Manufacturers’ tech stacks and industrial control systems (ICS) were designed to deliver speed and transaction efficiency first, with security as a secondary goal.
FREMONT, CA: Industrial control systems (ICS) and tech stacks used by manufacturers were created with speed and transaction efficiency as their primary objectives and security as a backup plan. Manufacturers were the subject of almost one in four attacks the previous year. Most attacks used ransomware, while 61 per cent of breaches targeted firms with connections to operational technology (OT).
Vulnerability exploitation was the first attack vector in manufacturing, an industry suffering from the effects of supply chain pressures and delays, according to IBM Security's X-Force Threat Intelligence Index 2022.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Manufacturing companies are suffering from a digital pandemic called cyberattacks, costing them millions of dollars in lost revenue and hours of production time. In the third quarter of this year, 68 per cent of all industrial ransomware cases involved the manufacturing sector. Dragos also found that the number of industrial ransomware instances encountered by manufacturers was seven times higher than that of the food and beverage sector. Due to a cyberattack earlier this year, 44 per cent of firms had to temporarily shut down their production lines.
Threat actors view supply chain attacks as ransom multipliers that can bring in millions of dollars in a matter of days. This is because manufacturing supply chains are fundamental to a manufacturer's capacity to fulfil customer orders and increase revenue. Many producers are forced to pay the ransom covertly because they have no other alternative.
The fact that manufacturers frequently have tech stacks based on outdated ICS, OT, and IT systems that were streamlined for production speed, shop floor efficiency, and process control, with security frequently being a secondary concern, is another factor contributing to their popularity as targets.
Another major factor in why manufacturers are compromised so frequently is a lack of visibility across OT, IT, supply chain, and partner networks. 86 per cent of manufacturers, according to Trend Micro, have poor visibility into their ICS settings, making them a prime target for a range of hacks. A typical ICS is built for process visibility, control, and optimization.
Air gaps serve as the initial line of defence for the majority of ICS systems. To circumvent the air gaps that industrial distributors, manufacturers, and utilities rely on for that first line, ransomware attackers are employing USB devices to deliver malware. Additionally, according to Honeywell's Industrial Cybersecurity USB Threat Report, 2021, 79 per cent of USB attacks can interfere with the operational technology (OT) that powers industrial processing plants. A notice concerning attacks on ICS and SCADA devices was released earlier this year by the Cybersecurity and Infrastructure Security Agency (CISA). An industrial security compromise typically causes USD 2.8 million in losses. 89 per cent of manufacturers whose supply chains were disrupted by ransomware attacks or breaches.
More in News