Most Industrial Cyber Incidents Down To Human Error – Kaspersky
![Cyber Security](/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBNmVHRGc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--fa0641c85b7232cf8724678309e43fee732c0427/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaDdCem9MWm05eWJXRjBTU0lJYW5CbkJqb0dSVlE2QzNKbGMybDZaVWtpRFRjMU1IZzBOVEJlQmpzR1ZBPT0iLCJleHAiOm51bGwsInB1ciI6InZhcmlhdGlvbiJ9fQ==--9a8cb233bbd899661209fac1218cb930366c2398/computer_1591018_1920%20(7).jpg)
Cyber security incidents in industrial systems are mostly down to employee error, Kaspersky has warned in a new report.
The report, “State of Industrial Cybersecurity 2019”, found that employee errors or unintentional actions were behind 52% of incidents affecting operational technology and industrial control system (OT/ICS) networks in 2018.
Last month a number of large blue-chip industrial firms in Germany confirmed they have been subjected to cyber-attack. BASF and Henkel are chemical giants, Siemens makes power-generating kit among other things, and Roche is a drug company.
Industrial cyber incidents
Part of the problem for industrial entities is the shortage of professionals to handle modern cyber risks, coupled with low awareness among employees.
The problem is getting worse as more industrial groups change from manual processes to computer systems, some of which can be highly complex.
In March, for example, large Norwegian manufacturing firm Norsk Hydro admitted it had lost more than $40m, in the week following a devastating ransomware attack.
The Kaspersky report confirmed that industrial groups are increasingly recognising the importance of securing their systems, with 87 per cent of respondents agreeing that cybersecurity is becoming a top priority for industrial companies.
A fine sentiment, but the Kaspersky study also found that only just over half of companies (57 per cent) have the allocated budget for industrial cybersecurity.
Matters are not helped by a shortage of skilled staff.
“Organisations are not only experiencing a lack of cybersecurity experts with the right skills to manage protection for industrial networks but are worried that their OT/ICS network operators are not fully aware of the behaviour that can cause cybersecurity breaches,” the security experts said.
“These challenges make up the top two major concerns relating to cybersecurity management and go some way to explaining why employee errors cause half of all ICS incidents – such as malware infections – and also more serious targeted attacks,” it added.
Kaspersky said that in almost half of companies (45 per cent), the employees responsible for IT infrastructure security also oversee the security of OT/ ICS networks. It said this approach may carry security risks: although operational and corporate networks are becoming increasingly connected, specialists on each side can have different approaches (37 per cent) and goals (18 per cent) when it comes to cybersecurity.
“This year’s study shows that companies are seeking to improve protection for industrial networks,” said Georgy Shebuldaev, brand manager at Kaspersky Industrial Cybersecurity.
“However, this can only be achieved if they address the risks related to the lack of qualified staff and employee errors,” Shebuldaev added. “Taking a comprehensive, multi-layered approach – which combines technical protection with regular training of IT security specialists and industrial network operators – will ensure networks remain protected from threats and skills stay up to date.”
IoT protection
Kaspersky also warns organisations to consider specific protection for Industrial IoT which can become highly connected externally.
In April this year security officials at the German multinational pharmaceutical and life sciences giant Bayer AG reported that they detected and then contained a cyber attack.
The hackers using the Winnti malware had apparently gained access to Bayer’s network in early 2018 by using malware to spy on the company.
But security teams at Bayer reportedly detected the intrusion and covertly monitored it for over a year.
source silicon
Industry: Cyber Security
![Banner Default Image](https://www.dclsearch.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdytMRGc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--683221fba4088f48e5f9c99e2719b73064c09cee/banner-default.jpg)
Latest Jobs
-
- Network & Security Consultant
- Spain
- Upto €54000 per year and benefits
-
Senior Network & Security Engineer to join a Managed Network & Security Team in Europe. In this critical role, you will: Play a pivotal role in managing and securing network infrastructure across datacenters, customer connections, and on-premise deployments. Proactively monitor network and security devices, analyse incidents, and implement solutions to ensure optimal performance and security. Collaborate with colleagues and customers to troubleshoot issues, troubleshoot outages, and implement effective resolutions. Lead and participate in network system installations for new facilities and expansions. Develop and maintain network infrastructure procedures, recommend technical strategies, and propose improvements to enhance network capabilities. Stay up-to-date on the latest network and security technologies and trends. Work as part of a collaborative international team, contributing to team presentations and knowledge sharing. To be successful, you'll need: Proven expertise in Cisco network solutions (CCNP R&S/Sec/Wireless preferred)for both BAU and project work. In-depth knowledge of network security principles and experience with Fortinet firewalls. Experience deploying and managing large, complex network infrastructure (routing, switching, wireless, security). Solid understanding of ITIL v3 framework for incident, change, and problem management. Excellent troubleshooting skills with experience using Wireshark or similar protocol analysers. Strong communication and teamwork skills, with the ability to work independently and collaborate effectively.
-
- Security Analyst - Internal role. London commutable. £50,000
- London
- £50,000
-
Security Analyst - Internal role. London commutable opportunity. Operational Security - Investigate, escalate and proactively work to ensure household name remains protected. Project Security - Coordinate, log change requests with project delivery teams to meet security requirements Policy / compliance - work with team to aid in uplifting these as and where needed This role is role to investigate, escalate and proactively work to protect a globally recognised brand. You must have current hands on operational analytical security experience with Microsoft technology stack Someone with a SOC Analyst / security engineering background would be well suited. This position will join a small team and would suit someone that has broad experience across the security threat landscape. Experience / knowledge across industry GRC standards such NIST, ISO27001 etc would be advantageous. You will work across multiple teams proactively working to secure the business. Must be able to commute to Central London 3 days a week. Visa sponsorship not available Apply today to find out more.
-
- Network & Security Consultant
- Romania
- €54000 plus benefits
-
Senior Network & Security Engineer to join a Managed Network & Security Team in Europe. In this critical role, you will: Play a pivotal role in managing and securing network infrastructure across datacenters, customer connections, and on-premise deployments. Proactively monitor network and security devices, analyse incidents, and implement solutions to ensure optimal performance and security. Collaborate with colleagues and customers to troubleshoot issues, troubleshoot outages, and implement effective resolutions. Lead and participate in network system installations for new facilities and expansions. Develop and maintain network infrastructure procedures, recommend technical strategies, and propose improvements to enhance network capabilities. Stay up-to-date on the latest network and security technologies and trends. Work as part of a collaborative international team, contributing to team presentations and knowledge sharing. To be successful, you'll need: Proven expertise in Cisco network solutions (CCNP R&S/Sec/Wireless preferred) for both BAU and project work. In-depth knowledge of network security principles and experience with Fortinet firewalls. Experience deploying and managing large, complex network infrastructure (routing, switching, wireless, security). Solid understanding of ITIL v3 framework for incident, change, and problem management. Excellent troubleshooting skills with experience using Wireshark or similar protocol analysers. Strong communication and teamwork skills, with the ability to work independently and collaborate effectively.
-
- Network & Security Consultant
- Hungary
- Upto €54000 per year and benefits
-
Senior Network & Security Engineer to join a Managed Network & Security Team in Europe. In this critical role, you will: Play a pivotal role in managing and securing network infrastructure across datacenters, customer connections, and on-premise deployments. Proactively monitor network and security devices, analyse incidents, and implement solutions to ensure optimal performance and security. Collaborate with colleagues and customers to troubleshoot issues, troubleshoot outages, and implement effective resolutions. Lead and participate in network system installations for new facilities and expansions. Develop and maintain network infrastructure procedures, recommend technical strategies, and propose improvements to enhance network capabilities. Stay up-to-date on the latest network and security technologies and trends. Work as part of a collaborative international team, contributing to team presentations and knowledge sharing. To be successful, you'll need: Proven expertise in Cisco network solutions (CCNP R&S/Sec/Wireless preferred) for both BAU and project work. In-depth knowledge of network security principles and experience with Fortinet firewalls. Experience deploying and managing large, complex network infrastructure (routing, switching, wireless, security). Solid understanding of ITIL v3 framework for incident, change, and problem management. Excellent troubleshooting skills with experience using Wireshark or similar protocol analysers. Strong communication and teamwork skills, with the ability to work independently and collaborate effectively.