It goes without saying that the inexorable — and overwhelming — sophistication of the technological fabric underpinning digital society forces us to catch up at forced march in order to keep it in check, and keep it running. And yes, that inevitably means getting to work relentlessly and without rest. Cybersecurity is not exempt from this dense breeding ground, so hard to season, least of all in one of its most extreme and critical forms: the industrial one.

At the same time, the flood of sector regulations and those generated by Europe — well-intentioned but convoluted and lacking harmonization — make an accelerated catch-up in the growing tasks of cyber protection advisable, under pain of major shocks and/or penalties.

To this colossal task ahead — hardly trivial in itself — is added the specific casuistry required to attend rigorously and in detail to each and every one of the sectors that sustain that digital fabric, whose scope, incidentally, is planetary, as we saw after the recent widespread IT collapse caused by "disagreements" between a certain technology giant and one of its main suppliers of defensive technologies.

In this mission, the sophistication of industrial cybersecurity is no small matter, since new challenges and more risks keep emerging from its many facets. So much so that it is urgent to go deeper into the demands and fluency of knowledge required to serve this specific and distinct segment of cyber protection: if it remains stuck in its most standard, generalist framing, it is by now clearly obsolete and short of reach, and it needs to shape itself around current and future OT and IoT particularities in order to take on these tasks successfully.

ICSO — Industrial Cyber Security Officer

It is enough to recall the events that recently took place in the well-known Middle East conflict, caused by a devastating act of sabotage backed by a massive explosive incursion, capable of tampering with communication devices — with intelligence support — and hiding high-pyrotechnic "gifts" inside them, bypassing the obsolete supply chain controls in use. This audacious and brutal action will force a root-and-branch rethink of how the supply chains of any industrial component are supervised, from now on sure targets for cyberterrorism and next-generation cybercrime.

This disturbing fact must be read alongside the forthcoming European Cyber Resilience Act, which is — presumably — meant to encourage (not guarantee) that hardware and software with digital components meet minimum security levels, with requirements scaling according to criticality. Going forward, we will have to see how reliable supervision systems are articulated — legal liability included — for each of the checks at the manufacturing, assembly, transport, distribution, and supply stages.

In this context, and in the wake of legislation, we can expect a high-octane legal and regulatory recognition of the cybersecurity officer role (read CISO and its derivatives: digital security, technology risk, industrial risk). Its consolidation, also spurred by the unsettling free-for-all around AI, makes it advisable to build, as soon as possible, a solid specialization genuinely deserving of its own name.

On that note, it is satisfying to see the early stance of the Industrial Cybersecurity Center, which promotes the acronym ICSO (Industrial Cyber Security Officer), aptly summarizing the need for a "formalized" savoir faire in this bounded specialty, perhaps destined to merge with its close cousin, IT.

The CCI's solid track record in professional training, capable of understanding that practicality and flexibility are decisive today, bodes well for its effort to drive the specialization of the next generation of industrial cybersecurity leaders.


Source: Industrial Cybersecurity Center (CCI).
Author: Luis Fernández Delgado — Editor of Revista SIC, Co-chair of SECURMATICA.