This page was machine-translated and may differ from the original. View original
Now is the time for manufacturing security to raise its awareness to the 'zero security' level.
Just as important as technical elements is the need to have a 'security' awareness.
'Minimum security requirements' and other measures should be created considering the realities of small and medium-sized enterprises
With the advancement of the Fourth Industrial Revolution, security is both a matter that needs improvement and an immediate challenge. The importance of industrial development is evidenced by the government's 'Smart Manufacturing Innovation Vision 2025' and companies' push for automation. However, currently, the focus is on the blind adoption and strategic aspects of smart factories rather than their qualitative aspects.
Professor Han Geun-hee of the Graduate School of Information Security at Konkuk University stated, “The importance of security has already been emphasized through domestic and international cases. Information security measures for smart factories are necessary, and the starting point requires not only technological capabilities but also a prior awareness of security among the public.” Through the interview, the current situation and various case studies were discussed to explain why security is important, what is needed, and what attitude we should adopt in dealing with it.

Many companies recognize the importance of security. Could you explain the necessity of security a little more clearly?
The importance of security can be best illustrated by looking at accident cases resulting from a lack of security. In manufacturing sites, equipment frequently malfunctions due to errors, malicious code is intentionally embedded, or vulnerabilities are exploited to halt normal operation. In the manufacturing sector, if equipment such as PLCs, sensors, and actuators malfunction due to hacking, it can lead not only to massive losses but also to human casualties. Representative examples include the wireless hacking attack on Australia's wastewater treatment system and Stuxnet. Security incidents resulting from such attacks can cause large-scale national and social disruption and escalate to a level that threatens national security. To prevent this, effective security countermeasures must be established.
- What is the level of our country's technological capability regarding security, and what other requirements do we need to meet?
I believe that both technological capabilities and physical security are close to zero. Looking at the government's smart factory initiatives and other policies, they focus solely on quantitative aspects while neglecting security. Moreover, what is actually more critical is the significant lack of awareness regarding the importance and perspective of security. The Stuxnet case is a prime example. This security incident involved a power plant that shut down because the internal devices were not detected, despite the facility appearing intact on the outside. This case demonstrates a breach in human security. The fact that an infection occurred despite strict internal controls and a lack of connection to external networks indicates that it was an accident caused by humans. Security incidents at the site of personal information leaks are also human-related. While technological capabilities and physical security are important, human security is the top priority when it comes to safety and security.
- What efforts do you think should be made first to strengthen human security?
This refers to security personnel training. For the sake of personal information protection, training should be conducted once a year. Unlike large corporations, small and medium-sized enterprises (SMEs) may avoid implementing such training due to concerns regarding the time and cost involved. However, the long-term losses resulting from incidents are far greater than the short-term costs invested in security. This includes not only monetary costs but also the company's reputation and image. In other words, training is crucial. Nevertheless, the reality is that such training is not being conducted even by the Smart Factory Promotion Team or other public institutions. It is necessary to prioritize strengthening security education under government leadership.
- In addition to awareness and human factors, what aspects need to be improved regulatoryly or technically?
The United States is strong in security. We need to refer to this. Recognizing the importance of ICS for a long time, they have introduced various countermeasures. One of these is the 'Minimum Security Requirements.' These were created considering the circumstances of small and medium-sized enterprises (SMEs) that have limited investment capabilities. In this regard, Korea's countermeasures are significantly lacking. We also need to recognize that many companies face difficulties in adopting systems, and rather than pushing forward unreasonably, we need to refer to these foreign examples and apply the 'Minimum Security Requirements.'
'Minimum security requirements' and other measures should be created considering the realities of small and medium-sized enterprises
With the advancement of the Fourth Industrial Revolution, security is both a matter that needs improvement and an immediate challenge. The importance of industrial development is evidenced by the government's 'Smart Manufacturing Innovation Vision 2025' and companies' push for automation. However, currently, the focus is on the blind adoption and strategic aspects of smart factories rather than their qualitative aspects.
Professor Han Geun-hee of the Graduate School of Information Security at Konkuk University stated, “The importance of security has already been emphasized through domestic and international cases. Information security measures for smart factories are necessary, and the starting point requires not only technological capabilities but also a prior awareness of security among the public.” Through the interview, the current situation and various case studies were discussed to explain why security is important, what is needed, and what attitude we should adopt in dealing with it.
Many companies recognize the importance of security. Could you explain the necessity of security a little more clearly?
The importance of security can be best illustrated by looking at accident cases resulting from a lack of security. In manufacturing sites, equipment frequently malfunctions due to errors, malicious code is intentionally embedded, or vulnerabilities are exploited to halt normal operation. In the manufacturing sector, if equipment such as PLCs, sensors, and actuators malfunction due to hacking, it can lead not only to massive losses but also to human casualties. Representative examples include the wireless hacking attack on Australia's wastewater treatment system and Stuxnet. Security incidents resulting from such attacks can cause large-scale national and social disruption and escalate to a level that threatens national security. To prevent this, effective security countermeasures must be established.
- What is the level of our country's technological capability regarding security, and what other requirements do we need to meet?
I believe that both technological capabilities and physical security are close to zero. Looking at the government's smart factory initiatives and other policies, they focus solely on quantitative aspects while neglecting security. Moreover, what is actually more critical is the significant lack of awareness regarding the importance and perspective of security. The Stuxnet case is a prime example. This security incident involved a power plant that shut down because the internal devices were not detected, despite the facility appearing intact on the outside. This case demonstrates a breach in human security. The fact that an infection occurred despite strict internal controls and a lack of connection to external networks indicates that it was an accident caused by humans. Security incidents at the site of personal information leaks are also human-related. While technological capabilities and physical security are important, human security is the top priority when it comes to safety and security.
- What efforts do you think should be made first to strengthen human security?
This refers to security personnel training. For the sake of personal information protection, training should be conducted once a year. Unlike large corporations, small and medium-sized enterprises (SMEs) may avoid implementing such training due to concerns regarding the time and cost involved. However, the long-term losses resulting from incidents are far greater than the short-term costs invested in security. This includes not only monetary costs but also the company's reputation and image. In other words, training is crucial. Nevertheless, the reality is that such training is not being conducted even by the Smart Factory Promotion Team or other public institutions. It is necessary to prioritize strengthening security education under government leadership.
- In addition to awareness and human factors, what aspects need to be improved regulatoryly or technically?
The United States is strong in security. We need to refer to this. Recognizing the importance of ICS for a long time, they have introduced various countermeasures. One of these is the 'Minimum Security Requirements.' These were created considering the circumstances of small and medium-sized enterprises (SMEs) that have limited investment capabilities. In this regard, Korea's countermeasures are significantly lacking. We also need to recognize that many companies face difficulties in adopting systems, and rather than pushing forward unreasonably, we need to refer to these foreign examples and apply the 'Minimum Security Requirements.'
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














