Category Archives: Technology

Keeping Your Industrial Control System Secure

Recently, the evil hackers have stepped up their assault with the design of viruses designed specifically to attack and exploit industrial control systems, including the Stuxnet worm specifically written to attack Supervisory Control and Data Acquisition (SCADA) systems, and, according to reports, Siemens control systems in particular.

As a result, you need to step up your efforts to secure your systems. How do you go about it? Start with the advice in this recent article in Industry Week that gives you “five keys to keep your industrial control system secure”.

  • Develop Security Awareness
    Viruses don’t just come from the internet. They also come from flash & USB drives that were infected on another computer. Be sure to install end-to-end anti-virus solutions and only copy / run new software after it has been scanned and determined to be virus free.
  • Do a Risk Assessment
    Determine the risk posed by each organizational system and lock it down appropriately. Mission critical systems or systems that control dangerous process or use dangerous materials should be locked down, and, if at all possible, taken completely off the internet.
  • Find the Legacy Systems
    Some of these systems might be so old that they are no longer supported. As a result, they’ll be especially vulnerable to new exploits as there will be no future patches to plug the holes and newer AV products will not support the legacy systems.
  • Triple Lock-down the Wireless Networks
    Now that Blackberries, iPhones, and Android devices can be used to control your network, the last thing you want is an open network that anyone with the right software and a mobile smartphone can use to log in locally and take control.
  • Communicate
    Talk to the IT people and keep abreast of the emerging security issues and have a plan to deal with them before they have their way with you.

Then do the following:

  • Lock down any output/display-only devices tighter than Fort Knox.
    Disable the USB / external drives, prevent installation of unauthorized programs downloaded over the internet, and make sure the approved anti-virus/anti-spyware programs can’t be disabled. It won’t prevent every threat, but it will prevent known threats from getting in and making more holes that other threats could exploit.
  • Do a regular security audit at least quarterly.
    You can’t just update your anti-virus programs once a year and assume everything is A-OK. Every install, every update, every new machine and new device is a risk. While you don’t need to go psycho and lock everything down and run a level 5 security threat assessment every week, you should run a basic set of scans and penetration tests once a quarter to make sure you or your staff haven’t inadvertently opened the back door wide open.

 

Share This on Linked In

DnB’s Mobile Capability is Good But …

… it’s no substitute for the real thing.

There’s been a lot of hype recently about Dunn & Bradstreet’s new Supplier Risk Manager Mobile functionality, and a lot of coverage on the blogs. I’m not going to say it’s undeserved, as it is one of the first enterprise applications in the supply chain space to make an effort to embrace mobile computing, but I’m not going to hype it either.

The reality is that while D&B are advertising three capabilities, there is really only one real use for the offering (and I’m pleased to say that, when grilled, they readily admitted it), which is:

determining whether or not an alert needs to be acted on now, or later.

A properly configured Supplier Risk Management System will be configured to send out alerts anytime something might need to be looked at — as the system will be ignored otherwise. When an alert is sent out, the first thing that a recipient needs to do is determine how serious the alert is and whether or not more research needs to be done and/or an action needs to be taken. With the mobile platform, that works on ‘Berries, ‘Droids, and iPhones, a risk manager can drill into the alert and see why it was issued (reduced credit score, late shipments, plant shutdown, etc.) and then drill into the supplier profile to determine what effect the reason for the alert could have on the supplier and/or the relationship. The manager can then determine if the alert needs to be followed-up on or not, and if the follow-up (whether additional research, a call, or another action) has to happen now or later. This is useful if the manager is on the road and doesn’t have easy access to the regular application or if the manager is just enjoying personal time and doesn’t want to drop everything to run to the [home] office to figure out whether or not something needs to be done — which could be the situation if the alert is for a major supplier of critical inventory.

The mobile app also allows you to search for suppliers and look up (random) company profiles, but let’s face it, that’s not something you’re going to be doing when you’re on the road or on personal time — especially when it’s so much easier on the full application. It’s neat, but you’re only going to be doing it when conduction sourcing events back at the [home/hotel] office. In short, it’s good, but don’t place unreasonable expectations on it, or they’ll be dashed.

For Real Value, You Must Own the TCO

CRM Buyer just published one of the best articles I’ve ever stumbled across. In TCO, ROI, and the Difference Between Price and Cost, the author makes a point that is overlooked far too often by far too many buyers when they are shopping for new supply chain solutions:

      Customers must be sure that THEY own the definition and calculation of TCO and don’t allow the vendor to drive the agenda.
     

As the author clearly states, vendors will try to manipulate and obfuscate the true TCO of their solution and it will be different for each installation. Plus some of the costs, like risk and opportunity, are nebulous and hard to define. Vendors will try to make other vendors’ solutions look risky when, in fact, for you they might be less risky.

That’s why, on multiple occasions, I’ve tried to lay out the true, long term, costs of supply management solutions, as I did in this post in Uncovering the True Cost of On-Premise Sourcing & Procurement Software, in this post The Total Cost of Ownership Equation in a Green Economy, and this post on Know Your Software TCO & TVM, for example. The true, long term, cost is always more than you think and much more than the vendor will let on. It’s like the car example given in the article. If you’re going to sell after five years, the total cost is the price plus five years of maintenance and repairs (and insurance and gas) minus the expected selling price, and when everything is factored in, a more expensive car that costs more but retains its value might be worth more than a cheap car that loses the majority of its value and costs four times as much to maintain.

Before you make a decision, you have to determine the total cost of each solution over the intended lifetime. Only then you can decide if the solution with the greater (annualized) cost truly brings more value. If a solution costs 20% more but increases productivity by 40% or decreases risks by 30%, it might be worth it. However, if a solution costs 100% more but brings no additional value of any kind, it’s not worth a second look. And this is not something you will know until you slice through the vendor obfuscation and normalize the costs, which is something you can only truly do if you own the calculation.

Logistics Carriers: Black Boxes are Coming

As per this recent article over on Logistics Management, all five leading U.S. trucking companies endorse EOBRs for commercial trucks. The rationale: to verify legal duty status of their drivers.

Schneider National, U.S. Xpress, Hunt Transportation Services, Knight Transportation, and Maverick USA are endorsing the “Commercial Driver Compliance Improvement Act” (S. 3884) put forward by Senators Mark Pryor (D-Ark) and Lamar Alexander (R-Tenn) which, if passed, would require (commercial) trucks have electronic on-board recorders (EOBRs) within three years. The companies have formed the industry coalition “Alliance for Driver Safety & Security” to urge Congress to pass legislation designed to improve highway safety.

The alliance believes that EOBRs will improve safety on our nation’s highways by applying technology to document driver compliance to the hours of service rules because early evaluation of the Comprehensive Safety Analysis (CSA 2010) data suggests that carriers with higher levels of hours of service compliance have lower crash involvement.

But will they really verify legal duty status? And, more importantly, will they really improve highway safety? If your truck has two drivers, will a box tell you who was driving? And if a driver really wants to push through, I’m sure it won’t be long before someone figures out a way to bypass them, just like your best car thief can bypass any car alarm or lojack in 60 seconds (or less). But more importantly, how will it directly improve highway safety. While it’s true that a tired driver is more likely to get into an accident than an alert driver, how is a black box going to determine if a driver is tired or not? Every driver is different. If the driver didn’t sleep the night before due to illness or personal stress, the driver might tire in just a few hours on a crowded highway. But if the driver got a great night’s sleep, is rested and relaxed, doesn’t have to deal with demanding driving situations, and breaks every few hours, he or she might be able to easily drive 12 hours in a day, especially if he or she gets the next day off.

While I’m all for safety, I can’t help wondering if there is an ulterior motive by some of the bigger players to bankrupt the smaller players. These boxes are going to cost at least 500 per truck, and there are going to be installation, maintenance, and training costs on top. This could break a small carrier operating on a razor-thin margin, and offer no additional security or safety if the carrier’s drivers are professional self-conscious drivers who always obey the rules and keep good books.

But what do you think?

Share This on Linked In