Drives & Controls Magazine September

THE GEOPOLITICAL THREATS TO INDUSTRIAL AUTOMATION Industrial automation seems to have become a politically hot topic in recent months. First of all, we had a group of US government agencies – including the FBI and the National Security Agency – accusing “Iran-affiliated cyber-actors” of targeting OT (operational technology) devices, including Rockwell Automation PLCs (specifically the Allen-Bradley MicroLogix 1100 and 1400 series), resulting in a potential loss of control and monitoring functions. After accessing Internet-connected devices remotely, they warned, attackers could change IP address and passwords, potentially leading to effects such as loss of pressure and flooding. At least one organisation reported that its PLC files had been modified, after noticing ladder logic discrepancies across several sites. Shortly after this warning, reports emerged that water utilities in at least seven US states – with more than 30 in Minnesota alone – had suffered a series of cyberattacks on their PLC-based control and monitoring systems, resulting in customers being told to boil water, and the need to operate the plants by hand. A few weeks later, the US agencies issues another warning – this time about cyberattackers using AI-generated scripts, disguised as monitoring tools, to find Internet-exposed Siemens S7 PLCs that are poorly protected or running outdated software (see page 8). Although the agencies didn’t identify the source of the attacks this time, they said that the use of AI represents “an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools”. They added that exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or damaged equipment, compromised data, compliance violations, and cascading impacts across interconnected systems. “This is not a theoretical risk – it is an active threat,” the agencies cautioned. Meanwhile, an inter-agency body convened by the White House identified another threat, this time in the form of foreign-made goods including inverters (but excluding variable-speed drives) and advanced robotics devices – such as AMRs (autonomous mobile robots), humanoids and quadrupeds – saying that such items posed “unacceptable risks to the national security of the US, or the safety and security of US persons”. The Federal Communications Commission then banned their sale in the US. This time, the main target was thought to be China – the world’s biggest producer of humanoid robots as well as inverter systems. And the main aim of the ban seems to be to protect US manufacturers operating in these sectors (even though Chinese manufacturers of humanoid robots have yet to enter the US market). Although these warnings have so far focussed on the US, the implications could be global – especially the risk of cyberattacks on the control systems that we now rely on to run our critical infrastructure. With Russia making vociferous threats against the UK, we need to ensure that such systems are protected as effectively as possible. Tony Sacks, Editor n COMMENT

RkJQdWJsaXNoZXIy MjQ0NzM=