SLC 2019: Taking the Risk Out of Your Security Management

SLC 2019: Taking the Risk Out of Your Security Management

Nov. 12, 2019
“Companies must understand that safety and security yare no longer separate issues,” says Steve Ludwig, Safety Program Manager for Rockwell Automation

As companies are digitally transforming their operations and increasing connectivity, they are also increasing their risks, explained Steve Ludwig, Safety Program Manager for Rockwell Automation at  EHS Today’s Safety Leadership Conference.

“Does your company view security risks as safety risks?” Ludwig asked the audience during this session. “When you talk about cybersecurity there is a belief that you are talking about information, but we are also talking about risk to workers, assets, the environment and a company’s reputation.”

To make his point Ludwig gave a few examples. A German steel mill whose system was manipulated and resulted in massage damage when it was unable to shut down. And at a water treatment plant in Australia, radio commands were sent to sewage equipment causing 800,000 liters of raw sewage to spill into local parks and rivers which killed marine life.

How does this happen?  IT and OT are now connected. While being able to access information from operations is essential to secure the data needed to perform the higher analytic function that provides the benefit of Iot and IIot, there is also a higher risk. Often hackers are now getting into the safety systems in order to get into the process systems. 

Who are the people behind these cyberattacks?

At the top of the list are insiders. Sometimes it’s disgruntled workers and sometimes it’s just worker errors. Then there are cybercriminals, hacktivists, terrorists and even nation-states.

No matter who is trying to enter a company's network, there are ways that company's can protect themselves. Ludwig offered some fundamentals of cybersecurity that companies should follow.

Asset Management: know your assets and their potential risks

Authentication Authorization Accounting: know your users

Implement patch management policies and procedures

Computer and mobile endpoint protection

Disaster recovery (Backup and restore)

Raising awareness to personnel

Basic network security tasks

“Companies must understand that safety and security are no longer separate issues,” says Ludwig. “ The solution is to have a risk management approach and collaborate across all functions of the company.”

Sponsored Recommendations

Committing to Safety: Why Leadership’s Role in Safety Excellence is Key

Jan. 13, 2025
Leadership has the power to transform an organization through their behavior and vision, which can result in the creation of an organizational culturethat supports safety excellence...

Speak Up! Cementing "See Something, Say Something" to Drive Safety

Jan. 13, 2025
Many organizations promote "see something, say something" to encourage their people to intervene and make work safe. But most don't go far enough to equip teams with the skills...

The Truth and Challenges of Cultivating Chronic Unease

Jan. 13, 2025
DEKRA announces its latest white paper, “The Truth and Challenges of Cultivating Chronic Unease,” as a definitive look into why being vulnerable to incidents strengthens our commitment...

Mitigating Risks: Strategies for Safeguarding Workers in Hazardous Workplaces

Jan. 13, 2025
Join our expert team in taking on the challenge to make safety part of your organization’s DNA as work, the workforce, and workplaces evolve.

Voice your opinion!

To join the conversation, and become an exclusive member of EHS Today, create an account today!