
BY CHRISTIAN DOW, EXECUTIVE VICE PRESIDENT OF INDUSTRY LEADERSHIP, MHI
AS SUJIT MOITRA, vice president of enterprise technology at MHI member Top Hat Engineering, reflects on present‑day cybersecurity, he believes the material handling industry must look beyond traditions. In fact, he stresses that cybersecurity—within modern warehouses and material handling environments alike—extends well beyond conventional IT security.
After all, cybersecurity systems now directly control physical operations, from conveyors, to order fulfillment, to robotics. Thus, cyber risk is no longer just an “information security concern.” Now it’s an “operational safety and business continuity risk,” too.
“A strong cybersecurity program is therefore designed to protect people, physical operations and customer fulfillment outcomes, not just data,” Moitra stressed.
With this in mind, he says that a mature cybersecurity strategy should focus on six core objectives today: operational continuity, asset visibility, access control, segmentation, threat detection and resilience.
When it comes to operational continuity, Moitra advises warehouses to have incident response plans. Above all else, these plans should include manual fallback operations, such as continued picking and shipping. Ransomware and system outage scenarios, robotics and warehouse automation failures, and vendor compromise scenarios should be considered as well.
“These plans will ensure warehouses remain functional even during cyber incidents,” he emphasized.
Asset visibility and control must be a cybersecurity fundamental for material handling facilities, too. A complete inventory of all IT and operational technology (OT) systems—including cloud services, programmable logic controllers (PLCs), robotics, scanners and WMS—has to be maintained.
“Without this, securing the environment is not possible,” Moitra added.
With regard to access control, it’s important to remember that third‑party vendors can be a primary risk vector. Consequently, all access should be approved, logged, monitored and time‑bound. It should also be restricted, via multi‑factor authentication and virtual private networks, and segregated, according to each vendor’s specific role and purpose.
Identity controls will reduce any likelihood of unauthorized access as well, from multi‑factor authentication, to role‑based access control, to privileged access management, which is provided specifically to engineers and vendors.
“This will ensure only authorized users, systems and vendors can interact with operations,” Moitra said.
Network segmentation is also crucial, particularly IT versus OT separation. In Moitra’s opinion, warehouse environments should be segmented into “controlled zones.” For instance, they can be segmented into enterprise IT systems like enterprise resource planning, human resources and emails. In addition, they may be segmented into OT systems, such as conveyors, PLCs and robotics, vendor access zones and warehouse applications (WCS, WES and WMS).
“That will prevent cyber threats from spreading into physical operations,” Moitra explained.
As far as threat detection is concerned, Moitra stresses that warehouses must identify—and then respond to—any potential cybersecurity threats as quickly as possible. Such speed is important not only across their IT layers, but their OT layers, too.
To do so quickly, consistently and successfully, Moitra recommends warehouses to utilize authentication and access logs. API and system activity monitoring should also constantly occur, along with anomaly detection for operational behaviors. Centralized Security Information and Event Management (SIEM) visibility is vital as well.
“Again, security monitoring must span IT and OT environments,” Moitra added.
Finally, another key cybersecurity fundamental, resilience, must not be overlooked either. According to Moitra, backups will enable rapid recoveries whenever cybersecurity threats become actual attacks. The faster a warehouse’s recovery capabilities are, the better off they’ll be during and after a cyberattack, both short and long term.
OT configurations and WMS should be regularly backed up. Offline and immutable backups are also significant, while warehouses should consider having tested recovery procedures, too. Of equal importance, defined recovery objectives like recovery point objective (RPO) and recovery time objective (RTO) are very helpful. Simply put, the more prepared warehouses are, the more resilient they’ll be, regardless of which cyberattacks they may encounter.
While reflecting on cybersecurity fundamentals, Corey Hlavacek, senior director of information security at MHI member enVista, believes multi‑factor authentication (MFA) remains critical, just as it was in the past. However, in order to prevent most cyberattacks these days, it’s typically not enough.
Click here to read the full article.
MHI Solutions Improving Supply Chain Performance
