In focus manufacturing

The leading and longest established online Process Engineering publication serving the Process Manufacturing Industries

Growing tide of IT integration in the UK is leaving critical sectors exposed to cyber threats, warns KPMG study

The UK's critical infrastructure and manufacturing base is more vulnerable than ever to cyber-attacks as businesses integrate industrial control and corporate information systems, but can fail to put in place adequate cyber defences. This is the key finding of a new KPMG study of 350 senior IT, engineering and operations professionals responsible for ensuring the security of some of the UK's most strategically important businesses.*

Whilst openly reported incidents are still rare, a 2014 German steel mill breach provides evidence of how real the threat is. In this instance attackers gained access to the corporate network and were able to jump across to production systems to inflict real physical damage to a blast furnace. The impact here was economic but knowledgeable attackers could craft exploits to bypass safety systems and processes, potentially leading to environmental or even safety impacts.

Integration is becoming increasingly common as businesses reap benefits from merging corporate and operational systems. 80 per cent of respondents surveyed said they already have or are planning to merge their production and corporate IT systems. However, the study revealed that while businesses are aware of the risks involved with integration, with 83 per cent believing that their production systems are likely to be targeted, many are still not doing enough to address the problem. As testimony to this two-thirds of the respondents said their organisation had not factored in the significant threat that cyber criminals pose to their industrial control systems and almost half stated that their businesses were not investing enough to improve cyber security.

Despite this, 61 per cent said they were pushing ahead with integration programmes regardless of these concerns. This oversight could lead to harm to vulnerable, yet vital industrial assets such as oil refineries, power and manufacturing plants.

Roy McNamara of KPMG's Cyber Security team, says: "As industrial control systems evolve companies are looking to reduce costs and improve efficiency by consolidating IT services and adopting sophisticated data analytics, integrating previously standalone control systems with corporate intranets or even the internet. In doing so, they may open themselves up to threats including organised crime, hacktivism and even state sponsored attack."

"Industrial control systems operate the majority of our critical national infrastructure and manufacturing sector such as power grids, oil refineries, production plants and traffic controls systems. In a worst case scenario cyber criminals could target these control systems in order to sabotage critical infrastructure or cause economic damage.

"This doesn't mean that businesses should halt the process of converging these systems, with potentially huge benefits in doing so, but they do need to identify and manage the associated risks - and that means thinking about cyber security up front before regulation or security incidents force their hand."

For more information, please contact:

KPMG LLP 
15 Canada Square
London
E14 5GL
Tel:  +44 207 694 8812
Email: nahidur.rahman@KPMG.co.uk
Web:  www.kpmg.com

Request FREE information from the supplier on the products in this article

Login or Register

Process and Control Today are not responsible for the content of submitted or externally produced articles and images. Click here to email us about any errors or omissions contained within this article.

Get the weekly eNewsletter from Process and Control Today