DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports Events Over 2 million developers have joined DZone. Join Today! Thanks for visiting DZone today,
Edit Profile Manage Email Subscriptions Moderation Admin Console How to Post to DZone Article Submission Guidelines
View Profile
Sign Out
Refcards
Trend Reports
Events
Zones
Culture and Methodologies Agile Career Development Methodologies Team Management
Data Engineering AI/ML Big Data Data Databases IoT
Software Design and Architecture Cloud Architecture Containers Integration Microservices Performance Security
Coding Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones AWS Cloud
by AWS Developer Relations
Culture and Methodologies
Agile Career Development Methodologies Team Management
Data Engineering
AI/ML Big Data Data Databases IoT
Software Design and Architecture
Cloud Architecture Containers Integration Microservices Performance Security
Coding
Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance
Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones
AWS Cloud
by AWS Developer Relations
  1. DZone
  2. Software Design and Architecture
  3. Security
  4. Is the Industrial Sector Ready to Rumble?

Is the Industrial Sector Ready to Rumble?

Now that the modern Internet is reaching maturity and connected devices are finding homes in the industrial sector, see what it will take to make it secure.

Jeffrey Lewis user avatar by
Jeffrey Lewis
·
Nov. 01, 16 · Opinion
Like (1)
Save
Tweet
Share
2.32K Views

Join the DZone community and get the full member experience.

Join For Free

How prepared is the industrial sector to fight and defend against cyber attacks? Wurldtech wanted to take a closer look, and so asked YouGov to conduct a survey of nearly 900 senior IT/security professionals from oil and gas, utilities, transportation, and healthcare organizations around the globe to find out more about their critical infrastructure security readiness.

What we learned had us nodding our heads, “Yes, makes sense, not surprising.” But also shaking them a bit, thinking, “Hold on a minute, this is curious, the plot thickens.”

The Age-Old Balancing Act: Efficiency vs. Security

Even before the days of big data, the Internet, or rudimentary computer coding, balancing operational efficiency with adequate security has been an issue. But now, with companies in the industrial sector beginning to embrace the Internet of Things (IoT) and moving toward greater connectivity to increase revenue, lower costs, and enhance automation, the balancing act just got that much more complicated.

For good or for bad, the scales have historically seemed to tip in efficiency’s favor. Performance trumped all and even a hint of security hindering productivity was not allowed—lest competition move in and the business falter. The flip side, of course, is that without adequate defenses, isn’t business at risk by default?

For many managers, IT security remains a no-contest top investment priority. That’s not a bad thing, but is it enough? What about OT-specific security? Is it going to take a hard knocks lesson on compromise before organizations can fully accept, too, the criticality of OT security readiness. Or will it be like Saul getting knocked off his Damascus-bound donkey—and will organizations need to be hit hard by a breach before they “see the light.”

A Case of Misunderstanding OT Security?

In order of importance, execs listed their top investment priorities as IT security, compliance, safety, adoption of new technologies, and operational technology (OT) security.

While it makes sense that organizations are looking to new technologies to gain efficiency, increase production, and reduce costs, it is a bitter pill to swallow that OT security—specific to running critical production assets and process controls—would rank last.

We think this may be a case of misunderstanding.

Since IT security ranks high on the investment priority list, we don’t think anyone is underestimating the new risks associated with an increasingly connected world. Rather, we might deduce that the disparity highlights organization’s possible misunderstanding of the unique requirements of OT (versus IT) security and how it requires a different type of expertise to manage.

While it’s possible to derive lessons from IT that can be applied to OT, it’s critical to differentiate the two and understand that protecting one is not the same as protecting the other. With specialized OT security, organizations can be much more protected—especially considering that while respondents are prioritizing IT security investments, they, as a whole, also lack confidence that those investments will adequately mitigate a cyber attack. In this sense, maybe they get that IT tools and techniques don’t work in OT environments.

To learn more about the survey and results, check out our infographic from Critical Infrastructure Security Readiness 2016 Report. 

security IT

Published at DZone with permission of Jeffrey Lewis, DZone MVB. See the original article here.

Opinions expressed by DZone contributors are their own.

Popular on DZone

  • Chaos Engineering Tutorial: Comprehensive Guide With Best Practices
  • Secure APIs: Best Practices and Measures
  • Multi-Tenant Architecture for a SaaS Application on AWS
  • Integrate AWS Secrets Manager in Spring Boot Application

Comments

Partner Resources

X

ABOUT US

  • About DZone
  • Send feedback
  • Careers
  • Sitemap

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 600 Park Offices Drive
  • Suite 300
  • Durham, NC 27709
  • support@dzone.com
  • +1 (919) 678-0300

Let's be friends: