The reality of integrating physical and cyber

March 2018 Editor's Choice, Information Security, Security Services & Risk Management

Security is undoubtedly a primary focus for any organisation, particularly in this digital age where assets extend beyond the physical to include virtual assets such as data. The emergence of cloud or Internet-based devices, such as smart meters and smart CCTV cameras, is expanding the reach of traditional security measures and enabling a host of heretofore unknown benefits.

Sanjay Vaid.
Sanjay Vaid.

For most industries traditional security mechanisms such as perimeter and access control are still of vital importance. Technology has, however, introduced new ways for these to be managed and automated. These technologies are yielding faster response times and improved security. Meshing technology with physical security can vastly improve the overall security landscape for any organisation.

Introducing Internet of Things (IoT) devices into an operational environment aids the reduction of many health and safety risks. These can range from smart cameras for surveillance, to sensors implanted on vehicles which track and trace progress, prevent breakdowns and enable pre-emptive maintenance. For example, sensors can quickly identify gas leaks, enabling quick resolution. Another example would be IoT-enabled construction equipment, which help avoid collisions or load-related accidents. Technology is making the industry safer.

There is a flip side to this however, as advanced technology also introduces a number of threats into security environments. Operations of organisations in entirety can be brought down by cyber-attacks, launched on a seemingly innocuous piece of technology such as a sensor or smart device.

Recently, a casino in Las Vegas was infiltrated via its fish tank, albeit a very high-tech fish tank connected to a wireless access point – the intent being to steal data. Fortunately, technology also came to the rescue in this case, as the systems were closely monitored and the hackers could be stopped before too much damage was done. Another recent attack saw an entire critical infrastructure plant’s operations being shut down due to hackers accessing and taking control of an Internet enabled workstation.

The likes of these attacks highlight how effectively cyber criminals can damage or cripple an entire business in a matter of minutes. In certain industries where health and safety is of paramount import – such as mining, oil and gas, engineering and health – the derailing of infrastructure and the halting of operations can cause more than simply financial or reputation damage – there are lives at stake.

A challenge facing industries such as those involving chemical plants, mines and oil and gas organisations, is that technology can also introduce physical threats. Wi-Fi, for example, can cause a fire hazard in environments sensitive to sparking. In such cases, organisations need to investigate alternative, environmentally suitable technologies to bring these sites onto their cybersecurity network, and maintain central surveillance, access control and identity management.

Access, both physical and network, is the area that businesses need to closely monitor and secure. Physical access is critical and ensures only the right people gain entry to the right areas of a business at any given time. Technology is allowing businesses to apply the likes of biometrics to manage access enabling quicker, more accurate access control.

From a virtual access and data security point of view, it is critical that organisations implement proper identity controls such as authentication and passwords, as well as multiple layers of encryption across their data-at-rest and data-in-motion.

Integration and centralisation is critical in order to properly manage and monitor all of these technology-backed security measures. Businesses need to ensure that the security technology they invest in, from physical to cyber, is capable of integrating with a central management platform from which they can efficiently and effectively control their entire security environment.

It’s also important to have the right security policies and processes in place, so that organisations are able to follow proper protocol in times of breach, or when a risk is identified. This is especially important as new regulations emerge, such as the Protection of Personal Information (PoPI) Act and the General Data Protection Regulation (GDPR). Such regulations will be pivotal when redefining data security policies and are likely to have a larger impact on sectors such as the financial, retail, and insurance sectors.

Budget and security concerns are likely to come up against each other, as businesses weigh risk against costs. Costs, however, will be in line with the risks, which inevitably vary across different industries. For many organisations where it is less critical for security to be wholly controlled within the business, opting for security-as-a-service will be a win-win answer to the risk vs cost debate.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AI-enabled tools reducing time to value and enhancing application security
Editor's Choice
Next-generation AI tools are adding new layers of intelligent testing, audit, security, and assurance to the application development lifecycle, reducing risk, and improving time to value while augmenting the overall security posture.

Read more...
2024 State of Security Report
Editor's Choice
Mobile IDs, MFA and sustainability emerge as top trends in HID Global’s 2024 State of Security Report, with artificial intelligence appearing in the conversation for the first time.

Read more...
Cyberthreats facing SMBs
Editor's Choice
Data and credential theft malware were the top two threats against SMBs in 2023, accounting for nearly 50% of all malware targeting this market segment. Ransomware is still the biggest threat.

Read more...
Are we our own worst enemy?
Editor's Choice
Sonja de Klerk believes the day-to-day issues we face can serve as opportunities for personal growth and empowerment, enabling us to contribute to creating a better and safer environment for ourselves and South Africa.

Read more...
How to spot a cyberattack if you are not a security pro
Editor's Choice
Cybersecurity awareness is straightforward if you know what to look for; vigilance and knowledge are our most potent weapons and the good news is that anyone can grasp the basics and spot suspicious activities.

Read more...
Protecting IP and secret data in the age of AI
Editor's Choice
The promise of artificial intelligence (AI) is a source of near-continuous hype for South Africans. However, for enterprises implementing AI solutions, there are some important considerations regarding their intellectual property (IP) and secret data.

Read more...
Super election year increases risks of political violence
Editor's Choice
Widening polarisation is expected in many elections, with terrorism, civil unrest, and environmental activism risks intensifying in a volatile geopolitical environment. Multinational businesses show an increasing interest in political violence insurance coverage in mitigation.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...