Opens in a new tab
vmblog logo 2024 wht (updated)

Cybersecurity threats from poor API security in the industrial sector

Share: 

David Marshall | Published: December 20, 2022

By Ali Cameron

In the last year, supply chain issues have run rampant. A product of a variety of factors – including the COVID-19 pandemic, numerous climate disasters, and a one-week blockage of the Suez Canal – supply chain concerns have impacted many businesses around the world. However, despite ongoing conversations around this topic and the need for building resilient systems, there’s one risk to the manufacturing and industrial sectors that isn’t often addressed: API security.

The truth is, the manufacturing sector sees more API security incidents than other industries, including retail, financial services, and the public sector. A big reason for this is that businesses in this sector have multiple vulnerabilities – and they’re the least likely to deploy API security capabilities. This isn’t particularly surprising. With global economic, political, and social pressure to have operational supply chains, the industrial sector is forced to prioritize speed over everything else, leaving little to no time to build a strong security posture. 

In this article, we’re taking a closer look at the role APIs play in the industrial sector, and the types of vulnerabilities they can generate for businesses in this space.

The role of APIs in the industrial sector

It’s no real secret that the industrial sector has been a laggard when it comes to digital transformation. While customer-facing industries have prioritized digital initiatives in order to remain relevant and competitive, manufacturers and shipping companies have historically had less pressure to transform their business models. The increased focus on the global supply chain has changed this.

Now, as customers and businesses alike demand increasingly rapid turnaround and delivery times, the industrial sector has to keep up. This requires digitizing processes, creating seamless connections between customers and partners, and relying more on data and automation. Ultimately, it means making an inherently collaborative space even more collaborative. This is where APIs come into play, as they connect mission-critical systems, data, and businesses, sharing information quickly and easily to keep the supply chain operating effectively.

However, with each new API, there can be an added potential for a bad actor to gain access and compromise the business and wreak havoc on their operations. This is particularly true for businesses that aren’t focusing on API security.

The threat of cyber attacks on APIs in the industrial sector

Within the industrial sector, the potential impact of a cyber attack is significant. While businesses in this industry won’t have the same wealth of customer data or personally identifiable information (PII) as a retail or financial services organization, a bad actor can still be extremely destructive if they gain access via an unsecured API.

Risks associated with cybersecurity attacks include:

  • Disrupted shipments leading to loss of revenue
  • Derailed production timelines
  • Delayed payments to trusted partners
  • Disgruntled customers due to incorrect or missing tracking information
  • Compromised schedules in production, shipping, yard management, and more
  • Product spoilage

With these risks in mind, here are three potential cybersecurity vulnerabilities related to APIs to look out for.

1. Lack of visibility into the API inventory

As we mentioned above, APIs have become ubiquitous in the industrial sector. The more digitally enabled and collaborative businesses in this space become, the more they rely on APIs to share data and get everyone on the same page. This is true in other industries as well – the API landscape is constantly evolving and that makes it hard to keep track.

This explains why so many organizations in this space have a hard time keeping track of their API inventory. Not only that, they also don’t have a clear understanding of which of their APIs return sensitive, mission-critical data. This makes it impossible to take a targeted approach to securing their APIs, and is guaranteed to leave gaps that bad actors can exploit.

2. API security is often an afterthought

Recent research shows that the manufacturing and industrial sector doesn’t always prioritize API security – in fact, they’re also having issues scaling it effectively. This likely means that API security isn’t as widespread as it needs to be. Not only should developers be “shifting security left” and including pre-production into their practices, there also needs to be a deep review of any business logic embedded into each API.

3. Credential threat is rampant

According to recent data, nearly 80% of hacking attacks on manufacturing businesses originate from stolen credentials. This means that APIs that aren’t set up with robust authentication mechanisms that ensure that the right person is trying to access their data can be compromised. In this example, a cyber criminal with an employee’s workplace credentials could access the API’s data if there is no authentication mechanism in place to further verify the user’s identity.

Conclusion

To stay ahead of these threats, businesses in the industrial sector need to take a preventative approach to their API security. At the end of the day, the cost of remediating vulnerabilities is vastly reduced when they are detected and fixed early in the development cycle.

##

ABOUT THE AUTHOR

Ali-Cameron 

Ali Cameron is a content marketer that specializes in the cybersecurity and B2B SaaS space. Besides writing for Tripwire’s State of Security blog, she’s also written for brands including Okta, Salesforce, and Microsoft. Taking an unusual route into the world of content, Ali started her career as a management consultant at PwC where she sparked her interest in making complex concepts easy to understand. She blends this interest with a passion for storytelling, a combination that’s well suited for writing in the cybersecurity space. She is also a regular writer for Bora.