Ehstoday 10767 Cybersecurity 7
Ehstoday 10767 Cybersecurity 7
Ehstoday 10767 Cybersecurity 7
Ehstoday 10767 Cybersecurity 7
Ehstoday 10767 Cybersecurity 7

SLC 2019: Taking the Risk Out of Your Security Management

Nov. 12, 2019
“Companies must understand that safety and security yare no longer separate issues,” says Steve Ludwig, Safety Program Manager for Rockwell Automation

As companies are digitally transforming their operations and increasing connectivity, they are also increasing their risks, explained Steve Ludwig, Safety Program Manager for Rockwell Automation at  EHS Today’s Safety Leadership Conference.

“Does your company view security risks as safety risks?” Ludwig asked the audience during this session. “When you talk about cybersecurity there is a belief that you are talking about information, but we are also talking about risk to workers, assets, the environment and a company’s reputation.”

To make his point Ludwig gave a few examples. A German steel mill whose system was manipulated and resulted in massage damage when it was unable to shut down. And at a water treatment plant in Australia, radio commands were sent to sewage equipment causing 800,000 liters of raw sewage to spill into local parks and rivers which killed marine life.

How does this happen?  IT and OT are now connected. While being able to access information from operations is essential to secure the data needed to perform the higher analytic function that provides the benefit of Iot and IIot, there is also a higher risk. Often hackers are now getting into the safety systems in order to get into the process systems. 

Who are the people behind these cyberattacks?

At the top of the list are insiders. Sometimes it’s disgruntled workers and sometimes it’s just worker errors. Then there are cybercriminals, hacktivists, terrorists and even nation-states.

No matter who is trying to enter a company's network, there are ways that company's can protect themselves. Ludwig offered some fundamentals of cybersecurity that companies should follow.

Asset Management: know your assets and their potential risks

Authentication Authorization Accounting: know your users

Implement patch management policies and procedures

Computer and mobile endpoint protection

Disaster recovery (Backup and restore)

Raising awareness to personnel

Basic network security tasks

“Companies must understand that safety and security are no longer separate issues,” says Ludwig. “ The solution is to have a risk management approach and collaborate across all functions of the company.”

Sponsored Recommendations

3 Essential Elements for a Strong Safety Culture

March 13, 2024
Organizations globally have increased their attention on safety culture: trying to figure out what it really is and the aspects that are necessary to develop and sustain it. And...

Making the Case for Occupational Health Software

March 13, 2024
Deciding to invest in Occupational Health (OH) software can be a challenging leap for many organizations. This article will equip businesses with insightful strategies for effectively...

Fighting the Flu: Solutions for the Workplace

March 13, 2024
Seasonal flu continues to wreak considerable havoc both on individual wellness, as well as on our business continuity and productivity. Explore these solutions for protecting ...

Preventing SIFs with Digitization: Reduce Serious Injuries and Fatalities with Technology

March 13, 2024
This eBook discusses the origins of SIF prevention, outlines principles, models and tools available to EHS leaders to better detect and address SIF potential in their business...

Voice your opinion!

To join the conversation, and become an exclusive member of EHS Today, create an account today!