Don’t Let OT Hackers Spoil Your Holiday

2022-12-27
关注

Don’t Let OT Hackers Spoil Your Holiday
Illustration: © IoT For All

Online business has been booming since the start of the Covid-19 pandemic, and holiday retail sales are projected to increase between 4 percent and 6 percent this year. Manufacturers, logistics companies, and retail giants like Walmart face extraordinary pressures to meet customers’ online demands and maintain zero downtime while ensuring warehouse security from threats including OT hackers.

'To ensure a smooth flow of goods and prepare for this year's holiday peak season, organizations should optimize warehouse operations.' -Daniel BrenClick To Tweet

These factors have compelled many to invest in automated logistics and smart warehouse technologies that are known to be more efficient than individual workers performing the same tasks. For example, a new Amazon robot can reportedly handle 1,000 items per hour. As such, digital transformation has accelerated and delivered rapid advancements in digital supply chain logistics, warehouse components, and tools. 

The Cyber Risks of Digitalization

Unfortunately, all of this modernization has led to greater complexity from geographically distributed warehouses as a critical element of supply chain logistics, as well as multi-vendor and multi-generation technology opening vulnerabilities in an increasingly dynamic threat landscape. As SLAs and ROIs are key drivers in smart warehouse operations, everything is connected; air gapping is no longer a feasible approach. And this makes it extremely challenging for teams to continuously map and understand their security posture.

Threat actors have identified this reality as a low-hanging, lucrative market; they continually search for new ways to find and exploit security vulnerabilities and disturb supply chain operations. Hackers have already carried out successful cyberattacks against some of the world’s largest smart logistics and freight forwarding companies. In some cases, operations had to be halted, resulting in disruption, downtime, financial losses, and regulatory disclosures to shareholders.

In December 2021, Germany-based Hellman Worldwide Logistics, which has hundreds of offices and operates in 173 countries, was hit by a cyber attack that forced it to shut down its IT. The company’s refusal to pay the ransomware demand resulted in a leak of 70.64GB of documents, credentials, correspondence, agreements, orders, etc.  

For another example, Expeditors, a Seattle-based global logistics company with more than 350 locations across 100 countries, was hit by a targeted cyber-attack earlier this year that disrupted its global operating systems. The attack ultimately caused $60 million in damages.

The Inherent Cyber Risks of Warehouse Management Systems

Smart logistics and warehouse companies rely upon integrators to streamline warehouse management systems (WMS) for their operations. A WMS is a software solution that provides visibility into the company’s inventory and manages supply chain fulfillment operations all the way from the distribution center to the store shelf.  It is a must-have in today’s digital age.

However, integrators face several challenges that can create security gaps, including:

  • Ensuring seamless communication between the WMS and multiple technologies
  • Overcoming cybersecurity skill gaps: IT and operations teams are experts at building smart logistics systems and managing their enormous databases but face challenges identifying digital assets prioritizing risks appropriately and lack vulnerability management skills
  • Ensuring reliable and efficient operations: Downtime and network delays result in lost revenue, impact supply chain security, and can affect brand integrity

Ensuring the Security of Smart Warehouses

The goal of the business is to achieve zero downtime and ensure that robotic automation and procedures work seamlessly and reliably. This makes it a far better strategy to proactively assess, manage, and mitigate cyber risks than to react only after attacks have already happened. 

Whether you are a smart logistics integrator, WMS vendor, or smart warehouse vendor, you must lay a foundation for securing your operations. Here are my top recommendations:

  • Maintain central continuous visibility of digital assets in monitored warehouses. This is key to closing cybersecurity gaps, exposures, and vulnerabilities. Visibility is not only asset inventory and vulnerabilities, as it also includes visibility over unsecured communication such as unencrypted traffic between the assets at the warehouse.  
  • Make sure that management systems of IoT devices are patched and protected with complex passwords.
  • Assess and identify network segmentation gaps. Smart warehouse networks should be divided into VLANS, and the communication between processes should be passed through a firewall. Moreover, the Firewall policy should be reviewed carefully to make sure that the allowed connection between the environment and the IT/Internet is properly hardened. 
  • Process data internally while providing controlled visibility for customers.
  • Continuously analyze risks that can impact security controls and industrial systems to ensure that the OT driving the warehouse’s functions securely and reliably 24/7.

Conclusion

To ensure a smooth flow of goods and prepare for this year’s holiday peak season, organizations should optimize warehouse operations for speed, efficiency, accuracy, and cybersecurity. Using these strategies to streamline smart warehouse environments will ensure peace of mind from attacks, even during the peak holiday season demand. 

As an added bonus, these operational changes translate into a first-rate customer experience, which fosters brand loyalty, generates positive customer feedback, helps grow the business, and improves the bottom line long after the holiday rush has passed.

Tweet

Share

Share

Email

  • Manufacturing
  • Factory Automation
  • Internet of Things
  • Smart Manufacturing

  • Manufacturing
  • Factory Automation
  • Internet of Things
  • Smart Manufacturing

参考译文
不要让加班黑客破坏你的假期
自新冠肺炎大流行开始以来,网上业务一直在蓬勃发展,今年的假日零售额预计将增长4%至6%。制造商、物流公司和沃尔玛这样的零售巨头面临着巨大的压力,要满足客户的在线需求,保持零停机时间,同时确保仓库安全,免受包括OT黑客在内的威胁。这些因素迫使许多公司投资于自动化物流和智能仓库技术,这些技术被认为比个体工人执行相同任务更有效率。例如,据报道,亚马逊的一款新机器人每小时可以处理1000件商品。因此,数字化转型加速了数字供应链物流、仓库组件和工具的快速发展。不幸的是,所有这些现代化都导致了作为供应链物流关键要素的地理分布仓库的更大复杂性,以及在日益动态的威胁环境中多供应商和多代技术开放漏洞。由于sla和roi是智能仓库运营的关键驱动因素,因此一切都是连接的;气隙不再是可行的方法。这使得团队持续绘制和理解他们的安全态势极具挑战性。威胁行为者将这一现实视为一个唾手可得、利润丰厚的市场;他们不断寻找新的方法来发现和利用安全漏洞,扰乱供应链运作。黑客已经成功地对世界上一些最大的智能物流和货运代理公司进行了网络攻击。在某些情况下,不得不停止运营,导致中断、停机、财务损失和对股东的监管披露。2021年12月,总部位于德国的海尔曼全球物流公司(Hellman Worldwide Logistics)遭到网络攻击,迫使其关闭了it部门,该公司在173个国家拥有数百个办事处。该公司拒绝支付勒索软件的要求,导致70.64GB的文件、凭证、通信、协议、订单等泄露。另一个例子是,总部位于西雅图的全球物流公司Expeditors在100个国家拥有350多个地点,今年早些时候遭到了有针对性的网络攻击,导致其全球操作系统中断。这次袭击最终造成了6000万美元的损失。智能物流和仓库公司依靠集成商来简化其运营的仓库管理系统(WMS)。WMS是一种软件解决方案,可提供对公司库存的可见性,并管理从配送中心到商店货架的供应链履行操作。在当今的数字时代,这是必不可少的。然而,集成商面临着一些可能会产生安全漏洞的挑战,包括:业务的目标是实现零停机时间,并确保机器人自动化和流程无缝可靠地工作。这使得主动评估、管理和减轻网络风险比在攻击已经发生后才做出反应要好得多。无论您是智能物流集成商、WMS供应商还是智能仓库供应商,都必须为确保运营安全奠定基础。以下是我的主要建议:为了确保货物的顺畅流动,并为今年的假日旺季做好准备,企业应该优化仓库操作的速度、效率、准确性和网络安全。使用这些策略来简化智能仓库环境将确保免受攻击,即使是在假日需求高峰期间。作为额外的奖励,这些运营上的变化转化为一流的客户体验,从而培养品牌忠诚度,产生积极的客户反馈,帮助发展业务,并在假日高峰过后很长一段时间内提高底线。
  • en
您觉得本篇内容如何
评分

相关产品

EN 650 & EN 650.3 观察窗

EN 650.3 version is for use with fluids containing alcohol.

Acromag 966EN 温度信号调节器

这些模块为多达6个输入通道提供了一个独立的以太网接口。多量程输入接收来自各种传感器和设备的信号。高分辨率,低噪音,A/D转换器提供高精度和可靠性。三路隔离进一步提高了系统性能。,两种以太网协议可用。选择Ethernet Modbus TCP\/IP或Ethernet\/IP。,i2o功能仅在6通道以太网Modbus TCP\/IP模块上可用。,功能

雷克兰 EN15F 其他

品牌;雷克兰 型号; EN15F 功能;防化学 名称;防化手套

Honeywell USA CSLA2EN 电流传感器

CSLA系列感应模拟电流传感器集成了SS490系列线性霍尔效应传感器集成电路。该传感元件组装在印刷电路板安装外壳中。这种住房有四种配置。正常安装是用0.375英寸4-40螺钉和方螺母(没有提供)插入外壳或6-20自攻螺钉。所述传感器、磁通收集器和壳体的组合包括所述支架组件。这些传感器是比例测量的。

TMP Pro Distribution C012EN RF 音频麦克风

C012E射频从上到下由实心黄铜制成,非常适合于要求音质的极端环境,具有非常坚固的外壳。内置的幻像电源模块具有完全的射频保护,以防止在800 Mhz-1.2 Ghz频段工作的GSM设备的干扰。极性模式:心形频率响应:50赫兹-18千赫灵敏度:-47dB+\/-3dB@1千赫

ValueTronics DLRO200-EN 毫欧表

"The DLRO200-EN ducter ohmmeter is a dlro from Megger."

评论

您需要登录才可以回复|注册

提交评论

iotforall

这家伙很懒,什么描述也没留下

关注

点击进入下一篇

LoRaWAN为速食餐厅提供食品安全

提取码
复制提取码
点击跳转至百度网盘