• ISA provides technical resources and standards to help industrial automation professionals advance their careers and the field. We enable automation professionals worldwide to solve problems and enhance their skills by bringing people together to create new technologies and share best practices with future automation professionals.
    • Industry Insights

  • We attract over 140,000 unique automation professionals monthly, making us the premier online content provider and the only dedicated electronic magazine in the automation industry.

    Monthly Magazine

    • More things to read

    Back
    Back
  • M logo for Automation.com Monthly. Link to current issue.

Search

Current Filters Clear

Refine Results

Content Type

Topics

  • Digital Transformation
  • Industrial Automation and Control
  • Industrial Data and Connectivity
  • Industrial Safety
  • Industrial Security
  • Operations Management

Industry

59,203 Results Found
  • Thumbnail for ISA Vision 2020: Can you see the duck?

    ISA Vision 2020: Can you see the duck?

    ISA Vision 2020: Can you see the duck?
    By: ISA Past-Presidents
    10 July, 2014 | 11 minutes
  • How to Link HAZOP and LOPA to Calculate a Safety Instrumented System

    Plant owners, operating staff & control systems specialists develop the credible performance requirement for the safety instrumented system.
    By: Contributing Authors
    23 October, 2017 | 5 minutes
  • Thumbnail for Where Do Humans Fit in the Factory of the Future?

    Where Do Humans Fit in the Factory of the Future?

    As technology grows in sophistication and complexity, it is vital to define new and improved skills, knowledge, and experiences.
    By: Contributing Authors
    19 September, 2016 | 3 minutes
  • Thumbnail for Applying Mechanical Integrity and Inspections to Asset Performance Management

    Applying Mechanical Integrity and Inspections to Asset Performance Management

    Promote process equipment mechanical integrity and risk mitigation using risk-based strategies for asset performance management.
    By: Contributing Authors
    11 January, 2016 | 8 minutes
  • Thumbnail for Response to Automation Industry Problem: React or Positively Act?

    Response to Automation Industry Problem: React or Positively Act?

    It is not important how you react to automation industry problems, issues, and challenges, but how you positively act.
    By: Bill Lydon
    04 April, 2016 | 2 minutes
  • Thumbnail for AutoQuiz: Best Strategy for Finding Efficient Operating Points with Complex Shifting Process Conditions

    AutoQuiz: Best Strategy for Finding Efficient Operating Points with Complex Shifting Process Conditions

    Real-time optimization with a detailed process model is the best approach to fining the most efficient operating points.
    By: Joel Don
    12 May, 2017 | 1 minute
  • Thumbnail for Is the Internet of Things Creating Unfocused Urgency to Monitor Everything?

    Is the Internet of Things Creating Unfocused Urgency to Monitor Everything?

    The hyper-focus on IoT is creating an unfocused urgency monitor everything, which could lead to over instrumenting automation systems & creating data noise.
    By: Bill Lydon
    11 January, 2017 | 2 minutes
  • Thumbnail for Manufacturers Must Reduce Risk of Upstream and Downstream Supply Chain Attacks

    Manufacturers Must Reduce Risk of Upstream and Downstream Supply Chain Attacks

    Supply chain disruptions are among the most pressing issues for today’s manufacturers. While geopolitical tension and events like the COVID-19 pandemic have taken the spotlight in this area, another risk factor — cybersecurity — deserves attention, too. Upstream and downstream supply chain attacks pose serious risks to manufacturers and their partners. As manufacturers embrace Industry 4.0 technologies, their cyber vulnerabilities throughout the supply chain rise. Many organizations now realize the need to address these risks, but fewer understand that an interconnected supply chain means shared weaknesses between parties. The Importance of Supply Chain Cybersecurity Manufacturing experienced the most cyberattacks of any sector in 2022. One of the primary reasons manufacturers are such popular targets is because their attack surfaces are massive. In addition to a skyrocketing number of internet-connected devices, they have extensive third-party dependencies, opening them to supply chain attacks. Supply chains have digitized to increase efficiency and reliability, and parties share vast amounts of data. A manufacturer’s upstream suppliers, 3PLs and downstream partners may all have access to their systems and sensitive data. Consequently, an attack on one entity in the supply chain can affect everyone involved. One such attack in 2022 led an automaker to fall 13,000 vehicles behind production targets despite not targeting the manufacturer directly. Instead, it hit a parts supplier, leading to a network shutdown at its facility. As a result, the supplier couldn’t fulfill orders or communicate with its downstream customers. Other attacks could target a software provider to steal sensitive customer information from manufacturing partners. If a breach from a downstream supply chain partner reveals enough personal information about a manufacturer’s customers, it could also land them in legal trouble. These situations will become more likely as cybercriminals realize how much disruption they can cause through one attack. How to Reduce the Risk of Supply Chain Attacks Given how severe supply chain attacks can be, manufacturers must prevent them whenever they can and mitigate them when they can’t. Here are some strategies to reduce the risks of upstream and downstream attacks. Conduct a Risk Assessment Supply chains are large and complex, so it can be challenging to know your weak points. Consequently, performing a cyber-risk assessment is essential to reveal what makes your chain vulnerable and how you can address it. Third-party risk assessments should involve network mapping to show dependencies and penetration testing to judge the strength of existing cybersecurity measures. These services incur extra expenses but save money in the long term by preventing costly attacks. The average cost of a data breach in the U.S. reached $9.44 million in 2022, so the upfront cost is well worth the investment. You can’t defend what you don’t know is vulnerable, and that’s precisely what a risk assessment reveals. These tests should look at a manufacturer’s internal controls and processes and those of their upstream and downstream partners. Many organizations likely give too much access and information to too many parties. Thorough assessments bring these to light to inform more effective changes. Hold Supply Chain Partners to a Higher Standard Manufacturers should require more from their upstream and downstream partners. Just as some companies only work with those who meet certain ESG criteria, manufacturers should require proof of high security standards before working with anyone. This selection begins with researching potential partners’ security backgrounds before reaching out. Any business that has experienced a major breach or handled a cybersecurity incident poorly is a liability. You should also look for third-party security standards like ISO 27002 or NIST SP 800-53 certification. It’s important to remember that you can’t reasonably ask for something you don’t achieve on your own end. Manufacturers also should pursue cybersecurity certifications to offer assurance that they won’t jeopardize partners’ data either. Minimize Access Privileges Even if everyone in the supply chain meets higher security standards, attacks are still possible. No defense is 100% secure, and even the most experienced employees can still make mistakes that let attackers in. Given these risks, manufacturers must restrict who can access what data. The safest solution is to implement the principle of least privilege. This holds that every user, app and device should only be able to access the data and systems it needs to do its job. This may seem like limiting visibility at first, but it ensures one breach at any point in the network can’t jeopardize all your data. Minimizing access privileges is also an important way to stop insider threats. Over half of all organizations have experienced one in the last year, so preventing internal breaches is crucial. These are usually a matter of human error rather than malicious employees, but the effect is the same. Implement Continuous Monitoring Many technical controls necessary to stop supply chain attacks vary depending on the specific technology in use. However, some are essential in every situation. That’s the case with continuous monitoring. Continuous monitoring uses artificial intelligence (AI) to watch for suspicious activity across company devices and networks. If something off occurs — such as unusually large file transfers or a user trying to access a database they don’t normally need — the AI stops it and alerts IT staff. These quick responses are crucial for preventing internal and external breaches. Using AI also removes the need for a dedicated security operations team and enables faster, more accurate warnings. Create a Backup and Recovery Plan Even if every party in the supply chain implements these other steps, breaches are still possible. Despite rising awareness around cybersecurity, 68% of all organizations have experienced a cyberattack in the past year. These occurrences are too common to assume they’ll never happen to you, so you need a backup plan. Manufacturers must keep backups of all sensitive data and mission-critical systems, both offline and in the cloud. Every organization in the supply chain also needs a formal process for using these backups to recover from a breach. That plan should include communicating the breach to affected parties and several mitigation measures. Supply chain organizations should review these plans annually to ensure they’re still relevant and effective. Repeated risk assessments can also help by revealing any new vulnerabilities to address. Supply Chain Attacks Demand Attention Supply chain attacks can be devastating and happen in any part of the process. While digitization is important, cybersecurity improvements must be part of manufacturers’ initiatives to address the resulting vulnerabilities. Effectively mitigating these threats requires cooperation among all a manufacturer’s partners. These broad shifts can be challenging but are far less costly and disruptive than a successful attack. Security is always worth the effort.
    By: Emily Newton
    12 September, 2023 | 4 minutes
  • How to Test and Validate a Pipeline Leak Detection System

    Pipeline leak detection testing provides the assessment of how a system can work, how it’s working now, the tools for analyzing unusual occurrences, and a vehicle for training and testing operators.
    By: Edward J. Farmer
    10 October, 2018 | 5 minutes
  • Thumbnail for ISA Training and Education Programs in April

    ISA Training and Education Programs in April

    ISA's training and education opportunities in April 2016.
    By: Joel Don
    14 March, 2016 | 13 minutes
  • Thumbnail for AutoQuiz: Which Signal Type Indicates Direction and Velocity in a Motion Control Application?

    AutoQuiz: Which Signal Type Indicates Direction and Velocity in a Motion Control Application?

    To indicate both direction & velocity, a signal with both positive and negative characteristics is required. Motion controls use either ±10 V or ±5 V signals to accomplish this.
    By: Joel Don
    24 May, 2019 | 1 minutes
  • Thumbnail for New Year Ushers In ISA Classroom, Webinar, and Online Education Opportunities

    New Year Ushers In ISA Classroom, Webinar, and Online Education Opportunities

    New Year Ushers In ISA Classroom, Webinar and Online Education Opportunities
    By: Joel Don
    16 December, 2013 | 6 minutes
  • Thumbnail for 10 Benefits of Having an Electrical Control Panel

    10 Benefits of Having an Electrical Control Panel

    See how you might improve your processes by upgrading to an electrical control panel.
    By: Alisha Hill
    08 October, 2021 | 2 minutes
  • Thumbnail for How to Apply Generalized Eigenvalue Minimization to Processes That Can Be Described by a First-Order Plus Time-Delay Model

    How to Apply Generalized Eigenvalue Minimization to Processes That Can Be Described by a First-Order Plus Time-Delay Model

    An algorithm to transform the uncertain first-order plus time delay model into a state-space model with uncertainty polyhedron is detailed in this technical paper.
    By: ISA Transactions
    31 October, 2014 | 1 minute
  • Thumbnail for Simplified Predictive Control Algorithm for Disturbance Rejection

    Simplified Predictive Control Algorithm for Disturbance Rejection

    Model predictive control (MPC) offers several advantages for control of chemical processes. However, the standard MPC may do a poor job in suppressing the effects of certain disturbances.
    By: ISA Transactions
    28 August, 2013 | 1 minute
  • Thumbnail for How to Improve Quality with Industry 4.0

    How to Improve Quality with Industry 4.0

    New methods brought on by the Fourth Industrial Revolution have either hypercharged previous QC/QA methods or brought on completely new ones.
    By: Ryan Kershaw
    20 September, 2022 | 5 minutes
  • Thumbnail for Leveraging DoD Wireless Security Standards for Automation and Control

    Leveraging DoD Wireless Security Standards for Automation and Control

    Industrial control systems are increasingly under attack and basic wireless security is inadequate. Government-validated technologies can be used to achieve greater cybersecurity
    By: Contributing Authors
    04 September, 2013 | 10 minutes
  • Thumbnail for Is Industrial Automation and Manufacturing Behind the Digital Marketing Curve?

    Is Industrial Automation and Manufacturing Behind the Digital Marketing Curve?

    Industrial automation & manufacturing has been slow to adopt modern digital marketing practices, they have not embraced social media & mobile computing.
    By: Joel Don
    08 June, 2015 | 5 minutes
  • Simple Nonlinear PD Controller for Integrating Processes [Technical]

    Technical research fdocuses on performance of a nonlinear PD controller is tested and compared with other PD and PID tuning rules for pure integrating plus delay.
    By: ISA Transactions
    11 July, 2014 | 1 minute
  • Thumbnail for AutoQuiz: What is the Cause of a High Process Variability?

    AutoQuiz: What is the Cause of a High Process Variability?

    An oversized control valve will operate next to the seat where the friction and stick slip is greatest.
    By: Joel Don
    17 February, 2017 | 1 minutes
Advertisement