Securing the Industrial Internet of Things

1 May 2019 Information Security, Infrastructure, Industrial (Industry)

The very benefits that makes the IIoT so compelling, makes it equally capable of damaging infrastructure operations and processes through bad actors.

Beginning with the Industrial Revolution in the mid 1700s, the manufacturing industry has undergone several revolutions. However, in today’s age of skyrocketing technological advancements, times are changing at a far more rapid pace, as we see the automation era being replaced by the Fourth Industrial Revolution (4IR).

The 4IR has been driven by several factors. Digital transformation, evolving business models, increased pressures around costs and time to market, have all ushered in this new age and given rise to the Industrial Internet of Things (IIoT), which facilitates unprecedented levels of real-time connectivity, visibility and control across operations.

However, alongside the plethora of benefits, is one major downfall: a dramatic increase in cybersecurity risks. Although the IIoT aims to streamline manufacturing processes, it also endangers Industrial Control Systems (ICS) as they are vulnerable to exploits that can be found freely on the Internet. The vulnerabilities range from basic issues like systems without passwords or with hard-coded passwords to configuration issues, software bugs and hardware vulnerabilities.

“Once a threat actor has the ability to run software on a host that has access to a controller, the chances of a successful attack are extremely high,” says Andre Froneman, business unit manager and industrial cybersecurity adviser at Axiz.

According to Froneman, traditional security is not enough to protect against proliferating cyber threats to both operational technology (OT) and IT systems. ICS on OT networks have totally varying operational requirements that affect the entity’s ability to adapt and respond to evolving cyber security threats.

“This opens up the organisation to new avenues for attackers. ICS cyber security strategies must be designed with asset and operational requirements in mind to protect critical processes without negatively impacting efficiency, productivity and safety. In addition, effective ICS cyber security requires a combination of tools, processes and skills.”

He says to remember that when ICS systems were designed it was with manageability and control with maximum reliability in mind. “Essentially, they were never designed to be attached to the Internet. In this way, these systems now face all the expected challenges associated with vulnerabilities and exploits, but with the additional burden of these systems operating in dispersed geographical environments that can be physically difficult to reach or that can never be taken offline.”

Moreover, all of the equipment that runs these systems is monitored and controlled by industrial controllers (PLC, RTU, and HMI) as well as sensors. They are connected to management systems such as Distributed Control Systems (DCS) and Supervisory Control and Data Acquisition (scada) systems

He says consider critical infrastructure facilities, such as electricity, oil, gas, water, waste, and suchlike, that are key to keeping nations up and running. “One can’t simply switch off these facilities, and it doesn’t take much imagination to think about what could happen if control of these systems fell into the wrong hands. Take for example, the air traffic control at an airport such as OR Tambo, the ramifications should hackers be able to control this, defy thought.”

The wide adoption of these systems is due to their benefits – they are dependable, as well as rugged and stable, allowing critical infrastructure facilities to use them for decades at a time. However, the benefits that make them so compelling, make them equally capable of damaging infrastructure operations and processes through malfeasance.

Froneman explains that these systems commonly employ propriety operating systems that have not been subjected to any form of security hardening. In addition, default passwords and baseline configurations make it child’s play for attackers to compromise them. Similarly, the software they use can’t be updated or patched often, due to the limitations of their geographical locations, as well as worries about downtime. The software run is more often than not, legacy software that lacks the appropriate user and system authentication, data authenticity verification, as well as data integrity checking features. Legacy SCADA controllers are also unable to encrypt communications and this can enable cyber crooks to employ sniffing software to find out username and passwords.

These and other flaws give hackers the ability to inject commands and manipulate parameters to modify, delete, or copy information on controlled access systems. “Should a threat actor alter commands sent to the controllers, changing the controller logical sequence or alter the sensors readings, attackers can change the industrial processes themselves,” he explains.

So what can industrial organisations do to protect their data and systems? Froneman says ICS security needs to be built in layers to prevent attacks from both external and internal sources. “There is no one-size-fits-all approach when it comes to securing ICS/ SCADA infrastructures. A segmented, multi-layer defence-in-depth strategy must be designed for their specific and highly tailored needs.”

He says that a good number of attacks suffered by ICS networks happened via IT attack vectors, including spear phishing via email and ransomware on endpoints. “Using a solution such as Check Point Threat Prevention that has features including sandboxing, as well as network and endpoint security, can prevent and eliminate this type of attack before it hits the ICS system. These technologies are also effective when used in OT networks. SCADA vendors release vulnerability advisories for their ICS devices on an ongoing basis, although OT environments are not quick to install and upgrade their machines, leaving systems unpatched, and creating a vulnerability window. Having this type of solution on the OT network, closes that window.”

Froneman says another way of securing ICS systems is by segmenting IT and OT, and applying the principle of least privilege access. “Boundary protection has been cited as number one for several years in a row by US ICS-CERT, and this type of protection should ensure the availability, integrity and confidentiality of this data, and maintain physical network separation between the real time components of the industrial network.”

“To prevent tampering with legacy data that is communicated in open text without encryption on these systems, secure site-to-site VPN tunnels between boundaries interconnects should be created. In addition, security gateways should be installed at all interconnects, guaranteeing that only relevant and legitimate traffic is able to enter or leave the network. All communication, protocols, methods, queries and responses and payloads should be validated using a firewall, application control, IPS and antivirus.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...
What is your ‘real’ security posture? (Part 2)
BlueVision Editor's Choice Information Security Infrastructure
In the second part of this series of articles from BlueVision, we explore the human element: social engineering and insider threats and how red teaming can expose and remedy them.

Read more...
Onsite AI avoids cloud challenges
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure AI & Data Analytics
Most AI programs today depend on constant cloud connections, which can be a liability for companies operating in secure or high-risk environments. That reliance exposes sensitive data to external networks, but also creates a single point of failure if connectivity drops.

Read more...
Sophos announces evolution of its security operations portfolio
Information Security
Sophos has announced significant enhancements to its security operations portfolio via Sophos XDR and Sophos MDR offerings, marking an important milestone in its integration journey following the acquisition of Secureworks in February 2025.

Read more...
Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
The overlooked risks of everyday connectivity
Information Security
That free Wi-Fi you are using could end up costing you a lot more money than your hotspot data if it has been compromised, says Richard Frost, head of technology solutions and consulting at Armata Cyber Security.

Read more...
Syndicates exploit insider vulnerabilities in SA
Information Security Security Services & Risk Management
Today’s cyber criminals do not just exploit vulnerabilities in your systems; they exploit your people, turning trusted team members into unwitting accomplices or deliberate collaborators in their schemes.

Read more...
GenAI fraud forcing banks to shift from identity to intent
AI & Data Analytics Information Security Financial (Industry)
The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools; they need adaptability and expanding the security net.

Read more...
Short-range indoor LiDAR sensor
OPTEX Perimeter Security, Alarms & Intruder Detection Infrastructure Products & Solutions
The REDSCAN Lite RLS-1010L has been developed to provide comprehensive coverage and protect high-risk security zones and vulnerable, narrow indoor spaces that are difficult to protect with traditional sensors.

Read more...
Global Threat Intelligence Report for October 2025
Information Security News & Events
Africa was pipped to the post as the most attacked region by Latin America, which averaged 2966 attacks per organisation per week (+16% YoY). Africa followed with (2782, – 15%) and APAC (2703, – 8%).

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.