While the threats of cyberattacks are significant, they are not unavoidable. Warehouses that proactively ensure they are taking appropriate actions to protect their OT environment can feel secure in their operations and know that they are maximising uptime and activity of their systems.
PROACTIVE APPROACHES TO MITIGATE RISKS
Although warehouses are compliant with regulations and frameworks that help protect against cyberthreats to their IT infrastructure, these are insufficient if a warehouse becomes an OT environment. As soon as one intelligent system is added to a warehouse, it is an OT environment, which requires different industry standards and regulatory requirements.
The best place to begin for guidance is the IEC 62443 standards, which are considered the industry standard for securing industrial automation and control systems. They provide best practice options for risk assessments, system design, access management and security. Within the EU, the NIS2 Directive adds a further level of security for cybersecurity governance. Understanding these regulations and how to consistently apply them is vital for proactive warehouse safety.
The responsibility for sufficient cybersecurity is not the job of one person; it is managed by a combination of internal and external teams with an ongoing commitment to proactive maintenance. Beginning from procurement, the service options for cybersecurity must be discussed with the service provider, including how they ensure that they safely set up the system and protect the network it will join.
Following on from this, an agreement must be made in relation to the ongoing protection, including agreed ways to manage patching, threat monitoring, and specialist expertise throughout the system’s lifetime. Ensuring that this is agreed on at this stage means that if any issues do arise, the next steps and responsibilities will be already specified, rather than costing time to choose a course of action at a crucial moment .
Through these discussions, the focus should be on ensuring uptime is prioritised and actions are taken by both parties to ensure long-term operations and system integrity. Response protocols need to be agreed on, with both parties understanding their priorities and which actions to take at each stage. This should form the basis of an ongoing relationship between the service provider and the warehouse operators, in order to ensure the best long-term success.
EXAMPLES OF RESPONSIBILITIES
While the exact procedures will vary from company to company, warehouses that are aiming to maintain their uptime and minimise any threats that come from attacks to their OT environment should take responsibility for the following actions.
AREAS WHERE A COMPANY OWNER SHOULD TAKE RESPONSIBILITY
| Area of responsibility |
Actions that may be included |
| Risk accountability |
Building an appropriate CSMS, implementing and maintaining it to handle governance, policies, and continuous monitoring. |
| Zone and conduit definition |
Segmenting warehouse areas into distinct security zones, with target levels for each. |
| Procurement and supply chain control |
Qualifying system integrators and service providers, enforcing security requirements for third-party hardware or software. |
| Patch and maintenance management |
Ensuring there is no unplanned downtime and actions are taken in a timely manner. |
| Asset inventory management |
Creating an asset inventory of all updated hardware, software, cloud service and operational technology. |
| Business continuity and recovery management |
Ensuring that backups are performed, protected, and regularly tested to verify the ability to recover systems and data after an incident, should one occur. |
| Personal accountability |
For executives, accepting direct regulatory penalties if a major security breach occurs due to unmanaged risks. |
AREAS WHERE THE SERVICE PROVIDER SHOULD TAKE RESPONSIBILITY
The service provider also plays a vital role, with their responsibilities likely to include the following activities. Successful risk management is the result of both the service provider and the company owner taking appropriate responsibility for their defined areas.
| Area of responsibility |
Example of relevant activities |
| Lifecycle security |
Managing all aspects of security from the initial design through to the eventual retirement. |
| Cybersecurity Requirements Specification (CRS) |
Creating the CRS, setting security zones, and targeting specific security levels. |
| System monitoring |
Using formal processes to assess risks and plan security controls. |
| Implementing required defence strength |
Ensuring defence strength is appropriate against all attack types, from accidental misuse to sophisticated cyber attacks. |
| Third party verification |
Ensuring every integration has appropriate verification. |
| Incident reporting |
Reporting incidents within the agreed timeframes to the correct authorities. |
| Management accountability |
Training to ensure executives approve measures and maintain a mandatory level of knowledge. |
TAKEAWAY
Cybersecurity is not an afterthought; it must be considered from procurement in order to ensure there is an effective setup that will keep the entire warehouse safe. Warehouses can benefit greatly from smart and automated intelligent technology, however in order to receive the optimal benefits, the system and OT must be protected appropriately.
Developing a strong cybersecurity plan that considers the entire network, hardware and software, and responsibilities for both the warehouse and service provider, minimises unexpected downtime and ensures optimal operations. When this is implemented and protocols are followed, the system will recover rapidly from any risks or attacks, and will be sufficiently protected throughout its lifetime.