Keeping the Lines Moving: Why Cybersecurity Is Critical for Manufacturing

This SubRosa white paper argues that digitalization has widened the attack surface of manufacturers, especially the OT systems many firms leave unprotected while securing IT. It supports the case with industry statistics and attacks on Norsk Hydro, OXO, Mondelez and DuPont, then sets out a top-down approach built on protecting, preventing and responding.

JP
John Price
  • Reviewed by Kevin Schewe and Ratan Gupta
  • 7 min read
  • Download PDF
Share

Key Highlights

  • Many manufacturers secure their IT networks but leave OT such as control units and machinery exposed, and legacy components make it harder to protect.
  • Studies cited from 2019 found manufacturing made up half of organizations hit by cyber-attacks and paid more in ransomware than any other sector ($6.9 mn).
  • Real incidents show the cost: LockerGoga ransomware cost Norsk Hydro an estimated $71 million, and malware losses at Mondelez topped $100 million.
  • Irdeto research puts average manufacturing losses from IoT weaknesses above $330,000.
  • The paper frames defence as leadership-led: protect enterprise, IoT and ICS assets, prevent through routine assessments, and plan ahead to respond to incidents.

The wave of digitalization in manufacturing

The digital era has ushered in massive changes in the manufacturing industry.As an industry that focuses on scalability and efficiency, it has embraced technology with open arms. Today's fast-paced market environment demands manufacturers to not only keep up with the pace of developments but also to innovate and think ahead.

Automation, IoT, smart equipment have all helped improve every facet of the manufacturing process. Be it increasing production capacities or ensuring better quality control. Interconnected control systems, automated monitoring systems, smart machinery, and real-time data analysis processes are enabling manufacturing lines to work with smooth cohesion and utmost efficiency.

Manufacturing companies must face the cyber threat head on.

How this implementation opens up cybersecurity risks.

Yes, technology is an enabler on a scale never seen before. But with the immense importance that it holds, protecting these business-critical systems is a paramount need.

Cyber attacks present an immense threat to interconnected infrastructure

Every piece of connected technology presents a potential attack vector. Cyber threats can expose a company's infrastructure, intellectual property, finances, sensitive data, and other assets to grave threats. Digitalization and interconnectedness have led to all these business-critical systems being centralized which increases the vulnerability manifold.

With the adoption of technology in manufacturing, the lines between different phases of manufacturing are gradually fading away.

Manufacturing lines and supply chains rely on the smooth functioning of each phase. Targeted or not, even a single cyberattack may have deep implications as it can not only cripple operations at the affected point but may cause a far-reaching domino effect.

For manufacturing companies, OT infrastructure is the backbone of the company. Control units, machinery, monitoring systems are all usually controlled by a central network. Many manufacturing companies will employ cybersecurity for their IT infrastructure but leave their OT infrastructure exposed. This leaves OT infrastructure vulnerable to cyber threats. Moreover, OT infrastructure may contain components of a wide variety and legacy systems which makes cybersecurity implementation a challenge.

The dynamic landscape and the allure of manufacturing companies

In today’s ever-changing cyber landscape. Threats continue to emerge every day. Hackers continue to develop newer techniques and deploy more dangerous tools to exploit vulnerabilities. Cybersecurity can no longer be thought of as a mere afterthought.

Incidents like the attacks on Stuxnet in Iran and Triton in Saudi-Arabia have cemented the importance of cybersecurity for industrial networks. Attacks on critical infrastructure have shown how cybercriminals have exposed the vulnerabilities of industrial networks with increasingly sophisticated tools and techniques. Due to the value that these networks hold, manufacturing companies have become an appealing target for cyber attacks.

  • 32% of MSPs report manufacturing and construction as being most target by ransomware.
  • 77% of industrial companies rank cybersecurity as a top priority.

Protecting your assets

The statistics that tell the tale

The 2019 Deloitte and MAPI Smart Factory Study revealed several risks relative to smart factory initiatives, from operational to financial and strategic to compliance. Forty-eight percent of manufacturers surveyed identified operational risks, which include cybersecurity, as the greatest danger to smart factory initiatives.

  • IoT Device Weaknesses According to research by Irdeto, eight in ten companies have experienced a cyberattack on their IoT devices in the past year.
  • Operational Impact 90% of these organizations experienced an impact affecting their operations or data as a result of the cyberattack.
  • Monetary Loss Irdeto Global Connected Industries found that organizations in manufacturing suffered substantial losses due to IoT-related vulnerabilities, of more than $330,000 on average.
  • Ransomware According to a study by Kivu Consulting, the manufacturing industry spent more than any other sector (in 2019) on ransomware payments, paying out $6.9 mn.
  • Research conducted by IBM's X-Force IRIS incident response team revealed that 50% of organizations affected by cyber-attacks in 2019 are in the manufacturing sector. According to the same report, 60% of manufacturing firms were hit with at least one WannaCry-related attack in the first six months of 2019.

50% of organizations affected by cyber-attacks in 2019 were in the manufacturing sector.

Cyber-attacks in manufacturing

Norsk Hydro cyber attack

In March 2019, a cyber attack hit Norwegian aluminum giant Norsk Hydro. The company’s operations in 40 countries and 35,000 Norsk Hydro employees were affected. The company was hit by the LockerGoga ransomware. The financial cost of the attack was estimated to be $71 million dollars.

OXO International payment skimming

In 2018, OXO International discovered a vulnerability in the form of malicious code on its website. The malicious code was intended to steal customer data. OXO’s customer and payment details were skimmed to a remote server by the cybercriminals.

Mondelez malware

In June 2017, a global malware attack on Mondelez. Mondelez, one of the world’s largest snack companies, was severely affected. The estimated losses due to the attack were estimated to be in excess of $100 million dollars.

DuPont insider attack

In 2007, an insider attack on DuPont resulted in IP data worth hundreds of millions of dollars being stolen. The research chemist responsible for the incident had accessed over 16,000 documents. The data included DuPont’s sensitive R&D material.

Top down risk management

Leadership Oversight

50% of manufacturing executives feel they are underprotected.

48% of manufacturing companies lack sufficient funding

Organizational Oversight

40% of the top threats involve employees

75% Lack skilled talent

Protect

Implement strategies to proactively manage cyber risk across the enterprise.

Enterprise Systems

36% of manufacturers are most concerned with IP theft

IoT and Connected Devices

45% use IoT devices and smart products

55% encrypt the data on said devices

Industrial Control Systems

50% Isolate ICS on their network

31% Do not conduct ICS assessments

Prevent

Implement detection technologies and conduct routine technical assessments enterprise-wide.

A major concern of IT and security executives is the frequency and sophistication of manufacturer-target cyber attacks

77% Perform product assessments

50% Perform ICS vulnerability assessments less than monthly

Respond

Implement plans and procedures to ensure that when an incident occurs, organizational resources can respond efficiently and in a timely manner.

37% Have had a breach within the last 12 months.

38% Had losses of $1m-$10m

37% Have not included ICS in their incident response plans.

27% Have not included ICS in their incident response plans.

The debilitating fallout of cyberattacks

The financial brunt of a cyber attack can be immense

In some cases, cyber-attacks have permanently crippled a company’s operations and in many cases, they have had to bear damages in tens of millions of dollars. It goes without saying that financial losses resulting from breaches and attacks can be sizable. The operational downtime may further jeopardize a company’s finances, its obligations to clients, and its reputation. A cyberattack that results in the loss of IP could lead to the company losing its critical edge in the market. Attacks intended for corporate espionage may give access to highly-sensitive data to a competitor. Damage to critical equipment can cause a meltdown in the entire production or supply chain.

In several cases, when customers’ private data is left exposed. The impact on the company’s trust and reputation can be incredibly damaging. In some cases, the legal ramifications can be dire and may even stretch up to regulatory sanctions. What happens when production lines are brought to a complete standstill in a matter of minutes? What happens when an entire supply chain is crippled? What happens when a company’s customers’ data is exposed?In the hyper-connected and globalized business environment of today, technology plays an irreplaceable role.

In manufacturing, technology and digitalization have brought incredible changes. But, they have not made it invulnerable. Cyberattacks can devastatingly damage the entire infrastructure upon which today’s companies rely on. To protect these business-critical systems and infrastructure is the need of the hour.

Cyberattacks can devastatingly damage the entire infrastructure upon which today’s manufacturing companies rely on.

Cybersecurity for manufacturersSee how SubRosa helps manufacturers protect OT, supply chains and production.Explore manufacturing security

Frequently asked questions

Why is cybersecurity important for manufacturers?

Modern plants run on interconnected control systems, smart machinery and real-time data, so a single attack can stop a line and ripple out through the supply chain. The paper lists downtime, lost intellectual property, exposed customer data and regulatory sanctions among the consequences.

Why is OT security a weak spot in manufacturing?

Control units, machinery and monitoring systems are typically run from one central network, yet many manufacturers invest in protecting IT while leaving these OT assets exposed. A mix of varied and legacy components also makes OT harder to secure.

Which cyberattacks have hit manufacturing companies?

The paper cites the 2019 LockerGoga ransomware attack on Norsk Hydro, card-skimming code found on OXO International's website in 2018, a 2017 malware attack on Mondelez, and a 2007 insider theft of R&D documents at DuPont.

How much can a cyberattack cost a manufacturer?

Figures quoted range from average IoT-related losses above $330,000 to an estimated $71 million for Norsk Hydro and over $100 million for Mondelez. In the survey data shown, 38% of respondents reported losses between $1m and $10m.

Ready to strengthen your security posture?

Have questions about this article or need expert cybersecurity guidance? Connect with our team to discuss your security needs.