Organizations have made digitalization of the industrial process a necessity, with the goal of becoming more competitive and better meeting customer needs by shortening production cycles, improving process yields and efficiency, and, as a result, reducing operating costs and increasing business margins.
Industrial equipment and systems stop being isolated islands of automation and connect to other industrial, corporate, or external networks, so that process data integrates with other business data and makes the operation more efficient and controlled, enabling better decisions, more precise and in real time.
Why an Industrial Cybersecurity Management System?
Thanks to the connectivity of new technologies in industrial environments, we can control the whole production chain easily. Industrial control systems, however, will no longer be affected only by breakdowns or operating errors: cybersecurity is now a factor too, leaving them exposed to hackers and cybercriminals. Given the nature of control systems, a security failure caused by a digital attack can endanger:
- The production process
- Worker safety
- The operation of production equipment and devices
- The surrounding environment
- The organization's image with its customers
Organizations must prepare to protect industrial systems, networks, and programs against cyberattacks that seek to access, alter, or damage the industrial process. Providing the procedures and tools needed to guarantee the cybersecurity of operational environments is essential.
What is an Industrial Cybersecurity Management System?
An Industrial Cybersecurity Management System (ICMS) means making available to the organization the resources needed to efficiently manage the cybersecurity risks associated with industrial control systems, with effective, continuous, and aligned treatment of the pillars to be protected: availability, integrity, and confidentiality. The ICMS should be based on norms and standards accepted as international reference frameworks, including:
- ISO 27001: how to manage information security.
- ISO 27002: good practices for improving information security.
- IEC 62443: procedures for implementing security in industrial automation and control systems.
Steps to implement an ICMS
1. Define an industrial cybersecurity strategy and policy
It must be integrated within the corporate strategy, making it possible to identify and delimit the scope of the ICMS, which may be extended in the future as the industrial process changes.
2. Manage industrial cybersecurity risks
A risk analysis methodology is applied, identifying industrial assets, vulnerabilities, and threats. The likelihood of a threat exploiting a vulnerability, together with its impact, identifies the risk level and the unacceptable risks, which then require action plans to mitigate them.
3. Promote a culture of industrial cybersecurity
Train and raise awareness among all members of the organization, since they are the ones managing its critical resources. Training is the only tool for improving their cybersecurity skills, and it has a positive effect on the company.
4. Establish protection standards for industrial facilities
Physical security of equipment; logical access control to devices and systems; network protection based on the "zones" and "conduits" theory under IEC 62443; protection of custom industrial software; protection of sensitive process data and of relationships with third parties.
5. Guarantee resilience and continuity of operating systems
Mechanisms that improve cyber resilience against incidents that put the continuity of the production process at risk, reducing impact and developing recovery capabilities.
6. Manage, review, improve, and sustain the ICMS
Like any management system, it must be reviewed to determine its level of compliance and to establish improvement plans, since cybersecurity is a process of continuous improvement.
A guide for applying an ICMS
The Industrial Cybersecurity Center (CCI) has developed a practical guide that helps the industrial cybersecurity officer design, implement, and develop the policies, procedures, culture, and protection measures needed to manage technology risks. The guide is based on six domains, each matching the steps above, and references the controls recommended by ISO 27001, ISO 27002, and IEC 62443.

Author: Antonio Rodríguez Usallán — Industrial Cybersecurity Expert.
