Avoiding the Internet of Insecure Industrial Things
Lachlan Urquhart, Derek McAuley

TL;DR
This paper analyzes security risks in the industrial internet of things, emphasizing regulatory and technical challenges, and uses a smart energy supply chain case study to highlight key concerns and responses.
Contribution
It identifies four main security concerns in industrial IoT and discusses regulatory frameworks, providing a comprehensive overview of emerging risks and mitigation strategies.
Findings
Industrial IoT shifts infrastructure online, increasing vulnerabilities.
Regulatory measures like EU NIS Directive and GDPR aim to improve security.
Key concerns include infrastructure complexity and implementation gaps.
Abstract
Security incidents such as targeted distributed denial of service (DDoS) attacks on power grids and hacking of factory industrial control systems (ICS) are on the increase. This paper unpacks where emerging security risks lie for the industrial internet of things, drawing on both technical and regulatory perspectives. Legal changes are being ushered by the European Union (EU) Network and Information Security (NIS) Directive 2016 and the General Data Protection Regulation 2016 (GDPR) (both to be enforced from May 2018). We use the case study of the emergent smart energy supply chain to frame, scope out and consolidate the breadth of security concerns at play, and the regulatory responses. We argue the industrial IoT brings four security concerns to the fore, namely: appreciating the shift from offline to online infrastructure; managing temporal dimensions of security; addressing the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Information and Cyber Security · Blockchain Technology Applications and Security
