โ
What is NIS2?
From summer 2024, the NIS2 (Network and Information Security) standard will come into force, bringing significant changes to strengthen the protection of critical infrastructures. As a reminder, the latter adds its own set of constraints and sanctions for manufacturers:
- Compliance obligation: Companies will have to comply with the security measures set out in the NIS2 standard. They will have to set up incident detection and response systems, manage vulnerabilities and protect sensitive data.
- Responsibility of subcontractors: Greater vigilance will be exercised over subcontractors in terms of cybersecurity. They will have to comply with the strict requirements of the NIS2 standard, ensuring a consistent level of security throughout the supply chain.
- Financial penalties for non-compliance - (approx. 2-4% of sales): Companies that fail to comply with the NIS2 standard will be subject to sanctions, including financial fines. It is essential to take proactive measures to ensure compliance and avoid such consequences.
- Holistic approach to cybersecurity ๐๐ง ๐ฒ๐ ๐ข๐ง: companies will need to adopt measures to prevent, detect, react to and recover from cyber incidents on the IT and OT perimeters.
โ
It's time to start thinking about your OT/IT convergence strategy!
โ
Why work towards OT/IT convergence?
Today, the need for real-time production data (OT) is becoming ever more pressing for operational staff. It's only natural, as this data serves the ๐ผ๐ฏ๐ท๐ฒ๐ฐ๐๐ถ๐ณ๐ of ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐๐ถ๐ผ๐ป, ๐พ๐๐ฎ๐น๐ถ๐๐ฒฬ, ๐บ๐ฎ๐ถ๐ป๐๐ฒ๐ป๐ฎ๐ป๐ฐ๐ฒ or even ๐ฒฬ๐ฐ๐ผ-๐ฒ๐ณ๐ณ๐ถ๐ฐ๐ถ๐ฒ๐ป๐ฐ๐ฒ.
Meanwhile, the IT department tends to close the doors as much as possible to protect the integrity of the plant. It's only natural, since its role is to ensure thesafety of the run.
As a result, numerous pilots are emerging: they're quick and easy to set up, respond to a precise use case and upload data directly to the cloud, often without the IT department's knowledge (via IoT 4G & VPN, for example).
โ
How can driver strategy be a problem?
In general
- Prevents the contextualization and formatting needed to master production data before use.
- Reproduces data silos and slows down the deployment of use cases that need it.
- Significantly slows down scaling.
- Compromises system integrity and production.
And if we add to the equation ๐๐ฝ๐ฒฬ๐ฐ๐ถ๐ณ๐ถ๐ฐ๐ถ๐๐ฒฬ๐ ๐ฑ๐ฒ ๐น'๐ข๐ง
- Multiplicity of specific protocols, real-time, determinism, no stopping
- Potential need for physical update
- Equipment often not inventoried (on average 30% of stock unknown)
- Machines communicating via deprecated / exotic protocols that no longer run on up-to-date operating systems.
Understandably, this further weakens the plant system, which was already under strain.
It is therefore essential to seize on these issues and embark on a real IT-OT convergence process, bringing together teams who didn't necessarily talk to each other beforehand, to build a secure, scalable infrastructure that meets business needs and the challenges of the "factory of the future".
โ
How are you preparing for this paradigm shift?