Building a Resilient World:
The ISAGCA Blog

Welcome to the official blog of the ISA Global Cybersecurity Alliance (ISAGCA).

This blog covers topics on automation cybersecurity such as risk assessment, compliance, educational resources, and how to leverage the ISA/IEC 62443 series of standards.

The material and information contained on this website is for general information purposes only. ISAGCA blog posts may be authored by ISA staff and guest authors from the cybersecurity community. Views and opinions expressed by a guest author are solely their own, and do not necessarily represent those of ISA. Posts made by guest authors have been subject to peer review.

All Posts

How Digital Twins Improve Industrial Supply Chain Cybersecurity

As the industrial supply chain faces larger and more frequent cyber threats, it’s up to you to defend against cyberattacks, data breaches and unauthorized access attempts. Could digital twin technology provide some necessary tools to improve your facility’s security posture?

How the Industrial Supply Chain Uses Digital Twins

A digital twin is a high-fidelity virtual replica of a real-world object, process or person. While it doesn’t have to be three-dimensional, it often is — visualization can help your company’s nontechnical experts understand its readings. Either way, its purpose is to simplify monitoring or management by offering you near real-time updates on the asset’s condition.

Hardware-wise, digital twins leverage Internet of Things (IoT) sensors, data storage systems, network devices, visualization components — typically computer-aided design software — and a user interface. They use these tools to extract, interpret and present data in a convenient, centralized format.

You may have seen others in your industry use this technology to simulate disruptions or monitor assembly robots. In one case study, a factory that utilized a digital twin for its assembly line increased its product quality by 70% and its productivity by 17% — you can see why it’s quickly catching on.

These virtual replicas have demonstrated they can consistently generate value, which is why they’re becoming so prevalent in the industrial supply chain. In manufacturing alone, experts estimate their worth will reach 6.69 billion USD in 2025, up from 590 million USD in 2020. This 1,033.9% increase far outpaces other industries’ average of 910.7%.

That said, you may have noticed the trend of more manufacturers turning to these copies for security instead of productivity. Regulations are tightening; supply chain traceability is becoming a legal requirement everywhere, from pharmaceutical to food manufacturing; and cyberattacks are on the rise. These actions illustrate why this novel use case is taking off.

How Digital Twins Improve Supply Chain Security

Considering the average data breach cost has increased by 15% since 2021, amounting to over 4 million USD per incident, seeking cutting-edge security solutions is in your facility’s best interest. Since the industrial supply chain is quickly becoming a larger target for cybercriminals, investing in a digital twin for real-time, comprehensive visibility is a sound strategy.

Digital twin technology gives you a virtual, no-risk testing ground where you can passively run multiple simulations simultaneously while generating realistic insights. You could simulate various supply chain cyberattacks to understand where attackers will target and how your defenses will hold up, enabling you to improve your incident response strategies.

Despite how novel it sounds, this approach isn’t a proof of concept. The National Institute of Standards and Technology (NIST) and the University of Michigan developed a cybersecurity framework for use cases. Operational data is telling — while subtle temperature changes, executed commands and error signals may be from natural interference, they could also indicate a cyberattack. The ISA/IEC 62443 series of standards establishes security levels for industrial and automation control systems (IACS) to help organizations enhance their cybersecurity posture over time.

Digital twin technology can help your team immediately identify discrepancies, helping you recognize tampering in cases where a bad actor forces an asset to incorrectly report readings. You can avoid false positives and address high-priority incidents more consistently if you leverage a human-in-the-loop system and have a colleague interpret findings.

Alternatively, you can monitor your asset’s condition to prevent on-premises threats. Say you are remotely watching a virtual replica of a server room when a staff member enters alone. Their access may be legitimate and look unsuspicious on surveillance cameras, but your insights would reveal whether they’re an insider threat attempting to aid a bad actor.

Tips for Implementing Digital Twin Technology

While digital twin technology can be a powerful cybersecurity tool, it takes time to be effective. Leveraging these tips can help you navigate common implementation pain points.

1.    Consider the Costs

Since installation costs hundreds of thousands of US dollars on the low end — and often requires a lengthy trial-and-error process — it may take some time before your digital twin begins providing returns. Consider proactively adjusting your cybersecurity budget or using other companies’ integration success stories as incentives to alleviate sticker shock and secure board buy-in.

2.    Use Artificial Intelligence

Merging artificial intelligence with digital twin technology is uncommon but not unheard of — and it’s becoming more prevalent as these two emerging technologies make a name for themselves. If you have a small or understaffed team, you should consider this combination since automating monitoring, analysis, insight generations and alerts would lighten workloads.

Unlike other automation technologies, advanced machine learning models aren’t limited to simulating known attack types. Since they evolve as they absorb new information, they are ideal for fast-paced, ever-evolving environments like cybersecurity. Plus, they can process data in real time alongside the virtual replica.

3.    Encrypt Data

When replicating a physical or information asset, you duplicate your access points and sensitive data. This is an issue, especially considering hackers would love to uncover information on your cybersecurity strategies by exfiltrating details on the simulations you run or what you monitor. Leverage encryption to deter them and protect your company.

4.    Continue Monitoring

Ongoing monitoring is vital because your digital twin may produce inaccurate or misleading outcomes if you set it up incorrectly or go too long without updating your devices. You can substantially increase your accuracy if you have a tool or a human-in-the-loop system to catch anomalies early. This helps maintain your security posture.

How to Get Your Team on Board About Digital Twins

Whether you want to secure board buy-in or convince your team implementing a digital twin is the right choice, consider turning industry success stories and relevant metrics into visuals. Make sure to research measurable benefits to present your case concisely and get the desired outcome.


Interested in reading more articles like this? Subscribe to the ISAGCA blog and receive weekly emails with links to the latest thought leadership, tips, research and other insights from OT cybersecurity leaders.

Zac Amos
Zac Amos
Zac Amos is the features editor at ReHack, where he covers trending tech news in cybersecurity and artificial intelligence. For more of his work, follow him on Twitter or LinkedIn.

Related Posts

What Does the Future of Zero Trust in OT Look Like?

Zero trust principles have established themselves in the mindshare of cybersecurity practitioners worldwi...
Jacob Chapman Dec 20, 2024 7:00:00 AM

North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) and ISA/IEC 62443 Comparative Analysis

The Utilities Technology Council and Cumulys recently prepared a report in partnership with the ISA Globa...
Kara Phelps Dec 13, 2024 7:00:00 AM

Securing PLCs Through the Backplane: Balancing Performance and Simplicity

With the increasing convergence of operational technology (OT) and information technology (IT), the need ...
Ashraf Sainudeen Dec 6, 2024 7:00:00 AM