Better protect connected packaging lines from cyberattacks
Within the Engineering of the Future Club, GEPPIA member manufacturers of process and packaging machinery, their suppliers, and industrial end-users are working together to build concrete solutions for the Factory of the Future. They discuss topics such as connectivity, interoperability, the use of production data, and predictive maintenance. These subjects share a common thread: the convergence of OT and IT in the management and monitoring of production tools.
Cybersecurity naturally became a topic of discussion. It must be said that the subject lends itself particularly well to collective reflection. The digitalization of factories creates increasingly extensive cyber-physical production systems (CPPS) involving a significant number of stakeholders.
The diversity of implemented programs and the proliferation of connection points contribute to the vulnerability of these systems. Therefore, consultation appears essential to ensure consistency in the security approach and simplify the task for end-users.
Towards "secure by design" packaging lines?
To smoothly take the step towards digitizing their production lines, industrial end-users need solutions designed for a connected environment.
They therefore encourage machine manufacturers to design their equipment in accordance with the best practices promoted by government bodies such as ANSSI, ENISA or CISA.
Four of them would already significantly improve the intrinsic resistance of production lines to cyberattacks:
- A clear separation between the field network and the factory network. Segmentation remains one of the best ways to protect against cyberattacks or limit their consequences.
- Updating the operating systems on operator terminals. These operating systems must be patchable when a vulnerability is detected, and the update must be easily performed by the end-user. This is to optimize IT maintenance across the plant.
- Securing the processes for updating the machines' source code. The update operation must not be usable for injecting malicious code.
- Strengthening authentication procedures and access rights management.
Xavier Texier – Head of Automation and OT at Groupe Savencia,
Member of the Engineering of the Future Club
"The COVID-19 epidemic reminded us how vital the agri-food industry is: our factories must remain operational even in times of crisis. However, a cyberattack can force us to stop production for several days.".
Cybersecurity is all the more essential because, like all industries, we tend to increase the exchanges between OT and IT systems. We need to collect field data to use it in analysis and management software.
What I expect today from machine builders and automation manufacturers is that they offer me solutions that fully integrate into our IT infrastructure, and that can interact as efficiently as possible with our IT world, whether it be our ERP, our LIMS or our CMMS.
And I think they need to rely on the following for this:
- the best cybersecurity practices recommended in the IFS standard (Food Defense, Chapter 6) and the guidelines adopted by the European Cybersecurity Act,
- shared international standards, such as the ISA-TR 88 standard.
Furthermore, we do not want to be locked into a technology; the use of proprietary systems becomes an eliminatory criterion in our selection process.
We also want open systems; that's where the use of OPC-UA makes perfect sense
Cybersecurity open to innovation
The main players in the packaging ecosystem favour a pragmatic and positive co-construction approach, in line with the vision defended by ANSSI at the 2019 security conference. They have chosen to share their expertise in order to define clear common guidelines, on which everyone can rely at their level.
In doing so, industrial end-users should eventually have access to a much broader catalog of secure solutions, preventing excessive standardization that could potentially stifle innovation. This is a real advantage for the food and pharmaceutical industries, which are torn between the need to innovate and the absolute necessity of protecting themselves from malicious actions to ensure consumer safety.