Safety vs. Security: What's One Without the Other
Industrial safety systems have evolved over the years to become
increasingly complex. You rely on your safety system to protect
employees, production, and the environment surrounding your facility.
The investment in these systems is great, but the possible
ramification of their malfunction is even greater.
The media has made the potential impact of industrial accidents on
both companies and their surrounding communities very clear. Incidents
such as the refinery explosion in Texas City or the Bhopal chemical
leak disaster illustrate the significant impact that can occur when
things don’t going according to plan.
Game Changers: Connectivity & Automated Notification
The evolution of safety systems has been largely influenced by our
ability to connect various systems and to automate notifications and
alarm in the event of a safety breach.
The ability to connect plant systems together enables them to become
more efficient and dependable components of your facility’s infrastructure.
At the same time, this connection via networks (for example, TCP/IP
routable) also makes the system more vulnerable to security infringements.
Increasing regulations and standards are a direct result of the importance
being placed on safety systems, not just as a reactive alert system to crisis,
but as a more proactive and predictive way of avoiding disaster.
Much like our telephone and internet connections, we expect our safety systems
to function correctly and we rely on them to alert us if the need arises. It
is easy to overlook security issues as a possible cause for a malfunctioning
safety system.
The Advantages of a Comprehensive Security Program
The overall impact of implementing a comprehensive security program in the process
control environment is far reaching, and typically includes:
- Improving employee safety, satisfaction and morale
- Reducing loss of production and revenue from intrusion incidents
- Improving data integrity so that operators can act on accurate information
- Preventing unauthorized disclosure of information
- Preventing unauthorized denial of services
- Preventing regulatory fines by ensuring environmental information is recorded and within limits
- Preventing loss of major tangible assets or resources
- Improving public opinion and investor support
- Protecting intellectual property and trade secrets
- Preventing harm to the organization’s mission, reputation or interest
An effective industrial security program can be complex; however, it is
critical to understand the direct correlation between security and safety.
The volume of information that is moving around a facility at any given time
makes it imperative that security controls are put in place and maintained.
Process industries have traditionally focused on safety and productivity;
however, with recent threats to North American critical infrastructure, the
spotlight is on the importance of tightening security measures as well.
Mitigating control system vulnerabilities against physical and cyber attack
is necessary to ensure the safety, reliability, integrity and availability
of these systems.