Can manufacturing become a well-oiled cyberattack-free machine?
09/11/2022 ExtraHop
By Jamie Moles
Cyber vulnerability is a major disrupter of business and growth. It threatens a loss of data, theft of capital, or intellectual property and brand reputation damage. The manufacturing industry is particularly vulnerable with its global supply chains, legacy tech infrastructure and large production sites and warehouses littered with internet-connected devices.
All manufacturers need to reassess their cyber exposure in light of recent attacks and take the appropriate steps to protect themselves like never before. The truth is, for some time now, the manufacturing sector has been a significant target for malicious cyber activity. Unfortunately, many manufacturing businesses still underinvest in cyber protection and are hamstrung by legacy tech, allowing ransomware and phishing scams to enter via chinks in their cyber armour.
In 2017, the WannaCry attack saw a huge amount of damage done to the manufacturing sector. Renault-Nissan was amongst the global manufacturers attacked, and the automotive giant was forced to halt production at global facilities at vast expense. Plants were ground to a halt in France, which had two production facilities in separate locations shut down. Slovenia, Romania and India also experienced forced shutdowns.
While the attack was effectively halted, the attackers did a huge amount of collateral damage across 150 countries and infected over 200,000 devices at Renault-Nissan alone. Research shows a single public internet-exposed device is enough to bring down an entire enterprise.
Five years on, the entire global manufacturing industry faces similar vulnerabilities and does not seem much better prepared. Illustrated with an attack on SafeStyle UK, a Bradford-based PVCu windows and doors manufacturer. The company saw an attack cause disruption to customer service and an unplanned increase in material price, costing the company £4m.
Avoidable risk
Beyond being targets of cybercrime themselves, manufacturing companies must be alert to the fact that their systems can be used as a backdoor into other systems and their business partners. Research from cybersecurity company ExtraHop shows that the manufacturing industry is still working with a large amount of insecure tech, putting themselves and their partners at risk.
One example of how the manufacturing sector is putting itself at risk is through network protocols. A network protocol is an established set of rules determining how data is transmitted between different devices in the same network. Modern factories could not run without them.
Manufacturing companies were noted to have open ports publicly exposed to the internet. A further 33% of companies in the sector are open to attack through the Lightweight Directory Access Protocol, (LDAP) and a further 22% through the Server Message Block Protocol, (SMB).
A specialist report revealed that 55% of the manufacturing industry is at risk of cyberattack due to Secure Shell protocols (SSH) being left vulnerable.
Both LDAP and SMB are internet-exposed protocols. LDAP is an industry-standard application protocol used for accessing and maintaining distributed directory information services over an internet connection. SMB is a client-server communication protocol used for sharing access to files, printers, serial ports and other resources on a network.
Both these protocols are used in many tasks undertaken in the manufacturing industry, and one single exposed protocol could be the doorway that lets an attacker in, leading to a business' economic downfall.
Ransomware fears
One alarming variant of cyberattack is ransomware, and this is specifically one that the manufacturing industry needs to be wary of. According to IBM threat data, 1 in 4 cyber attacks on manufacturing firms are from ransomware.
Ransomware is frequently used for stealing data and is further used for double extortion purposes. Double extortion ransomware allows attackers to extract companies' or employees' data and then further encrypt that data. Subsequently making it unretrievable and the victim more liable to pay the ransom charges.
Manufacturing and the ‘factory of the future’ will all be built upon more and more interconnected cyber-physical systems and communications. This can vary from sales floors to the manufacturing plant. Without proper integration of Information Technology (IT) and Operational Technology (OT), opportunities will be abundant for ransomware attacks to be carried out through internet-exposed protocols.
Reacting is not enough, monitoring is essential
For manufacturers to ensure cyber-readiness, they need to ensure the correct implementation of cybersecurity systems. Allowing IT departments to track down the origin of performance problems before they can derail operations is essential.
Manufacturing companies in severe cases might need to overhaul their entire environment, moving from physical servers to hyper-converged cloud systems. Equipment on the shop floor requires constant connectivity, so they need a security solution that guarantees zero downtime.
It is simply not enough for companies to react quickly to cyberattacks like in the Nissan-Renault case, the modern day cyber approach is that organisations should focus on their security hygiene as the first step in their building cyber posture. By analysing their own network, device configurations and traffic patterns, organisations can better understand their security risks and take action to improve their cybersecurity readiness before it is too late.
XDR: the new way
This understanding of the network is powered by Extended Detection and Response, XDR. XDR is the next step within the manufacturing industry's cyber revolution. XDR integrates leading endpoint, network and log-based security solutions.
Currently, most cyber budgets are spent preventing intrusions, rather than monitoring the network for signs of suspicious activity. However, this has not sufficed. Research shows that despite 75% of security budgets spent on prevention technologies, 80% of organisations have experienced a ransomware attack in the past five years.
XDR marries network detection response (NDR) responsible for exposing hackers post intrusion, security information and event management (SIEM) which can navigate the issues that lead to the attack by gathering data from your network and endpoint detection and response (EDR), which responds precisely to detected threats from a collation of data across multiple sources.
This means that not only are businesses protected from attacks, but create a completely streamlined incident response system with complete end-to-end visibility. With an XDR-based approach, manufacturers will have proper defences against the increasingly frequent, targeted and malicious attacks affecting their industry.
For more information, please contact:
Ashley Stewart
ExtraHop
520 Pike St Suite 1600
Seattle
WA 98101
USA
Tel: +1 877-333-9872
Email: Ashleys@extrahop.com
Web: www.extrahop.com
Share article:
Process and Control Today are not responsible for the content of submitted or externally produced articles and images. Click here to email us about any errors or omissions contained within this article.

