| | 9 OCTOBER 2022As supply chain continues to expand with Robots, there is a growing need to link and integrate business systems with distribution operations systems to create efficiencies. However, it is critical to note that this convergence between IT and OT carries risk because Industrial Control Systems (ICS), which are used in almost every machine or infrastructure including Robots. These physical devices are often unpatched and do not play nice with anti-virus software so they are highly susceptible to attacks if they are not properly segregated. Organizations responsible for critical infrastructure take cyber security very seriously. This requires businesses to start planning to secure infrastructure environments and proper segregation between IT and OT (Robots). Most Business Technology Systems have proper anti-virus and anti-malware capabilities with standard connection protocols which puts them at less risk than OT systems. OT systems such as robots, do not have the ability to protect against many of the threats from viruses or malware that business systems do primarily due to their Industrial Control Systems (ICS) software and operating system; this is why it is so critical to segregate them and control connection protocols. OT systems use a wide array of UDP/TCP/IP protocols, many of which are specific to either function, industries, geography, etc. which must be closely controlled to maintain security. Each connection to each robotic system should be controlledFirst, OT systems should be using true HTTPS (not HTTP that resolve to HTTPS) connection protocols as a critical step to keeping businesses safe. The infrastructure containing robotics servers or virtual machines should also be sure in a DMZ layer (ref; ISA 95 blue zone) and separate from business systems Virtual Machines or servers. A Zero-Trust policy should be put into place to eliminate most threats with physical firewall devices; only allowing connection from specific IP to specific endpoint: For example, the Robot IP address (yellow zone industrial network) to the Virtual Machine IP address on the segregated hardware. The DMZ servers should also have zero trust into the green zone (business systems). Threat actors are an IMPORTANT consideration when deploying OT systems. Many OT devices are frankly terrifying because many of these devices are plug-and-play without the need for passwords or secure configurations which essentially makes security optional. In fact, many of these types of devices are shipped with commonly known default passwords to provide easy access to configuration panels. Could you imagine that it is common for hackers to create botnets to trigger distributed denial-of-service (DDoS) which freezes or disables systems? You should understand that these types of attacks have complex mechanisms that are undetected due to the nature of how they disguise themselves as encrypted and how they profile processes. Poorly secured OT environments are more easily attacked and can enter your business systems to exfiltrate organizational data and threaten to leak it or steal proprietary information. Now that we know that the devices are not secure and pose threats to organizations, but there are additional concerns regarding IT/OT convergence that need to be mentioned such as the accidental insider who makes simple mistakes; external actors who make mistakes; or malicious insiders or outsiders. If this sounds alarming or terrifying, it should; this is why it is so critical to segregate and control and monitor. Yes, this will cost money to add additional hardware and hardening processes initially; but you will need to ask yourself, what is the cost of a breach or shutdown? (Especially with less employees to perform manual processes) So do yourself a favor and create a detailed process flow map that can lead to architecture discussion, which will lead to system needs, which leads to secure environments and real organizational value. A Zero-Trust policy should be put into place to eliminate most threats with physical firewall devices; only allowing connection from specific IP to specific endpoint
<
Page 8 |
Page 10 >