You Don’t have to be IoT-ish to Love Cybersecurity

Category:
Industry Trends
For old drones like me, watching the 1960s-focused “Mad Men” TV series brought back a lot of childhood memories. Though I never knew of anyone, even on Madison Avenue, who could survive half the self-destructive behaviors of a Don Draper, I still enjoyed watching him. One of the most iconic 1960s ad campaigns was for Levy’s Rye bread. Remember it? Their slogan was “You don’t have to be Jewish to love Levy’s”, and the ads were made into posters that adorned many a 60s dorm room. I don’t write ad copy (obviously), but the whole point of this post comes down to:

“You don’t have to be IoT-ish to love cybersecurity”.you-dont-have-to-be-jewish-to-love-levys

Maybe not loving security, but loving the feeling of being secure and having secure systems. Do you remember having that feeling about your systems, years ago, in the days before Stuxnet?

Last month the Industrial Internet Consortium (IIC) published its Industrial Internet Security Framework (IISF). Such a document is badly needed. Poll after poll has shown that THE major barrier to IIoT deployments is concern about cybersecurity. The IISF really tries to frame the discussion about IIoT security very broadly, and also highlight the most important considerations. I’m impressed by the parts of it that I have read so far.

Right at the beginning the document clearly draws the distinction between industrial control systems (ICS) and IIoT. Since, I spend a lot of my time working on ICS topics the main points I was interested in was why there were differences and how big the differences really were. My take is that the IIoT security considerations are necessarily broader than just ICS. However when I drilled down to look at areas where the IIoT and ICS should be similar, they were in fact VERY, VERY similar. In fact it is phenomenally similar to what a startup firm in the ICS market, Bedrock Automation, has been preaching at ARC events and elsewhere for the last couple of years (note the similarity of their figures).
figure
What struck me about the IISF discussion of Endpoint Protection was how closely it aligned with what ICS suppliers and end users want to have. Not “have” but “want to have”. Remember that ICS can have service lifetimes of 20 years or more. As a result the vast majority of the ICS installed base has very little intrinsic security. What security they do have is provided by network isolation. This isolation is done through network separation and through sets of firewall appliances, many of which are specifically tailored to the behaviors of the automation networks and systems they protect.

End users accept this, but they don’t like it. They believe that security takes up too much of their time and too much of their system engineering resources and budgets. They would much rather spend their time and money using the ICS to improve their manufacturing process rather than protecting their systems from, say, third generation foreign dictators of questionable sanity.

So I suggest to ICS professionals that they should familiarize themselves with the IISF document. What they will find is that much of the framework could be just as applicable to their installations. And being familiar with the framework will give them a good understanding of how their present ICS security stands in the IIoT security continuum.

And if you are an ARC Advisory Service subscriber, later this week I’ll be publishing an ARC Insight on this topic if you wish to read further. If not, there are always reruns of Don Draper.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients