Cyber is the last thing on your mind
With AI, climate change, Brexit and dare I mention Trump, running a business right now must feel like a game of whack a mole. For manufacturers specifically, margins are being squeezed from every direction, with the cost of energy, wages and raw materials increasing dramatically; the thought of spending money on something that may or may not happen, to protect against a problem you can’t even see, is a much harder sell than a more efficient machine, retraining an engineer, or simply keeping the lathe spinning.
Manufacturing businesses in this country have always been built on engineering excellence. Managing physical risk, equipment and production is your bread and butter, the digital side has never really had to be a part of that equation. Until now.
The price of ignorance
The issue is, the risk isn’t hypothetical. According to the recent Cyber security in Manufacturing report by Make UK (link here), 30% of UK manufacturers faced a “serious” cyber incident in the past year. And in manufacturing, certainly with the increasing push towards digital transformation within the sector, a cyber incident doesn’t stay a cyber incident for long. When your systems go down, so does production, scheduling, invoicing. Everything.
You don’t have to look far to see what that can look like in practice. Last August JLR suffered a relatively simple human based phishing attack which, due to a combination of poor cyber policy and integrated systems, meant that the entire operation was shut down for weeks affecting over 5,000 businesses costing the economy £1.9bn and costing JLR themselves around £200m, which could’ve been significantly reduced if they had adequate cyber insurance.
Be aware to protect your ware
The mistake a lot of people make with cyber security is they think about software first; the firewall, the password manager, the antivirus, and while all important, it’s not the right place to start.
If we think about cyber security how you would approach safety on the shop floor, you’ll realise the most important factor is awareness. You don’t just buy a light curtain for your CNC machine and deem it to be safe, the human steps before that are what prevents injuries.
Much like how you train an operator to never place their hands in a pinch point or to bypass a physical guard, cyber security is much the same. Even something as simple as ensuring staff know to question suspicious emails, or update their PCs can make a huge difference.
Lack of awareness, training and procedure result in issues, getting lazy with incoming emails and falling for a phishing scam is the same as lazily operating a press brake, only you lose data instead of a finger.
The best part is, much like proper lockout/tagout policies, creating a culture of awareness and process is much cheaper than buying fancy software without really understanding why.
Foundation not a finish line
Cyber Essentials, I believe, is the perfect place to start. It’s a relatively simple, government backed baseline which is becoming increasingly recognised and required in the industry. Being a low cost self assessment, becoming Cyber Essentials certified is relatively straightforward, especially if working with an IT provider; and it’s certainly much cheaper and more straightforward than the likes of ISO 27001 or similar.
The reason I would recommend starting with Cyber Essentials is twofold.
On the one hand, it’s becoming increasingly required for not just defence contracts but most larger companies throughout their supply chain. If you are already or are looking to expand into larger primes or public sector contracts, Cyber Essentials is essentially mandatory rather than a nice to have.
The second, more subtle reason is that it creates a ‘safety first’ mindset, by forcing yourself to self audit as well as think about things such as permissions which normally wouldn’t be on your radar, you help create that all important awareness around the risks involved with leaving cyber security untouched.
The one thing Cyber Essentials isn’t however is the finish line. Being Cyber Essentials certified does not automatically mean you are safe, and without making sure yourself and your staff are aware of the risks year round it becomes an almost pointless exercise.
Consider Cyber Essentials your cheap easy ticket into bigger contracts that can act as a foundation for security awareness in your business.
A Chain Only as Strong as Its Weakest Link
Cyber security really doesn’t have to be complicated, and it definitely doesn’t have to require huge system overhaul or expensive software. It starts with accepting that cyber criminals are real threats to your business, and then building a culture of good habits and mindset around the issue at hand.
There’s no point installing a state of the art security system at your factory if staff keep leaving the door open when they go for a break.
Cyber security, and more broadly IT in general aren’t just issues for boffins in a backroom anymore. At the end of the day these issues have to be understood and prioritised by every single person organisation wide in order simply to keep the business operating and the lathe spinning.





