drj logo

"*" indicates required fields

Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!
This field is for validation purposes and should be left unchanged.

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
DRJ Fall 2025 Dallas Show
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2025
    • DRJ Spring 2026 Call for Papers
    • DRJ Scholarship
    • Other Industry Events
    • Schedule & Archive
    • Send Your Feedback
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • DRJ ACADEMY
    • DRJ Academy
    • Beginner’s Guide to BC
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • Business Resilience Decoded
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • DEI
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • Glossary Committee
      • Rules and Regulations Committee
  • Podcast

Report Reveals: Industry Exposes Itself to Cybersecurity Risks

by Jon Seals | November 8, 2024 | | 0 comments

  • The digitalisation of manufacturing and logistics introduces unknown software vulnerabilities that hackers can exploit.
  • ONEKEY’s “OT+IoT Cybersecurity Report” reveals: Smart factories are often insufficiently protected.

DUESSELDORF – German industry is increasingly exposing itself to security vulnerabilities due to the ongoing digitalisation of production and logistics. Many connected devices, machines, and systems acquired as part of Industry 4.0 rely on electronic control systems that hackers can often infiltrate with ease. The main reason is that the software embedded in these components is often outdated, as manufacturers do not consistently provide the updates needed to patch newly discovered vulnerabilities. These are the findings of the “OT+IoT Cybersecurity Report 2024” by the Duesseldorf-based cybersecurity company ONEKEY. The report is based on a survey of 300 industry executives.

“Smart Factory is a great concept,” said Jan Wendenburg, CEO of ONEKEY, “but the associated cyber risks are still too often neglected.” According to the survey, only 29 percent of industrial companies conduct a comprehensive security assessment when procuring connected devices and machines to determine how well new acquisitions are protected against hacker attacks. A further 30 percent admit to limiting their assessments to superficial tests or spot checks. Uncertainty is high, according to the report, with more than a quarter (26 percent) of respondents unable to answer the question. “The number of outdated software instances in manufacturing facilities appears to be alarmingly high,” added Jan Wendenburg.

More Policies for Industrial Control System Security

According to the survey, only 28 percent of companies have specific compliance policies for the security of industrial control systems or devices for the Industrial Internet of Things. While a good third (34 percent) do not have specific OT or IoT security policies, these are included as part of the company’s general cybersecurity guidelines. A further 19 per cent say they have no specific policy in place.

Firmware, the software embedded in digital control systems, connected devices, machines, and plants, is not systematically tested for cyber resilience in the industry, according to ONEKEY’s “OT+IoT Cybersecurity Report 2024”. Less than a third (31 per cent) of organisations regularly test the embedded programs in connected devices to identify and fix vulnerabilities that could be entry points for hackers. Nearly half (47 percent) only test firmware occasionally or not at all. In addition, more than half of the companies surveyed (52 percent) report that they have been attacked by hackers via OT or IoT devices at least once. A quarter of them are aware of three or more instances in which cybercriminals targeted the company via industrial control systems.

Industry Should Demand and Use Up-To-Date Software

“Connected devices sometimes run very outdated software,” said Jan Wendenburg. “Because it has worked perfectly for years, or even decades, no one thinks to update it. However, this can have serious consequences if hackers exploit the outdated software to attack the digital control system.” The ONEKEY CEO gave an example from the manufacturing industry: “Through unprotected firmware, cybercriminals can remotely change the internal configuration of a CNC machine, damaging both the machine and the workpieces. The damage to the machine could be irreparable, and an entire production batch could be rendered useless.” Hackers can also use the firmware to infiltrate the company’s network and launch a ransomware attack, for example: In this type of attack, critical business data is encrypted and only released after a ransom is paid.

Jan Wendenburg pointed out that the responsibility for outdated machine software lies equally with both manufacturers and users. He references the EU Cyber Resilience Act (CRA), which will ban the sale of connected devices with known vulnerabilities in the European Union starting in 2026/2027. In addition, the CRA will require manufacturers to monitor all firmware after delivery and provide updated versions immediately when new security vulnerabilities are discovered. However, this is far from the current reality, according to ONEKEY’s “OT+IoT Cybersecurity Report 2024”, which states that only 28 percent of companies currently comply with the directive, which will become mandatory in 2027, and systematically provide updated software for connected devices and machines delivered to customers. Thirty percent carry out occasional updates, while 17 percent do not update at all. “It’s time for manufacturers to align their software development and monitoring with the upcoming legal requirements,” advised Jan Wendenburg.

According to the “OT+IoT Cybersecurity Report 2024” by ONEKEY, only about a quarter (26 percent) of companies assess their operational maturity in product and project development as adequate in terms of cyber resilience. These companies have a defined process for a secure development cycle that is actively pursued. Another 12 percent have established such a security process, but according to their own assessment, it is poorly managed and mainly handled in a reactive manner. In nearly one in ten of the surveyed companies (9 percent), no such process for quality assurance in product and project development exists.

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of an automated Product Cybersecurity & Compliance Platform (PCCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life. 

Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated Software Bill Of Materials (SBOM) generation. “Digital Cyber Twins” enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle. 

The patent-pending, integrated Compliance Wizard™ already covers the upcoming EU Cyber Resilience Act (CRA) and existing requirements according to IEC 62443-4-2, ETSI EN 303 645, UNECE R 155 and many others.

The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritisation of vulnerabilities, significantly reducing the time to remediation.

Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform and ONEKEY Cybersecurity Experts.

Contact us: ONEKEY GmbH,
Kaiserswerther Str. 45, 40477 Duesseldorf, Germany,
Sara Fortmann, e-mail: sara.fortmann@onekey.com,
website: https://onekey.com

Related Content

  1. Disaster Recovery Journal
    The State of Enterprise Risk Management 2016
  2. Disaster Recovery Journal
    State of Enterprise Risk Management 2019
  3. The State of Business Continuity Preparedness 2023

Recent Posts

Abstract Security Delivers 4X Operational Efficiency at Juul Labs

July 9, 2025

Fortinet Report: OT Cybersecurity Risk Elevates within Executive Leadership Ranks

July 9, 2025

EGGER Group Achieves 99.99% Uptime Across Global Operations with SIOS LifeKeeper for Linux

July 9, 2025

Aligned’s Phoenix Data Center Earns Three Green Globes Certification

July 9, 2025

Portnox Unleashes Fast, Frictionless, Cloud-Native ZTNA

July 8, 2025

Blue Mantis to Empower Massachusetts Agencies with Advanced Cybersecurity Preparedness

July 8, 2025

Archives

  • July 2025 (15)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (91)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2025
    • Spring 2025

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal is the industry’s largest resource for business continuity, disaster recovery, crisis management, and risk management, reaching a global network of more than 138,000 professionals. Offering weekly webinars, the latest industry news, rules and regulations, podcasts, the industry’s only official mentoring program, a quarterly magazine, and two annual live conferences, DRJ is leading the way to keep professionals up-to-date and connected in an ever-changing world.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2025 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy