Mining companies’ digital transformation roadmaps must be cognisant of cyber risks
Against the backdrop of a slowed economy and an increasingly volatile market, digital transformation in mining companies has become a business imperative to drive efficiencies, optimise competitiveness and reduce risks associated with human error. This shift, which brings the convergence of Operational Technologies (OT) and Information Technologies (IT), creates new cyber security challenges for mining enterprises and calls for proactive strategies to manage these risks.
The Change Drivers in Mining
“A combination of market volatility, rising costs, and changing global demand are driving a shift in the mining industry. As with most industries, mining companies are increasingly looking for ways to leverage technology to improve the efficiency of their operations and reduce their operational risks. Most of our mining clients have collapsed their IT and OT under one management structure.
“While mining companies must ensure that their OT and IT systems are effectively aligned to create value, they must have stringent measures in place to manage the cyber security-related risks associated with this convergence. As Mining was one of the highest cyber-attacked industries in 20191, it is crucial to make sure the convergence of systems eliminate room for these kinds of threats and that access control is well-managed,” says Charl Ueckermann, CEO at AVeS Cyber Security.
A combination of market volatility, rising costs, and changing global demand are driving a shift in the mining industry.
Digital Mining Is The Future
Citing the World Economic Forum’s Digital Transformation Initiative whitepaper, Ueckermann says that digital mining is set to become a significant driver for the global mining sector. The whitepaper states that digitisation could create more than $320 billion in value for the industry by the end of 2025.2,3
Although South African mining companies lag behind their Australian mining counterparts, technology, digitalisation, and data planning are becoming more advanced.
Ueckermann says that leading mining companies in Southern Africa are actively implementing massive digital transformation projects that are connecting more systems.
How To Start Preparing For The Future
1. Do An OT Security Vulnerability Assessment
Mining companies should first have a comprehensive understanding of their OT and IT environments and how the different parts of the organisation are connected before they implement OT security solutions. Translating their understanding into governance policies before they call on technology to protect their systems and data will result in more cost-effective and long-term solutions.
An OT security vulnerability assessment should be performed on interconnected systems to understand how they are exposed to other engineering workstations/SCADA systems and the Internet. This includes all internet-connected devices, such as smartphones, which employees might be plugging into their computers. This is a vital building block to determine where are the high-risk security areas of the operations, and where to prioritise security efforts. Knowing what to tackle first is crucial, and will be important when security alerts are set up to notify OT Security experts of anomalies or possible security incidents.
2. Implement A Security Operations Centre
AVeS Cyber Security recommends that mining organisations implement a Security Operations Centre from where interconnected systems can be managed from one place, and the mine’s OT security posture can be monitored and analysed on an ongoing basis.
3. Create Role-Specific KPA Dashboards
With supporting technologies, mining companies can implement role-specific dashboards, that are presented on the production floor and provide real-time access to data that is relevant to specific roles.
“These dashboards help people make better decisions on the fly because they have all the information they need on hand, whether the information is on a screen in their hands or on a screen next to their workstation in the processing plant.
There are three main areas for dashboards that include executive dashboards, maintenance or engineering dashboards, and logistical dashboards. Executive dashboards can, for example, provide data on financial performance indicators in the office; maintenance and engineering dashboards can provide information on environmental performance indicators in the production plant; and logistics dashboards can, for example, provide important on-time shipping schedule data in the loading bay.”
“Dashboards can be built in line with Key Performance Areas (KPAs) to get predictability around production efficiencies and production risks. It is possible to visually track, analyse, and display KPAs, key metrics and workflows to monitor risks of the different areas and production processes.
“Dashboards can connect you to essential data in your files, attachments, services or APIs, and visualise the data in a single dashboard in a way that makes sense, whether it’s displaying it in the form of tables, line charts, bar charts, or gauges. A data dashboard is the most efficient way to track multiple variables because it provides a central location for businesses to monitor and analyse performance, and make informed decisions in real-time.
Real-time monitoring reduces the hours of analysing and long lines of inefficient back-and-forth communication, which can result in miscommunication, that previously challenged businesses. It can, therefore, assist in identifying when something is ‘out-of-the-ordinary.’”
Ueckermann concludes: “These are exciting times for mining companies. Leveraging digital mining technologies has tremendous potential to create value and drive efficiencies in mines all over the world. For a start, with machines becoming more automated and interconnected as well as connected to the Internet, mines can now collect real-time data about stock levels, as well as minimise human safety hazards.
“New smart mine environments should be built on a foundation of industry-specific cyber security solutions to manage risks effectively. With IT and OT convergence, digital roadmaps need to be implemented to achieve a decent risk profile.”
- Symantec, (2019, 02). Internet Security Threat Report: Volume 24.
- Accenture, W. E. (2017, 01 01). Mining and Metals Industry.
- Claassen, L. (2018, 06 18). Mining goes digital.
Do you like this article? Sign up to receive updates of new articles like these straight in your email inbox >>
Expert Industrial Security Tailored for Mining Operations
Assess. Measure. And smartly manage your mine’s OT risks.