<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mohammed Ayoub Kara-Ali, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/mohammed-ayoub-kara-ali/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Fri, 13 Sep 2024 09:20:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Mohammed Ayoub Kara-Ali, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyber Resilience Act: A revolution redefining product security and transforming the ecosystem</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/#respond</comments>
		
		<dc:creator><![CDATA[Mohammed Ayoub Kara-Ali]]></dc:creator>
		<pubDate>Wed, 11 Sep 2024 12:20:22 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=23850</guid>

					<description><![CDATA[<p>The Cyber Resilience Act (CRA) represents a significant step forward in ensuring the cybersecurity of products with digital elements within the European Union. As digital products increasingly integrate into every aspect of daily life, ensuring their security becomes paramount. The...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/">Cyber Resilience Act: A revolution redefining product security and transforming the ecosystem</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="auto">The <strong>Cyber Resilience Act (CRA)</strong> represents a significant step forward in ensuring the cybersecurity of products with digital elements within the European Union. As digital products increasingly integrate into every aspect of daily life, ensuring their security becomes paramount.</span> <span data-contrast="auto">The CRA thus represents a </span><b><span data-contrast="auto">steep change in the security of products </span></b><span data-contrast="auto">as the first regulation of this kind worldwide. Wavestone, as a key player in cybersecurity consultancy, is particularly invested in this regulation due to its involvement in the exploratory studies that shaped the CRA.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">In a few words, if you either manufacture, import or resell a product with digital elements, you will surely be affected by the CRA, and need to ensure compliance. This article is intended to shed light on: What does this regulation entail? Who is affected? How can compliance be achieved?</span></b><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<h1><b><span data-contrast="auto">What is the cyber resilience act and what does it entail?  </span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h1>
<p><span data-contrast="auto">To understand the necessity of the Cyber Resilience Act, it&#8217;s crucial to consider the broader context of cybersecurity in Europe. The CRA is an ambitious regulation designed to </span><b><span data-contrast="auto">ensure the security of EU citizens</span></b><span data-contrast="auto"> by addressing the currently observed low levels of cybersecurity in products with digital elements through a European Union policy intervention. In response, comprehensive studies focusing on the cybersecurity of digital products were conducted, leading to the proposal of legislation defining the obligations for the whole products supply chain actors, from manufacturers to distributors.</span><span data-contrast="auto"> </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Wavestone&#8217;s involvement in this process underscores its commitment to enhancing cybersecurity standards. We participated in an </span><b><span data-contrast="auto">in-depth exploratory study commissioned by the EU</span></b><span data-contrast="auto">, engaging with a broad spectrum of stakeholders involved to varying degrees in the products ecosystem, including national authorities, EU bodies, hardware and software manufacturers, trade associations, consumer organizations, researchers, academia, and cybersecurity professionals. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Through Wavestone’s position as a global, and particularly European leader in the field of cybersecurity, several interviews, focus groups and workshops were conducted.  Valuable insights were gathered from a wide range of different interlocutors, providing a comprehensive view that takes into account the perspectives of all stakeholders and allowed the foundation for the development of the CRA.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<h2 aria-level="3"><b><span data-contrast="auto">Definition and Scope</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">The Cyber Resilience Act is a legislative proposal </span><b><span data-contrast="auto">defining the obligations of manufacturers, importers, and distributors of products containing digital elements marketed in the EU</span></b><span data-contrast="auto">, all of which must bear the CE mark across all sectors. As defined in the regulation, this includes “</span><i><span data-contrast="auto">any software or hardware product and its remote data processing solutions, encompassing components that can be marketed separately</span></i><span data-contrast="auto">”. The regulation&#8217;s aim is not only to secure standalone products but also to ensure the security of data transmission chains and central infrastructures through the application of this standard.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">To this notion of product is added a notion of criticality, therefore the CRA differentiates two types of products: </span><b><span data-contrast="auto">products with digital elements</span></b><span data-contrast="auto"> and </span><b><span data-contrast="auto">critical products with digital elements</span></b><span data-contrast="auto">. As detailed below in “Checklist for CRA compliance”, it will affect how compliance can be achieved.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">A few examples of products with digital elements include consumer products, smarts cities and non-essential software. Critical products with digital elements include for example industrial control systems and firewalls. The detailed list of concerned products can be found in the regulation’s annexes.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> <img fetchpriority="high" decoding="async" class=" wp-image-23883 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143800.png" alt="" width="674" height="406" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143800.png 1254w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143800-317x191.png 317w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143800-65x39.png 65w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143800-768x463.png 768w" sizes="(max-width: 674px) 100vw, 674px" /></span><span data-contrast="auto">However, as is detailed below in “A complex ecosystem”, the </span><b><span data-contrast="auto">CRA does not apply universally</span></b><span data-contrast="auto">; products in some specific sectors do not have to comply to the requirements</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<h2 aria-level="3"><b><span data-contrast="auto">Stakeholders and Responsibilities</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">The CRA impacts the entire lifecycle of digital products, from development by </span><b><span data-contrast="auto">manufacturers</span></b><span data-contrast="auto">, </span><b><span data-contrast="auto">importers</span></b><span data-contrast="auto">, </span><b><span data-contrast="auto">distributers</span></b><span data-contrast="auto"> to the final </span><b><span data-contrast="auto">consumer</span></b><span data-contrast="auto">, but also the vulnerability management from conception to the product end-life, through a share responsibility.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> <img decoding="async" class=" wp-image-23885 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143733.png" alt="" width="550" height="340" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143733.png 1214w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143733-309x191.png 309w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143733-63x39.png 63w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143733-768x475.png 768w" sizes="(max-width: 550px) 100vw, 550px" /><br /></span></p>
<h2 aria-level="3"><b><span data-contrast="auto">Essential Requirements</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">As said earlier, the CRA’s objective is to allow a sufficient level of cybersecurity in products with digital elements. To do so, it introduces essential requirements built on three pillars:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:360,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Product Security:</span></b><span data-contrast="auto"> Ensuring products are designed, developed, and manufactured to meet appropriate cybersecurity levels and are free from known exploitable vulnerabilities.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">User Documentation:</span></b><span data-contrast="auto"> Providing documentation to ensure safe use from commissioning to end of life.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Vulnerability Management:</span></b><span data-contrast="auto"> Identifying and documenting vulnerabilities, conducting regular security tests, and implementing a vulnerability disclosure policy.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">In the event of </span><b><span data-contrast="auto">non-compliance with the essential requirements</span></b><span data-contrast="auto">, sanctions may be applied on any of the three stakeholders. Like GDPR, each Member State shall determine the </span><b><span data-contrast="auto">penalties applicable</span></b><span data-contrast="auto"> to infringements of this Regulation. Penalties are based on the company&#8217;s annual turnover and the severity of the infraction, with fines reaching up to 15 million euros or 2.5% of the total worldwide annual turnover for significant breaches. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:360,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<h1 aria-level="2"><b><span data-contrast="auto">How to achieve compliance with the CRA?</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h1>
<h2 aria-level="3"><b><span data-contrast="auto">Timeline of the CRA</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">The CRA has been a long-term project, with almost </span><b><span data-contrast="auto">10 years</span></b><span data-contrast="auto"> from identification of the need to application, reflecting the complexity of establishing comprehensive cybersecurity regulations:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> <img decoding="async" class=" wp-image-23905 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-13-111854.png" alt="" width="751" height="362" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-13-111854.png 1261w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-13-111854-396x191.png 396w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-13-111854-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-13-111854-768x370.png 768w" sizes="(max-width: 751px) 100vw, 751px" /><br /></span></p>
<p><span data-contrast="auto">Businesses have until the 2026 to achieve compliance, with interim obligations. Similar requirements can be found in other regulations, such as NIS2, but contrary to other regulations, the CRA does not need a national transposition. The CRA was passed by the European Parliament in March 2024, and it is awaiting a vote by the European Council to become a law.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<h2 aria-level="3"><b><span data-contrast="auto">A complex ecosystem</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">One of the major concerns raised during the preparation of the Cyber Resilience Act was how to navigate the multitude of existing regulations and </span><b><span data-contrast="auto">achieve regulatory harmony</span></b><span data-contrast="auto">, particularly in sectors where safety, privacy, and cybersecurity standards intersect. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The CRA aims to foster interoperability by aligning with the general product safety framework, the Cyber Security Act&#8217;s requirements for ICT products, processes, and services, and the CE marking standards for European compliance.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">To streamline compliance, the CRA includes</span><b><span data-contrast="auto"> presumptions of conformity</span></b> <b><span data-contrast="auto">with existing regulations</span></b><span data-contrast="auto"> such as the RED Directive, the AI Act, and certain sector-specific rules. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">However, the </span><b><span data-contrast="auto">CRA does not apply universally</span></b><span data-contrast="auto">; some sectors, such as medical, aviation, and automotive, are already governed by established regulations and are thus exempt from the CRA&#8217;s provisions.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-23881 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143818.png" alt="" width="1410" height="677" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143818.png 1410w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143818-398x191.png 398w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143818-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-143818-768x369.png 768w" sizes="auto, (max-width: 1410px) 100vw, 1410px" /></p>
<h2><b><span data-contrast="auto">Checklist for CRA compliance</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:259}"> </span></h2>
<p><span data-contrast="auto">Compliance with the CRA involves a thorough understanding of the regulation&#8217;s core text and two annexes, which detail: the list of concerned products, essential requirements, the obligations for manufacturers, importers, and distributors and national competent authorities and sanctions. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">The certification process varies based on product criticality:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">For non-critical products</span></b><span data-contrast="auto"> : a self-assessment is necessary</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">For critical products</span></b><span data-contrast="auto"> </span><span data-contrast="auto"> : third-party assessment is necessary, meaning the product compliance to the CRA will be assessed by a certified entity. At the time of writing this article, the exact certification schemes have yet to be specified but in France, the CESTI certification is in discussion. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Five main checkpoints</span></b><span data-contrast="auto"> are to be considered to achieve compliance: </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-23853 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-140243.png" alt="" width="1298" height="376" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-140243.png 1298w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-140243-437x127.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-140243-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Capture-decran-2024-09-11-140243-768x222.png 768w" sizes="auto, (max-width: 1298px) 100vw, 1298px" /></p>
<ol>
<li><b><span data-contrast="auto">Legislative Gap Analysis:</span></b><span data-contrast="auto"> Identify discrepancies between current practices and the requirements of the CRA by reviewing existing cybersecurity policies, processes, and controls to pinpoint areas needing improvement.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="%1." data-font="" data-listid="25" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:768,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Product Security Assessment:</span></b><span data-contrast="auto"> Conduct thorough assessments to ensure product identification and security. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">User Instructions Update:</span></b><span data-contrast="auto"> Provide clear and comprehensive user documentation by ensuring that all products are accompanied by documentation in adequation with the regulation standards.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li data-leveltext="%1." data-font="" data-listid="25" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:768,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">Vulnerability Management:</span></b><span data-contrast="auto"> Set up a process for identifying and sharing vulnerabilities.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Internal Organization Review:</span></b><span data-contrast="auto"> Implement a permanent procedure to ensure compliance, covering the above-mentioned key points and enforce a watch on product or legislation changes that may imply new gaps to remediate</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:240}">.</span></li>
</ol>
<p><span data-contrast="auto">In conclusion, the Cyber Resilience Act represents a comprehensive framework to enhance the cybersecurity of digital products within the EU. Compliance with this legislation requires thorough preparation.</span> <span data-contrast="auto">For businesses, adhering to the CRA is not just a legal obligation but also an </span><b><span data-contrast="auto">opportunity to enhance their standing in a market</span></b><span data-contrast="auto"> increasingly aware of cybersecurity issues. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:720,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/">Cyber Resilience Act: A revolution redefining product security and transforming the ecosystem</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/09/cyber-resilience-act-a-revolution-redefining-product-security-and-transforming-the-ecosystem/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PLC network: the history of industrial systems  facing up to the challenges of the future</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/02/plc-network-the-history-of-industrial-systems-facing-up-to-the-challenges-of-the-future/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/02/plc-network-the-history-of-industrial-systems-facing-up-to-the-challenges-of-the-future/#respond</comments>
		
		<dc:creator><![CDATA[Mohammed Ayoub Kara-Ali]]></dc:creator>
		<pubDate>Tue, 27 Feb 2024 08:56:47 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=22588</guid>

					<description><![CDATA[<p>Introduction Industrial systems are a category of information systems of their own, with codes and properties that differ from &#8220;classic&#8221; IT systems. It is well known that the level of maturity of the industrial sector in terms of cybersecurity is...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/02/plc-network-the-history-of-industrial-systems-facing-up-to-the-challenges-of-the-future/">PLC network: the history of industrial systems  facing up to the challenges of the future</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1>Introduction</h1>
<p>Industrial systems are a category of information systems of their own, with codes and properties that differ from &#8220;classic&#8221; IT systems. It is well known that the level of maturity of the industrial sector in terms of cybersecurity is generally lagging in comparison with what is done in IT systems. This delay can be explained by several factors, one of which being the historical legacy of industrial systems that sometimes are in place since several decades. This article will focus on one of these historical aspects which can be found in many industrial networks today: which are known as<strong> &#8216;PLC&#8217; or &#8216;field&#8217; networks</strong>. We will first look at the history that led to the existence of these networks, then examine the strengths and weaknesses of the model with respect to current and future cybersecurity needs, to answer the following question: <strong>Are field networks adapted to new cyber security needs?</strong></p>
<p> </p>
<h1>History</h1>
<p>Let&#8217;s go back in time: we are not going to talk about the different industrial revolutions, but our story begins at the start of the 70s. At the time, there was no Ethernet network, OSI model or even IT. Industrial production systems relied on physical mechanisms using <strong>pneumatic</strong> or <strong>electrical signals</strong>. The 1970s saw the arrival of the first principles of automation, and the integration of the first intelligent equipment: <strong>the programmable logic controllers (PLC)</strong>. This equipment allows resources to be pooled, as a PLC can manage several electrical inputs and outputs, and therefore centralise the management of processes. PLCs also incorporates communications modules, and this led to the appearance of<strong> the firsts bus networks </strong>in industrial systems, using <strong>serial communications protocols</strong>.</p>
<p>This architecture model will continue to develop in the 80s with the increase of industrial protocols, based on <strong>the &#8220;Controller-Workers&#8221; model</strong>: A main PLC contains the centralised database and plays the role of an orchestrator by being linked to the &#8220;Workers&#8221;, corresponding to other PLCs, remote input/output cards, etc&#8230; This architecture simplifies process programming at a single point, as well as communication with supervisory devices such as the man-machine interface or proprietary SCADA.</p>
<p>The 1990s brought <strong>the </strong><strong>democratisation</strong><strong> of the TCP/IP model</strong> and the integration of &#8216;traditional&#8217; IT into industrial environments: no more need for proprietary equipment, SCADA software can now be installed on conventional systems&#8230; but these computers still need to be able to communicate with the PLCs! Serial network cards exist, but industrial protocols are beginning to adapt to operate on a conventional Ethernet network. Master controllers are gradually being replaced to enable them to use TCP/IP protocols on the main network, while continuing to have serial network cards for field equipment. Then it was the turn of field equipment to adapt to the standardisation of TCP/IP use everywhere, so that today the use of serial communications is minimal. Even electrical inputs/outputs are now tending to be replaced by IP links on sensors and actuators, via the use of &#8220;Single Pair Ethernet&#8221; connectors, for example, which provide a low-cost and space-saving connection.</p>
<p style="text-align: center;"><em><img loading="lazy" decoding="async" class="alignnone  wp-image-22589" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1.png" alt="" width="601" height="358" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1.png 1572w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1-321x191.png 321w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1-768x457.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN1-1536x914.png 1536w" sizes="auto, (max-width: 601px) 100vw, 601px" /><br />Evolution of field architectures</em></p>
<p>As a result, the following architecture is now commonplace: <strong>A &#8220;main&#8221; industrial physical network</strong> (in star or ring topology) containing all the supervision and external communications equipment (SCADA, Data Historian, operator station, etc.) as well as the PLC controllers, each of which has a second network port. This second network port makes it possible to create an isolated sub-network on each PLC on which the equipment closest to the physical process is located. The PLC controller then acts as a &#8220;functional pivot&#8221;, exchanging data with the SCADA system on the one hand, and with field equipment via the PLC&#8217;s data registers on the other. This architecture can be adapted in several ways, for example, by replacing the pivot PLC with a server, or by combining several layers of isolated networks with a SCADA server having two network ports, separating the main industrial network and the supervision network in which the controller PLCs are found, on which a new separation is made with field networks.</p>
<p style="text-align: center;"><em><img loading="lazy" decoding="async" class="alignnone  wp-image-22591" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2.png" alt="" width="600" height="380" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2.png 1559w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2-301x191.png 301w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2-768x487.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN2-1536x973.png 1536w" sizes="auto, (max-width: 600px) 100vw, 600px" /><br />Example of industrial architecture integrating field networks</em></p>
<p>Now that we&#8217;ve looked at the past, let&#8217;s talk about the present, and in particular the three evolutions that are leading us to question the relevance of this architectural model today:</p>
<ul>
<li><strong>Industry 4.0</strong>, which has changed the face of industrial networks, moving from an isolated model to an ultra-connected model to meet the challenges of Big Data, interconnection with the Cloud, the digital twin, etc&#8230;</li>
<li><strong>The </strong><strong>standardisation</strong><strong> of industrial technologies</strong>, enabling us to move away from industrial suppliers, via the development of &#8220;Soft PLCs&#8221; on Linux or onboard Windows, or the use of standardised industrial protocols such as OPC-UA.</li>
<li><strong>The introduction of cybersecurity solutions </strong>at the core of the industrial network, such as update servers, firewalls, antivirus and even EDR or network probes, whose presence makes sense with the modernisation of IT infrastructures and the development of cybersecurity in the industrial environment.</li>
</ul>
<p>To study the relevance of field networks in the light of these new challenges, we are going to look at four operational security issues: network security, remote access, update management, and detection and mapping.</p>
<p> </p>
<h1>Network security</h1>
<p>The first question to ask is simple: What are the advantages of field networks from a cyber security point of view? This advantage is reflected in the very principle of the architecture model: the use of pivot equipment provides physical isolation between an industrial network and a field network. In principle, therefore, it is not possible for the two networks to communicate directly, as information is transmitted via a database (registers for PLCs, OPC database for a server, etc.). There is no need for a firewall or diode: no flow can go from one network to another, which is the best way of protecting against propagation to field equipment.</p>
<p><strong>But is this separation, made using a physical equipment not dedicated to the network, foolproof? </strong>On equipment operating on a &#8216;classic&#8217; Windows or standard Linux system, the answer is no. There are many examples of attacks that convert these systems into pivots, exploiting the many possibilities offered: exploitation of remote access protocols such as RDP, VNC or SSH, RAT, C2C implants, etc. As a result, a separation with this type of system will slow down an attacker but does not significantly reduce the possibilities of reaching field networks that would exist on other network cards.</p>
<p>In the case of a &#8220;classic&#8221; PLC, this is usually a piece of equipment running on a proprietary operating system that offers few functions: at the very least it can run industrial programs and communicate with one or more industrial protocols and can optionally contain more traditional HTTP or FTP type servers. The equipment therefore offers far fewer functions than a computer or server and is not designed to provide gateways between its various network cards&#8230; or so we tend to think. However, it has been shown that it is possible to <strong>create gateways</strong> between the various network ports of a PLC: via research work such as that by Nicolas Delhaye and Flavian Dola presented at GreHack 2020 (the video <a href="https://www.youtube.com/watch?v=PfdoaxYkmUE"><u>here</u></a>), but more concretely via <strong>the Pipedream malware</strong> discovered in 2022. This malware enables network routes to be created on Schneider PLCs, transforming them into proxies and giving them the ability to route any protocol to field networks.</p>
<p style="text-align: center;"><em><img loading="lazy" decoding="async" class="alignnone  wp-image-22593" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3.png" alt="" width="671" height="227" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3.png 1892w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3-437x148.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3-71x24.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3-768x259.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN3-1536x519.png 1536w" sizes="auto, (max-width: 671px) 100vw, 671px" /><br />Illustration of how the Pipedream module targeting Schneider equipment works.</em></p>
<p>We have therefore proved that, even in the case of separation by a PLC, the model is not infallible, but it still makes it possible to greatly reduce the risks by only exposing the field networks to very advanced attacks.</p>
<p> </p>
<h1>Mapping and supervision</h1>
<p>Following the previous paragraph, a question naturally comes up: how do you supervise a network whose strong point is its isolation? Firstly, about logging, <strong>the current observation is that PLCs and industrial equipment are still very rarely included in security supervision perimeters</strong>: for technical reasons, as not all equipment is necessarily capable of sending back syslog-type logs, but also for organisational reasons, as SOC teams still lack the maturity to make proper use of event logs from this type of industrial equipment.</p>
<p>To overcome this lack of visibility, industrial environments are becoming increasingly subject to the installation of a network probe, enabling supervision and mapping requirements to be met. In particular, systems falling within the scope of the French Military Programming Laware required to install an ANSSI-qualified detection probe. Technically, it is possible to make isolated networks communicate with a probe by using network TAPs, whose function is to passively copy network traffic so that it can be listened in on. Strategically, field networks are rarely the place to monitor the network side. Priority should be given to interconnection points with other networks (company, supplier, etc.) or critical control equipment such as SCADA.</p>
<p style="text-align: center;"><em> <img loading="lazy" decoding="async" class="alignnone  wp-image-22595" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4.png" alt="" width="600" height="313" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4.png 1706w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4-366x191.png 366w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4-768x401.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/EN4-1536x801.png 1536w" sizes="auto, (max-width: 600px) 100vw, 600px" /><br />Example of a supervision architecture integrating field networks </em></p>
<p>However, the TAPs solution is not applicable to &#8220;active&#8221; probes, which seek to map by questioning the various devices on the network. But this type of solution is rarely implemented in an industrial context, to avoid &#8216;stressing&#8217; the network and the equipment.</p>
<p>The field network model therefore remains compatible by focusing on network supervision with the installation of probes for detection, as well as passive mapping. The feedback of system logs from PLCs and industrial equipment is still not sufficiently relevant to the analysis capabilities of SOCs.</p>
<p> </p>
<h1>Update</h1>
<p>To be able to make updates, it is necessary to have a network interconnection with a system allowing these updates to be sent to endpoints, which is opposed to the isolation of field networks. Does the need for updates in an industrial environment make the field network model obsolete?</p>
<p>Maintaining security is a complex issue when it comes to industrial systems: the high level of availability prevents any major intervention, systems that are isolated from the Internet mean that updates cannot be downloaded over the network, etc. In the case of networks made up mainly of PLCs, update mechanisms have evolved to take account of these constraints, with the result that today the number of PLCs kept up to date is very small (even on an annual basis), and these updates are mainly deployed manually by maintenance staff. The use of field networks to partition the architecture does not prevent these same mechanisms from being applied to PLCs.</p>
<p>On the other hand, the integration of IT technologies is changing the rules: one of the first security solutions recommended for a Windows installation is to set up a WSUS server to centralise the deployment of updates, and the same principle is also applicable to Linux technologies. This brings us to a new constraint for field networks with equipment such as Soft-PLCs or dedicated operator PCs: <strong>partitioning by dual network cards prevents centralised management of updates</strong>, forcing the implementation of a manual patching process that can be complex and time-consuming for many devices.</p>
<p>However, this constraint must be evaluated in relation to the need. The main argument in favour of updates is that they enable vulnerabilities to be corrected that increase the attack surface of an equipment. As the field network model strongly isolates systems, their attack surface is already greatly reduced. It is therefore acceptable for systems not to be constantly updated, and in this case a manual annual update of the equipment meets the need.</p>
<p>However, this model is not suited to the need for antivirus software to be constantly updated to guarantee optimum protection. This is why it is necessary in this case to rely on systems that move very little over time, which makes it easier to use whitelisted application filtering solutions such as AppLocker or WDAC (see <a href="https://www.riskinsight-wavestone.com/en/2023/12/application-control-what-strategy-you-should-adopt-for-your-industrial-supervision-system/"><u>our article on application filtering</u></a>).</p>
<p>Finally, updating practices in industrial environments have adapted to the very principle of network isolation, enabling these needs to be reduced. These practices do, however, require equipment to be hardened when installed, and solutions to be put in place to maintain system security levels with a minimum of maintenance.</p>
<p> </p>
<h1>Remote access</h1>
<p>Having looked at &#8220;automated&#8221; update flows, what about flows initiated by a user to access remote equipment for business or maintenance operations? For PLCs, such access is rare: they do not need human intervention to perform their tasks, and in the case of internal maintenance, this is often carried out by accessing the PLC from the network on which it is located (dedicated administration networks for PLCs are still very rare). If the PLC is accessible from the main production network, maintenance can be centralised from a single connection point. On the other hand, since field networks are isolated from the production network, the PLCs located there can be accessed by connecting the maintenance laptop to the &#8216;right&#8217; switch, interconnecting the various items of equipment on the sub-network, or even directly to the PLC&#8217;s USB port with a serial link.</p>
<p>On the other hand, there are limits when it comes to field networks with equipment maintained by a supplier or maintenance service provider. This is because remote maintenance has become the preferred method, and it is quite rare these days to have third-party maintenance staff available to physically visit the site at any time. The most common solution to this problem is to install a VPN termination directly on a field network, with a tunnel connected to the service provider. This effectively addresses the problem, but also bypasses the whole principle of isolating field networks, which are then exposed in the event of the service provider being compromised.</p>
<p><strong>This is where we reach the biggest limitation of the field network model</strong>, reinforced by the trend towards centralising remote access and installing bastion-type solutions that cannot cover access to field networks due to their isolation.</p>
<p> </p>
<h1>Conclusion</h1>
<p>The existence of field networks is mainly historical, due to the old controller/worker architecture models and the gradual introduction of the TCP/IP model in industrial networks. These architectural models have adapted to the life cycle of systems: they are accessed very little by users and are designed to operate autonomously by sending data back to the controller.</p>
<p><strong>Partitioning is the main strength of field networks</strong>: transforming a PLC in a rebound equipment to two different network interfaces is a highly advanced attack technique. To detect possible attacks, solutions exist for setting up supervision on isolated networks, in particular with TAPs.</p>
<p>The other advantage of network isolation is <strong>that it reduces the effort required to maintain security</strong>. The need to update isolated equipment is not necessarily the same as for equipment used by humans and interacting with third-party networks. Since isolated equipment has a lifecycle with few changes, <strong>the focus should be on hardening when it is brought into service</strong>.</p>
<p><strong>However, the isolation of these networks poses several problems in terms of remote access</strong>: it is possible to limit this when the industrial estate is managed internally, but it is essential when a service provider needs to intervene remotely. To avoid local initiatives or third-party solutions, it is advisable to implement a controlled remote access solution (VPN, bastion, etc.), with the accessed equipment placed on a dedicated sub-network with a filtered and controlled entry point.</p>
<p>In conclusion<strong>, the field network model is still relevant today</strong>. However, <strong>recent trends, particularly those linked to Industry 4.0, will raise new issues</strong>: the emergence of Industrial IOTs, involving the implementation of IoT network buses interconnected with the outside world, calls into question the relevance of having isolated IP networks cohabiting with more exposed IoT buses.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h5>Source</h5>
<p>Dragos Analyzing PIPEDREAM: Results from Runtime Testing<br /><a href="https://www.dragos.com/blog/analyzing-pipedream-results-from-runtime-testing/">https://www.dragos.com/blog/analyzing-pipedream-results-from-runtime-testing/</a></p>
<p>GreHack 2020: A full chained exploit from IT network to PLC’s unconstrained code execution<br /><a href="https://www.youtube.com/watch?v=PfdoaxYkmUE">https://www.youtube.com/watch?v=PfdoaxYkmUE</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/02/plc-network-the-history-of-industrial-systems-facing-up-to-the-challenges-of-the-future/">PLC network: the history of industrial systems  facing up to the challenges of the future</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/02/plc-network-the-history-of-industrial-systems-facing-up-to-the-challenges-of-the-future/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
