IDEAS home Printed from https://ideas.repec.org/a/eee/reensy/v209y2021ics095183202100051x.html
   My bibliography  Save this article

Analysis of Cybersecurity-related Incidents in the Process Industry

Author

Listed:
  • IAIANI, Matteo
  • TUGNOLI, Alessandro
  • BONVICINI, Sarah
  • COZZANI, Valerio

Abstract

The digital transition in the process industry is characterized by a high level of automation and an increasing connection with external networks, which makes facilities vulnerable to cybers-threats. A cyber-attack, beside economic and reputational damages, can potentially trigger major events (e.g. releases of hazardous materials, fires, explosions) with severe consequences on workers, population, and the environment. In the present study, the cybersecurity-related incidents that occurred in the process industry and in similar industrial sectors (chemical, petrochemical, energy production, water/wastewater treatment) were investigated. The aim of the study is to frame a clear picture of the cyber-attacks on the automated control systems of process facilities and to issue lessons learnt from past incidents. The study is based on the development and analysis of a database of 82 cybersecurity-related incidents gathered from various sources. Time trend, geographical distribution, distribution among the industrial sectors, impacts of the incidents, and nature of the cyber-attacks (attacker, intentional/accidental type, system infected) were investigated. The analysis of a sub-set of more detailed incidents allowed the identification of the general steps of a cyber-attack on automated control systems of a process facility, the main hacking techniques used by the attackers and the more common cybersecurity countermeasures applicable to the prevention of a cyber-attack.

Suggested Citation

  • IAIANI, Matteo & TUGNOLI, Alessandro & BONVICINI, Sarah & COZZANI, Valerio, 2021. "Analysis of Cybersecurity-related Incidents in the Process Industry," Reliability Engineering and System Safety, Elsevier, vol. 209(C).
  • Handle: RePEc:eee:reensy:v:209:y:2021:i:c:s095183202100051x
    DOI: 10.1016/j.ress.2021.107485
    as

    Download full text from publisher

    File URL: http://www.sciencedirect.com/science/article/pii/S095183202100051X
    Download Restriction: Full text for ScienceDirect subscribers only

    File URL: https://libkey.io/10.1016/j.ress.2021.107485?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to search for a different version of it.

    References listed on IDEAS

    as
    1. Nicola Paltrinieri & Nicolas Dechy & Ernesto Salzano & Mike Wardman & Valerio Cozzani, 2012. "Lessons Learned from Toulouse and Buncefield Disasters: From Risk Analysis Failures to the Identification of Atypical Scenarios Through a Better Knowledge Management," Risk Analysis, John Wiley & Sons, vol. 32(8), pages 1404-1419, August.
    2. Jan Fagerberg & Martin Srholec, 2017. "Capabilities, economic development, sustainability," Cambridge Journal of Economics, Cambridge Political Economy Society, vol. 41(3), pages 905-926.
    3. ., 2020. "Economic development in Europe and the United States," Chapters, in: The Rule of Law, Economic Development, and Corporate Governance, chapter 6, pages 149-177, Edward Elgar Publishing.
    4. Lam, C.Y. & Tai, K., 2020. "Network topological approach to modeling accident causations and characteristics: Analysis of railway incidents in Japan," Reliability Engineering and System Safety, Elsevier, vol. 193(C).
    5. Konstandinidou, Myrto & Nivolianitou, Zoe & Kefalogianni, Eirini & Caroni, Chrys, 2011. "In-depth analysis of the causal factors of incidents reported in the Greek petrochemical industry," Reliability Engineering and System Safety, Elsevier, vol. 96(11), pages 1448-1455.
    6. Churchwell, Jared S. & Zhang, Katherine S. & Saleh, Joseph H., 2018. "Epidemiology of helicopter accidents: Trends, rates, and covariates," Reliability Engineering and System Safety, Elsevier, vol. 180(C), pages 373-384.
    7. Rubene, Ieva, 2020. "Recent developments in euro area food prices," Economic Bulletin Boxes, European Central Bank, vol. 5.
    8. Landucci, Gabriele & Reniers, Genserik & Cozzani, Valerio & Salzano, Ernesto, 2015. "Vulnerability of industrial facilities to attacks with improvised explosive devices aimed at triggering domino scenarios," Reliability Engineering and System Safety, Elsevier, vol. 143(C), pages 53-62.
    9. Matteini, Anita & Argenti, Francesca & Salzano, Ernesto & Cozzani, Valerio, 2019. "A comparative analysis of security risk assessment methodologies for the chemical industry," Reliability Engineering and System Safety, Elsevier, vol. 191(C).
    10. -, 2020. "Regional Agenda for Inclusive Social Development," Libros y Documentos Institucionales, Naciones Unidas Comisión Económica para América Latina y el Caribe (CEPAL), number 45330 edited by Eclac.
    11. Tai-Sen He & Lili Qin, 2020. "On the developmental origin of intrinsic honesty," PLOS ONE, Public Library of Science, vol. 15(9), pages 1-10, September.
    12. Sandor Vajna & Burchardt C & Pascal Le Masson & Armand Hatchuel & Benoit Weil & Bercsey T & Pilz F, 2020. "Models and Procedures of Product Development," Post-Print hal-03053964, HAL.
    13. Oecd, 2020. "Museums and Local Development in Poland," OECD Local Economic and Employment Development (LEED) Papers 2020/05, OECD Publishing.
    14. Milch, Vibeke & Laumann, Karin, 2019. "The influence of interorganizational factors on offshore incidents in the Norwegian petroleum industry: Challenges and future directions," Reliability Engineering and System Safety, Elsevier, vol. 181(C), pages 84-96.
    15. ., 2020. "The development of the continental rule through law," Chapters, in: The Rule of Law, Economic Development, and Corporate Governance, chapter 3, pages 46-87, Edward Elgar Publishing.
    16. Omotunde E. G. Johnson, 2020. "Financial Sector Development in African Countries," Springer Books, Springer, number 978-3-030-32938-9, October.
    17. Skogdalen, Jon Espen & Vinnem, Jan Erik, 2012. "Combining precursor incidents investigations and QRA in oil and gas industry," Reliability Engineering and System Safety, Elsevier, vol. 101(C), pages 48-58.
    Full references (including those not matched with items on IDEAS)

    Citations

    Citations are extracted by the CitEc Project, subscribe to its RSS feed for this item.
    as


    Cited by:

    1. Moghadasi, Negin & Collier, Zachary A. & Koch, Andrew & Slutzky, David L. & Polmateer, Thomas L. & Manasco, Mark C. & Lambert, James H., 2022. "Trust and security of electric vehicle-to-grid systems and hardware supply chains," Reliability Engineering and System Safety, Elsevier, vol. 225(C).
    2. Bożena Gajdzik & Radosław Wolniak, 2021. "Digitalisation and Innovation in the Steel Industry in Poland—Selected Tools of ICT in an Analysis of Statistical Data and a Case Study," Energies, MDPI, vol. 14(11), pages 1-25, May.
    3. Chen, Chao & Yang, Ming & Reniers, Genserik, 2021. "A dynamic stochastic methodology for quantifying HAZMAT storage resilience," Reliability Engineering and System Safety, Elsevier, vol. 215(C).
    4. Iaiani, Matteo & Tugnoli, Alessandro & Macini, Paolo & Cozzani, Valerio, 2021. "Outage and asset damage triggered by malicious manipulation of the control system in process plants," Reliability Engineering and System Safety, Elsevier, vol. 213(C).
    5. Witold Torbacki, 2021. "A Hybrid MCDM Model Combining DANP and PROMETHEE II Methods for the Assessment of Cybersecurity in Industry 4.0," Sustainability, MDPI, vol. 13(16), pages 1-35, August.
    6. Berghout, Tarek & Benbouzid, Mohamed, 2022. "EL-NAHL: Exploring labels autoencoding in augmented hidden layers of feedforward neural networks for cybersecurity in smart grids," Reliability Engineering and System Safety, Elsevier, vol. 226(C).
    7. Iaiani, Matteo & Sorichetti, Riccardo & Tugnoli, Alessandro & Cozzani, Valerio, 2024. "Modelling standoff distances to prevent escalation in shooting attacks to tanks storing hazardous materials," Reliability Engineering and System Safety, Elsevier, vol. 241(C).

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Iaiani, Matteo & Casson Moreno, Valeria & Reniers, Genserik & Tugnoli, Alessandro & Cozzani, Valerio, 2021. "Analysis of events involving the intentional release of hazardous substances from industrial facilities," Reliability Engineering and System Safety, Elsevier, vol. 212(C).
    2. Marroni, Giulia & Casini, Leonardo & Bartolucci, Andrea & Kuipers, Sanneke & Casson Moreno, Valeria & Landucci, Gabriele, 2024. "Development of fragility models for process equipment affected by physical security attacks," Reliability Engineering and System Safety, Elsevier, vol. 243(C).
    3. Iaiani, Matteo & Sorichetti, Riccardo & Tugnoli, Alessandro & Cozzani, Valerio, 2024. "Modelling standoff distances to prevent escalation in shooting attacks to tanks storing hazardous materials," Reliability Engineering and System Safety, Elsevier, vol. 241(C).
    4. Jan Fagerberg & Bengt-Åke Lundvall & Martin Srholec, 2018. "Global Value Chains, National Innovation Systems and Economic Development," The European Journal of Development Research, Palgrave Macmillan;European Association of Development Research and Training Institutes (EADI), vol. 30(3), pages 533-556, July.
    5. Steven A. Mejia, 2023. "Global inequities in the prevalence of undernourishment," Social Science Quarterly, Southwestern Social Science Association, vol. 104(3), pages 329-344, May.
    6. Basu, Sayantani & Campbell, Roy H., 2020. "Going by the numbers : Learning and modeling COVID-19 disease dynamics," Chaos, Solitons & Fractals, Elsevier, vol. 138(C).
    7. Weili Duan & Bin He, 2015. "Emergency Response System for Pollution Accidents in Chemical Industrial Parks, China," IJERPH, MDPI, vol. 12(7), pages 1-18, July.
    8. Jakub Szczepkowski, 2022. "Marketing relacji w pracy brokera innowacji (Relationship Marketing in the Work of an Innovation Broker)," Research Reports, University of Warsaw, Faculty of Management, vol. 2(37), pages 48-56.
    9. Chen, Chao & Yang, Ming & Reniers, Genserik, 2021. "A dynamic stochastic methodology for quantifying HAZMAT storage resilience," Reliability Engineering and System Safety, Elsevier, vol. 215(C).
    10. Saliu Mojeed Olanrewaju, 2021. "Financial System Stability and Manufacturing Performance in Nigeria," International Journal of Finance & Banking Studies, Center for the Strategic Studies in Business and Finance, vol. 10(1), pages 109-118, January.
    11. Angelica Sbardella & Emanuele Pugliese & Andrea Zaccaria & Pasquale Scaramozzino, 2018. "The role of complex analysis in modeling economic growth," Papers 1808.10428, arXiv.org.
    12. Delera, Michele & Pietrobelli, Carlo & Calza, Elisa & Lavopa, Alejandro, 2022. "Does value chain participation facilitate the adoption of Industry 4.0 technologies in developing countries?," World Development, Elsevier, vol. 152(C).
    13. Chien, Fengsheng & Anwar, Ahsan & Hsu, Ching-Chi & Sharif, Arshian & Razzaq, Asif & Sinha, Avik, 2021. "The role of information and communication technology in encountering environmental degradation: Proposing an SDG framework for the BRICS countries," Technology in Society, Elsevier, vol. 65(C).
    14. Wang, Wenyi & Zhao, Zhongfan & Zhou, Qun & Qiao, Yiyuan & Cao, Feng, 2021. "Model predictive control for the operation of a transcritical CO2 air source heat pump water heater," Applied Energy, Elsevier, vol. 300(C).
    15. Oscar Chiwira, 2021. "The Co-Integrating Relationship between Financial Inclusion and Economic Growth in the Southern African Development Community," Eurasian Journal of Economics and Finance, Eurasian Publications, vol. 9(3), pages 170-188.
    16. Bhardwaj, U. & Teixeira, A.P. & Guedes Soares, C., 2022. "Casualty analysis methodology and taxonomy for FPSO accident analysis," Reliability Engineering and System Safety, Elsevier, vol. 218(PB).
    17. Majeed Abimbola & Faisal Khan, 2018. "Dynamic Blowout Risk Analysis Using Loss Functions," Risk Analysis, John Wiley & Sons, vol. 38(2), pages 255-271, February.
    18. Van Hemelryck, Tamara & Berner, Heidi, 2021. "Social information systems and registries of recipients of non-contributory social protection in Latin America in response to COVID-19," Documentos de Proyectos 46868, Naciones Unidas Comisión Económica para América Latina y el Caribe (CEPAL).
    19. Liu, Zhichen & Li, Ying & Zhang, Zhaoyi & Yu, Wenbo, 2022. "A new evacuation accessibility analysis approach based on spatial information," Reliability Engineering and System Safety, Elsevier, vol. 222(C).
    20. Kinga Wasilkiewicz Edwin & Marie Nilsen & Eirik Albrechtsen, 2021. "Why Is the Construction Industry Killing More Workers Than the Offshore Petroleum Industry in Occupational Accidents?," Sustainability, MDPI, vol. 13(14), pages 1-23, July.

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:eee:reensy:v:209:y:2021:i:c:s095183202100051x. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catherine Liu (email available below). General contact details of provider: https://www.journals.elsevier.com/reliability-engineering-and-system-safety .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.