Loading
Rockwell Automation Home
  • Industries
    • Industries Chevron RightChevron Right
      • Automotive & Tire
      • Cement
      • Chemical
      • Entertainment
      • Fibers & Textiles
      • Food & Beverage
      • Household & Personal Care
      • Infrastructure
      • Life Sciences
      • Marine
      • Metals
      • Mining
      • Oil & Gas
      • Power Generation
      • Print & Publishing
      • Pulp & Paper
      • Semiconductor
      • Water Wastewater
      • View All
    Industries
    Case StudyRockwell Automation's case studies Case Studies DistributorDistributor How to Buy EventEvent Events
  • Capabilities
    • Capabilities Chevron RightChevron Right
      • The Connected Enterprise
      • Consulting & Integration Services
      • Cybersecurity
      • Digital Transformation
      • Industrial Analytics
      • Industrial Automation & Control
      • Industrial Maintenance & Support
      • Industrial Networks
      • Lifecycle Services
      • Machine & Equipment Builders
      • MES Solutions
      • Process Solutions
      • Safety Solutions
      • View All
    Capabilities
    Blogs DistributorDistributor How to Buy EventEvent Events
  • Products
    • Hardware Chevron RightChevron Right
    • Software Chevron RightChevron Right
      • Circuit & Load Protection
      • Condition Monitoring
      • Connection Devices
      • Distributed Control Systems
      • Drives & Motors
      • Energy Monitoring
      • Human Machine Interface
      • Independent Cart Technology
      • Industrial Computers & Monitors
      • Input/Output Modules
      • Industrial Control Products
      • Lighting Control
      • Motion Control
      • Motor Control
      • Networks Security & Infrastructure
      • Packaged Solutions
      • Power Supplies
      • Programmable Controllers
      • Push Buttons & Signaling Devices
      • Relays & Timers
      • Safety Instrumented Systems
      • Safety Products
      • Sensors & Switches
      • Signal Interface
      • View All Hardware Products
      • DesignSuite
    • OperationSuite
      • FactoryTalk Edge Gateway
      • FactoryTalk Batch
      • FactoryTalk Historian
      • FactoryTalk View - HMI Software
      • FactoryTalk Metrics
    • MaintenanceSuite
      • FactoryTalk Analytics for Devices
      • FactoryTalk AssetCentre
      • FactoryTalk Emonitor
      • FactoryTalk Network Manager
      • FactoryTalk TeamOne
      • Fiix CMMS
    • InnovationSuite
      • Augmented Reality
      • FactoryTalk Analytics
      • MES
      • ThingWorx IIoT Platform
    • DesignSuite
      • Dynamic Digital Twin Software
      • Studio 5000 Design Software
    Products
    Find Products by Our Brands: Allen-Bradley FactoryTalk
  • Support
    • Product Support Chevron RightChevron Right
    • Documentation Chevron RightChevron Right
    • Knowledgebase Chevron RightChevron Right
    • Training Chevron RightChevron Right
    • Downloads
      • 2D & 3D Drawings
      • Activations
      • Add-on Profiles
      • Application Code Libraries
      • Compatibility & Downloads
      • Drivers & Firmware
      • Electronic Datasheets
      • EPLAN Macros
      • Sample Code Library
      • Software Patches
      • View All
    • Selection & Configuration
      • Control Systems Configuration Tools
      • Procurement Specifications
      • ProposalWorks Proposal Builder
      • Global Short-circuit Current Ratings Tool
      • Integrated Architecture Builder
      • View All
    • Compatibility & Migration
      • Migration & Modernization
      • Lifecycle Status
      • Product Replacement Lookup
      • View All
      • Technical Documentation Center
      • Technical Specifications
      • Product Certifications
      • Product Drawings
      • Release Notes
      • Literature Library
    • Support Center
      • Support Options
      • Search for Answers
      • Chat Online
      • Call Us
      • View All
    • Online Forum
      • My Inbox
      • My Favorites
      • My Subscriptions
      • View All
    • My TechConnect
      • Chat History
      • Service Ticket History
      • Manage Your Favorite Answers
      • Field Service Request
      • View All
      • E-Learning Courses
      • Instructor-led Courses
      • Training Workstations
      • Training Calendar
      • View All
    Support
    Contact Us HelpHelp Get Support LaunchpadTools and applications View All Tools
  • Company
    • Events Chevron RightChevron Right
    • News Chevron RightChevron Right
    • Careers Chevron RightChevron Right
    • PartnerNetwork Chevron RightChevron Right
    • About Us Chevron RightChevron Right
    • Featured Events
      • Automation Fair
      • Process Solutions User Group
      • Smart Machine Workshops
      • VirtualConnect: Smart Manufacturing
      • View All
    • Webinars
      • Live
      • On-Demand
      • View All
      • Blogs
      • Case Studies
      • Automation Today
      • Podcasts
      • Press Releases
      • Media Contacts
      • View All
      • View Jobs
      • Teams & People
      • Hackathon
      • Employee Video Spotlight
      • Authorized Distributors
      • Encompass Product Partners
      • Licensed Developers
      • OEM Partners
      • Strategic Alliance Partners
      • System Integrator Partners
      • PartnerNetwork Portal
      • View All
      • Our Brands
      • Our Community
      • Our History
      • Integrity & Sustainability
      • Investor Relations
      • View All
    Company
    ProductivityProductivity Investor Relations
  • Sales
  • Sales
  • View All Industries
  • View All
  • View All
  • View All
  • View All
  • Automotive & Tire
  • Cement
  • Chemical
  • Entertainment
  • Fibers & Textiles
  • Food & Beverage
  • Household & Personal Care
  • Infrastructure
  • Life Sciences
  • Marine
  • Metals
  • Mining
  • Oil & Gas
  • Power Generation
  • Print & Publishing
  • Pulp & Paper
  • Semiconductor
  • Water Wastewater
  • View All
  • The Connected Enterprise
  • Consulting & Integration Services
  • Cybersecurity
  • Digital Transformation
  • Industrial Analytics
  • Industrial Automation & Control
  • Industrial Maintenance & Support
  • Industrial Networks
  • Lifecycle Services
  • Machine & Equipment Builders
  • MES Solutions
  • Process Solutions
  • Safety Solutions
  • View All
  • Circuit & Load Protection
  • Condition Monitoring
  • Connection Devices
  • Distributed Control Systems
  • Drives & Motors
  • Energy Monitoring
  • Human Machine Interface
  • Industrial Computers & Monitors
  • Input/Output Modules
  • Industrial Control Products
  • Lighting Control
  • Motion Control
  • Motor Control
  • Networks Security & Infrastructure
  • Packaged Solutions
  • Power Supplies
  • Programmable Controllers
  • Push Buttons & Signaling Devices
  • Relays & Timers
  • Safety Instrumented Systems
  • Safety Products
  • Sensors & Switches
  • Signal Interface
  • View All Hardware Products
  • DesignSuite
  • View All
  • View All
  • Technical Documentation Center
  • Technical Specifications
  • Product Certifications
  • Product Drawings
  • Release Notes
  • Literature Library
  • View All
  • Instructor-led Courses
  • Training Workstations
  • Training Calendar
  • View All
  • View All
  • Blogs
  • Automation Today
  • Podcasts
  • Media Contacts
  • View All
  • View Jobs
  • View All
  • Authorized Distributors
  • Encompass Product Partners
  • Licensed Developers
  • OEM Partners
  • System Integrator Partners
  • PartnerNetwork Portal
  • View All
  • Our Brands
  • Our History
  • Investor Relations
  • View All
  • iTRAK Intelligent Track Systems
  • MagneMover Lite Intelligent Conveyor System
  • QuickStick Intelligent Conveyor System
  • View All
  • FactoryTalk Edge Gateway
  • FactoryTalk Batch
  • FactoryTalk Historian
  • FactoryTalk View - HMI Software
  • FactoryTalk Metrics
  • FactoryTalk Analytics for Devices
  • FactoryTalk AssetCentre
  • FactoryTalk Emonitor
  • FactoryTalk Network Manager
  • FactoryTalk TeamOne
  • Fiix CMMS
  • Augmented Reality
  • FactoryTalk Analytics
  • MES
  • ThingWorx IIoT Platform
  • Dynamic Digital Twin Software
  • Studio 5000 Design Software
  • 2D & 3D Drawings
  • Activations
  • Add-on Profiles
  • Application Code Libraries
  • Compatibility & Downloads
  • Drivers & Firmware
  • Electronic Datasheets
  • EPLAN Macros
  • Sample Code Library
  • Software Patches
  • View All
  • Control Systems Configuration Tools
  • Procurement Specifications
  • ProposalWorks Proposal Builder
  • Global Short-circuit Current Ratings Tool
  • Integrated Architecture Builder
  • View All
  • Migration & Modernization
  • Lifecycle Status
  • Product Replacement Lookup
  • View All
  • Support Options
  • Search for Answers
  • Chat Online
  • Call Us
  • View All
  • My Inbox
  • My Favorites
  • My Subscriptions
  • View All
  • Chat History
  • Service Ticket History
  • Manage Your Favorite Answers
  • Field Service Request
  • View All
  • My Training
  • View All
  • Automation Fair
  • Process Solutions User Group
  • Smart Machine Workshops
  • VirtualConnect: Smart Manufacturing
  • View All
  • Live
  • On-Demand
  • View All
  • Digital Transformation at Norbord
  • View All
  • Brighter, More Flexible Tower Light Now Available from Rockwell Automation
  • Delphi Award Received For Asset Management
  • Internal Bypass Expands Smart Motor Functionality
  • New IaaS Bundle Eases Industrial Networking
  • Rockwell Automation Names Sebastien Grau as Regional Sales Director for Middle East, Turkey and Sub Saharan Africa
  • Expanded Power Range for PowerFlex 6000 MV Drives
  • Studio 5000 Software Update Optimizes Productivity
  • FLEX 5000 I/O Modules Bring Greater Productivity and Flexibility to a Connected Enterprise
  • New Cable-Pull Switch Enhances Industrial Safety
  • Instant Industrial Device Analytics
  • Rockwell Automation to name Al Ghandi Electrical & Automation as Authorised Distributor in the UAE
  • Rockwell Automation to Broaden Connected Enterprise Consulting Expertise with Acquisition of Kalypso
  • Single-Control Multi-Well Pad Solution Cuts Costs
  • Advanced Light Curtain System Improves Flexibility and Safety
  • Automation University
  • Rockwell Automation to Showcase the ConnectedProduction Solutions and Premieres its ThinManager Software at ADIPEC 2018
  • Safe Torque Off Option Simplifies Machine Design
  • Machine Performance Analytics Bring OEM Expertise Into Producer’s Digital Environment
  • Software-Powered Connected Services
  • New Managing Director of Rockwell Automation for Sub-Saharan Africa announced
  • Rockwell Automation Simplifies Analytics for Industrial Productivity
  • New Managing Director of Rockwell Automation for Sub-Saharan Africa announced
  • Securely Deploy Cloud and Mobile Technologies with New Network Guidance
  • Rockwell Automation drive system selected for Sumitomo Rubber’s rubber mixers
  • PlantPAx DCS Roadmap
  • View All
  • Students & New Grads
  • View All
  • Hackathon Use Case for Manufacturing Optimization
  • Hackathon Use Case for Sustainability
  • Hackathon Use Case for Visual System Modernization
  • Hackathon Use Case for Dynamic Filtering
  • View All
  • 24toCode Event Recap - Winter 2019
  • 24toCode Event Recap // IT Internal Hackathon
  • Meet the 2019 IT Summer Interns
  • 24toCode Promo Video
  • Harbor View Plaza Ribbon Cutting
  • Check Your Blind Spots Mobile Tour at Rockwell Automation
  • Mechanic & Tool Apprenticeship at Rockwell Automation
  • Working at Rockwell Automation in Karlsruhe
  • Summer Internships at Rockwell Automation
  • The Intrapreneurial Skills Accelerator at Rockwell Automation
  • Makers Wanted
  • #LifeatROK w Katowicach
  • IT Summer Internship Program
  • #LifeatROK with Diogo
  • View All
  • Cisco
  • Endress+Hauser
  • FANUC
  • Microsoft
  • Panduit
  • View All
  • Our Focused Giving
  • STEM Education
  • Lifelong Learning
  • View All
  • Sustainability Report
  • Our Commitment to Diversity, Equity and Inclusion
  • Environmental, Health, & Safety
  • Ethics & Compliance
  • Global Supply Chain & Sourcing
  • Product Environmental Compliance
  • Quality Management Systems
  • Trust & Security
  • Workforce of Tomorrow
  • View All
Case StudyRockwell Automation's case studies Case Studies DistributorDistributor How to Buy EventEvent Events
Blogs DistributorDistributor How to Buy EventEvent Events
Find Products by Our Brands:
Allen-Bradley FactoryTalk
Contact Us HelpHelp Get Support LaunchpadTools and applications View All Tools
ProductivityProductivity Investor Relations
  • Literature LibraryLiterature Library
    Literature Library

    Access technical and commercial publications for hardware and software products, applications, services and solutions.

    PCDCProduct Compatibility and Download Center
    Compatibility & Downloads

    Find downloads including firmware, release notes, associated software, drivers, tools and utilities.

    KnowledgebaseKnowledgebase Support Center
    Knowledgebase

    Browse the database of questions and answers on a variety of products and technologies.

    Product ConfiguratorProduct Configurator
    Product Configurator

    Configure and select products rapidly.

    Software SubscriptionsSoftware Subscriptions
    Software Subscriptions

    One stop shopping for software and subscription services.

    2D & 3D Drawings Bill of Materials CrossWorks Electronic Datasheets Motion Analyzer My Equipment My Training E-Learning Portal Product Lifecycle Status Product Registration Product Selection Toolbox Repairs Sample Code Library Software Activations View All
    Tools
    UserUser Sign In/Create an Account
  • User Account User
Tools
Literature LibraryLiterature Library
Literature Library
PCDCProduct Compatibility and Download Center
Compatibility & Downloads
KnowledgebaseKnowledgebase Support Center
Knowledgebase
Product ConfiguratorProduct Configurator
Product Configurator
Software SubscriptionsSoftware Subscriptions
Software Subscriptions
2D & 3D Drawings Bill of Materials CrossWorks Electronic Datasheets Motion Analyzer My Equipment My Training E-Learning Portal Product Lifecycle Status Product Registration Product Selection Toolbox Repairs Sample Code Library Software Activations View All
Blog
Recent ActivityRecent Activity

Using CIP Security to Strengthen Your Defense In Depth Strategy

Share This:

LinkedInLinkedIn
TwitterTwitter
FacebookFacebook
PrintPrint
EmailEmail
Main Image

Industrial operations are increasingly becoming the target of cybersecurity attacks. There are new devices adding network connectivity as they migrate from traditional fieldbuses and standalone operation. Additional connections are being created between the IT and OT space and machine builders increasingly offer analytics if their machine can be connected to the cloud. International standards for cybersecurity, known as IEC 62443, are being updated and expanded, including requirements for end users, system integrators, and device manufacturers. These standards require defense in depth strategies to reduce the risk of attacks that cause harm considering the additional connectivity.

As you advance the cybersecurity of your operations, you need more capability at deeper levels of the defense in depth strategy. Have you performed cybersecurity assessments, minimized your attack surface with cybersecurity essentials and implemented best network segmentation practices? If you're ahead of all these, you're on the right track!

Even once you have strong security policies and protections, adding security at each layer improves your resilience against attacks. For example, how will you protect your process if a malicious actor has access behind your firewall? You may be susceptible to various attacks that need additional measures to mitigate.

What do you mean, a firewall isn’t enough?

A malicious actor could create an unauthorized connection to hardware in your system by pretending to be another kind of device. This has been demonstrated recently in industrial automation, with an imposter computer improperly configuring devices and injecting code based on insecure identification credentials.

Another attack type that's possible without communication integrity is the man-in-the-middle attack and a variant of that - the replay attack. During these attacks, someone would intercept and modify data between two devices, sometimes after collecting data that can be used to mimic normal operation. That could mask abnormal behavior that can cause equipment damage or endanger human safety.

Cybercriminals could also gain proprietary information by snooping on the network traffic between industrial devices. Whether those are secret recipes going from the MES to the PLCs, analytic data that could be used to steal manufacturing best practices, or production volume information that could be used to short stocks, data transmitted without confidentiality could be used for harm.

Every layer of defense helps, so get to the devices

To bolster security at the device level and reduce the risk of those attacks, IEC 62443-3-3 and IEC 62443-4-2 include common minimum requirements for device identity, integrity and authenticity of communications, and options for confidentially transmitting data. Four of the requirements in the standard (SR 1.2, SR 3.1, SR 3.13, SR 4.1) are almost impossible to implement at a system level without the right hardware and firmware at the device level. If you want to use devices from multiple vendors that meet those system requirements, standards and conformance testing are needed.

The CIP Security™ protocol is an open standard from ODVA, which helps solve important communication requirements that device vendors using industrial Ethernet cannot solve themselves. This standard is the only standard designed for securing communications between PLCs and devices. The CIP Security protocol provides mechanisms for validating device identity, device authentication, data integrity and data confidentiality. All three of the functional requirements and their requirement enhancements can be met using CIP Security and configured using FactoryTalk Policy Manager.

Rockwell Automation is releasing CIP Security on more products each year and other vendors are adopting this standard right now. Some of upcoming devices include retrofit opportunities to reduce the risk of cyber incidents with existing equipment too, so don’t think that you must wait for a greenfield plant to make improvements. Start considering when and how you will add more layers to your defense in depth!


Oliver Haya
Oliver Haya
Business Development Manager, EtherNet/IP Technology Adoption, Rockwell Automation
Connect:
EmailEmail
Subscribe

Subscribe to Rockwell Automation and receive the latest news, thought leadership and information directly to your inbox.

Subscribe

Recommended For You

Loading
  • Technical Question
  • Chat Technical Support
  • Phone Support
  • Contact Sales
  • General Questions
  1. Chevron LeftChevron Left Home Chevron RightChevron Right
  2. Chevron LeftChevron Left Company Chevron RightChevron Right
  3. Chevron LeftChevron Left News Chevron RightChevron Right
  4. Chevron LeftChevron Left Blogs Chevron RightChevron Right
Discover
  • The Connected Enterprise
  • Create Your Account
  • Case Studies
  • Events
Information for...
  • Distributors
  • OEM
  • System Integrators
  • Encompass Partners
  • Investors
  • Career Seekers
Contact Us
  • General Questions
  • Technical Questions
  • Local Sales & Service
  • Pricing & Availability
  • Report Ethical Concerns
Site Information
  • Legal
  • Privacy Policy
  • Cookie Preferences
  • Terms of Use
  • Trademarks
Change Country Site SelectionChange RockwellAutomation.com site selection to a different country, region or language Change Country
Romania/English

Keep Updated With Us

Sign up to receive our latest headlines for free.

Stay Informed Now
Follow Us
BlogRockwell Automation's Blog
Copyright ©2021 Rockwell Automation, Inc.
Home