ABB Ability Cyber Security Event Monitoring

Transcription

—ABB Ability Cyber SecurityEvent Monitoring Gain unique insights into industrial security events

—Industry 4.0 has the potential totransform your productivity,minimize your costs, and enhanceyour product quality.Digitally connecting your assets andcontrol systems helps to optimizeyour process performance and drivecustomer value. ABB helps you gainthese benefits without compromisingcyber security.Industry 4.0 success dependson Industry 4.0 security.

ABB ABILIT Y CYBER SECURIT Y EVENT MONITORING3—Industrial systems face elevatedcyber security risksEmbrace digital transformation for your organizations without compromising cybersecurity. Connectivity across OT (Operational Technology) / IT (Information Technology)increases the amount of vulnerabilities that can be exploited by cyber attackers.Cyber attacks against process facilities are becoming more sophisticated—and costly.60%of surveyed organizations1 experienced a breach in their industrialIn fact,control systems (ICS) or supervisory control and data-acquisition systems (SCADA).Actively managing cyber security is crucial to addressing cyber security risk andreducing potential impact.Key risk factorsDistributedsystemsInsufficientsecurity visibilityAssetcomplexityPotential impactsProcesscomplexityInsufficientsecurity awarenessInsufficientsecurity expertiseLucrative andattractive targetthat leads sHealth andsafetyKey considerations when protecting your OT environmentTo protect your OT environment, a cyber security solution should meet as many of these criteria as possible:ComprehensiveProvides visibilityof your entire OTenvironment to detectthreats, and helps yoursecurity team accuratelyrespond to attackers.1McKinseyAutomatedEliminates manuallog collection andinvestigation tospeed up responseto security incidents.CompliantSupports internationalrequirements such asIEC62443 and ISO27001to streamline compliance.ProvenImplemented by an organizationwith demonstrated domainexpertise in deploying andmaintaining industrialautomation systems anddeep experience protectingOT environments.

4ABB ABILIT Y CYBER SECURIT Y EVENT MONITORING—ABB Ability Cyber Security Event MonitoringPeople, process, and technologyABB Ability Cyber Security Event MonitoringService is the first to bring event monitoring tothe industrial space, enabling your organizationto focus on providing value to your end customer.How it worksABB Ability Cyber Security Event Monitoringhas two distinct solution packages: people &process, and technology.This unique solution leverages established ITtechnology and processes and applies them tothe industrial space to expose potentiallymalicious activity. Our OT solution package incombination with IT technology solves manychallenges posed by industrial systems that can'tbe solved with IT technology alone.Technology: ABBs proprietary technology collectsevents from OT and IT systems and devices in theproduction system and forwards them to theSecurity Information & Event Manager (SIEM),where they are analyzed using ABBs unique set ofuse-cases specifically developed for IndustrialControl Systems (ICS).People & process: ABBs industrial cyber expertsdeploy the required technology, monitor thesystem and respond to malicious activity. Ourrunbooks enable our incident response teams topromptly and effectively address identified threats.—Three steps to protecting your OT networks1CollectCollect log data fromindustrial systems anddevices without impactingproduction.2DetectAccurately detect cyberthreats using purpose-builtOT use-cases.3RespondLeverage ABBs industrialcyber experts to quicklyrespond to detected threats.

E F F E C T I V E C Y B E R -T H R E AT D E T E C T I O N A N D A N A LY T I C S5—FeaturesABB Ability Cyber Security Event Monitoring enables yoursecurity team to more effectively detect, prioritize andrespond to threats across your OT network. In turn, mitigatingthe impact of security incidents significantly.Non-intrusive Event CollectionAccess to ExpertsIndustrial Cyber AnalystsCompliance AssistancePurpose-built Use-casesFlexible SIEM deploymentMulti-system support—Opportunity for customers with an existing IT event monitoring solution Before ABB My team has to manually retrieve andinvestigate logs from various sources.This is a long, tedious process that: delays detection often fails to detect a cyber threat misuses resources by investigatingunimportant or low criticality events We have an SIEM solution that monitorsour IT environment and need the sameprotection for our OT environment.W ith ABBA BB Ability Event Monitoring gavemy security team visibility into ourentire OT environment. We spendless time performing manualmonitoring tasks, detect threatssooner, and with the time wepreviously spent on manual tasks,we can now focus on innovatingour processes and providing valueto our end customers.Amanda, VP of IT

6ABB ABILIT Y CYBER SECURIT Y EVENT MONITORING—BenefitsFor industrial operations looking to have visibility into theirentire OT network, ABB Ability Cyber Security Event Monitoringprovides a solution that exposes malicious activity.Meet complianceYour security team quickly meets internal and external compliance requirements reducing risk of failing to meet regulations.Provides insightABB Ability Cyber SecurityEvent MonitoringQuick responseYour security team gains valuableinsight into OT systems andnetworks, enabling them to detectand prioritize threats acrossmultiple systems and sites.Flexible solutionABBs Industrial Cyber Experts,spread across the world, ensuresquick and professional responseto detected threats.Developed to integrate with yourexisting setup and strategy.—Opportunity for customers without an IT event monitoring solution Before ABB My OT systems are at constant risk ofcyber attacks. I have a process thatneeds 24x7 monitoring with quickresponse times, but I lack the resourcesto manage and monitor my OTenvironment myself. And, I don’t have an SIEM solution.I am looking to improve our OT cybersecurity, and need ABB’s expertise andresources to handle security-relevantevents and threats.W ith ABBA BB monitors and manages myOT environment with a mixture ofpeople and technology. They deliverquick detection, classification,investigation, and response toalerts. Plus, ABB provides detailedreports, including alert analysis,improvement suggestions, and ROI.Fred, Plant Manager

E F F E C T I V E C Y B E R -T H R E AT D E T E C T I O N A N D A N A LY T I C S7—Two flexible ways to deployABB Ability Cyber Security Event Monitoring can be deployed inone of two flexible ways, each one depending on your strategy.If you have IT monitoring.If you do not have any monitoringsolution.You maximize the value of your investment byprotecting your OT environment using yourcurrent setup.Leverage ABBs personnel and experience to startto monitor your OT systems for threats.ABB provides Collect & Correlate package ABB technology that enables safe and securecollection of events from your ABB OTsystems ABB OT Use Cases Support Bring your own IBM Security QRadar SIEMABB provides Monitor & Respond packageIn addition to the features of Collect andCorrelate, Monitor & Respond adds: 24x7 Monitoring using IBM Security QRadar SIEM deployed in a cloud or onpremise Incident Response—Services packages tailored to your needsCollect & CorrelateMonitor & RespondABB Event Collection Technology33ABB OT Use Cases33Support33Bring your own IBM Security QRadar SIEM3oIBM Security QRadar SIEM (cloud or on-premise)o3Event Monitoring (24x7)-3Response Retainero3Incident Responseo311Professional installation included3 included o optional - not included

—Why ABBABB delivers superior technologyand proven domain expertisePeopleABB pioneered the development of electrical and automation technologiesand has years of experience helping customers protect control systems andother automation assets.ProcessABB’s control systems are present globally across many industries. We knowthe type of cyber threats our customers face and what needs to be done tomitigate risks. We stay ahead of threats by investing heavily in research anddevelopment to continuously improve our security offerings.TechnologyABB can support our customers throughout the lifecycle of their assetsthrough our products, services and expert operations by making technologyrelevant to customers in industrial sectorwww.abb.com/cybersecurity Copyright 2021 ABB. All rights reserved. Specifications subject to change without notice.9AKK107991A8218—ABBOperating in more than 100 countries.

For industrial operations looking to have visibility into their entire OT network, ABB Ability Cyber Security Event Monitoring provides a solution that exposes malicious activity. Fred, Plant Manager Before ABB My OT systems are at constant risk of cyber attacks. I have a process that needs 24x7 monitoring with quick