Ongoing Convergence of IT and Security in Industrial Network Infrastructure

Author photo: Chantal Polsonetti
By Chantal Polsonetti

Keywords: Industrial Network Infrastructure, Industrial Ethernet Switches, Cybersecurity, ARC Advisory Group.

Overview

Industrial networking infrastructure is in the midst of major transformation. IT/OT convergence in even mission-critical control and network infrastructures is now a given due to ongoing incorporation of COTS-based CPUs (Intel/ARM), operating systems (Linux, Windows), and descent of cloud-based architectural components (orchestration, virtualization, edge computing, AI, analytics.)  This convergence is now extending to the security realm as operations environments emerge as a leading target due to their large attack surfaces, plethora of vulnerable devices, and potential for widespread disruption.

Convergence of IT and Security

Manufacturers, machinery builders, system integrators, and other network implementers increasingly recognize that secure network infrastructure is the foundation for not only comprehensive threat defense, but also for achieving both operational improvements and business innovation. Increasingly stringent regulations regarding both sustainability and cybersecurity, including the requirements of the pending European Cyber Resilience Act (CRA), NIS2, and other directives, are further driving the need to securely establish and communicate with an increasingly data-centric mission critical infrastructure.

At the same time, both industrial networking technology and associated security mechanisms are increasing in complexity, while the onslaught of potential disruptors continues to escalate. Coupled with the increasingly data-driven and software-defined profile of the operations environment and associated support network infrastructure, a converged strategy that incorporates not only IT and OT but also security is mandated.

Manufacturing’s Increasing Attractiveness

Customers are keenly aware that the move to digitize all aspects of the enterprise, including operations and integrated supply chains, brings with it the prospect of cybersecurity breaches. The prospect of AI adoption throughout the enterprise, from C suite business improvement applications to assistance with overcoming skilled worker labor shortages, is also furthering the push towards convergence.

Cybercriminals are increasingly targeting manufacturing environments due to their large potential attack surface area, increasing vertical and horizontal connectivity, plethora of vulnerable devices, and ongoing penetration of commercially available (vs. proprietary) components for both computation and communication. These bad actors also recognize that the high cost of downtime in industrial operations is a strong incentive to pay large ransoms.

According to ARC’s industrial cybersecurity practice, industrial operations are now prime targets for cyberattacks, with manufacturing facilities accounting for upwards of 20 to 25 percent of all cyber targets. Most of the recent cyber-related operational disruptions have been caused not by OT system compromises, but rather infiltration of connected systems. Living off the land (LoTL) attacks are especially concerning given their ability to lurk undetected in IT networks until an opportunity to connect to the OT network presents itself. 

Infrastructure as a Target

Of increasing concern are threats targeting specific industries, including infrastructure. The Chinese State-sponsored Volt Typhoon LoTL threat, for example, has targeted infrastructure installations such as electrical substations, water treatment plants, and transportation hubs.

Regulatory Compliance and Industry Certifications

Increasing cybersecurity regulations at the regional and industry level are also driving convergence. The requirements of the upcoming European Cyber Resilience Act (CRA), a legal framework that describes the cybersecurity requirements for hardware and software products sold in the EU, mandate further certification, including availability of free security firmware updates. 

The Network and Information Security 2 (NIS2) directive introduces a range of obligations on manufacturers, importers, distributors, and other stakeholders in the digital ecosystem, including automation system suppliers and any company with greater than €10 million in revenues. Non-compliance can result in fines of up to 10 percent of annual revenues. NIS-2 is designated to be adopted by the individual EU member states as of October 2024.

Specific industries may also have their own increasingly must-have certifications. Customers in the electric power industry, for example, are now requiring IEC 62351 (NERC CIP in the US) certification for power automation.

The Need for Converged Networking and Security

With network infrastructure increasingly targeted for disruption, it is vitally important for the network to function as an extension of the security infrastructure. Network operations are likewise increasingly recognized as the vehicle for enhancing uptime, data availability, innovation, and remote access, which has been a primary catalyst driving IT/OT convergence.

Horizontal and vertical integration throughout the enterprise and operations necessitates a converged strategy that incorporates the centralized management and security policies instituted by the IT organization with the need for safe, resilient, and continually operating OT processes. Network infrastructure purchases must therefore incorporate the priorities and requirements of three groups of key stakeholder organizations:  OT, IT, and security.

 

ARC Advisory Group clients can view the complete report at the ARC Client Portal.

Please Contact Us if you would like to speak with the author.

Obtain more ARC In-depth Research at Market Analysis

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients