IT-OT convergence: When ransomware hits the factory floor | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


What do ransomware attacks on manufacturers look like?

Picture production lines going absolutely dark for days or weeks at a time. Store shelves, normally stocked with products, sitting empty due to serious and prolonged supply chain disruptions. These challenges impact everyone, from frontline workers to the president of the board.

See also: For sweeter AI adoption, Hershey and KDP utilize Augmentir’s connected worker platform

Ransomware infects computers, locks them down, and encrypts files or systems until a ransom is paid. Malware can expand quickly in manufacturing environments, taking over computers one by one across the entire network. Every piece of equipment, from the mixer to the labeling machine, likely are talking to each other in this networked, IoT environment.

Although ransomware attacks can target anyone, food and beverage companies can be particularly vulnerable and hard-hit by coordinated strikes.

Why food and beverage makers are targeted

Among manufacturers, food and beverage are highly visible consumer products. There are massive reputational stakes on the line, with any loss of consumer confidence potentially damaging the company’s standing in a crowded marketplace. A halt to the production line has immediate ripple effects on everything from packaging and overtime to meeting product demand for consumers.

A manufacturing plant’s performance is predicated on the use of IT and reliability of their OT networks. As connectivity, automation, data-driven and even AI-enabled systems have become the standard, manufacturers have adapted their OT systems and processes to try to keep up, often developing patchworked networks over time.

See also: U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

Vendor integrations, remote access, unpatched third-party exposures, and shadow IT are more susceptible to ransomware that can cause significant disruption.

OT networks are essentially set up to be attacked, with one end of the plant accessible to the other end. And there are so many open targets, with over 42,700 food and beverage processing sites in the U.S. alone.

All of these factors combine to make food and beverage relatively low-hanging fruit for ransomware attackers.

Years of attacks against manufacturers

Arizona Beverages, one of the largest beverage suppliers in the country, suffered a significant ransomware attack in March 2019 that led to weeks-long disruptions. The ransomware infection was exacerbated by the use of outdated operating systems that were unpatched and no longer supported. The company reportedly spent hundreds of thousands of dollars to recover from the incident and rebuild their entire network.

——————————————————–


Click Here For The Original Source.

.........................