• Latest
  • Trending
Four Steps Manufacturers to Build a Robust Security Program

Four Steps Manufacturers to Build a Robust Security Program

January 26, 2022
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023
How Your Storage System Will Still Be Viable in 5 Years’ Time?

How Your Storage System Will Still Be Viable in 5 Years’ Time?

February 20, 2023
The Broken Promises From Cybersecurity Vendors

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

February 20, 2023
Instagram and Facebook to get paid-for verification

Instagram and Facebook to get paid-for verification

February 20, 2023
YouTube CEO Susan Wojcicki steps down after nine years

YouTube CEO Susan Wojcicki steps down after nine years

February 20, 2023
Inaugural AfCFTA Conference on Women and Youth in Trade

Inaugural AfCFTA Conference on Women and Youth in Trade

September 6, 2022
Instagram fined €405m over children’s data privacy

Instagram fined €405m over children’s data privacy

September 6, 2022
8 Most Common Causes of a Data Breach

5.7bn data entries found exposed on Chinese VPN

August 18, 2022
  • Consumer Watch
  • Kids Page
  • Directory
  • Events
  • Reviews
Saturday, 24 May, 2025
  • Login
itechnewsonline.com
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion
Subscription
Advertise
No Result
View All Result
itechnewsonline.com
No Result
View All Result

Four Steps Manufacturers to Build a Robust Security Program

by ITECHNEWS
January 26, 2022
in Leading Stories, Opinion
0 0
0
Four Steps Manufacturers to Build a Robust Security Program

In the not-too-distant past, manufacturers spent the vast majority of their security resources on physical security. But now with the convergence of IT and OT (operational technology), that’s not an option. In fact, manufacturing was the second most-attacked industry in 20201 (we’re still waiting on 2021 figures). This means taking surface-level measures like air gapping (ensuring a computer or network has no network interfaces connected to outside networks), is not enough. In this blog, we’ll take manufacturers through the four steps they can build a robust security program. Plus, we offer a free downloadable checklist at the end of the article.

Step One: Identify your assets and their vulnerabilities

YOU MAY ALSO LIKE

ATC Ghana supports Girls-In-ICT Program

Vice President Dr. Bawumia inaugurates ICT Hub

Manufacturers’ network perimeters are becoming more fluid, which means there may be IT or OT assets that aren’t visible or secured. At this step, we recommend beginning by identifying all fixed and mobile endpoints. Then take a look at the risks. These could be traditional, human, environmental, quality and vulnerability risks that include IT/OT network configurations. A helpful tip? Consider conducting a risk assessment. You can reference the Guide to Industrial Control Systems (ICS) Security from NIST for guidance.

Next, review your security policies. Make sure they’re documented and call out specific requirements within security categories. Some policies to consider include acceptable use, asset management, security incident management and access management.

Finally, audit your requirements and security frameworks. Identify the information needed for audits from sources such as executive management, auditors, internal policies, industry regulation and your board of directors. Choose a security framework that aligns with these requirements and covers the basic security activities. At Nuspire, we use our Security in Action framework – you can learn all about it here.

Step Two: Create a thoughtful, comprehensive security plan

Having a security plan in place for your manufacturing business is table stakes these days. But what should it include? First, look at your security monitoring. Are you using a dedicated staff or a managed security services provider (MSSP) to monitor and manage your gateways, IT/OT networks and endpoints? Either way, require 24x7x365 security monitoring to help identify normal versus abnormal behavior and potential malicious activity.

Next, determine how you’ll address threat detection. Figure out how you’ll detect threats and manage them. Consider how frequently your detection capabilities evolve. Attackers shift tools and tactics continually, so your detection methods also need regular updating. We recommend evaluating managed detection and response (MDR) services to augment your detection and response capabilities. When you vet MSSPs, ask about their cybersecurity experts, experience and detection technologies.

Incident response (IR) is another important area to plan for. Develop an IR plan that details how security breaches will be handled. Include a variety of scenarios and matching responses. Here’s an example of an IR plan you can reference.

Disasters can happen anytime, anywhere. Make sure your security planning includes a disaster recover (DR) plan that specifies what actions will be taken before, during and after a disaster. Include roles and responsibilities for responders, communication procedures for employees and vendors, a detailed asset inventory and restoration procedures, and data backup procedures. Consider special handling procedures for sensitive information like

intellectual property.

Lastly, confirm you and your team know the process for shutting down production if you are breached. It should be clear when and how to shut down and restart operations.

Step Three: Implement a cadence for managing security essentials

Manufacturing organizations need to implement the right security protections and continually manage them to stay ahead of cyberattacks. Security essentials include:

Access Control: Safeguard IP, technology, assets and production lines with appropriate controls for onsite and remote access. Consider solutions such as identity and access management (IAM), privileged access management (PAM), multi-factor authentication and endpoint detection and response for fixed and mobile devices.

Intrusion Detection System (IDS) and Intrusion Prevention System (IPS): IDS (monitoring) and IPS (control), combined with skilled security analysts, block and respond to network intrusions.

Patch Management: After you identify and list IT and OT assets such as operating systems, software and servers, assign ownership to ensure regular patching. Follow a consistent patch management process to lower your risk of attack and breach.

Password Management: Introduce and reinforce an employee process to ensure passwords meet requirements and are reset regularly. Consider additional security layers such as vaulting, rotation and re-authentication settings.

Network Segmentation: Segment the networks of different departments or groups and the IT network from the ICS network and demilitarized zones (DMZ). This allows IT to observe behavior and performance and apply security controls within segments. Segmentation also allows IT to block communications from suspect IP addresses, limit an attacker’s lateral movement, and keep proprietary information limited to need-to-know groups.

Step Four: Conduct regular audits of your security program

The bad guys are always evolving, so it’s important to review your manufacturing organization’s security measures to ensure they are meeting current needs. Look at your security event triggers and verify you are identifying security events quickly. It’s critical you maintain visibility of your entire network to monitor malicious or anomalous behavior and review security actions with context.

Revisit your process for identifying assets and endpoints and their security status. There’s technology out there that can track and monitor these for you.

Evaluate your security program performance against the policies you created. Are they aligned? If not, make the necessary adjustments.

And finally, evaluate your security program performance against threats documented in your risk assessment. Be sure that the risk factors you identified in the assessment are eliminated or managed to your risk tolerance profile.

By conducting these four steps – Identify, Plan, Implement and Audit – your manufacturing organization will be well-positioned to address today’s security challenges and the many unknowns that lie ahead.

Source: Team Nuspire
Via: Security Boulevard
Tags: Robust Security Program
ShareTweetShare
Plugin Install : Subscribe Push Notification need OneSignal plugin to be installed.

Search

No Result
View All Result

Recent News

ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023

About What We Do

itechnewsonline.com

We bring you the best Premium Tech News.

Recent News With Image

ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023

Recent News

  • ATC Ghana supports Girls-In-ICT Program April 25, 2023
  • Vice President Dr. Bawumia inaugurates ICT Hub April 2, 2023
  • Co-Creation Hub’s edtech accelerator puts $15M towards African startups February 20, 2023
  • Data Leak Hits Thousands of NHS Workers February 20, 2023
  • Home
  • InfoSec
  • Opinion
  • Africa Tech
  • Data Storage

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

No Result
View All Result
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Go to mobile version