial Internet of Things: Challenges and Opportunities. It highlights an impending threat to critical infrastructure from cyberattacks, given the growing reliance on the Internet of Things (IoT), say Robert Hannigan, executive chairman international at BlueVoyant and Sadie Creese, professor of Cyber security, Department of Computer Science, University of Oxford.

The report specifically focuses on the inherent risks for Industrial IoT (IIoT), fast becoming a core part of critical global infrastructures, across sectors including energy, transport, the built environment and physical infrastructure, and manufacturing. Safety is particularly critical in IIoT environments, and so it is essential to understand how to deliver secure and resilient infrastructures.

The IIoT also exacerbates security challenges that already exist. The report aims to prioritise action by identifying key emerging risks, and gaps in capability for which the current pace of change in operational cyber security will not be sufficient. In these environments, the consequences of failure can be systemic, and the report calls for the urgent adoption from the IIoT community of guiding principles to increase resilience to cyberattacks.

The report notes the differing perspectives of those responsible for managing risk within industry, which includes operations and board members, companies and regulators, procurement and cyber security teams, and provides a useful overview to increase cyber awareness for all.

The core finding of the report is that the current pace of change will not match the fast emergence of new security threats to IIoT environments. Current capabilities, the report points out, either do not scale, have not been tested or simply do not yet exist. The report additionally points to the approaching tipping point for recovering from cyberattacks, and the challenges for mindset, regulation and insurance that can build preventative security practices.

Whilst regulation, the requirements of cyber-insurance providers, and the adoption of a cyber security mindset within organisations could drive progress towards bridging operational capability gaps and developing risk controls that translate effectively into the IIoT, there are new, pressing challenges to confront.

The management of cyber security risk for traditional systems already faces many challenges. These include the sheer difficulty of trying to map the complicated relationships between technical and human systems, and the challenges of communication between different communities where the frameworks for understanding risk are fundamentally different.

Many of these existing challenges will remain and be exacerbated, and new ones will arise, as risk-management approaches are translated into the IIoT, creating key capability gaps.

In addition to exploring these challenges as IIoT expands, the report expands on actionable findings including:

  1. Always consider harm consequences when planning how to manage risks
  2. Consider how security controls may fail as you increase use of IoT devices
  3. Use techniques that can provide you with a continuous assessment of your position (near real-time) as opposed to periodic assessments
  4. Consider how your supply-chains are using IoT: consider their failure to maintain cyber security as risk to your security risk management plans
  5. Invest in forensic readiness processes
  6. Include a consideration of future scenarios in your risk assessments
  7. Invest in training for staff on IoT standards and good practice
  8. Collaborate to establish a device interface protocol for sharing security monitoring information

The authors are Robert Hannigan, executive chairman international at BlueVoyant and Sadie Creese, professor of Cyber security, Department of Computer Science, University of Oxford.

About the authors

Sadie Creese

Robert Hannigan

Robert Hannigan, executive chairman international at BlueVoyant, former director of GCHQ, the UK security establishment, and co-author of the report, says,“Over the last few years we have seen a rise in deliberate attacks aimed at critical infrastructures across the globe. As adoption of IoT in the industrial sector continues to grow, clear action and guidance is needed. Our report frames the context of IIoT, the imminent problems facing key infrastructure as they increasingly rely on connected systems, and possible solutions to safeguard against cyber incidents.”

Sadie Creese, professor of Cyber security, Department of Computer Science, University of Oxford and co-author, adds, “We need to build resilient infrastructures that guarantee security to the ever-expanding connected network of ‘things’. There is clearly an urgent need for further research to understand and evidence risk control performance; to explore liability models, practicalities and implications for IoT markets; and to develop international cooperation to build trust in the IIoT supply chain.”

Comment on this article below or via Twitter: @IoTNow_OR @jcIoTnow

RECENT ARTICLES

Smart home technology saves money and helps protect the planet

Posted on: April 22, 2024

In the global battle against climate change and to be more sustainable, the quest for energy efficiency has taken centre-stage. The focus on sustainability is an increasing emphasis on humanity’s finite resources and the effect of our energy-consumption habits on the world around us. This heightened awareness is leading to a radical rethinking of how

Read more

Rajant Corporation boosts Mirato’s efficiency with Reios IoT solutions

Posted on: April 22, 2024

Rajant Corporation has announced the success of its Reios suite of IoT solutions for an Italian manufacturer Mirato, a maker of personal hygiene products, such as hair care, makeup and fragrances. Looking to improve energy efficiency and safety, along with optimised vehicle utilisation within plant operations, Mirato chose Reios Smart Lighting industrial LED lamps for

Read more
FEATURED IoT STORIES

What is IoT? A Beginner’s Guide

Posted on: April 5, 2023

What is IoT? IoT, or the Internet of Things, refers to the connection of everyday objects, or “things,” to the internet, allowing them to collect, transmit, and share data. This interconnected network of devices transforms previously “dumb” objects, such as toasters or security cameras, into smart devices that can interact with each other and their

Read more

The IoT Adoption Boom – Everything You Need to Know

Posted on: September 28, 2022

In an age when we seem to go through technology boom after technology boom, it’s hard to imagine one sticking out. However, IoT adoption, or the Internet of Things adoption, is leading the charge to dominate the next decade’s discussion around business IT. Below, we’ll discuss the current boom, what’s driving it, where it’s going,

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way you work, play, and live. But is it just another buzzword, or is it the as-promised technological holy grail? The truth is that Internet of

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT Platform 2021? authors Robin Duke-Woolley, the CEO and Bill Ingle, a senior analyst, at Beecham Research. Figure 1 shows these parts and, although not all

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for smart home automation will reach $40 billion by 2020.

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into a more switched-on place to live.

Read more