Featured Image

Building an Advanced Cybersecurity Plan: Engagement and Reinforcement

Cybersecurity protects your – and your clients' – assets. This series dives into how you can integrate a successful cybersecurity plan. From company culture to training and maintaining your personnel, creating a safe business environment starts here.
May 02, 2022

There are multiple strategic and competitive reasons to implement an advanced cybersecurity plan.

From a defensive perspective, a cybersecurity implementation is designed to protect company assets from threats that can disrupt operations. It is also intended to protect against intruders who may try to access company information and data. While developing and maintaining an advanced cybersecurity implementation is burdensome, it also is a strategic initiative to protect a company’s bottom line.

From an offensive perspective, customers want to do business with companies that they can depend on – a secure supply chain. An advanced cybersecurity plan can reassure existing customers that that their supply chain partners will be there when they need them, reliable and consistent. This can also position a company to secure new business, as it demonstrates their commitment to being a consistent and reliable partner and provides a differentiation that will take others time and effort to match.

Industry recognizes a couple of different cybersecurity models that are being deployed by U.S. companies. The National Institute of Standards and Technology (NIST) standard SP 800-171 has been adopted by the Department of Defense (DOD) for their Cybersecurity Maturity Model Certification (CMMC) program. Other government agencies and companies in the DOD supply chain are adopting, or considering adopting, this standard. Since this standard is going to have a significant impact on the manufacturing industry, we will use it as a guideline for this “Building an Advanced Cybersecurity Plan” series of articles.

A company’s cybersecurity plan should be integrated into the very fabric of the company’s culture, which ensures the company operates in a secure manner. This means that everyone in the company, and everyone who interacts with the company, has a responsibility to protect company assets and proactively avoid the introduction of cybersecurity threats into the company’s systems and network.

Not every individual has the same interaction with business systems nor has the same responsibilities relative to cybersecurity issues. Early in the process of developing a cybersecurity plan, a company should define a set of specific roles that categorize everyone in the business based on how they interact with business systems. As various aspects of your cybersecurity plan are developed, consideration should be given to how each part of the plan interacts with each of these roles. This provides a foundation upon which a company can clearly communicate to every individual their personal responsibilities relative to protecting company assets.

Typically, a cybersecurity plan is not fully evolved before it is launched. Additionally, a cybersecurity plan is never complete – it should be continually updated to address changes in security threats. Communications and training are key to drive personnel engagement with the security plan. Periodic training is required to reinforce the importance of each person’s contribution to the security of business assets. This also provides the opportunity to communicate changes and updates to the security plan relative to each role.

Training content should be customized to the scope of information applicable to each role; not everyone should be burdened with trying to understand all aspects of the cybersecurity plan. However, the content of the training should include information about the security responsibilities of others with whom an individual may interact. For example, a manager’s training should be extended to include content applicable to those who report to the manager. Training for purchasing personnel should be extended to include content applicable to the exchange of information with vendors. Likewise, training for maintenance personnel should include content applicable to outside service providers.

Once you have defined a communications and training plan optimized by role, you have the foundation to advance your company’s cybersecurity culture and engage everyone associated with your security strategy. Periodic training furthers engagement with your strategy and reinforces each person’s responsibilities for protecting the company’s assets.

As you continue to build out the balance of your cybersecurity program, you can then utilize this structure to communicate changes/enhancements to your program and how those changes impact the responsibilities of each person associated with your business.

For more details of specific actions to take when building the training and engagement portions of your cybersecurity plan, see section 3.2, “Awareness and Training,” of NIST standard SP 800-171.

John Turner
Director of Technology for FA Consulting & Technology (FAC&T) and member of the MTConnect Institute.
Recent technology News
To build or enhance your company's cybersecurity plan, one of the first steps to consider is mapping out all access points to your company’s systems and network, including the interaction points between various systems within and outside the network.
Interested in adding MTConnect? Recently the AMT-Virginia Tech team simulated a manufacturing environment of robotic arms performing material transportation. The collected and visualized data provides insight into process monitoring and machine efficiency.
Check in for the highlights, headlines, and hijinks that matter to manufacturing. These lean news items keep you updated on the latest developments.
Proactively addressing cybersecurity can turn a “necessary evil” into a competitive advantage. Implementing a solid cybersecurity plan can reassure existing customers that they have made the right choice in choosing your company as a supplier.
Everything from the chemistry of the insert to the capacity of the spindle drive to the control algorithms for the axes is different. And the differences are accelerating. So what we “know” could be what we “knew” because of the change in tech.
Similar News
By Stephen LaMarca | May 13, 2022

Additive repairs for the F-35. LIFT’s initiative doesn’t let down. Harder, better, faster, stronger. Agility robotics has Amazon’s attention.

5 min
By Tim Shinbara | May 11, 2022

Collaborative robots (cobots) aren’t superheroes, but they are rescuing manufacturers of all sizes from the grip of a crippling labor shortage. Their ease of use and flexibility to take on many tasks are increasing their popularity.

5 min
By Benjamin Moses | May 06, 2022

New way to produce metal powders. Pittsburgh is an automation powerhouse. Nothing is ever certain. Always a new way. Set phasers to culture.

5 min