OT security for SMEs: the risk nobody sees in industry
A talk from IT-Sicherheitstag NRW 2024 on the growing threats to industrial control systems. Ali Recai Yekta took apart a dangerous assumption: a successful attack on industrial systems does not require OT specialists.
OT security for SMEs: the risk nobody sees in industry
A talk from IT-Sicherheitstag NRW 2024 on the growing threats to industrial control systems
At IT-Sicherheitstag NRW 2024, Ali Recai Yekta took apart a dangerous assumption: a successful attack on industrial systems does not require OT specialists. Colonial Pipeline showed that plainly. Ransomware in the IT network led to the precautionary shutdown of a pipeline that supplies 45 percent of the US East Coast with fuel. Specialised malware such as Stuxnet or Triton was built for targeted manipulation, but far simpler attacks can already put critical infrastructure at risk. How industrial systems become vulnerable The biggest risks come from office and production networks being wired together. Unprotected maintenance access, systems past their support date and missing monitoring create ideal conditions for an attacker. The awkward part: many companies consider their production systems safe because they believe them to be isolated. Protection through a systematic approach Effective protection starts with knowing your own systems, which means asset management. On that basis, continuous security monitoring makes it possible to detect attacks early. For the day it happens, documented emergency plans and clear responsibilities decide the outcome. The protection does not have to be perfect. What matters more is starting with the basics now and improving steadily. Talk at IT-Sicherheitstag NRW, 11 December 2024, Bonn