| | MAY 2022ENTERPRISE SECURITY8IN MY OPINIONHats off to the industrial community who performed extraordinary efforts to keep the civilization running under the challenging circumstances ofthe COVID-19 pandemic. As a result, many industrial entities shifted their ways of conducting business to espouse an increasingly connected industrial grid.Taking this fact into consideration, the trend continues, and cyber-attacks keep on coming with no end in sight. Billions of US dollars were spent over the past ten years on cyber-attacks. Such attacks exist in the digital space but today they are having a real and tangible effect on our physical world.Facilities that aid economy, public safety as well as public health are categorized under the umbrella of critical infrastructure. Due to the exploding digital transformation that is happening in the recent years in the critical national infrastructure, there is a path nowadays for attackers to run from spoofed email in an email inbox all through the network to the ICS crown jewels and industrial assets. We learned a lot from the recent industrial attacks that took place in 2021, we learned that the initial attack vector is usually simple due to poor security perimeter, we also learned that ransomware gangs are maturing more and more, and we learned that when there is a critical public service on the line there is more chance that the ransom will be paid.Given that, building a comprehensive industrial cyber security program is more important than ever. Compared to previous years, the industrial regulatory spectrum in many geographical areas in the world is becoming mature. To battle cyber threats, many countries have drafted their own custom standards as regulatory vehicles based on infamous By Mohamad Mahjoub, CISO, Veolia Middle EastBuilding a Comprehensive Industrial Cyber Security Program
<
Page 7 |
Page 9 >