Loading
Rockwell Automation Home
  • Industries
    • Industries Chevron RightChevron Right
      • Automotive & Tire
      • Cement
      • Chemical
      • Entertainment
      • Fibers & Textiles
      • Food & Beverage
      • Household & Personal Care
      • Infrastructure
      • Life Sciences
      • Marine
      • Metals
      • Mining
      • Oil & Gas
      • Power Generation
      • Print & Publishing
      • Pulp & Paper
      • Semiconductor
      • Water Wastewater
      • View All
    Industries
    Case StudyRockwell Automation's case studies Case Studies DistributorDistributor How to Buy EventEvent Events
  • Capabilities
    • Capabilities Chevron RightChevron Right
      • The Connected Enterprise
      • Consulting & Integration Services
      • Cybersecurity
      • Digital Transformation
      • Industrial Analytics
      • Industrial Automation & Control
      • Industrial Maintenance & Support
      • Industrial Networks
      • Lifecycle Services
      • Machine & Equipment Builders
      • MES Solutions
      • Process Solutions
      • Safety Solutions
      • View All
    Capabilities
    Blogs DistributorDistributor How to Buy EventEvent Events
  • Products
    • Hardware Chevron RightChevron Right
    • Software Chevron RightChevron Right
      • Circuit & Load Protection
      • Condition Monitoring
      • Connection Devices
      • Distributed Control Systems
      • Drives & Motors
      • Energy Monitoring
      • Human Machine Interface
      • Independent Cart Technology
      • Industrial Computers & Monitors
      • Input/Output Modules
      • Industrial Control Products
      • Lighting Control
      • Motion Control
      • Motor Control
      • Networks Security & Infrastructure
      • Packaged Solutions
      • Power Supplies
      • Programmable Controllers
      • Push Buttons & Signaling Devices
      • Relays & Timers
      • Safety Instrumented Systems
      • Safety Products
      • Sensors & Switches
      • Signal Interface
      • View All Hardware Products
    • DesignSuite
      • Dynamic Digital Twin Software
      • Studio 5000 Design Software
      • View All
    • OperationSuite
      • FactoryTalk Edge Gateway
      • FactoryTalk Batch
      • FactoryTalk Historian
      • FactoryTalk View - HMI Software
      • FactoryTalk Metrics
      • View All
    • MaintenanceSuite
      • FactoryTalk Analytics for Devices
      • FactoryTalk AssetCentre
      • FactoryTalk Emonitor
      • FactoryTalk Network Manager
      • FactoryTalk TeamOne
      • View All
    • InnovationSuite
      • Augmented Reality
      • FactoryTalk Analytics
      • MES
      • ThingWorx IIoT Platform
      • View All
    Products
    Find Products by Our Brands: Allen-Bradley FactoryTalk
  • Support
    • Product Support Chevron RightChevron Right
    • Documentation Chevron RightChevron Right
    • Knowledgebase Chevron RightChevron Right
    • Training Chevron RightChevron Right
    • Downloads
      • 2D & 3D Drawings
      • Activations
      • Add-on Profiles
      • Application Code Libraries
      • Compatibility & Downloads
      • Drivers & Firmware
      • Electronic Datasheets
      • EPLAN Macros
      • Sample Code Library
      • Software Patches
      • View All
    • Selection & Configuration
      • Control Systems Configuration Tools
      • Procurement Specifications
      • ProposalWorks Proposal Builder
      • Global Short-circuit Current Ratings Tool
      • Integrated Architecture Builder
      • View All
    • Compatibility & Migration
      • Migration & Modernization
      • Lifecycle Status
      • Product Replacement Lookup
      • View All
      • Technical Documentation Center
      • Technical Specifications
      • Product Certifications
      • Product Drawings
      • Release Notes
      • Literature Library
    • Support Center
      • Support Options
      • Search for Answers
      • Chat Online
      • Call Us
      • View All
    • Online Forum
      • My Inbox
      • My Favorites
      • My Subscriptions
      • View All
    • My TechConnect
      • Chat History
      • Service Ticket History
      • Manage Your Favorite Answers
      • Field Service Request
      • View All
      • E-Learning Courses
      • Training Workstations
      • On-Site Training
      • View All
    Support
    Contact Us HelpHelp Get Support LaunchpadTools and applications View All Tools
  • Company
    • Events Chevron RightChevron Right
    • News Chevron RightChevron Right
    • Careers Chevron RightChevron Right
    • PartnerNetwork Chevron RightChevron Right
    • About Us Chevron RightChevron Right
    • Featured Events
      • Automation Fair
      • Process Solutions User Group
      • Smart Machine Workshops
      • VirtualConnect: Smart Manufacturing
      • View All
    • Webinars
      • Live
      • On-Demand
      • View All
      • The Journal
      • Blogs
      • Case Studies
      • Automation Today
      • Podcasts
      • Press Releases
      • Media Contacts
      • View All
      • View Jobs
      • Teams & People
      • Hackathon
      • Employee Video Spotlight
      • EMEA Graduate Programme
      • Authorized Distributors
      • Encompass Product Partners
      • Licensed Developers
      • OEM Partners
      • Strategic Alliance Partners
      • System Integrator Partners
      • PartnerNetwork Portal
      • View All
      • Our Brands
      • Our Community
      • Our History
      • Integrity & Sustainability
      • Investor Relations
      • View All
    Company
    ProductivityProductivity Investor Relations
  • Sales
  • Sales
  • View All Industries
  • View All
  • View All
  • View All
  • View All
  • Automotive & Tire
  • Cement
  • Chemical
  • Entertainment
  • Fibers & Textiles
  • Food & Beverage
  • Household & Personal Care
  • Infrastructure
  • Life Sciences
  • Marine
  • Metals
  • Mining
  • Oil & Gas
  • Power Generation
  • Print & Publishing
  • Pulp & Paper
  • Semiconductor
  • Water Wastewater
  • View All
  • The Connected Enterprise
  • Consulting & Integration Services
  • Cybersecurity
  • Digital Transformation
  • Industrial Analytics
  • Industrial Automation & Control
  • Industrial Maintenance & Support
  • Industrial Networks
  • Lifecycle Services
  • Machine & Equipment Builders
  • MES Solutions
  • Process Solutions
  • Safety Solutions
  • View All
  • Circuit & Load Protection
  • Condition Monitoring
  • Connection Devices
  • Distributed Control Systems
  • Drives & Motors
  • Energy Monitoring
  • Human Machine Interface
  • Industrial Computers & Monitors
  • Input/Output Modules
  • Industrial Control Products
  • Lighting Control
  • Motion Control
  • Motor Control
  • Networks Security & Infrastructure
  • Packaged Solutions
  • Power Supplies
  • Programmable Controllers
  • Push Buttons & Signaling Devices
  • Relays & Timers
  • Safety Instrumented Systems
  • Safety Products
  • Sensors & Switches
  • Signal Interface
  • View All Hardware Products
  • View All
  • View All
  • Technical Documentation Center
  • Technical Specifications
  • Product Certifications
  • Product Drawings
  • Release Notes
  • Literature Library
  • View All
  • Training Workstations
  • On-Site Training
  • View All
  • View All
  • The Journal
  • Blogs
  • Automation Today
  • Podcasts
  • Media Contacts
  • View All
  • View Jobs
  • View All
  • Authorized Distributors
  • Encompass Product Partners
  • Licensed Developers
  • OEM Partners
  • System Integrator Partners
  • PartnerNetwork Portal
  • View All
  • Our Brands
  • Our History
  • Investor Relations
  • View All
  • iTRAK Intelligent Track Systems
  • MagneMover Lite Intelligent Conveyor System
  • QuickStick Intelligent Conveyor System
  • View All
  • Dynamic Digital Twin Software
  • Studio 5000 Design Software
  • View All
  • FactoryTalk Edge Gateway
  • FactoryTalk Batch
  • FactoryTalk Historian
  • FactoryTalk View - HMI Software
  • FactoryTalk Metrics
  • View All
  • FactoryTalk Analytics for Devices
  • FactoryTalk AssetCentre
  • FactoryTalk Emonitor
  • FactoryTalk Network Manager
  • FactoryTalk TeamOne
  • View All
  • Augmented Reality
  • FactoryTalk Analytics
  • MES
  • ThingWorx IIoT Platform
  • View All
  • 2D & 3D Drawings
  • Activations
  • Add-on Profiles
  • Application Code Libraries
  • Compatibility & Downloads
  • Drivers & Firmware
  • Electronic Datasheets
  • EPLAN Macros
  • Sample Code Library
  • Software Patches
  • View All
  • Control Systems Configuration Tools
  • Procurement Specifications
  • ProposalWorks Proposal Builder
  • Global Short-circuit Current Ratings Tool
  • Integrated Architecture Builder
  • View All
  • Migration & Modernization
  • Lifecycle Status
  • Product Replacement Lookup
  • View All
  • Support Options
  • Search for Answers
  • Chat Online
  • Call Us
  • View All
  • My Inbox
  • My Favorites
  • My Subscriptions
  • View All
  • Chat History
  • Service Ticket History
  • Manage Your Favorite Answers
  • Field Service Request
  • View All
  • My Training
  • View All
  • Automation Fair
  • Process Solutions User Group
  • Smart Machine Workshops
  • VirtualConnect: Smart Manufacturing
  • View All
  • Live
  • On-Demand
  • View All
  • Digital Transformation at Norbord
  • View All
  • Brighter, More Flexible Tower Light Now Available from Rockwell Automation
  • Delphi Award Received For Asset Management
  • Internal Bypass Expands Smart Motor Functionality
  • New IaaS Bundle Eases Industrial Networking
  • Rockwell Automation Names Sebastien Grau as Regional Sales Director for Middle East, Turkey and Sub Saharan Africa
  • Expanded Power Range for PowerFlex 6000 MV Drives
  • Studio 5000 Software Update Optimizes Productivity
  • FLEX 5000 I/O Modules Bring Greater Productivity and Flexibility to a Connected Enterprise
  • New Cable-Pull Switch Enhances Industrial Safety
  • Instant Industrial Device Analytics
  • Rockwell Automation to name Al Ghandi Electrical & Automation as Authorised Distributor in the UAE
  • Rockwell Automation to Broaden Connected Enterprise Consulting Expertise with Acquisition of Kalypso
  • Single-Control Multi-Well Pad Solution Cuts Costs
  • Advanced Light Curtain System Improves Flexibility and Safety
  • Automation University
  • Rockwell Automation to Showcase the ConnectedProduction Solutions and Premieres its ThinManager Software at ADIPEC 2018
  • Safe Torque Off Option Simplifies Machine Design
  • Machine Performance Analytics Bring OEM Expertise Into Producer’s Digital Environment
  • Software-Powered Connected Services
  • New Managing Director of Rockwell Automation for Sub-Saharan Africa announced
  • Rockwell Automation Simplifies Analytics for Industrial Productivity
  • New Managing Director of Rockwell Automation for Sub-Saharan Africa announced
  • Securely Deploy Cloud and Mobile Technologies with New Network Guidance
  • Rockwell Automation drive system selected for Sumitomo Rubber’s rubber mixers
  • PlantPAx DCS Roadmap
  • View All
  • Students & New Grads
  • View All
  • Hackathon Use Case for Manufacturing Optimization
  • Hackathon Use Case for Sustainability
  • Hackathon Use Case for Visual System Modernization
  • Hackathon Use Case for Dynamic Filtering
  • View All
  • 24toCode Event Recap - Winter 2019
  • 24toCode Event Recap // IT Internal Hackathon
  • Meet the 2019 IT Summer Interns
  • 24toCode Promo Video
  • Harbor View Plaza Ribbon Cutting
  • Check Your Blind Spots Mobile Tour at Rockwell Automation
  • Mechanic & Tool Apprenticeship at Rockwell Automation
  • Working at Rockwell Automation in Karlsruhe
  • Summer Internships at Rockwell Automation
  • The Intrapreneurial Skills Accelerator at Rockwell Automation
  • Makers Wanted
  • #LifeatROK w Katowicach
  • IT Summer Internship Program
  • #LifeatROK with Diogo
  • View All
  • Open Positions For EMEA Graduate Programme
  • View All
  • Cisco
  • Endress+Hauser
  • FANUC
  • Microsoft
  • Panduit
  • View All
  • Our Focused Giving
  • STEM Education
  • Lifelong Learning
  • View All
  • Sustainability Report
  • Our Commitment to Diversity, Equity and Inclusion
  • Environmental, Health, & Safety
  • Ethics & Compliance
  • Global Supply Chain & Sourcing
  • Product Environmental Compliance
  • Quality Management Systems
  • Trust & Security
  • Workforce of Tomorrow
  • View All
Case StudyRockwell Automation's case studies Case Studies DistributorDistributor How to Buy EventEvent Events
Blogs DistributorDistributor How to Buy EventEvent Events
Find Products by Our Brands:
Allen-Bradley FactoryTalk
Contact Us HelpHelp Get Support LaunchpadTools and applications View All Tools
ProductivityProductivity Investor Relations
  • Literature LibraryLiterature Library
    Literature Library

    Access technical and commercial publications for hardware and software products, applications, services and solutions.

    PCDCProduct Compatibility and Download Center
    Compatibility & Downloads

    Find downloads including firmware, release notes, associated software, drivers, tools and utilities.

    KnowledgebaseKnowledgebase Support Center
    Knowledgebase

    Browse the database of questions and answers on a variety of products and technologies.

    Product ConfiguratorProduct Configurator
    Product Configurator

    Configure and select products rapidly.

    Software SubscriptionsSoftware Subscriptions
    Software Subscriptions

    One stop shopping for software and subscription services.

    2D & 3D Drawings Bill of Materials CrossWorks Electronic Datasheets Motion Analyzer My Equipment My Training E-Learning Portal Product Lifecycle Status Product Registration Product Selection Toolbox Repairs Sample Code Library Software Activations View All
    Tools
    UserUser Sign In/Create an Account
  • User Account User
Tools
Literature LibraryLiterature Library
Literature Library
PCDCProduct Compatibility and Download Center
Compatibility & Downloads
KnowledgebaseKnowledgebase Support Center
Knowledgebase
Product ConfiguratorProduct Configurator
Product Configurator
Software SubscriptionsSoftware Subscriptions
Software Subscriptions
2D & 3D Drawings Bill of Materials CrossWorks Electronic Datasheets Motion Analyzer My Equipment My Training E-Learning Portal Product Lifecycle Status Product Registration Product Selection Toolbox Repairs Sample Code Library Software Activations View All
Blog
Recent ActivityRecent Activity

Unpacking the Patch Management Process for Operations

Share This:

LinkedInLinkedIn
TwitterTwitter
FacebookFacebook
PrintPrint
EmailEmail
Main Image

Smart manufacturing brought us breakthrough productivity, but ICS cybersecurity lagged behind. We take a look at how the food and beverage industry is catching up.

The food and beverage industry has seen great momentum when it comes to addressing cyber hygiene – the starting point for industrial control system (ICS) cybersecurity. Where we used to have a lot of conversations about network infrastructure, cybersecurity techniques and strategy are now taking center stage. But how did we get here?

The problem dates back 20-30 years, when the food and beverage industry was rapidly adopting advanced, proprietary technology on the factory floor. Due to the closed and isolated nature of these systems, cybersecurity was not a true concern.

Fast forward to the past 10 years, and the proliferation of ICS and Ethernet-connected equipment has revolutionized productivity, quality, compliance and speed to market. It has also simplified connection of these legacy systems to each other and to new systems. This open, unmodified Ethernet communication brought increased cyber risk and a new concern: legacy system patch management.

A recent Food Protection and Defense Institute report details how this outdated legacy equipment can expose your operation to malicious attacks. Ones that can disrupt business, destroy equipment and compromise worker and product safety. A holistic cybersecurity program has become a business imperative, and the patch management process plays an important role.

<strong>WEBINAR</strong>: What every food & beverage manufacturer needs to know about cybersecurity. Sign up for the first in a 4-part series on cybersecurity best practices.

You can’t patch what you can’t see

The idea of an asset inventory isn’t new, and you may have already tried this exercise internally, or even enlisted outside help. But to capture everything is no easy task, and many are still working to get it right.

There are two ways to take inventory, and to set the right foundation for your ICS cybersecurity program, you need both.

  • Electronic interrogation tools can scan your network and automatically identify assets, getting you most of the way there.
  • Manual identification will catch the rest, but requires someone to literally walk around, open panels and do a physical survey of what’s out there.

A watch out here is to take both approaches at all of your locations. If only complete at nine of your 10 sites, I can just about guarantee the breach is coming through the one that was overlooked.

Setting a comprehensive patching strategy

Following the inventory, you may be left with a list of thousands of assets to wrap your head around. Luckily, not all assets are created equal. The next step is performing a risk analysis to identify the high priority assets to patch based on their criticality, exposure, age, anticipated risk, etc. Some assets aren’t even on the network, so are they really a risk?

There are two types of patches you’ll need to address:

  1. Operating system (OS) patching is commonplace for IT, so much so that Microsoft Patch Tuesday has been around for more than 15 years. You’ll have to time plant floor OS patching with scheduled downtime for minimal disruption. Some proactive IT/OT collaboration can take care of this in many instances.
  2. Application-level patching is a different story. There could be literally hundreds of applications from different vendors with different patches. So it’s incumbent upon you to go find patches on vendor websites, understand the vulnerabilities they protect against and if they are needed or not.

Because each application is configured differently, patching the application layer warrants a very deliberate, consistent testing standard. One conducted in a lab environment prior to implementation on the plant floor where you could run the risk of unintentionally shutting down production.

<strong>EBOOK</strong>: Explore the ins and outs of protecting networks and facilities against the fast-changing threat landscape (pdf).

A systematic approach to patch management

The “fingers crossed” approach is common throughout the food and beverage industry. Not for lack of trying, but for lack of the right resources and specialized expertise. Generally what I see in the field today is reactive. Responding to a high-priority patch notification and accomplished by shutting down production on a weekend as needed.

And the common progression looks like this:

  • Operations enlists IT to help manage OT patching.
  • IT fills in, but doesn’t have the ICS expertise or resources to manage the unique requirements and constraints.
  • So they hire a hybrid IT/OT resource, or more often, outsource to a company like Rockwell Automation or others.

If going the third-party route, seek a partner grounded in operations. One telltale sign is their service level agreement (SLA) response time. Traditional IT providers measure response in hours. But that kind of downtime in consumer goods production can mean millions of dollars lost. SLAs measured in minutes represent an operations-friendly approach.

The ICS cybersecurity end game

Patch management is one step on your way to getting a security operations center (SOC) up and running. An SOC can provide a holistic dashboard view of your security posture, include a disaster recovery strategy and ensure optimal operation of your connected factory.

Additionally, there are solutions available today that are designed for end point protection or “whitelisting.”  While these solutions do not entirely eliminate the need for patching, they are an effective solution to protect and buy you time while formulating a patching strategy.

The truth is, there is no silver bullet to effective cybersecurity. That is what defense-in-depth is all about. But with more than the bottom line at risk (think food and employee safety), reaction and a little luck is no longer a viable approach. If you’re looking for a little help kicking off your program, or bringing it to the next level, we’re here to help.


Mark Cristiano
Mark Cristiano
Network and Security Services Business Development Manager, Rockwell Automation
Connect:
EmailEmail
Subscribe

Subscribe to Rockwell Automation and receive the latest news, thought leadership and information directly to your inbox.

Subscribe

Recommended For You

Loading
  • Technical Question
  • Chat Technical Support
  • Phone Support
  • Contact Sales
  • General Questions
  1. Chevron LeftChevron Left Middle East Chevron RightChevron Right
  2. Chevron LeftChevron Left Company Chevron RightChevron Right
  3. Chevron LeftChevron Left News Chevron RightChevron Right
  4. Chevron LeftChevron Left Blogs Chevron RightChevron Right
Discover
  • The Connected Enterprise
  • Create Your Account
  • Case Studies
  • Events
Information for...
  • Distributors
  • OEM
  • System Integrators
  • Encompass Partners
  • Investors
  • Career Seekers
Contact Us
  • General Questions
  • Technical Questions
  • Local Sales & Service
  • Pricing & Availability
  • Report Ethical Concerns
Site Information
  • Legal
  • Privacy Policy
  • Cookie Preferences
  • Terms of Use
  • Trademarks
Change Country Site SelectionChange RockwellAutomation.com site selection to a different country, region or language Change Country
Middle East/English

Keep Updated With Us

Sign up to receive our latest headlines for free.

Stay Informed Now
Follow Us
BlogRockwell Automation's Blog
Copyright ©2021 Rockwell Automation, Inc.
Middle East