Smart factories. Digital manufacturing. Industry 4.0. The transformational possibilities from a hyper connected manufacturing enterprise has spawned several exciting initiatives throughout many organizations. The blurring of lines between IT and operational technologies (OT) has enabled real-time visibility of asset productivity, improved efficiencies in processes and enabled very different operating models.
What if a cyberattack slams enterprise IT, propagating at lightning speed to a company's servers? The network crashes; email is down. The company faces months-long delays before even email and other system layers are restored at all locations. What would earlier have been an impact only to IT systems, now has the ability to stop production. Orders cannot be fulfilled.
This isn't conjecture. It happened at a global manufacturing company. Because its manufacturing operations technologies were connected with IT’s ERP systems, the company’s business slowed to a crawl. Manufacturing was halted due to limited to no visibility as to when operations could fulfill customer demand.
The ever more connected systems at large, global manufacturing enterprises face a real risk of dis-connection as a result of disasters. Such disasters may be man-made, like a ransomware attack or cybersecurity breach. It could be natural, like a hurricane. In either case, shutdowns are costly and difficult to recover from, since they snap the links in vital chains of information exchange within and across the extended enterprise.
Connectedness engenders risk? How can this be in an era of information redundancy, distributed networks, incremental backups, and cloud-powered enterprise systems? Simple. The ongoing effort to connect OT at the facility with enterprise IT systems has led to informational dependencies that create operational risk. Unexpected or unplanned business interruptions shutter key enterprise IT systems that are linked to OT. When disaster hits, their necessary connection is severely impaired.
Last year, another global manufacturing company experienced a catastrophic shutdown of one of its core IT systems locations during a hurricane. Operating in multiple locations, the company has devoted substantial resources and time tying OT at facilities to its enterprise IT architecture --as many industrial companies have. But when the hurricane hit, its core facility housing its ERP system went down. With its manufacturing systems tied to enterprise IT, clean-room manufacturing facilities -- each having cost more than $1 billion to build -- were effectively shuttered. The company lost weeks of valuable production --with a corresponding impact on its top- and bottom-line.
Planning for Hyper-connectivity’s Unintended Consequences
Industry 4.0 has brought a marked shift in the management of the manufacturing function, from the C-suite to the factory floor. However, turning Industry 4.0 from a lofty concept to an enterprise reality is still a work in progress. Clearly, digitizing the enterprise is delivering more efficient processes, flexibility in responding to shifts in customer demand, improved integration of systems, greater visibility into operations, and lower costs. But, at what cost?
For instance, do manufacturers need to forsake these benefits and look to disconnect for fear of being victimized by hyper-connectivity? Certainly not. But disaster planning at today's companies must extend to full contingency planning for breakdowns in communications between enterprise IT and factories OT. Scenario planning, disaster planning, and taking the necessary precautions toward being able to run individual manufacturing factories in isolation for short periods is vitally important.
Such planning proceeds along two tracks. One addresses how to manage enterprise IT systems and local-factory operations in the event that one factory faces an impending threat: a hurricane or flood, a corresponding mandated evacuation, and or a forecast shutdown of power from local utilities. The other addresses a completely unexpected, unanticipated systems breakdown that can occur as a result of a malicious cyberattack -- a virus, ransomware, denial of service, or corruption of key operational or enterprise data.
Insulated by Design -- For a Time
Companies need to know how to isolate individual factories and operate in a mode where they are disconnected from enterprise IT systems for a pre-determined period -- a day, a week, or a month --even if not running at optimal levels. One option for today's hyper-connected enterprise must run such disconnected operations by implementing an architecture that works for IT applications, as in using an enterprise service bus (see figure 1.). This abstraction can be achieved by an equivalent manufacturing service bus (MSB) in an operational mode where it functions in a secure, isolated "bubble."
That way, the MSB acts as a buffer between planning systems, production systems in each facility and the enterprise applications. For example, in the case of non-availability of a production system, MSB buffers order related information (i.e. specification, targets, etc.) from the enterprise system. When the production systems re-connect to the network, necessary enterprise information is downloaded to ensure current and available data arrive safe to production runs.
In case of non-availability of an enterprise system, the MSB buffers order / WIP transactions from the production system until it is delivered to the enterprise system. This enables resiliency at the plant level allowing the plant to run in isolation. When connectivity is restored, the MSB can securely exchange local data with the enterprise systems.
Individual factories and facilities -- think of them as nodes on the network of the hyper-connected enterprise -- must operate as disconnected entities for a predefined period. Getting there won't be simple.
We believe manufacturers can prepare their organizations to conceptually define an IT-OT architecture for resilient plant operations. This will allow operations at manufacturing sites to continue business-as-usual and minimize the financial impact of operational failures which can run into the billions of dollars if left unchecked. It's an investment worth making now.
Thank you to our contributors: Pawan Kale, Chief Architect of Cognizant Connected Products.
About Your Guest Blogger:
Frank is the global leader for Cognizant's Connected Products practice, comprised of 3,000 IoT and product engineering talent. He is working with companies to help drive the integration of IT and OT systems and deliver powerful synergies between the Physical World of machines, industrial operations, factories and the Digital World of IoT enabled platforms, applications and insights. This synergy helps global organizations drive efficiency, enhance safety, improve customer experience and deliver new business models and revenue streams. A Computer Engineer from the University of Madras in India, Frank has over 20 years of experience in leading transformational programs for Fortune 500 customers using a global delivery model.