{"title":"围绕石化行业的工业控制系统(ICS)采取网络安全措施","authors":"Lushen Rajaruthnam, Rina Peach","doi":"10.1016/j.jlp.2025.105803","DOIUrl":null,"url":null,"abstract":"<div><div>The fast adoption of technologies that enable the Fourth Industrial Revolution (4IR) in the South African industrial sector has been well noted, and is advancing to meet global pressures. Cybersecurity countermeasures to protect and safeguard the expanding interconnected nature of several industrial sectors have not kept pace. The steadfast march toward digitalization and Industrial Internet of Things (IIoT) optimization increases industrial control systems' (ICSs) vulnerabilities, and they become ripe targets for the wicked. This study aimed to identify the current level of the cybersecurity maturity of ICS assets in the South African petrochemical sector and to investigate the root causes of that level of maturity. Extensive research was done into industry best practices, lessons learned, and global governing bodies of knowledge. A target maturity (from NIST 800-xx and IEC 62443-x-x) and possible contributing factors to poor adoption were identified and tested with a population in a cluster of South African petrochemical facilities. The research propositions concurred with the results, showing systemic barriers to adequate ICS cybersecurity adoption. A risk-based approach and a high-level recommendation roadmap were developed to address poor maturity levels. More specific sector studies could be conducted in the future to refine the findings, but this framework and roadmap could be implemented directly as a starting point for an organization's ICS cybersecurity journey.</div></div>","PeriodicalId":16291,"journal":{"name":"Journal of Loss Prevention in The Process Industries","volume":"99 ","pages":"Article 105803"},"PeriodicalIF":4.2000,"publicationDate":"2025-09-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Incorporating cybersecurity measures around industrial control systems (ICS) within the petrochemical sector\",\"authors\":\"Lushen Rajaruthnam, Rina Peach\",\"doi\":\"10.1016/j.jlp.2025.105803\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The fast adoption of technologies that enable the Fourth Industrial Revolution (4IR) in the South African industrial sector has been well noted, and is advancing to meet global pressures. Cybersecurity countermeasures to protect and safeguard the expanding interconnected nature of several industrial sectors have not kept pace. The steadfast march toward digitalization and Industrial Internet of Things (IIoT) optimization increases industrial control systems' (ICSs) vulnerabilities, and they become ripe targets for the wicked. This study aimed to identify the current level of the cybersecurity maturity of ICS assets in the South African petrochemical sector and to investigate the root causes of that level of maturity. Extensive research was done into industry best practices, lessons learned, and global governing bodies of knowledge. A target maturity (from NIST 800-xx and IEC 62443-x-x) and possible contributing factors to poor adoption were identified and tested with a population in a cluster of South African petrochemical facilities. The research propositions concurred with the results, showing systemic barriers to adequate ICS cybersecurity adoption. A risk-based approach and a high-level recommendation roadmap were developed to address poor maturity levels. More specific sector studies could be conducted in the future to refine the findings, but this framework and roadmap could be implemented directly as a starting point for an organization's ICS cybersecurity journey.</div></div>\",\"PeriodicalId\":16291,\"journal\":{\"name\":\"Journal of Loss Prevention in The Process Industries\",\"volume\":\"99 \",\"pages\":\"Article 105803\"},\"PeriodicalIF\":4.2000,\"publicationDate\":\"2025-09-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Loss Prevention in The Process Industries\",\"FirstCategoryId\":\"5\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S095042302500261X\",\"RegionNum\":3,\"RegionCategory\":\"工程技术\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"ENGINEERING, CHEMICAL\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Loss Prevention in The Process Industries","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S095042302500261X","RegionNum":3,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"ENGINEERING, CHEMICAL","Score":null,"Total":0}
Incorporating cybersecurity measures around industrial control systems (ICS) within the petrochemical sector
The fast adoption of technologies that enable the Fourth Industrial Revolution (4IR) in the South African industrial sector has been well noted, and is advancing to meet global pressures. Cybersecurity countermeasures to protect and safeguard the expanding interconnected nature of several industrial sectors have not kept pace. The steadfast march toward digitalization and Industrial Internet of Things (IIoT) optimization increases industrial control systems' (ICSs) vulnerabilities, and they become ripe targets for the wicked. This study aimed to identify the current level of the cybersecurity maturity of ICS assets in the South African petrochemical sector and to investigate the root causes of that level of maturity. Extensive research was done into industry best practices, lessons learned, and global governing bodies of knowledge. A target maturity (from NIST 800-xx and IEC 62443-x-x) and possible contributing factors to poor adoption were identified and tested with a population in a cluster of South African petrochemical facilities. The research propositions concurred with the results, showing systemic barriers to adequate ICS cybersecurity adoption. A risk-based approach and a high-level recommendation roadmap were developed to address poor maturity levels. More specific sector studies could be conducted in the future to refine the findings, but this framework and roadmap could be implemented directly as a starting point for an organization's ICS cybersecurity journey.
期刊介绍:
The broad scope of the journal is process safety. Process safety is defined as the prevention and mitigation of process-related injuries and damage arising from process incidents involving fire, explosion and toxic release. Such undesired events occur in the process industries during the use, storage, manufacture, handling, and transportation of highly hazardous chemicals.