Industrial IoT applications depend on networks that extend to industrial assets. And network connectivity to an industrial asset is non-trivial regardless of whether the asset is on a factory floor or at a remote location. For both types of assets, network security concerns abound.
Last night I listened to a podcast by a supplier (I will not name him) who described his company mission as “helping OEMs to make their industrial devices secure”. Now that is a most honorable mission, but it simply made my eyes roll. I’m sorry, but I won’t drink that Kool Aid. This is simply not going to happen, at least not in my lifetime! Industrial devices are never going to “catch up” technologically with state-of-the-art security. Here are a few reasons why:
- The industrial device life-cycle is too long; typically, 10-20 years.
- Industrial devices use insecure protocols that lack true network functionality (e.g. HART, Profibus PA, FF H1, Modbus, etc.)
- OEMs design their product lines with as much common technology as they can, so the tech going into a new industrial product is usually NOT new at all.
- Most industrial devices CAN’T be upgraded, period, let alone be upgraded remotely via a network.
- Trusted computing technology is just too difficult and costly for industrial devices.
- I could list many more reasons, but this is enough!
So, if industrial devices are never going to catch up with state-of-the-art security, does that mean the IIoT will always be a swamp of insecurity and a playground for cyber warfare? No! The reason for my uncharacteristic optimism is that while we cannot expect to make industrial devices as secure as they need to be, we CAN make industrial networks much more secure. And note that some manufacturers and suppliers are doing this TODAY. They are doing it by securing their industrial networks to a degree that goes far beyond what is common practice. They are using the technology of software-defined networks and secure overlay networks to secure industrial installations.
I recently wrote a report about 3 real-world examples of this entitled “
Software-defined Industrial Networks Deliver Cybersecurity Breakthroughs”. Breakthrough is a strong word, but it’s appropriate here. Therefore, let me give a “shout-out” to the 3 suppliers mentioned in the report who are doing great work in industrial SDN:
Schweitzer Engineering Laboratories (SEL),
Tempered Networks, and
Yokogawa. Do you know of others doing this kind of work in industry? Please let me know about them. I’m all ears on this topic.
