Why Facility Cybersecurity is Important in Hardening Defenses Against Cybercriminals
While today’s facilities are effectively integrating technology for building management and operations, organizations are lagging in adopting essential tools to strengthen their defenses against cybercriminals. The rise in global tensions has led to an increase in cyberthreats and disruptions to critical infrastructure worldwide. This evolving threat landscape leaves facilities vulnerable, particularly due to the common practice of compartmentalizing IT management, which often isolates expertise from building maintenance and capital planning. As a result, many facilities find themselves ill-equipped to defend against malicious intrusions.
In the article published in FMJ, “Growing Cyberthreats: Why it’s Time for Stronger Facility Cybersecurity,” Eric Headington, Engineering Manager, Instrumentation and Controls, and Andrew Harris, I&C MI Team Lead | Director of Business Development – Controls, discuss why cybersecurity risks to industrial facilities is growing, and what you can do to mitigate a threat. The article focuses on:
- What’s causing cybersecurity for industrial control systems to grow – Due to the growth of connected technologies like IoT, open infrastructure, and human vulnerabilities, making these environments more susceptible to malware, data breaches, and social engineering attacks.
- Facility cyberattack vulnerabilities and outcomes – Cybercriminals can exploit facility vulnerabilities, such as weak network segregation, unsecure remote access, or disgruntled insiders, leading to unauthorized access, ransomware attacks, or physical sabotage that can severely disrupt operations.
- Cybersecurity risk assessment checklist – A comprehensive cybersecurity risk assessment is essential for building cybersecurity defenses, as it identifies potential threats, prioritizes vulnerabilities, and outlines mitigation strategies with input from internal stakeholders and external experts to ensure effective protection against cyberattacks.
- When to conduct a cybersecurity risk assessment – Cybersecurity risk assessments should be conducted regularly, including during capital project planning and ongoing building maintenance, especially when new devices are added or systems are updated, to ensure facility cybersecurity security and operational alignment.
- Steps to immediately improve cybersecurity – Facility managers can immediately improve cybersecurity by documenting all connected devices, setting supplier and remote access standards, reviewing workflows for redundancy gaps, enforcing strong password hygiene, and starting conversations with management and IT to initiate a formal risk assessment.
As buildings become smarter, integrating a cybersecurity risk assessment checklist and drill testing into project planning and maintenance is essential to safeguard building cybersecurity, facility cybersecurity, and operational systems from increasing cyberthreats.
Read the full article here.