Industrial Machinery Cyber Security

Why Has This Changed?

The safety landscape in machinery is always evolving, but the rapid advancement of artificial intelligence has fundamentally changed the cyber security landscape. AI has significantly lowered the barrier to entry for cyber attacks, enabling individuals with little or no specialist knowledge to generate malicious code, identify vulnerabilities, produce convincing phishing campaigns and automate attacks that previously required experienced cyber security professionals.

Previously, malware attacks and cyber risks mostly targeted data. However, with the drive for new technology in industry to keep production flexible, costs under control and remain competitive, we have introduced more and more digital elements into our machines—elements that are prime targets for malicious intent.

The Human Factor

Thoughts on how to protect against this, in line with our normal machinery safety methodology, have also raised another question: what about non-malicious intent? Does an operator or technician fully understand the technology that they are working with, which may, unbeknown to them, be at the bleeding edge of technological progress?

It may be the same type of machine they have worked on for years, but a newer model with USB ports, Safety PLCs, PROFINET connecting all of the components, remote access and intelligent diagnostics. Do they know what threats may have transferred onto a maintenance laptop before it is plugged into the machine? Do they know that their easy way into the system may be just as easy for an attacker? Do they understand the importance of the safety application within the Safety PLC, that it has been validated by an expert, and that it should not be altered without proper assessment?

Insider Threats

This also leads to the issue of disgruntled employees. Although malicious in nature, how much skill would they really need to bring down an operational plant? A USB Killer device can be purchased for as little as £20 and has the potential to damage hundreds of thousands of pounds' worth of equipment. A programmable "BadUSB" device can automatically execute code as soon as it is connected, potentially introducing malware into a machine or industrial network. The opportunity for corruption is real.

The Machinery Regulation

The number of threats and attack pathways into industrial machinery is only increasing, which is why the new Machinery Regulation has introduced "Protection Against Corruption" as a significant new Essential Health and Safety Requirement.

As with the traditional safety of the machine, cyber security is a responsibility shared between both the machine manufacturer and the end user.

Although cyber security has been established within industrial control systems for many years, its application to individual machinery is still evolving.

The Standards

The tools being developed to support this include a range of standards:

  • prEN 50742 – Cybersecurity requirements supporting the Machinery Regulation.

  • IEC TS 63074:2023 – Guidance for machine builders on applying the relevant parts of the IEC 62443 series where cyber security threats could affect the functional safety of safety-related control systems.

  • ISO/TR 22100-4 – Guidance on integrating cyber security into machinery risk assessment alongside EN ISO 12100.

  • IEC 62443 series – Industrial Automation and Control Systems Security.

These standards provide guidance on how to apply the IEC 62443 series to machinery.

Effectively, the requirement is to conduct a cyber security risk assessment in accordance with IEC 62443-3-2 and utilise the technical requirements within IEC 62443-3-3 to demonstrate the Security Level that your machinery can achieve.

These assessments also provide the engineering basis for selecting appropriate cyber security technologies and system architecture.

Ongoing Responsibilities

There are also ongoing requirements to provide support when new vulnerabilities are identified within your machinery.

For example, if the manufacturer of a Safety PLC identifies a new vulnerability, you should assess the impact on your machinery, inform customers who operate the affected machines and provide guidance, mitigation measures or software updates where appropriate.

This is a new and demanding requirement being placed upon machinery builders and system integrators, and it will not always be straightforward to navigate.

How We Can Help

We are here to help, whether that is delivering a standalone cyber security risk assessment for your machinery, integrating cyber security into a complete machinery conformity assessment, or supporting you with the corrective actions identified throughout the assessment process.

Speak to an expert