In contrast to the IT security approaches for conventional IT networks, industrial control systems (ICS) and their automation components were not considered a potential security risk in the past. This attitude has changed in recent years. In the past, the causes of anomalies in ICS were often due to user errors or defective hardware and software.
However, cyber-attacks on ICS environments are no longer fiction but reality today. There is a need for companies with ICS to review their approach to cybersecurity - especially since previous protection methods have relied on operating industrial infrastructure in physically isolated environments.
In the age of digitalization, ICS are connected to more and more components that communicate directly via the Internet. This makes it possible to communicate online with automation systems, e.g. intelligent buildings, pipelines, or autonomous mobility.
In contrast to corporate networks that manage information, ICS manages physical processes. These components can be manipulated or even destroyed by cyber-attacks. Criminal organizations are now exploiting these possibilities, like a business model. Users must protect themselves with new, modern security methods to detect attacks and initiate countermeasures.
ARC Survey: Cybersecurity of Industrial Control Systems
In summer 2020, ARC Advisory Group conducted a survey on the state of cybersecurity of industrial control systems, as well as the priorities, concerns and challenges for industrial organizations. The objective of the research was to understand the measures and processes involved in the prevention of cyber-incidents in industry. Some questions addressed whether the current Corona pandemic is affecting ICS cybersecurity.
An ARC Report explores the results of the survey and is a follow-on to previous surveys on ICS cybersecurity by ARC and Kaspersky. 337 industrial companies and organizations across the globe were surveyed online, and 10 industry representatives were interviewed at trade fairs and ARC forums worldwide. Compared to the 2019 survey, this is an increase in responses of 25 percent. Most responses came from companies in Europe, America, Asia, and Middle East & Africa. This year, the survey was also translated into Japanese and Chinese. We experienced a strong influx of responses from these countries and have now achieved a much clearer assessment of the cybersecurity situation in Asia.
Survey respondents and interviewees work in a variety of roles in critical infrastructure, such as energy and water, as well as in process industries, including oil, gas and chemicals, and in manufacturing. About a quarter of the respondents work in ICS system integration, another 20 percent are responsible for the strategic management of ICS systems. This means that almost half of the respondents are responsible for the selection and configuration of ICS systems. The answers and assessments in this survey are therefore from professionals who are responsible for future ICS deployment strategies.
For more information on the results of this ARC Survey, or how to become an ARC client, please contact us.