INDUSTRIAL INTERNET OF THINGS VULNERABILITIES AND THREATS: WHAT STAKEHOLDERS NEED TO CONSIDER
The Industrial Internet of Things, or IIoT, introduces Internet-enabled devices into industrial process systems operating in the energy, transportation, healthcare, utilities, cities, agriculture, and other critical infrastructure sectors, establishing linkages between previously-air gapped information technology (IT) and operational technology (OT) networks. While the introduction of these Internet-enabled devices creates new efficiencies, improves performance, increases productivity, and increases profitability, it also introduces new security challenges and risks. IIoT is a system of systems; the architecture of a single IIoT system consists of different layers, with each layer performing a distinct function, having unique operational characteristics, and relying upon different devices and communication protocols than other layers of the system. Because of the unique characteristics of these various layers and functions, the vulnerabilities and threats associated with them also differ. Many internal stakeholders are involved in the conceptualization, planning and implementation of an organization's adoption of IIoT; while some may be experienced and knowledgeable technologists, others are not. Regardless of one's technical knowledge, recognition of the potentially-catastrophic consequences of successful exploitation of those vulnerabilities necessitate at least some familiarity with security vulnerabilities and threats associated with the various IIoT layers and sub-systems. The purpose of this article is to identify for IIoT stakeholders some of the vulnerabilities and threats associated with various layers and functions of an IIoT architecture and illuminate the need for a comprehensive, systematic, and layer-appropriate approach to IIoT security.
