zuruck zur Themenseite

Articles and background information on the topic

Interview with Herbert Hufnagl, TTTech

Andrea Gillhuber,

"Cybersecurity affects the entire supply chain"

TTTech Industrial is one of the first companies in Austria to be certified by TÜV Austria in accordance with the industrial cybersecurity standard IEC 62443-4-1. Herbert Hufnagel explains what this means for processes, products and users.

Herbert Hufnagl is General Manager and Member of the Board of TTTech Industrial.

© Uwe Niklas / Computer&Automation

What exactly does IEC 62443-4-1 certification mean?

Herbert Hufnagel: IEC 62443 is the established international cybersecurity standard for the industrial sector, which comprises several sub-standards. IEC 62443-4-1, to which TTTech Industrial has been certified, relates to secure product development and lifecycles. This is more or less the framework - the sub-standard defines the basics for security processes such as risk analyses, documentation and tests. This must first be established in the company and the employees must also live these processes - this does not happen overnight, but takes one to two years.

The implementation of the processes is checked and confirmed by an institute such as TÜV Austria as part of the certification process - this involves training, regular analyses and tests. This is then the basis on the company side and, building on this, you can look at the individual products. In our case, it's about our IIoT platform 'Nerve', which we will have certified according to the IEC 62443-4-2 sub-standard; our customers can then build their application on a certified basis, which they can then certify more easily.

Can you briefly explain the relationship between process and product certification?

During the Covid-19 pandemic, there was a huge leap in the networking of industrial systems, which unfortunately also led to a large number of cyberattacks in the industry. That's why cybersecurity is also very important for us as a supplier, because ultimately it's an issue that affects the entire supply chain. If a company that we supply has to implement the NIS2 directive, then it naturally also requires its suppliers to be able to meet the directive's requirements. We wanted to be able to offer this to our customers as quickly as possible.

We are therefore also aiming for IEC 62443-4-2 certification for Nerve next year: According to the standard, there are also very precise definitions and processes that must be adhered to at product level. We have already integrated cybersecurity features into 'Nerve', which we are revising and completing - after which TÜV Austria will carry out the audit.

The platform was launched in 2016 and is being continuously developed. What changes and functions will Nerve users have to expect as a result of the certification?

Nerve is an IIoT platform for machine manufacturers that offers scalable, cloud-managed edge computing - a kind of software infrastructure for manufacturing and the cloud that companies can use to implement their IIoT projects.

We have already integrated cybersecurity features into Nerve. With product certification, we can then guarantee customers that we are providing them with a secure system. In terms of handling, certification changes things in one place or another - for example, if authentication is required for certain functions.

Cybersecurity is on everyone's lips, but there are often problems with implementation. What do you generally recommend to potential customers on the way to more cybersecurity?

Advertisement

"Cybersecurity solutions at company level"

Implementation is definitely an issue - you have to provide resources, including trained personnel, and be prepared for a lead time.

Industrial cybersecurity solutions must not only include network-based security and user authentication, but also address the issue holistically at company level. Ultimately, it is of no use if web-based access to a machine is secured, but people can enter the company premises unchecked and access the machine directly.

To ensure cybersecurity, a company must therefore rethink its processes and make them as secure as possible - this is where time must be invested. However, solutions such as 'Nerve' can help to cover individual areas in this overall concept and shorten and facilitate implementation. You can also get help with creating a concept - TTTech Industrial also works with partners who can support customers on their way to secure digitalization of their company.

  • Xing Icon
  • LinkedIn Icon
Advertisement
Back to topic page
Advertisement

You might also be interested in

Advertisement

Armis

Five CISO forecasts for 2024

As the year draws to a close, security and IT professionals are turning their attention to preparations for the year ahead: they offer five key predictions for 2024 that are significant against the backdrop of a dynamic cyber threat landscape.

read more...

TTTech Industrial

The basis for secure IIoT projects

A comprehensive cybersecurity strategy is needed to counteract the professionalization of cyberattacks. Standardization bodies and the EU have issued guidelines for this. How IEC 62443 and NIS 2 compliance are linked and provide the basis for secure...

read more...
Advertisement
Advertisement

Review

The top articles in February 2023

In addition to annual trends and new developments, the topic of security and how to maintain it played a key role in our most-read articles of the past month. Find out which negative headlines also made it into the ranking here.

read more...
Advertisement

Whitepaper

Cost savings with edge computing

With TTTech Industrial's edge computing platform Nerve, multiple IPCs with different functions and/or operating systems as well as legacy software are migrated to new hardware as virtual machines and Docker containers and managed remotely.

read more...
Advertisement
Advertisement
Advertisement

TSN series part 17

First steps into practice

Is Time Sensitive Networking still grey theory or can TSN-based networks with controllers from different manufacturers already be implemented today? A setup with B&R and Beckhoff controllers was created at Kempten University of Applied Sciences....

read more...
Subscribe to our newsletter
Advertisement
Back to home