Skip to main content

Industry and manufacturing

Production plant is built for availability, not for maintainability. The most common finding is a flat network: whoever gains a foothold in the office area reaches the shop floor.

Cybersicherheit fuer Produktion Buero-IT, Fertigungsleitebene und Anlagennetz mit ihren Uebergaengen und dem Zugang eines Maschinenlieferanten. Darunter, was dafuer angeboten wird. OFFICE IT MANUFACTURING LEVEL PLANT NETWORK SUPPLIER RISK ASSESSMENTZONE MODEL COMPLIANCEIEC 62443 · CRA TRAININGOT STAFF INDUSTRY · AVAILABILITY FIRST
Threat picture

Ransomware hits the IT and stops production

In 2019 a wave of ransomware hit a Norwegian aluminium group. What was affected first was the office IT, but the plants had to switch to manual operation, because without the higher-level systems no orders, recipes or batch data reached production. The damage ran into the high tens of millions, caused by standstill rather than by damaged controllers.

In 2021 a pipeline operator in the United States stopped delivery as a precaution, even though the attack had hit the billing systems and not the process technology. Anyone who cannot say with certainty how far an attacker got shuts down. That uncertainty is the actual damage.

Neither case needed ICS malware. They needed only a network in which office and production are not effectively separated, and an organisation that could not determine the reach on the day.

What follows

Separation, evidence, ability to act

The first question is always the same: who gets how far, and would anyone notice.

Actually test the segmentation

Not the zone concept on paper but the transitions between office IT, manufacturing execution level and plant network. Alongside them the remote maintenance access of the machine suppliers: who gets how far, and does anyone notice.

Build the evidence

A zone and conduit concept to IEC 62443 that matches reality. For machine builders the Cyber Resilience Act comes on top, starting with the ability to report actively exploited vulnerabilities.

Enable the people

Maintenance, plant operators and IT work together on the day without ever having practised it. Training and a facilitated incident exercise close that gap.

Testing

How testing happens without touching production

Cybersicherheit fuer Produktion Buero-IT, Fertigungsleitebene und Anlagennetz mit ihren Uebergaengen und dem Zugang eines Maschinenlieferanten. Darunter, was dafuer angeboten wird. OFFICE IT MANUFACTURING LEVEL PLANT NETWORK SUPPLIER RISK ASSESSMENTZONE MODEL COMPLIANCEIEC 62443 · CRA TRAININGOT STAFF INDUSTRY · AVAILABILITY FIRST

Passive methods first. Analysis of the actual communication, evaluation of the firewall rules at the transitions, and review of configurations all run during operation and deliver most of the answer.

Active tests on controllers belong in an agreed maintenance window or on a lab rig. Abort criteria are fixed beforehand, and the report distinguishes what has to be fixed immediately from what can wait until the next shutdown.

At the control and operator level the findings are rarely spectacular: default accounts, open services, missing authentication on operator panels. Their effect only follows from the question of where they are reachable from.

Rebuilding

A real plant on which attacks are allowed

Der Demonstrator YekCity, eine Miniaturstadt mit Umspannwerk und Wasserwerk

Our lab holds a real Siemens installation: controllers of the S7-1500 and S7-300 series, a driven motor and a KTP400 operator panel, wired as they would be in a production cell.

The difference from a simulation is the motor. When a manipulated message arrives it turns differently, and you can see it. On that rig we develop detection rules, test our procedures before they go to a client, and run training in which participants are allowed to attack it themselves.

Practice

Training for maintenance, engineering and IT

OT-Trainings in zwei Stufen Professional arbeitet remote an einem virtuellen Wasserwerk ueber drei Ebenen und schliesst mit Pruefung und Notfalluebung ab. Expert steht in Praesenz vor echten Steuerungen und schreibt die Erkennungsregeln selbst. PROFESSIONAL 4 DAYS · REMOTE · 32 UNITS L2 HMI · OPC UA L1 MODBUS TCP L0 PUMP · TANK VIRTUAL WATERWORKS TEST 40 QUESTIONS EXERCISE WITH ROLES EXPERT 3 DAYS · ON SITE INSTRUMENTATION REAL PLCS modbus: function 6; WRITE THE RULES YOURSELF OT TRAINING · PROFESSIONAL, EXPERT

A production manager who does not understand why segmentation matters will work around it. An analyst who has never seen industrial traffic will click the alert away. Both are gaps in knowledge, not questions of character.

We train both sides: understanding for managers, craft for technical staff, and a joint incident exercise in which the judgement between standstill and continued operation gets made once under time pressure.

Regulation

NIS2 addresses the organisation, the CRA the product

The question of role decides the duties. NIS2 addresses the entity, that is, the operation. The Cyber Resilience Act addresses the manufacturer of a product with digital elements. Whoever builds machines and also produces is both, with two different sets of duties and two different deadlines.

For the operating side, IEC 62443 is the practical frame: zones, conduits and security levels give segmentation a form that can be checked. For the manufacturing side, the CRA does not begin with product certification but with the ability to report actively exploited vulnerabilities.

Common questions

What operators and machine builders ask

As a rule, no. Passive analysis, configuration review and evaluation of the segmentation run during operation. Active tests on controllers belong in a maintenance window or on a lab rig.

Especially then. With systems that cannot be patched, security shifts to segmentation, access control and detection. All of that can be done regardless of the age of the controller.

With the reporting capability. The duty to report actively exploited vulnerabilities applies before the other requirements. After that come the update path, the handling of key material, and the documentation of product security.

Through the real communication paths. We work out what was actually reachable from the affected zone, and delimit which areas of production can be ruled out.

Next step

Discuss your sector.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139