Gå direkt till innehåll
The IoT / OT challenge

Blogginlägg -

The IoT / OT challenge

”No one wants hackers to turn off power supply, nor change product compilations or steal data.” – Wim De Smet, CTO @ SecureLink

The problem with IoT and OT devices is that they aren’t designed with security in mind. Many operational devices for example run for 30 years, whereas their software is often outdated after 10. IoT devices in their turn, often lack security by design. This means that the code that goes with them, isn’t secure most of the time. Translation: they are easily compromised.

Besides, IoT and OT devices carry very important data you don’t want to lose. Just think of patient data in healthcare, ID information or secret recipes. Data itself is a new economy. It has great value and power which you don’t want to share with malicious actors.

Industry: productivity or security?

Production is often given priority to security. But networks have changed. Whereas the operational technology used to be separated from the IT network, it is now often connected to it. This makes it easier to report measurements for example, but it might have a negative effect on your security.

As the corporate network and the OT network are merging, security needs to be strengthened. And yes, if you don’t add the required security controls, you might experience downtime and data leakage. Security stands for uptime, not downtime. We need to cut out the assumption that it is the other way around.

How to secure your OT network?

It is highly recommended to proactively monitor for vulnerabilities and to segment your network. You can put your devices in separate VLANs to reduce the attack surface.

If you want to give third parties access to these OT networks for support or measurements, we advise you to use a Virtual Desktop Infrastructure (VDI) solution that disconnects the third party from the OT network. If you want to have audit trails you could also log the activities on these VDI clients.

You need to create visibility too. This can be done through specialized industrial control system monitoring tools that will give you more insights into which assets e.g. PLCs, SCADA, DCS are active on your OT network and what they are doing.

Healthcare: what about 3d party IoT devices?

A lot of healthcare organizations rely on third-party healthcare IoT devices. These devices often send information to third-party platforms which means you give away part of your control/data.

How to secure your IoT network

Be very careful about which devices you grant access to your network, and, to each other. Not all of them should be able to communicate. That is why we recommend segmentation of your IoT network through a next-generation firewall. Next-generation firewalls can also determine command & control traffic and scan for other vulnerabilities.

The majority of IoT and OT devices collect statistics and send them to a central environment. Many of these central environments are hosted in the cloud and thus accessible by anyone from anywhere, this means that Multi-Factor Authentication is a must for these solutions.

Then, last but not least, we advise you to equally protect the central environment against DDoS attacks with an MQTT broker.

SecureLink can assist you in designing this central infrastructure in a scalable, redundant and secure way, whether it is hosted in the cloud or on-premise.

Prevent, Detect and Respond

So far, there have already been several security incidents with IoT/OT devices. Most of the time, this results in shutting down production. This might seem far removed from your business, but don’t forget that such incidents can happen to you too. It might not be tomorrow, but you’d better be prepared.

So, apart from prevention and detection capabilities, you also need to have a good response process in place. You want the impact of a breach to be as low as possible to guarantee continuity and your good brand name.

SecureLink helps you map your risk. Don’t hesitate to contact our experts.

Ämnen

Kategorier

Regioner

Kontakter

Marie Waller

Marie Waller

Presskontakt Head of Marketing and Vendor Relations
Maria Lundmark

Maria Lundmark

Presskontakt Digital Marketing Manager Orange Cyberdefense Sweden
Camilla Gyllenberg

Camilla Gyllenberg

Presskontakt Content and Market Analyst Manager

Relaterat innehåll

Build a safer digital society

Om Orange Cyberdefense (f.d. SecureLink)
Orange Cyberdefense är Orange groups enhet för cybersäkerhet. Vi sköter säkerhetshantering, hotdetektering och motåtgärder åt organisationer världen över.

Som Europas mest använda säkerhetsleverantör arbetar vi för att skydda friheten och bygga ett säkrare digitalt samhälle.

Vi är en säkerhetsleverantör som genom att efterforska och samla in uppgifter om hot erbjuder oöverträffad information om aktuella och kommande hot.

Med över 25 års erfarenhet av informationssäkerhet, över 250 forskare och analytiker, 16 SOC fördelade över hela världen och försäljnings- och servicesupport i 160 länder, kan vi ge globalt skydd med lokal expertis och stödja våra kunder under hela hotlivscykeln.

Om Orange
Orange är en av världens ledande telekommunikationsoperatörer med en försäljning på 42 miljarder euro 2019 och 147 000 anställda världen över den 31 december 2019, inklusive 87 000 anställda i Frankrike. Koncernen har en total kundbas på 266 miljoner kunder världen över den 31 december 2019, inklusive 207 miljoner mobilkunder och 21 miljoner kunder med fast bredband. Koncernen finns i 26 länder. Orange är också en ledande leverantör av globala IT- och telekommunikationstjänster till multinationella företag under varumärket Orange Business Services. I december 2019 presenterade koncernen sin nya strategiska plan "Engage 2025", som styrd av socialt och miljömässigt ansvar har som syfte att göra om driftsmodellen i grunden. Samtidigt som tillväxten påskyndas och data och AI centreras i innovationsmodellen kommer koncernen att förbli en attraktiv och ansvarsfull arbetsgivare som anpassar sig efter framväxande yrken.

Orange är noterad på Euronext Paris (symbolen ORA) och på New York Stock Exchange (symbolen ORAN).
För mer information på internet och i mobilen: www.orange.com, www.orange-business.com eller för att följa oss på Twitter: @orangegrouppr.
Orange och andra Orange-namn på produkter eller tjänster som ingår i det här materialet är varumärken som tillhör Orange eller Orange Brand Services Limited.

Orange Cyberdefense Sweden AB

Hyllie boulevard 40
21535 Malmö
Sverige

Besök våra andra nyhetsrum