IT & Innovation

‘It’s Only a Matter of Time’: Manufacturers Need to Prepare for Possibility of Cyberattack

Posted

Greenville-based cybersecurity consultant Mike Holcomb has a warning for manufacturers: It’s just a matter of time before you become a victim of a cyberattack. Most manufacturers are not prepared, he warns.

“I work with quite a few manufacturers in the Carolinas, and, of course, globally,” Holcomb says. 

“You have larger manufacturers, like pharmaceuticals. They have the budget. They have resources to address these types of issues. But we have small or medium-sized manufacturers here in Greenville that might be struggling to keep the lights on. That’s especially true with startups. They’re worried about a million different things, and cybersecurity is not on their list.”

CEOs must realize that cyber security is something that they must address, otherwise they will find out the hard way.

“Maybe they don't have an incident tomorrow, but they're going to have one next week or next month or next year. It's coming. It's only a matter of time. So, they need to at least start.”

Manufacturers launching a cybersecurity program should emphasize fundamentals, Holcomb says, adding it doesn’t have to be complex or complicated. He advises companies to focus on backup and recovery, asset management, and secure network configuration such as putting a firewall in to limit the damage if an attacker succeeds at getting in.

Holcomb specializes in industrial, or OT (operational technology) security or ICS (Industrial Control System) cyber security. He says companies can avoid 90 percent of cyber threats if they adhere to a simple plan, for which he uses the acronym B.A.S.I.C.

  • Backup and Recovery: Always assume you will be compromised and will need to recover quickly. Make sure you have system backups, and those backups have been tested.

  • Asset Management: Having a complete list of assets is critical to vulnerability management and intrusion detection. 

  • Secure Network Architecture: The No. 1 way for limiting cyber risk is to limit the attackers and limit the paths attackers have. 

  • Incident Response Planning: It's only a matter of time before it happens. Operational technology (OT) will become compromised, or information technology will, and it will have an impact on OT. Be prepared with a plan to disconnect OT from IT.

  • Continuous Vulnerability Management: If you know what you have to protect, you can look for known vulnerabilities.

“We want to fix those before attackers can take advantage of them. If you do those five things, you essentially are going to reduce 90 percent of your risk. Those things are the most cost effective. So the nice thing is, those first controls you apply cost the least compared to everything else you will have to come back and do later.”

Gov. Henry McMaster announced last December the creation of the Center for Cybersecurity at the South Carolina Research Authority (SCRA). The new agency will lead implementation of the state’s cybersecurity strategic plan, which was developed from a study completed in 2024.

Brian Shea, co-founder of Simon Everett, a business management consultancy, is the center’s director. He says the strategic plan is focused on strengthening all the ingredients needed to improve cybersecurity across the state. It is much broader than securing state and local government. It includes finding ways to grow and attract cybersecurity companies, researchers, and private sector investment while also spurring cybersecurity innovation. 

“We want to make sure the ingredients are strong and sustainable, so all will succeed as we move forward,” Shea says.

Much work remains to prepare the workforce to handle cybersecurity threats, Shea says. That’s true not only for South Carolina, but across the U.S. The speed at which the world has become a digital society has far outpaced the speed at which people have been educated on how to do that securely.

“Across the country, we just need to keep accelerating, making cyber security everyone's problem again. We still think about if you work in an organization, and someone says cyber security, it's easy to think, well, that's the IT department's job. I don't have to worry about that. And yet, most cybersecurity threats aren't targeting the IT office. They're targeting the frontline worker who's going to click on an email that should have been considered suspicious. Starting at K through 12, we need to improve the degree to which kids at a young age are thinking about cybersecurity.” 

The challenges are many. In addition to improving cyber education, the speed at which cyber threats appear and adapt to overcome countermeasures is increasing. 

“Cybersecurity falls within a much larger field of information technology. It is natural for many people to be chasing the new shiny object in technology. We're focused on artificial intelligence, quantum computing, unmanned vehicles. You have a subset of people who focus on cybersecurity because it's near and dear to them. But you have another subset of people who I worry are forgetting about cybersecurity because they're chasing the next technology. One of those challenges is reminding everyone that what sets cybersecurity apart from the other ones is they all rely on it.” 

Shea says cybersecurity has to be a foundational part of all current and future technologies. It’s not something that had its moment and can be forgotten. Sustainability is another challenge. To achieve long-term success, industry must be properly staffed with cybersecurity workers well into the future.

Shea says there is one primary piece of advice he would give to CEOs.

“The No. 1 thing that everyone should do to improve their cyber security posture is use multi-factor authentication. It's annoying to use. Nobody likes it when you log on to a system, and have to receive a text or an email, but it is the single most effective thing that organizations can do to decrease their cyber security vulnerability.”

Comments

No comments on this item Please log in to comment by clicking here