TECHNOLOGY FOCUS Industrial cybersecurity
Chris Whyborn, Head of Cybersecurity Services (UK & Europe)
TO CYBERSECURITY A HOLISTIC APPROACH
Chris Whyborn, Head of Cybersecurity Services (UK & Europe) for TÜV SÜD Business Assurance, suggests ways of building a strong cybersecurity foundation to enable businesses to get ahead of threats
C
yber attacks on modern, increasingly interconnected plants are becoming more sophisticated, targeted and
effective, which demands a holistic security approach to ensure the highest levels of automation cybersecurity.
Internal threats While ransomware attacks from outside the organisation remains the biggest problem, cyber threats also come from within the organisation, both intentionally and unintentionally. This includes threats from current and former employees, business associates and the supply chain. The first line of defence against cyber threats is therefore a business’s employees. Increasing their cybersecurity and risk awareness, essentially makes them a human firewall. Comprehensive training for employees and other relevant stakeholders is therefore key to ensure employees can recognise potential threats and mitigate cyber risks. Beyond training, the creation of a cybersecurity culture within the organisation encourages an active and positive environment for employees to engage in cybersecurity. Examples include participating in industry consortia or public-private projects relating to cybersecurity. Cybersecurity must also be a top priority for management and trickle down to all parts of the organisation,
20 June 2026 | Automation
irrespective of size and location. It is also vital to ensure end-to-end security of the global value chain, not only securing the organisation but flowing down security requirements across the entire supply chain, including second tier and third tier suppliers. Businesses require a comprehensive cybersecurity strategy to maximise security by understanding the threat landscape and identifying risks and vulnerabilities. This strategy requires a combination of technical measures, human awareness and strategic alignment. It is critical to understand the level of risk that a business faces from a cyber attack, and then ensure the appropriate protection is in place. Cybersecurity risk assessments are therefore essential, and include testing for vulnerabilities, inspecting security controls and identifying risk. Vulnerability scanning helps organisations identify unknown vulnerabilities in their IT infrastructure and applications, proactively detecting weaknesses in systems to ensure that an organisation stays ahead of risks. New vulnerabilities are exposed daily, which means that regular scanning, testing and auditing are vital to maintaining an enterprise’s cybersecurity resilience. Certification for products, services and business processes demonstrates that an organisation has a mature cybersecurity approach. Such standards include ISO/IEC 27001 Information Security Management System, ISO/IEC 27701 Privacy Information Management System, the CSA
Cyber Essentials mark, and the CSA Cyber Trust mark. Having a robust Cybersecurity Management System (CSMS) plays a crucial role in identifying potential vulnerabilities and threats that a business may have. So, each system should be individually assessed with regular audits by a third-party. These counter- measures help establish a strong baseline in cybersecurity and demonstrate to customers and partners that the organisation is well prepared to defend itself against cyber attacks.
The concept of Security by Design was developed to mitigate risks of cyber- attack. This principle can be applied to many different types of system, including individual sensors or devices, integrated operational technologies and industrial processes. This means cybersecurity should be embedded within products and services from the design phase of that product, service or underlying process. Business disruption will not only result in loss of productivity, it will also erode customer trust, resulting in a loss of credibility and negative publicity. In the case of a data breach, businesses may face legal consequences from authorities and customers for failing to take appropriate security measures.
A robust infrastructure To build a strong cybersecurity foundation and enable a business to get ahead of potential threats before they materialise, a robust infrastructure, clear corporate policies, recognised certifications, and ongoing staff training are needed. Safeguarding sensitive information, proprietary assets and critical systems means organisations can pursue their digital transformation journey with confidence, positioning themselves to fully capitalise on the opportunities that new technologies, such as Industry 4.0, offer.
TÜV SÜD Business Assurance
www.tuvsud.com/en-gb/cybersecurity
automationmagazine.co.uk
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40