Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Shoprite ranks cybersecurity as its number one risk - Pieter Engelbrecht

      Shoprite ranks cybersecurity as its number one risk

      9 October 2026
      Standard Bank to take up to $200-million stake in OPay - Sim Tshabalala

      Standard Bank to take up to $200-million stake in OPay

      9 October 2026
      Shoprite takes on the banking apps with airtime on Sixty60

      Shoprite takes on the banking apps with airtime on Sixty60

      9 October 2026
      How to tell telemarketers to get lost - officially

      How to tell telemarketers to get lost – officially

      9 October 2026
      Data centres are the new front line in the Russia-Ukraine war

      Data centres are the new front line in the Russia-Ukraine war

      9 October 2026
    • World
      The memory crunch is making Samsung fabulously rich

      The memory crunch is making Samsung fabulously rich

      8 October 2026
      SpaceX to borrow $40-billion to buy Nvidia chips

      SpaceX to borrow $40-billion to buy Nvidia chips

      7 October 2026
      BMW restructuring plan bets on AI and new models

      BMW restructuring plan bets on AI and new models

      1 October 2026
      OpenAI's rogue agent problem keeps getting bigger - Sam Altman

      OpenAI’s rogue agent problem keeps getting bigger

      28 September 2026
      The new battle over the desktop

      The new battle over the desktop

      23 September 2026
    • In-depth

      10 days that changed the course of AI

      21 September 2026
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
    • TCS
      W&W | LDV's Gerhard Moolman on electric bakkies, fleet orders and 'school fees'

      W&W | LDV’s Gerhard Moolman on electric bakkies and fleets

      9 October 2026
      TCS | Frogfoot sees bigger fibre deals coming - TechCentral Show guests Abraham van der Merwe and Shane Chorley

      TCS | Frogfoot sees bigger fibre deals coming

      8 October 2026
      Meet the CIO | Vodacom's Mohamed Sami on the agentic future

      Meet the CIO | Vodacom’s Mohamed Sami on the agentic future

      5 October 2026
      Lexi Novitske, general partner at Norrsken22, on the TechCentral Show

      TCS | Norrsken22’s Lexi Novitske on how China is winning African tech

      1 October 2026
      TCS | Dominic White and Adam Ely on AI agents going rogue

      TCS | Dominic White and Adam Ely on AI agents going rogue

      29 September 2026
    • Opinion
      Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

      Let South Africans jailbreak their way to digital sovereignty

      5 October 2026
      South Africa's next energy crisis is in the accounts department - Craig Holmes

      South Africa’s next energy crisis is in the accounts department

      29 September 2026
      The steam engine lesson AI doomsayers keep missing - Sam Clarke

      The steam engine lesson AI doomsayers keep missing

      28 September 2026
      Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      What Revolut can and cannot take from South Africa's banks - Pambos Soteriades

      What Revolut can and cannot take from South Africa’s banks

      15 September 2026
    • Company News
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Publishared
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Kaspersky’s blueprint for industrial cyber resilience

    Kaspersky’s blueprint for industrial cyber resilience

    Promoted | Kaspersky outlines the elements of a high-performing security operations centre in industrial organisations.
    By Kaspersky25 June 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    Kaspersky's blueprint for industrial cyber resilience

    Industrial enterprises face an escalating wave of cyberthreats. The challenge lies in the complexity of industrial control systems (ICS), which often rely on legacy technology, lack built-in security and cannot afford downtime. Cyber resilience – ensuring systems can withstand, respond to and recover from attacks – is no longer optional but a business imperative.

    The importance of building an effective security operations centre (SOC) cannot be overstated, but it is far easier said than done. The SOC is not a separate system; above all else, it is primarily about people and processes.

    To build an effective SOC, organisations must first establish a strong cybersecurity foundation. This begins with comprehensive asset management – identifying and cataloguing all IT and operational technology (OT) assets, including ICS devices and network components, to understand the full attack surface.

    In industrial environments, a proactive, intelligence-driven SOC is essential – one that goes beyond traditional monitoring

    A thorough risk assessment should follow, evaluating vulnerabilities, potential threats and operational impacts through frameworks such as IEC 62443 or the Nist Cybersecurity Framework.

    With risks identified, essential security controls must be implemented, including OT-specific endpoint protection, firewalls and intrusion detection systems designed to prevent known threats. Once the tools and cybersecurity measures are in place, with integrations and telemetry collection set up, incidents are passed to the security information and event management (Siem) solution, which requires a team to analyse, respond to and investigate threats.

    Regular security audits are also critical, providing oversight and ensuring compliance with industry standards and internal policies. Finally, network segmentation – grouping systems into zones and conduits – helps to restrict lateral movement, making it harder for attackers to spread across the environment. Together, these measures help create the operational readiness needed for advanced threat detection and response.

    Building a mature SOC

    Your SOC is the nerve centre of your organisation’s cyber defence, continuously monitoring, detecting and responding to threats. In industrial environments, a proactive, intelligence-driven SOC is essential – one that goes beyond traditional monitoring. To defend against modern threats, the SOC must integrate three critical components: advanced technology, skilled experts and well-defined processes.

    A modern SOC serves as a strategic hub for threat intelligence, risk analysis and coordinated incident response. An effective SOC combines cutting-edge tools with experienced analysts who can interpret data, read analytics and respond appropriately. The human factor is vital – skilled professionals are capable of configuring products correctly, managing alerts and making informed decisions under pressure.

    Read: The new reality of enterprise security: scaling resilience amid complexity

    Future success depends in large part on an organisation’s ability to grow human capability, upskilling SOC analysts in industrial cybersecurity to ensure they understand OT environments and protocols.

    As noted, building an effective SOC is easier said than done, but several elements can help organisations achieve it. First, extended detection and response (XDR) plays a pivotal role by unifying data from endpoints, networks and cloud environments. This correlation enables holistic threat detection, allowing security teams to identify sophisticated attacks that might otherwise slip through isolated security tools.

    Kaspersky's blueprint for industrial cyber resilience

    Second, real-time threat intelligence feeds are essential for staying ahead of adversaries. These feeds deliver immediate updates on emerging malware, newly discovered vulnerabilities and evolving attacker tactics, ensuring the SOC can anticipate and block threats before they cause harm.

    Third, you should form an incident response team that unites IT, cybersecurity and OT specialists, and define roles and responsibilities for detection, analysis, prioritisation, containment and recovery. You should also name key stakeholders from legal, finance, marketing and other functions who will aid in non-technical response elements such as regulatory reporting and media management.

    Robust incident response capabilities ensure that when a breach occurs, the SOC can swiftly contain and remediate the threat. Rapid response minimises operational disruption, reduces downtime and prevents attackers from moving laterally through critical systems. Here, the expertise of analysts is crucial – they must interpret alerts accurately and act decisively.

    In industrial environments, cyberattacks can trigger catastrophic physical consequences

    Together, these elements transform a standard SOC into a highly effective cybersecurity nerve centre, capable of defending complex industrial networks against even the most advanced threats.

    The final piece in the puzzle is effective fault tolerance. In industrial environments, cyberattacks can trigger catastrophic physical consequences – from equipment damage and production shutdowns to safety hazards and environmental incidents. Fault tolerance acts as a safeguard, ensuring that critical operations continue even under attack and preventing operational paralysis. Achieving true fault tolerance requires a multilayered strategy. Redundancy and failover mechanisms form the first line of defence, with backup control systems standing ready to take over if primary systems are compromised.

    Training is essential

    To ensure ongoing success, you must train your team – it is crucial that your people have the technical skills and know-how to protect your unique industrial environment.

    You should mandate regular training focused on ICS, Scada and OT cybersecurity, and encourage cross-team collaboration, as IT, OT and cybersecurity units need to work in tandem to boost fault tolerance and response efficiency.

    Read: Addressing the 57% blind spot: Kaspersky on measuring SOC effectiveness

    Employees must be trained to recognise phishing attempts, social engineering tactics and insider threats, turning personnel into an active layer of defence. Regular incident response drills sharpen reaction times, ensuring that when an attack occurs the team responds with precision rather than panic.

    In the event of an attack, hold an incident response retrospective. A secure environment is not just about having a plan and procedures set out; you should action a full debrief after every cyber incident to learn lessons and build back stronger, updating your plan accordingly.

    Kaspersky's blueprint for industrial cyber resilience

    Resilience is not just about hardware – it must be rigorously tested. Large-scale cyberstorm exercises, simulating attacks such as ransomware outbreaks or denial-of-service assaults, stress-test systems under real-world conditions. These simulations answer critical questions: can the ICS continue functioning at reduced capacity? How quickly can full operations resume after an attack? By identifying weaknesses before adversaries do, organisations can fine-tune their defences.

    Secure state recovery is another essential element of fault tolerance. Industrial systems must be able to roll back to a known secure configuration after an incident, minimising downtime. Immutable backups play a key role here, ensuring that even ransomware cannot hold critical data hostage.

    Work with the experts

    Building mature security operations in industrial environments requires more than tools – it demands a cohesive, adaptive strategy that aligns people, processes and technologies around a shared goal of resilience. By working with third-party experts, organisations can concentrate on their core business without having to worry about integrating capabilities such as real-time network monitoring, tailored endpoint protection and behavioural anomaly detection.

    Expert guidance, research and incident response services further enhance fault tolerance and reduce recovery time when the unexpected occurs. Ultimately, cyber resilience is not a static goal but a continuous journey – one that empowers industrial enterprises to operate safely, sustainably and with confidence in an increasingly hostile digital landscape.

    To learn more about industrial cyber resilience and ways to protect critical infrastructure, visit Kaspersky’s interactive page.

    • The author, Moses Munguti, is technical expert and team lead in Africa at Kaspersky
    • Read more articles by Kaspersky on TechCentral
    • This promoted content was paid for by the party concerned
    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Kaspersky Moses Munguti
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleVisa, FNB and RMB take aim at corporate cash
    Next Article Datatec CEO lifts hedge ceiling as shares surge

    Related Posts

    Film piracy malware is reaching corporate machines

    Film piracy malware is reaching corporate machines

    21 September 2026
    How to build a security operations centre that actually works - Kaspersky

    How to build a security operations centre that actually works

    3 September 2026
    Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    13 August 2026
    Add A Comment

    Comments are closed.

    Company News
    Why fintechs need an insurance partner they can trust - Hollard Insurance

    Why fintechs need an insurance partner they can trust

    8 October 2026
    Reusable KYC means the end of 'please upload your ID' - Contactable

    Reusable KYC means the end of ‘please upload your ID’

    8 October 2026
    Eliminating the 'toggle tax': how CRM integration changes customer experience - Martie de Beer

    Eliminating the ‘toggle tax’: how CRM integration changes customer experience

    8 October 2026
    Opinion
    Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

    Let South Africans jailbreak their way to digital sovereignty

    5 October 2026
    South Africa's next energy crisis is in the accounts department - Craig Holmes

    South Africa’s next energy crisis is in the accounts department

    29 September 2026
    The steam engine lesson AI doomsayers keep missing - Sam Clarke

    The steam engine lesson AI doomsayers keep missing

    28 September 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Shoprite ranks cybersecurity as its number one risk - Pieter Engelbrecht

    Shoprite ranks cybersecurity as its number one risk

    9 October 2026
    Standard Bank to take up to $200-million stake in OPay - Sim Tshabalala

    Standard Bank to take up to $200-million stake in OPay

    9 October 2026
    Shoprite takes on the banking apps with airtime on Sixty60

    Shoprite takes on the banking apps with airtime on Sixty60

    9 October 2026
    How to tell telemarketers to get lost - officially

    How to tell telemarketers to get lost – officially

    9 October 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter