Cyber-attack Response Limits the Impact in Milliseconds (2024)

Supplier DirectorySubscribe

Cyber-attack Response Limits the Impact in Milliseconds (1)

Cyber-attack Response Limits the Impact in Milliseconds (2)

Home / Advanced, Real-time, Cyber-attack Response Limits the Impact Within Milliseconds at Machine Speed

SIBERprotec from Siemens delivers automatic cyber response solution for industrial OT systems.

Posted: May 15, 2024

Cyber-attack Response Limits the Impact in Milliseconds (3)

Cyber-attack Response Limits the Impact in Milliseconds (4)

Cyber-attack Response Limits the Impact in Milliseconds (5)

Cyber-attack Response Limits the Impact in Milliseconds (6)

SIBERprotect can isolate an effected area of production immediately, by engaging the actual PLC technology on machines and equipment, rather than simply alerting a Security Operations Center (SOC).

SIBERprotect activates a real-time lockdown in milliseconds.

Siemens SIBERprotect system for real-time protection of OT during cyber-attack.

SIBERprotect is part of the Siemens “Defense in Depth” suite, in accordance with IEC 62443, the international standard for industrial cybersecurity.

Cyber-attack Response Limits the Impact in Milliseconds (7)

Cyber-attack Response Limits the Impact in Milliseconds (8)

Following years of technical development and operational implementation design, Siemens introduces SIBERprotect for protection of critical infrastructure and OT systems at various industrial concerns, including power plants, water treatment facilities, all types of discrete manufacturing enterprises, military depots, data centers and control stations. SIBERprotect brings the SOAR (Security, Orchestration, Automation, Response) concept to cyber-physical systems with an OT-friendly and OT-managed methodology.

SIBERprotect can respond to and dramatically limit the impact of a cyber attack within milliseconds, resulting in the identification of the infected production equipment groups or plant networks and enabling full visibility and a fast initial response at the automation system level. This quick response leads to much easier remediation and resumption of normal operations, usually in less than a day.

Working in conjunction with Siemens SCALANCE S industrial security appliances, SIBERprotect can securely place OT into a safe, isolated condition, after determining the credible identification of a cyber-attack through best-in-class threat detection technology, including Intrusion Detection Systems, Next Generation Firewalls, Endpoint Solutions, Threat/Risk Intelligence and other attack or intrusion detection platforms, often enhanced with AI and machine learning capabilities. SIBERprotect then initiates a rule-based notification, network isolation and equipment management sequence to protect the selected equipment, as well as other desired response actions. Rapid assessment and remediation can then be performed, vastly limiting the risk of additional malware contamination. Work cells and equipment clusters can continue operation, while SIBERprotect prevents recontamination during remediation.

SIBERprotect further provides detailed situational awareness, alerting operators to the exact nature of the threat, where it was detected in the network and a criticality level. This level of immediately available detail allows the response engine to simultaneously execute emergency measures to alleviate predetermined worst-case scenarios. Unlike a conventional system that merely sends messages to an SOC (Security Operations Center), the SIBERprotect system is linked directly to network firewalls, automation hardware and a prioritized system of alarms to facilitate isolation of equipment and jumpstart the cyber incident response. After a thorough introduction to SIBERprotect, many automation engineers label it a cyber safety system or Cyber-SIS.

Other key features of SIBERprotect include the ability to automatically activate emergency backup equipment, interface with legacy technology such as Ethernet hubs, recover one segment or “restore all” functionality, isolate from the site IT network to prevent attack and provide all the benefits of a truly industrial solution.

As Chuck Tommey, a digital connectivity executive with Siemens, explains, “SIBERprotect represents the reimagining of how to do SOAR, that is, Security, Orchestration, Automation and Response, where an alert was typically sent to an SOC, then reviewed by a security analyst and addressed 30 minutes to hours after initial detection. Meanwhile, a virus could spread throughout a line or the entire plant. What Siemens is doing with SIBERprotect is sending the alerts directly to a PLC for instant action, based upon a predetermined priority of status and threat levels.” Tommey notes that the PLC parses the messages for its criticality level and instantly responds. (See the video below for a demonstration.)

SIBERprotect is part of the overall “Defense In Depth” suite offered by Siemens in compliance with IEC 62443, the international standard for industrial cybersecurity.

www.usa.siemens.com

SIBERprotect™.pdf

Subscribe to learn the latest in manufacturing.

Industry News

Woodward Inc. Announces Expansion of Metal Fabrication FacilityExpansion in Mars, Pa., houses new plasma-cutting system, enhances cutting and shaping capabilities.
Tecoi USA and Gladwin Machinery Announce Strategic Distributor PartnershipGladwin Machinery now supports Tecoi with sales, as well as application engineering and technical support for their line of advanced plate processing systems.
Kenworthy Named Global President of Shape Process AutomationSimon Kenworthy’s appointment as the global president of this robotics system integrator and process cutting solutions provider became effective May 1, 2024.

View All

Sign Up For e-Newsletter

Design-2-Part Show

June 5 - 6, 2024

Denver, CO

Design-2-Part Show

June 19 - 20, 2024

Novi, MI

RAPID + TCT

June 25 - 27, 2024

Los Angeles, CA

International Manufacturing Technology Show (IMTS)

September 9 - 14, 2024

Chicago, IL

Design-2-Part Show

September 10 - 11, 2024

Greenville, SC

FABTECH 2024

October 15 - 17, 2024

Orlando, FL

Cyber-attack Response Limits the Impact in Milliseconds (15)

Cyber-attack Response Limits the Impact in Milliseconds (16)

Cyber-attack Response Limits the Impact in Milliseconds (17)

  • Magazine
  • Supplier Directory
  • White Papers
  • Subscribe
Cyber-attack Response Limits the Impact in Milliseconds (2024)
Top Articles
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 5446

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.