Cybersecurity is a critical topic for many world regions, and indeed, for the middle east countries, this has become a natural defense and embedded in the industrial culture. Cyber-warfare is a relatively new phenomenon for the GCC, and since high-level attacks struck in 2012, these companies have made industrial cyber security awareness as a top priority. To help promote this awareness, EQUATE Petrochemical, and the Kuwait National Petroleum Company (KNPC) are hosting the 3rd Kuwait Industrial Automation Security Conference.
While the topic of cyber security will be the focus of the event, it is not without the recognition that these industries are in transition. With the onset of the Industrial IoT and Industrie 4.0, the deployment of systems and practices will inevitably change, including those to secure critical systems. Standards such as ISA 62443, NIST, ICS-CERT and others are effective to help plan critical infrastructure and industrial control systems, but the emergence of new business models, real-time data sharing outside the plant and other highly profitable outcomes have brought new organizations and frameworks such as the
Industrial Internet Consortium (IIC). Recently the IIC produced the
Industrial Internet Security Framework. This framework is unique and recognizes the changing technology deployment. Existing cybersecurity standards address the legacy technology stack and deployments of critical infrastructure and ICS systems defined by ISA-95 or Purdue Reference models.
ARC Advisory Group will present at the KIACS event and has closely monitored the development and adoption of ICS cybersecurity standards and best practices. ARC believes they are having a significant impact on the security of our plants and automation systems. But IIoT is disrupting fundamental assumptions underlying these efforts. Recognizing and addressing this situation is essential. Business managers are already redesigning processes to exploit IIoT capabilities. ARC believes that it is naïve to expect that they will wait for security to be addressed before implementing these capabilities; the cost and performance benefits are simply too large to ignore, and competition will force rapid adoption. Prudent ICS cyber security professionals appreciate the impact this will have on cybersecurity strategies and are looking for new guidelines that this should include:
- An extension of the scope of industrial cyber security to include systems and remote devices outside plant perimeters
- A shift in the focus of security strategies from protecting systems to managing devices
- Transition from cybersecurity silos to integrated IT-OT cyber security strategies
- Embedding security-by-design principles throughout organizations and cyber asset supply chains