<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emeline LEGRAND, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/emeline-legrand/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 19 Nov 2025 16:36:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Emeline LEGRAND, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Protecting Connected Instruments: A Growing Challenge for Laboratories</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/11/protecting-connected-instruments-a-growing-challenge-for-laboratories/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/11/protecting-connected-instruments-a-growing-challenge-for-laboratories/#respond</comments>
		
		<dc:creator><![CDATA[Emeline LEGRAND]]></dc:creator>
		<pubDate>Thu, 13 Nov 2025 10:53:42 +0000</pubDate>
				<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=28147</guid>

					<description><![CDATA[<p>Laboratory Equipment: An Overlooked Cybersecurity Risk Industries such as pharmaceuticals, chemicals or agri-food heavily rely on laboratory equipment, especially for quality control, R&#38;D or chemical analysis. These instruments are vital for numerous business processes, many of which are critical for...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/11/protecting-connected-instruments-a-growing-challenge-for-laboratories/">Protecting Connected Instruments: A Growing Challenge for Laboratories</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1>Laboratory Equipment: An Overlooked Cybersecurity Risk</h1>
<p>Industries such as pharmaceuticals, chemicals or agri-food heavily rely on <strong>laboratory equipment</strong>, especially for quality control, R&amp;D or chemical analysis. These instruments are vital for numerous business processes, many of which are critical for operational and regulatory compliance (i.e. in pharmaceutical industries, quality control of raw materials and finished products for batch release, or the production of regulatory reports). As a result, ensuring the <strong>availability </strong>and <strong>reliability </strong>of laboratory equipment is a top priority for these companies. However, these devices—originally designed to operate in isolation—are now<strong> increasingly connected</strong> to improve operational efficiency through automated data collection and harmonized analytical methods across sites.</p>
<p>These operational requirements have driven the widespread adoption of Laboratory Information Management Systems (<strong>LIMS</strong>). In pharmaceutical settings, LIMS manages analytical batch records, monitors quality parameters, and provides full traceability for regulatory audits. In environmental testing, they streamline data collection, validation, and reporting, reducing manual errors. In food safety labs, LIMS automate compliance reporting and trigger alerts when contamination thresholds are exceeded.</p>
<p>Centralizing the management of laboratory equipment data with LIMS requires instruments to be networked, even when this was not initially anticipated by manufacturers. This increased connectivity thus brings <strong>new cybersecurity challenges</strong>, as many laboratory systems are based on outdated technologies and thus potentially increase the attack surface.</p>
<h1>Obsolete Systems: A Growing Security Risk</h1>
<p>Many laboratory devices still run on <strong>proprietary </strong>or<strong> outdated operating systems</strong> (such as Windows XP) that no longer receive security updates. These legacy systems are highly vulnerable to known exploits and are difficult to patch.</p>
<p>Manufacturers rarely release <strong>patches </strong>for <strong>obsolete </strong>equipment, despite the long lifespan of these devices. Once deployed, patching is further complicated by governance issues—specifically, determining who is responsible for applying updates.</p>
<p>Most laboratory instruments also have<strong> limited built-in security features</strong>. They often use <strong>unsecure </strong>or <strong>outdated communication protocols </strong>(such as HTTP, FTP, or SMBv1/v2) and are frequently deployed with poor configuration practices, further weakening their security. Although newer models support secure standards like OPC UA or SFTP, these features are not always enabled or properly configured.</p>
<p><img fetchpriority="high" decoding="async" class=" wp-image-28129 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_1.png" alt="" width="686" height="444" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_1.png 997w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_1-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_1-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_1-768x498.png 768w" sizes="(max-width: 686px) 100vw, 686px" /></p>
<p style="text-align: center;"><em>Figure 1: Typical industrial network architecture in pharmaceutical manufacturing.</em></p>
<p><strong>Identity and access management</strong> is another major challenge in laboratory environments. Many devices still rely on default or shared local accounts and cannot enforce proper authentication mechanisms. These systems are rarely compatible with centralized directories through protocols such as LDAP, making it difficult to enforce consistent security policies across multiple sites. While from an operational perspective authentication may not seem necessary, when combined with obsolete operating systems, insecure communication protocols, and limited access control, these weaknesses turn laboratory devices into easy entry points for cyberattacks.</p>
<p>As laboratories increasingly interconnect their instruments with LIMS, cloud analytics, and centralized data historians, this lack of cybersecurity hygiene not only directly exposes devices but also puts the<strong> broader corporate network</strong> at risk.</p>
<h1>Securing Laboratory Systems with Isolation and Gateways</h1>
<p>When laboratory equipment cannot be secured due to its inherent limitations, <strong>exposure must be minimized</strong> as much as possible. This involves placing such devices behind secured intermediary systems—such as dedicated gateways or workstations—and defining specific network zones to limit the surface of a potential compromise. By segmenting the network and filtering data flows, potential compromises can be better contained and the impact on other critical systems limited.</p>
<p>Three key solutions can enhance security in this context:</p>
<ul>
<li><strong>Workstations equipped with cybersecurity tools</strong> to ensure compatibility between lab equipment and secured networks. This approach works best when modern workstations act as intermediaries, translating data securely and enabling monitoring. In reality, this approach has been the historical way to interconnect laboratory devices to manage them and manipulate their data.</li>
<li>Laboratory equipment <strong>isolation from broader network</strong> environments to limit exposure. This approach extends standard network segmentation practices to laboratory systems, controlling their exposure without fully isolating them, and maintaining necessary data flows for operations. It is cost-effective and easy to deploy, making it ideal for older systems that cannot be patched.</li>
<li><strong>Edge devices for protocol translation and network isolation</strong>. These devices are highly effective for environments needing real-time data exchange between incompatible systems.</li>
</ul>
<p><img decoding="async" class=" wp-image-28131 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_2.png" alt="" width="686" height="444" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_2.png 997w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_2-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_2-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/11/cyberpharma_en_2-768x498.png 768w" sizes="(max-width: 686px) 100vw, 686px" /></p>
<p style="text-align: center;"><em>Figure 2: Pharmaceutical network architecture implemented with laboratory equipment protection measures.</em></p>
<p>While these solutions help secure industrial environments, they also introduce new challenges such as <strong>patch management and equipment ownership </strong>— critical factors in maintaining long-term security. Ultimately, these are responses to an initially unsecured situation, and therefore not perfect: for instance, using workstations as gateways is a good practice, but it requires patching, lifecycle management, and can come with added costs and increased footprint in server rooms (increased infrastructure requirements).</p>
<p>The choice of solution to mitigating cybersecurity risks must align with organization’s technical constraints and operational context. A few common practices help illustrate the diversity of strategies:</p>
<ul>
<li><strong>Laboratory equipment isolation</strong> in a dedicated VLAN remains an effective first step. However, even segmented systems must rely on secure communication protocols to ensure data integrity and prevent unauthorized access.</li>
<li><strong>Edge devices </strong>offer another layer of protection. But they come with their own set of challenges, particularly around organizational ownership, management and maintenance responsibilities.</li>
<li><strong>Workstation equipped with cybersecurity tools</strong> often act as gateways by default, converting data into formats that can be read and processed downstream — whether by LIMS, cloud platforms, or internal databases. This setup is common and secured as long as the workstation is properly managed and hardened to avoid becoming single points of failure or introducing additional attack surfaces. Implementing this intermediary layer is ideal but this requires developing or integrating reliable translation mechanisms, sometimes not handled by the vendor.</li>
</ul>
<h1>Conclusion: Strengthening Cybersecurity in Laboratory Environments</h1>
<p>In given industries, ensuring the integrity of data, quality of final product and the safety of consumers remains one of the priorities. However, as laboratories become<strong> increasingly digitalized </strong>and <strong>interconnected</strong>, new use cases are emerging that challenge traditional architectures and operational models. This evolution demands a more <strong>comprehensive</strong>, <strong>end-to-end approach</strong> <strong>to cybersecurity</strong>—one that integrates <strong>technical safeguards</strong>, <strong>process </strong>maturity, and clear <strong>governance </strong>throughout the laboratory ecosystem.</p>
<p>Implementing a <strong>cybersecurity-by-design</strong> approach throughout the entire project lifecycle is essential—not only to anticipate risks early but also to support business teams in integrating security seamlessly into their operations.</p>
<p>The <strong>Cyber Resilience Act (CRA)</strong> will reinforce the cybersecurity of digital assets within the European Union for manufacturers as well as importers and distributors of such assets.</p>
<p>To go further: <a href="https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/">Cyber Resilience Act: A revolution redefining product security and transforming the ecosystem &#8211; RiskInsight</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/11/protecting-connected-instruments-a-growing-challenge-for-laboratories/">Protecting Connected Instruments: A Growing Challenge for Laboratories</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/11/protecting-connected-instruments-a-growing-challenge-for-laboratories/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The security of the MQTT protocol</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/#respond</comments>
		
		<dc:creator><![CDATA[Emeline LEGRAND]]></dc:creator>
		<pubDate>Wed, 01 Oct 2025 07:37:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=27856</guid>

					<description><![CDATA[<p>“Smart homes”, “Smart devices” and even “Smart cities”: these now familiar expressions illustrate how deeply embedded the Internet of Things (IoT) is in our daily lives. At the heart of these technologies, the MQTT protocol plays a subtle yet essential role....</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/">The security of the MQTT protocol</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><b><span data-contrast="none">“Smart homes”, “Smart devices” and even “Smart cities”: these now familiar expressions illustrate how deeply embedded the Internet of Things (IoT) is in our daily lives. At the heart of these technologies, the MQTT protocol plays a subtle yet essential role. This article presents methods for securing MQTT in response to the growing challenges of IoT.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">In 2024, the number of connected IoT devices worldwide was estimated at around 18 billion, more than double the world&#8217;s population. From connected alarms to smart elevators, industrial sensors, and medical devices, these technologies now shape our daily lives.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">Recent advances in the field of IoT have transformed the way we interact with connected objects. Designed to be intuitive, they are accessible without specific expertise. The connections between them, often wireless, go almost unnoticed by users. However, behind this apparent simplicity lie sophisticated communication protocols, including MQTT. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">Due to its popularity and growing presence in sensitive operations, MQTT has been the subject of research for several years regarding the risks associated with its use. Here, we will focus on how it works, its potential vulnerabilities, and best practices for ensuring secure communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">MQTT and the reasons behind its popularity</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<h2><span data-contrast="none">This protocol’s strengths</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p><span data-contrast="none">Developed in 1999 by Andy Stanford-Clark (IBM) and Arlen Nipper (Arcom), MQTT was designed to provide a</span><b><span data-contrast="none"> lightweight</span></b><span data-contrast="none">, </span><b><span data-contrast="none">efficient</span></b><span data-contrast="none"> solution with </span><b><span data-contrast="none">low energy</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">bandwidth consumption</span></b><span data-contrast="none"> for monitoring isolated oil pipelines in the desert via satellite link.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">It is precisely because of these fundamental properties that MQTT has now established itself as the standard for IoT data transmission. This protocol is also frequently used to upload data from sensors or connected objects to cloud platforms.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img decoding="async" class=" wp-image-27836 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1.png" alt="" width="776" height="364" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1.png 1410w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-768x360.png 768w" sizes="(max-width: 776px) 100vw, 776px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 1 – MQTT key features</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h2><span data-contrast="none">How it operates</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p><strong><i>Definitions of key terms</i> </strong></p>
<p><b><span data-contrast="none">MQTT Client: </span></b><span data-contrast="none">A device that exchanges information.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">MQTT Broker: </span></b><span data-contrast="none">An intermediary entity that allows MQTT clients to communicate and through which all MQTT messages pass. Specifically, the broker receives published messages and distributes them to the relevant recipients (subscribers to the corresponding topic). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">Topic: </span></b><span data-contrast="none">A string of characters used to filter and organize messages according to a hierarchical structure. When a client posts a message, they associate it with a topic. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">Publish/Subscribe:</span></b><span data-contrast="none"> A model derived from the classic client/server model, in which requests are not initiated by a client requesting resources from a server, but by a server regularly sending updates to clients without active solicitation.</span></p>
<p><span data-contrast="none">MQTT is a “Machine to Machine” or M2M communication protocol that operates according to a </span><b><span data-contrast="none">Publish/Subscribe model</span></b><span data-contrast="none">, allowing for great flexibility in its implementation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">MQTT clients can take on the role of</span><b><span data-contrast="none"> publisher</span></b><span data-contrast="none">, </span><b><span data-contrast="none">subscriber</span></b><span data-contrast="none">, or </span><b><span data-contrast="none">both</span></b><span data-contrast="none">. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">To receive the information they need, </span><b><span data-contrast="none">subscribers</span></b><span data-contrast="none"> subscribe to </span><b><span data-contrast="none">topics</span></b><span data-contrast="none"> (1), which are generally organized hierarchically within the broker (e.g., Home/Room/etc.). When a publisher sends a message intended for subscribers to that topic (2), they are notified by the </span><b><span data-contrast="none">broker</span></b><span data-contrast="none"> (3).</span></p>
<p><span data-contrast="none">As a result, MQTT clients are not required to share the same network or be active at the same time, and do not need to be synchronized with each other. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-27838 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361.png" alt="" width="1370" height="398" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361.png 1370w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-437x127.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-768x223.png 768w" sizes="auto, (max-width: 1370px) 100vw, 1370px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 2 – Illustration of a simplified MQTT architecture</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">Moreover, MQTT offers a </span><b><span data-contrast="none">“Quality of Service” mechanism</span></b><span data-contrast="none"> for its messages, allowing communications to be tailored to the requirements of the application. For example, it can guarantee message delivery in the event of an unstable connection. MQTT clients can select one of three QoS levels for the distribution of their messages:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="none">QoS 0</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">At most once » </span></i></b><span data-contrast="none">– The message will be delivered once or not at all, without acknowledgment.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="none">QoS 1</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">At least once » </span></i></b><span data-contrast="none">– The message will be delivered periodically until the sender receives an acknowledgment. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="none">QoS 2</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">Once » </span></i></b><span data-contrast="none">– The message is guaranteed to be delivered once and only once.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p><span data-contrast="none">The chosen QoS level also affects</span><b><span data-contrast="none"> how long the message is stored locally</span></b><span data-contrast="none"> by the sender and recipient. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">This architecture enables </span><b><span data-contrast="none">decentralized</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">scalable communications</span></b><span data-contrast="none">. These features are particularly advantageous in the IoT field, where flexibility is essential to accommodate a wide range of use cases. They also explain why MQTT extends far beyond the IoT and finds applications in many other environments, such as telemetry and industrial monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Is MQTT vulnerable?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">Like many other communication protocols, MQTT is </span><b><span data-contrast="none">not secure by default</span></b><span data-contrast="none">. Although most implementations now incorporate robust security solutions, certain weaknesses and configuration errors persist, leaving systems vulnerable.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">To illustrate these concepts, we will look at a standard example of how this protocol is used in an industrial environment.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27840 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3.png" alt="" width="614" height="545" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3.png 955w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-215x191.png 215w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-44x39.png 44w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-768x681.png 768w" sizes="auto, (max-width: 614px) 100vw, 614px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 3 – Illustration of an example of industrial use of MQTT</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">In this scenario, all systems represented contain an MQTT client that allows users to subscribe to topics and communicate with the on-premise broker. MQTT communications are unencrypted and there is no authentication of the broker or clients, leaving it possible for an attacker to access production data exchanged in clear text or to send commands to equipment by impersonating the broker or one of its clients.</span><span data-ccp-props="{}"> </span></p>
<h1><span data-contrast="none">How can you protect yourself?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">To effectively mitigate these risks, the broker and MQTT clients must be carefully deployed and configured. Here we propose various security measures to ensure confidentiality, integrity, authenticity, and availability of end-to-end communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="4"><span data-contrast="none">Securing the MQTT broker</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<h3><span data-contrast="none">Enabling default encryption for communications</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">When </span><b><span data-contrast="none">port 8883</span></b><span data-contrast="none"> is the only MQTT port defined, unencrypted communication attempts on the broker are rejected. Furthermore, it is essential that the broker has access to a </span><b><span data-contrast="none">valid certificate</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">private key</span></b><span data-contrast="none"> and that t</span><b><span data-contrast="none">he cryptographic suite</span></b><span data-contrast="none"> used is </span><b><span data-contrast="none">secure</span></b><span data-contrast="none"> (e.g., TLS 1.2 or 1.3). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27842 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4.png" alt="" width="701" height="435" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4.png 1036w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-308x191.png 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-63x39.png 63w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-768x477.png 768w" sizes="auto, (max-width: 701px) 100vw, 701px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 4 – Enabling encryption on a Mosquitto MQTT broker via a configuration file</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">Many IoT devices have </span><b><span data-contrast="none">low computing power</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">limited resources</span></b><span data-contrast="none">, so adding mechanisms such as TLS can represent a </span><b><span data-contrast="none">significant overhead</span></b><span data-contrast="none">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Implementation of customer authentication and control of their access rights</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">MQTT allows </span><b><span data-contrast="none">the</span></b> <b><span data-contrast="none">authentication of clients</span></b><span data-contrast="none"> connecting to a broker using common methods such as a username and password (with an associated password file) and </span><b><span data-contrast="none">verification of the client&#8217;s certificate</span></b><span data-contrast="none">, validated by a certification authority (the broker must have the certificate from this authority). Some brokers also allow</span><b><span data-contrast="none"> the use of external authentication solutions</span></b><span data-contrast="none">.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="none">To restrict subscriptions or publications on certain topics by clients, an</span><b><span data-contrast="none"> Access Control List or ACL</span></b><span data-contrast="none"> logic can be added.</span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27844 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5.png" alt="" width="660" height="429" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5.png 1030w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-294x191.png 294w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-768x500.png 768w" sizes="auto, (max-width: 660px) 100vw, 660px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 5 – Addition of a certificate and password authentication with access control on a Mosquitto MQTT broker</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><b><span data-contrast="none">Strict management of topics</span></b><span data-contrast="none"> is essential </span><b><span data-contrast="none">to prevent data leaks</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">limit the risk of compromising</span></b><span data-contrast="none"> the broker. The use of wildcards # and + must be carefully monitored, as an overly permissive configuration would allow an attacker to access all ongoing exchanges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Deployment of broker protection measures   </span><span data-ccp-props="{}"> </span></h3>
<p><span data-contrast="none">A quick search on the Shodan search engine reveals thousands of MQTT brokers exposed on the Internet, often left in their default configuration, whose users are unaware of their existence or implications. It is therefore essential </span><b><span data-contrast="none">to protect the broker from both internal and external threats</span></b><span data-contrast="none"> by applying </span><b><span data-contrast="none">good security practices</span></b><span data-contrast="none">, such as regularly updating the system or restricting the number of simultaneous requests and connections, to prevent denial-of-service attacks and ensure its availability.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="4"><span data-contrast="none">Securing MQTT clients</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<h3><span data-contrast="none">Enabling communication encryption</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">To connect to the broker, clients must use </span><b><span data-contrast="none">port 8883</span></b><span data-contrast="none"> and have a v</span><b><span data-contrast="none">alid certificate </span></b><span data-contrast="none">and </span><b><span data-contrast="none">private key</span></b><span data-contrast="none">, otherwise the connection will be rejected.</span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27846 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6.png" alt="" width="687" height="318" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6.png 1033w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-413x191.png 413w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-768x355.png 768w" sizes="auto, (max-width: 687px) 100vw, 687px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 6 – Encrypted connection on an MQTT Paho client</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">The use of self-signed certificates to connect to the broker is </span><b><span data-contrast="none">strongly discouraged</span></b><span data-contrast="none"> because they can be easily substituted. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Implementation of broker authentication (mutual authentication)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">In addition to client authentication, MQTT supports </span><b><span data-contrast="none">broker authentication</span></b><span data-contrast="none"> by verifying the certificate authority that signed its certificate, thus ensuring </span><b><span data-contrast="none">mutual authentication (mTLS)</span></b><span data-contrast="none"> and secure communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class=" wp-image-27848 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7.png" alt="" width="616" height="277" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7.png 1041w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-425x191.png 425w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-768x345.png 768w" sizes="auto, (max-width: 616px) 100vw, 616px" /></span></p>
<p><i><span data-contrast="none">Figure 7 – Broker authentication on an MQTT Paho client</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h3><span data-contrast="none">Implementation of customer protection measures</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">If an MQTT client is compromised, an attacker could access a significant amount of information depending on the configuration of the targeted broker. This is why clients, and their secrets, must also be protected by </span><b><span data-contrast="none">applying good security practices on the client&#8217;s host machine</span></b><span data-contrast="none"> and on the content of exchanges (e.g., adding anti-replay mechanisms to requests). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">What does the future hold for MQTT?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">Despite its maturity, MQTT remains an evolving protocol and is gradually incorporating innovative features to meet the growing demands of connected environments. In a context where demand for reliable, secure, and low-power communications continues to increase, it is likely that MQTT use cases will continue to multiply in the coming years.</span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/">The security of the MQTT protocol</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Artificial Intelligence, Industrials, and Cyber Risks: What’s the Current State?</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/11/artificial-intelligence-industrials-and-cyber-risks-whats-the-current-state/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/11/artificial-intelligence-industrials-and-cyber-risks-whats-the-current-state/#respond</comments>
		
		<dc:creator><![CDATA[Emeline LEGRAND]]></dc:creator>
		<pubDate>Wed, 20 Nov 2024 12:39:43 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=24655</guid>

					<description><![CDATA[<p>Artificial intelligence (AI) is transforming numerous sectors, including the industrial sector. The latest advancements, particularly those based on Machine Learning (ML) like generative AI, are paving the way for new opportunities in process automation, supply chain optimization, personalization, and so...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/11/artificial-intelligence-industrials-and-cyber-risks-whats-the-current-state/">Artificial Intelligence, Industrials, and Cyber Risks: What’s the Current State?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="auto">Artificial intelligence (AI) is transforming numerous sectors, including the industrial sector. The latest advancements, particularly those based on </span><i><span data-contrast="auto">Machine Learning (ML)</span></i><span data-contrast="auto"> like generative AI, are paving the way for new opportunities in process automation, supply chain optimization, personalization, and so on. These innovations enable companies to increase efficiency, reduce costs, enhance user experience, and foster innovative competitiveness.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, this evolution highlights specific cybersecurity challenges associated with these systems, prompting industrial companies to consider how to secure these applications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">What opportunities does Artificial Intelligence bring? And what are the potential cybersecurity risks that come with it? </span><span data-ccp-props="{}"> </span></p>
<h1>AI &amp; Industry </h1>
<p><span data-contrast="auto">To better understand the range of possibilities offered by these technologies, Wavestone has created the </span><i><span data-contrast="auto">2024 Generative AI Use Case Radar for Operations</span></i><span data-contrast="auto">. This radar lists the usage trends observed among its industrial clients, as well as other potential use cases that may develop in the coming years: </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> <img loading="lazy" decoding="async" class="size-full wp-image-24633 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1.png" alt="" width="1709" height="1039" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1.png 1709w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1-314x191.png 314w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1-768x467.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-1-1536x934.png 1536w" sizes="auto, (max-width: 1709px) 100vw, 1709px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure </span></i><i><span data-contrast="none">1</span></i><i><span data-contrast="none"> – Generative AI use cases Radar for Operations</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Wavestone has identified four types of use cases (decision support, tool and process improvement, document generation, and task assistance) that impact various industrial functions (production, quality, maintenance, inventory management, supply chain, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="size-full wp-image-24635 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2.png" alt="" width="1564" height="824" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2.png 1564w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2-363x191.png 363w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2-768x405.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-2-1536x809.png 1536w" sizes="auto, (max-width: 1564px) 100vw, 1564px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 2 – Main uses of generative AI in industrial operations</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Here are some concrete examples illustrating how these technologies integrate into the operations of various sectors, what they bring, and the potential impacts of cyberattacks on these systems:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="size-full wp-image-24637 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3.png" alt="" width="1872" height="983" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3.png 1872w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3-364x191.png 364w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3-768x403.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-3-1536x807.png 1536w" sizes="auto, (max-width: 1872px) 100vw, 1872px" /></span><i><span data-contrast="none">Figure 3 – Real AI use cases in industrial sector</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">These systems provide significant technological and strategic advantages, as well as considerable financial or time savings.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, integrating these technologies can also introduce new risks that companies must consider.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>AI Cyber Risks </h1>
<h2>How can an attacker compromise these systems? </h2>
<p><span data-contrast="auto">There are several categories of AI-specific attacks, all exploiting vulnerabilities present in different phases of these models’ lifecycle, providing a broad attack surface: </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><i><span data-contrast="none"> <img loading="lazy" decoding="async" class="size-full wp-image-24639 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4.png" alt="" width="1629" height="586" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4.png 1629w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4-437x157.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4-768x276.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-4-1536x553.png 1536w" sizes="auto, (max-width: 1629px) 100vw, 1629px" /></span></i></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 4 – AI lifecycle: possible attacks </span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Most of these attacks aim to divert AI from its intended use. The objectives can include extracting confidential information or making the AI perform unauthorized actions, thereby compromising the security and integrity of the systems.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">To understand these attacks in detail, Wavestone’s experts have illustrated </span><i><span data-contrast="auto">evasion </span></i><span data-contrast="auto">and</span> <i><span data-contrast="auto">oracle </span></i><span data-contrast="auto">methods in this dedicated article</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2>What is the situation regarding these risks for industrial companies? </h2>
<p><span data-contrast="auto">As it stands, the risks associated with AI in the industry vary greatly depending on the sector and its application.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">To carry out </span><i><span data-contrast="auto">oracle</span></i><span data-contrast="auto">, </span><i><span data-contrast="auto">manipulation</span></i><span data-contrast="auto">, and </span><i><span data-contrast="auto">prompt injection</span></i><span data-contrast="auto"> attacks against an AI system, being able to interact with it by providing input data is crucial. This is feasible with some generative AIs, like </span><i><span data-contrast="auto">ChatGPT</span></i><span data-contrast="auto">, which require a user input to start operating. Conversely, other systems, such as those used for </span><i><span data-contrast="auto">predictive maintenance</span></i><span data-contrast="auto"> (AI based solutions that anticipate and prevent equipment failures), do not rely on human instructions to function, making interactions more complex. Moreover, the types of input data for these systems are often very specific, hard to obtain, and manipulate.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><i><span data-contrast="auto">Data poisoning</span></i><span data-contrast="auto"> attacks could be an alternative, as this method does not require interacting with the AI system. However, this would first require infiltrating the information system to gain access to the AI, deeply understanding its architecture, and then attempting to alter its behavior- with no guarantee of success. Moreover, companies with a good level of cybersecurity already have countermeasures and protection methods in place which significantly reduces the chances of such an attack succeeding.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Comparatively, other methods that do not specifically target the AI system can be easier to implement and may provide an attacker with a greater opportunity to cause harm to a company.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, some AI applications, like generative AI assistants, are vulnerable to input-based attacks mentioned above.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Here is an example of an attack scenario on the vaccine production assistant shown in </span><span data-contrast="auto">Figure 3</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3>Context of the use-case </h3>
<p><span data-contrast="auto">Employees write their request to the assistant, attaching the specifications of the vaccine to be produced. The assistant runs the analysis and, using a RAG module (which provides the AI with additional data without retraining), cross-references this information with the company&#8217;s database. Finally, the assistant returns a machine instruction file to employees, which they can use directly to launch production. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3>Attack scenario </h3>
<p style="text-align: center;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img loading="lazy" decoding="async" class="size-full wp-image-24641 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5.png" alt="" width="1767" height="395" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5.png 1767w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5-437x98.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5-71x16.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5-768x172.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/AIIndustry-en-5-1536x343.png 1536w" sizes="auto, (max-width: 1767px) 100vw, 1767px" /> </span><i><span data-contrast="none">Figure 5 – Attack scenario killchain on vaccine production assistant</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:200,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The consequences of a theft of trade secrets such as this could include the resale of this information to competitors or its public disclosure, which could have significant financial and reputational implications. However, conventional access management security measures can help to reduce the risk of this type of attack.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Finally, although some AI applications are vulnerable to new attacks, specific security measures tailored to the weaknesses of each system ensure effective protection.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1>So, what are the points to remember? </h1>
<p><span data-contrast="auto">After all, the risks associated with AI technologies for industrial companies are not fundamentally new.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Although some AI systems are vulnerable to new attacks, the cybersecurity principles for protecting against them and limiting their impact remain unchanged.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">It therefore remains essential to adopt a risk-based approach and integrate </span><i><span data-contrast="auto">cybersecurity by design</span></i><span data-contrast="auto"> for any AI application. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/11/artificial-intelligence-industrials-and-cyber-risks-whats-the-current-state/">Artificial Intelligence, Industrials, and Cyber Risks: What’s the Current State?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/11/artificial-intelligence-industrials-and-cyber-risks-whats-the-current-state/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
