Industrial control system security: how to protect manufacturing from cyberattacks and reduce business losses

Cyberattacks on ICS can halt production and cost millions hourly. Learn how to reduce risks, secure equipment, and ensure operational stability.

  • Industrial Control Systems: Overview and Features
  • Industrial Control System Security: Main Risks
  • Methods for Protecting Automated Systems
  • Legal framework and liability

A production shutdown costs 2 million an hour - that is how much a business can lose for every 60 minutes of downtime caused by a cyberattack on automated control systems. We explain where security threats to industrial control systems come from, how to reduce risk with simple rules, and how to build protection to avoid multi-million losses.

Industrial Control Systems: Overview and Features

  1. Industrial control systems are systems that optimize production and business operations while keeping humans in control of key decisions. Unlike conventional IT systems that work with data, industrial control systems directly manage physical equipment: machine tools, pumps, and power equipment.

  2. They operate in real time and do not allow downtime, even for security updates.

  3. The service life of such systems can reach 30 years, creating unique security challenges: outdated software, conflicts with modern protection tools, and high risks from any failures.

  4. Therefore information security for automated systems is critical.

  5. If a cyberattack on an office network usually leads to data leaks, a failure in an industrial control system has more serious consequences: - it stops production; - it disables equipment; - it violates environmental regulations; - it creates a threat to people. For example, hacking an oil pipeline control system can lead to an oil spill, and an attack on an energy system can cause power outages across entire districts.

  6. In addition, regulators strictly control the protection of critical infrastructure, and violations can result in heavy fines. Investments in industrial control system security determine the stability of business processes and production operations.

  7. According to a study[InfoWatch Analytical Center](https://gk-ur.ru/info/news/prioritety-v-zashchite-asu-tp/), global spending on industrial system protection reached $20 billion in 2024, and companies that implemented comprehensive protection measures reduced downtime by 40-60%.

Industrial Control System Security: Main Risks

Attackers constantly invent new ways to break into automated systems. These attacks target critical infrastructure (energy, transport, manufacturing) and can halt operations within minutes. But if you know how criminals operate, you can identify threats faster and reduce losses. Threats to industrial control systems and how they are carried out:

Threat typeFrequency of occurrenceSeverityHow It Appears in Practice
Spyware45% of all malwareHighThey are introduced through phishing emails or software vulnerabilities. They often remain undetected for a long time, collecting data on technological processes and sending it to attackers.
Ransomware27% of all malwareCriticalThey block operators from working and demand a ransom to restore access. They can completely paralyze production for several days, causing significant financial losses.
Targeted APT attacks35 major attacks/quarterCriticalAPT attacks are hard to detect, but they destroy everything. Attackers use advanced methods to bypass defenses and gain control of critical equipment.
Supplier Attacks3x growth by 2025HighThey compromise software or hardware during the supply stage. A supplier breach gives access to the system before deployment - the attack takes effect once the equipment has already been installed.
Phishing and social engineering+28% phishing resourcesMediumAn employee receives an email from management, shares access, or installs malware, thinking they are completing a task.
Insider threats37% of all incidentsHighEmployees harm security by mistake or on purpose - disabling protections or sharing data with outsiders.

According to According to Kaspersky Lab, in early 2025 CIS was among the six regions worldwide where the number of attacks on industrial control system computers continued to grow, even though the global trend declined. Attackers are focusing on CIS industry - attacks are rising despite the global decrease.

Methods for Protecting Automated Systems

Standard protection tools (basic firewalls, signature-based antivirus, and simple password policies) often cannot handle targeted attacks on industrial infrastructure. To avoid downtime and financial losses, you need a comprehensive security system.

It should combine technical, organizational, and software-based security measures. Technical measures- include installing equipment and configuring systems that physically prevent unauthorized access and attacks: - Firewalls between corporate and production networks. - Intrusion monitoring systems to detect abnormal activity. - Multi-factor authentication for access to critical systems. - Regular data backups with integrity verification. Organizational measures - are aimed at establishing operating rules and training staff, helping reduce risks caused by human factors. - Clear security policies for working with industrial control systems. - Staff training on identifying phishing attacks. - Regular security audits and penetration testing. - Incident response plans with assigned roles. Software measures - are related to software updating and configuration, protect against software vulnerabilities, and ensure secure data transfer between systems: - Timely updating of software and firmware for industrial control system components (applying patches to SCADA systems, updating PLC controller firmware and network routers). - Specialized industrial protocol protection systems (using security gateways for Modbus, OPC UA, PROFINET). - Cryptographic data protection (VPN tunnels for remote access, GOST data signing). - Centralized logging and analysis of security events (collecting logs from PLCs, HMIs, and servers in a SIEM system to detect anomalies).

Discuss your challenge with an architect

Legal framework and liability

  1. Security standards help account for real risks and production-specific conditions when building a protection system. - IEC 62443 - an international standard that helps choose the right level of protection for a specific threat.

  2. This reduces costs and simplifies compliance with regulatory requirements. - ISO/IEC 27001 - an international standard for information security management systems.

  3. Provides a methodology for creating, implementing, and improving an ISMS.

  4. Focuses on risk management and continuous improvement of the security system. - FSTEC No. 31 - a mandatory standard for industrial control systems at critical facilities.

  5. FSTEC requirements help build protection based on the importance of the asset, which reduces costs and simplifies audits. - Federal Law No. 187 on Critical Information Infrastructure- governs the protection of critical information infrastructure.

  6. Under the law, organizations are required to notify regulators about incidents: violations are subject to fines starting at 50,000 rubles. In case of serious consequences, criminal liability is possible, including up to 10 years in prison.

How to Build Protection: A Step-by-Step Plan

Downtime costs businesses 2 million rubles per hour. Below is a step-by-step plan used by CIS industrial companies to reduce downtime by 60-80%.

1. Audit existing systems

Check the network, equipment, and event logs - this helps identify vulnerabilities before an attack. For example, at the Chelyabinsk Pipe Rolling Plant, an audit found 12 critical vulnerabilities in the furnace control system.

It took 3 weeks to fix, but they avoided a potential downtime cost of 23 million rubles per day. _To save time and resources, we recommend regularly conducting__a comprehensive security audit__, which will help identify critical vulnerabilities and create a remediation plan tailored to industry specifics._

2. Develop security policies

Clear and simple access rules reduce the number of incidents and errors when working with industrial control systems. By involving department heads in policy development, you get solutions that reflect real workflows and are adopted into practice faster. This reduces the load on the IT department and speeds up recovery after failures. For example, at the Kamaz plant, simple access rules were introduced for conveyor control systems. Operators can now no longer connect USB drives or install third-party software.

The number of incidents fell by 65% in six months.

3. Implement technical security controls

Use firewalls to protect the network perimeter and set up backups for important data. Monitor connections and data integrity so you can detect threats faster. Example: at an oil refinery in Ufa, firewalls were installed between the office network and the pipeline control system, which stopped 98% of external intrusion attempts.

4. Train employees

Trained employees are the first line of defense. Companies whose staff regularly undergo training face successful phishing attacks less often and recover faster after incidents. For example, a chemical plant in Tolyatti held 4 cybersecurity hygiene drills for engineers. A month later, phishing attacks against staff began to fail in 9 out of 10 cases.

5. Set up monitoring and response

24/7 monitoring makes it possible to detect attacks within minutes. This minimizes losses and prevents malicious code from spreading across the network. Set up alerts for suspicious activity around the clock. For example, an energy company in Yekaterinburg created a 24/7 monitoring center, and the plant now detects attacks in 12 minutes instead of the previous 3 hours.

6. Regularly update protections

Regular checks make it possible to find vulnerabilities before attackers exploit them. This reduces the risk of production shutdowns and losses from downtime. For example, a machine-building plant in Rostov-on-Don conducts penetration tests every quarter. Over 2 years, the company reduced the number of successful attacks by 90%.

Cyberattacks on Industrial Control Systems: How Global and CIS Companies Were Hit

Cyberattacks on industrial enterprises are becoming increasingly destructive. According to the study, in the first half of 2025, the number of attacks on CIS companies increased by 27%, reaching 63 thousand incidents.

At the same time 80%organizations suffered severe consequences, including production shutdowns and financial losses. We will look at real cases and how criminals carry out threats in industry and energy. The largest U.S. oil pipeline, Colonial Pipeline In 2021, it fell victim to a DarkSide ransomware attack. The attackers gained access to the pipeline control system through leaked employee credentials. The company shut down the pipeline for 5 days, triggering a fuel crisis.

03

Damage exceeded $4.4 million, excluding reputational losses. Bashneft In 2024, it faced a targeted attack on oil extraction and transport control systems. The attackers used compromised contractor accounts to access the industrial network. Rig operations were halted for 3 days, and losses from downtime and supply disruptions exceeded 200 million rubles.

04

These examples show three important trends: - attacks are moving from IT systems to industrial equipment; - attackers use supply chains to penetrate networks; - the damage includes not only financial losses, but also shutdowns of critical infrastructure.

The Economics of Security: How to Calculate ROI from Protection Investments

Without investing in protection, a business risks losing tens of times more - due to downtime, breaches, and fines.

To justify security spending, you need to count not only direct costs, but also the losses that were prevented.

The main performance indicator is ROI (return on investment).

The calculation formula is simple: ROI = (Prevented losses - Protection costs) /

Protection costs × 100%

According to studies, more than half of industrial enterprises lose over $1 million from cyberattacks.

At the same time, ransom paid to attackers accounts for only 12% of all losses.

The main expenses are: - incident remediation (22%); - lost profit (19%); - production downtime (17%); - equipment repairs (19%); - property damage (12%). Let's look at a specific example.

A hypothetical chemical plant estimates potential downtime losses at 50 million rubles per day. Assume the probability of an incident without protection is 15% per year.

The cost of implementing protection is **12 million** rubles

In this case, the prevented damage will be 50 million rubles × 0.15 = 7.5 million rubles per year.

Over 3 years: 7.5 million x 3 = 22.5 million rubles.

Thus: ROI = (22.5 million - 12 million) / 12 million × 100% = 87.5%

Security Checklist: 10 Practical Recommendations

We have prepared a list of recommendations to help managers apply the basic protections for automated systems. The checklist steps can be implemented quickly, even without a dedicated IT team, and will deliver results within the first month. 1. Start with a systems analysis, whose downtime will halt production. Assess the damage from attacks on each system and decide what to protect first. 2. Install firewalls. This will prevent attacks from spreading from the corporate network to the industrial one.

Set filtering rules for industrial protocols to block unauthorized commands. 3. Store critical data and verify its integrity.Make sure backups are stored separately from the main systems. Regularly test data recovery - this ensures they will work in an emergency. 4. Implement multi-factor authentication.The fewer permissions a user has, the lower the risk of error. Leaks most often happen through contractors.

5. Install security updates regularly.Without updates, vulnerabilities remain open for months. Test patches in isolation - this protects critical nodes without risking shutdown. 6. Run cyber hygiene and incident response drills. Use real examples from your industry - this increases employee engagement. Hold regular short sessions instead of occasional multi-hour lectures.

7. Check whether contractors comply with your security requirements.Include cybersecurity clauses in every contract. Regularly audit their access systems to your infrastructure. 8. Monitor abnormal activity in systems 24/7. Set up alerts for suspicious events in real time. Start by monitoring the most critical systems that production continuity depends on. 9. Define who is responsible for what in the event of an attack.

Specify the response sequence for different types of incidents and regularly run drills to practice the plan. 10. Regularly check the system for vulnerabilities. External audits help uncover vulnerabilities you cannot see from the inside - by fixing them, you reduce the risk of downtime and losses.

Discuss your challenge with an architect

Discuss the article: Industrial Control System Security: How...

Send via: