NEWS
A Growing Trend in Manufacturing Cyberattacks
|
In August, Siemens machines were targeted using Artificial Intelligence (AI)-generated code that was designed to mimic monitoring software for the S7 series Programmable Logic Controllers (PLCs). In April, Rockwell Automation PLCs were compromised as a part of the conflict with Iran, and in July it was identified that PLCs manufactured by Schneider Electric and Siemens were targeted as well. In May, zero-day vulnerabilities were discovered in CODESYS systems. All of these systems are International Electrotechnical Commission (IEC) 62443 certified and becoming increasingly software defined. In light of the “disappearing air gap” within manufacturing environments, ensuring effective implementation is becoming more important than checking the box for secure-by-design principles. Operational Technology (OT) cybersecurity has long prioritized availability, inverting the typical Confidentiality, Integrity, and Availability (CIA) Triad; however, in the face of reducing silos and airgaps, experts in designing these systems are challenged to reorient toward a more Information Technology (IT)-friendly understanding of the CIA Triad.
IMPACT
Confidentiality and Integrity Are Becoming as Important as Availability
|
AI is enabling hostile actors to create convincing duplicates of official software, which is becoming more difficult to differentiate. At the same time, Software-Defined Automation (SDA) is widening the prospective attack surface by migrating industrial tasks to IT and the cloud. Thus, while the secure-by-design principles of IEC 62443 help protect users, it is becoming increasingly evident that international cybersecurity needs have evolved beyond reliance on IEC 62443 alone as an internationally applicable, mandatory piece of cyber regulation. While the European Union’s (EU) Cyber Resilience Act (CRA) extends these principles horizontally to include vulnerability disclosures, documentation such as Software Bill of Materials (SBOM) and Conformity Assessment and CE Marking, the lack of international coordination may leave non-European exposure in the same place. As new systems come online and browser-based operations for PLC engineering are increasingly hitting the market, expansion of international obligations, potentially through new global standards, will be important in the face of growing AI threats.
The OT CIA Triad has long emphasized availability over confidentiality and integrity, minimizing downtime for critical systems. In the world of fully air-gapped systems and network-based security, this made sense, with systems largely offline or restricted on-premises networks. Now, accessibility demands are pushing systems further toward online environments, expanding the prospective attack surface for malicious threat actors, making a more balanced reconceptualization of the application of the CIA Triad within OT a necessary step forward within OT security. Designing confidentiality and integrity in a more balanced fashion is critical.
RECOMMENDATIONS
Successful Lifecycle Support Will Define Winning Cybersecurity for SDA
|
Industrial automation suppliers have historically focused on meeting compliance and safety requirements; however, even these are starting to fall behind in an AI world. Moving forward, it will become important for vendors to develop a stronger cybersecurity posture and educate downstream—whether directly to customers or through integrators—about best practices for IT-based cybersecurity practices and build a better understanding between IT expertise in designing cybersecure networks and OT expertise in maintaining system resilience and availability.
Breaking down the airgap with SDA is going to be especially challenging for smaller, less robust organizations, such as local utilities, which turn to SDA for the lower costs promised, with 40 water utilities’ automation systems compromised in Minnesota in July. Given their smaller budgets, these customers will be most reliant on support from suppliers to provide strong cybersecurity support. Considering AI-powered attacks and growing SDA interest, there is a developing position for companies that go directly to customers to be best-in-class cybersecurity automation providers, with deep integration and support beyond regulatory lifecycle management demands.