Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Nvidia's biggest customers are becoming its biggest threat - Jensen Huang

      Nvidia’s best customers are becoming its biggest threat

      30 August 2026
      Nasa launches telescope that will map two billion galaxies

      Nasa launches telescope that will map two billion galaxies

      30 August 2026
      Chinese car makers go after South Africa's EV and bakkie buyers

      Chinese car makers go after South Africa’s EV and bakkie buyers

      30 August 2026
      South African talk radio is now searchable - Locl.co.za

      South African talk radio is now searchable

      28 August 2026
      JSE-listed ICT firm suspended for not paying its own dividend

      JSE-listed ICT firm suspended for not paying its own dividend

      28 August 2026
    • World
      AI-generated music banned from Australian charts

      AI-generated music banned from Australian charts

      26 August 2026
      Traders brace for a R4.5-trillion swing in Nvidia's value

      Traders brace for a R4.5-trillion swing in Nvidia’s value

      25 August 2026
      Russia building its own Starlink - and faster than expected - Vadym Skibitskyi

      Russia building its own Starlink – and faster than expected

      11 August 2026
      Meta AI will now tell parents if their teen is in crisis

      Meta AI will now tell parents if their teen is in crisis

      17 July 2026
      IBM shares crash 25% as AI upends software spending - Arvind Krishna

      IBM shares crash 25% as AI upends software spending

      15 July 2026
    • In-depth
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
    • TCS
      Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

      Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

      24 August 2026
      Meet the CIO | Discovery's Derek Wilcocks on AI, guardrails and growth

      Meet the CIO | Derek Wilcocks on how AI personalised Vitality

      13 August 2026
      TCS | Money just became native to the internet - Steven Boykey Sidley

      TCS | Money just became native to the internet – Steven Boykey Sidley

      12 August 2026
      TCS+ | Specops' Darren James on continuous trust in an AI world

      TCS+ | Specops’ Darren James on continuous trust in an AI world

      7 August 2026
      TCS+ | How AI is turning hardware into a subscription service - Shane van der Merwe Merchant West

      TCS+ | How AI is turning hardware into a subscription service

      6 August 2026
    • Opinion
      The fragile joint in the Capitec machine - Pambos Soteriades

      The R197-billion market the banks can’t reach

      25 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      Management consulting as we know it is over

      21 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      The most dangerous customer is the quiet one

      10 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      South African tech’s compounding debt problem

      29 July 2026
      The fragile joint in the Capitec machine - Pambos Soteriades

      Best network, worst vibes: the puzzle of SA telecoms

      20 July 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Kaspersky’s blueprint for industrial cyber resilience

    Kaspersky’s blueprint for industrial cyber resilience

    Promoted | Kaspersky outlines the elements of a high-performing security operations centre in industrial organisations.
    By Kaspersky25 June 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Kaspersky's blueprint for industrial cyber resilience

    Industrial enterprises face an escalating wave of cyberthreats. The challenge lies in the complexity of industrial control systems (ICS), which often rely on legacy technology, lack built-in security and cannot afford downtime. Cyber resilience – ensuring systems can withstand, respond to and recover from attacks – is no longer optional but a business imperative.

    The importance of building an effective security operations centre (SOC) cannot be overstated, but it is far easier said than done. The SOC is not a separate system; above all else, it is primarily about people and processes.

    To build an effective SOC, organisations must first establish a strong cybersecurity foundation. This begins with comprehensive asset management – identifying and cataloguing all IT and operational technology (OT) assets, including ICS devices and network components, to understand the full attack surface.

    In industrial environments, a proactive, intelligence-driven SOC is essential – one that goes beyond traditional monitoring

    A thorough risk assessment should follow, evaluating vulnerabilities, potential threats and operational impacts through frameworks such as IEC 62443 or the Nist Cybersecurity Framework.

    With risks identified, essential security controls must be implemented, including OT-specific endpoint protection, firewalls and intrusion detection systems designed to prevent known threats. Once the tools and cybersecurity measures are in place, with integrations and telemetry collection set up, incidents are passed to the security information and event management (Siem) solution, which requires a team to analyse, respond to and investigate threats.

    Regular security audits are also critical, providing oversight and ensuring compliance with industry standards and internal policies. Finally, network segmentation – grouping systems into zones and conduits – helps to restrict lateral movement, making it harder for attackers to spread across the environment. Together, these measures help create the operational readiness needed for advanced threat detection and response.

    Building a mature SOC

    Your SOC is the nerve centre of your organisation’s cyber defence, continuously monitoring, detecting and responding to threats. In industrial environments, a proactive, intelligence-driven SOC is essential – one that goes beyond traditional monitoring. To defend against modern threats, the SOC must integrate three critical components: advanced technology, skilled experts and well-defined processes.

    A modern SOC serves as a strategic hub for threat intelligence, risk analysis and coordinated incident response. An effective SOC combines cutting-edge tools with experienced analysts who can interpret data, read analytics and respond appropriately. The human factor is vital – skilled professionals are capable of configuring products correctly, managing alerts and making informed decisions under pressure.

    Read: The new reality of enterprise security: scaling resilience amid complexity

    Future success depends in large part on an organisation’s ability to grow human capability, upskilling SOC analysts in industrial cybersecurity to ensure they understand OT environments and protocols.

    As noted, building an effective SOC is easier said than done, but several elements can help organisations achieve it. First, extended detection and response (XDR) plays a pivotal role by unifying data from endpoints, networks and cloud environments. This correlation enables holistic threat detection, allowing security teams to identify sophisticated attacks that might otherwise slip through isolated security tools.

    Kaspersky's blueprint for industrial cyber resilience

    Second, real-time threat intelligence feeds are essential for staying ahead of adversaries. These feeds deliver immediate updates on emerging malware, newly discovered vulnerabilities and evolving attacker tactics, ensuring the SOC can anticipate and block threats before they cause harm.

    Third, you should form an incident response team that unites IT, cybersecurity and OT specialists, and define roles and responsibilities for detection, analysis, prioritisation, containment and recovery. You should also name key stakeholders from legal, finance, marketing and other functions who will aid in non-technical response elements such as regulatory reporting and media management.

    Robust incident response capabilities ensure that when a breach occurs, the SOC can swiftly contain and remediate the threat. Rapid response minimises operational disruption, reduces downtime and prevents attackers from moving laterally through critical systems. Here, the expertise of analysts is crucial – they must interpret alerts accurately and act decisively.

    In industrial environments, cyberattacks can trigger catastrophic physical consequences

    Together, these elements transform a standard SOC into a highly effective cybersecurity nerve centre, capable of defending complex industrial networks against even the most advanced threats.

    The final piece in the puzzle is effective fault tolerance. In industrial environments, cyberattacks can trigger catastrophic physical consequences – from equipment damage and production shutdowns to safety hazards and environmental incidents. Fault tolerance acts as a safeguard, ensuring that critical operations continue even under attack and preventing operational paralysis. Achieving true fault tolerance requires a multilayered strategy. Redundancy and failover mechanisms form the first line of defence, with backup control systems standing ready to take over if primary systems are compromised.

    Training is essential

    To ensure ongoing success, you must train your team – it is crucial that your people have the technical skills and know-how to protect your unique industrial environment.

    You should mandate regular training focused on ICS, Scada and OT cybersecurity, and encourage cross-team collaboration, as IT, OT and cybersecurity units need to work in tandem to boost fault tolerance and response efficiency.

    Read: Addressing the 57% blind spot: Kaspersky on measuring SOC effectiveness

    Employees must be trained to recognise phishing attempts, social engineering tactics and insider threats, turning personnel into an active layer of defence. Regular incident response drills sharpen reaction times, ensuring that when an attack occurs the team responds with precision rather than panic.

    In the event of an attack, hold an incident response retrospective. A secure environment is not just about having a plan and procedures set out; you should action a full debrief after every cyber incident to learn lessons and build back stronger, updating your plan accordingly.

    Kaspersky's blueprint for industrial cyber resilience

    Resilience is not just about hardware – it must be rigorously tested. Large-scale cyberstorm exercises, simulating attacks such as ransomware outbreaks or denial-of-service assaults, stress-test systems under real-world conditions. These simulations answer critical questions: can the ICS continue functioning at reduced capacity? How quickly can full operations resume after an attack? By identifying weaknesses before adversaries do, organisations can fine-tune their defences.

    Secure state recovery is another essential element of fault tolerance. Industrial systems must be able to roll back to a known secure configuration after an incident, minimising downtime. Immutable backups play a key role here, ensuring that even ransomware cannot hold critical data hostage.

    Work with the experts

    Building mature security operations in industrial environments requires more than tools – it demands a cohesive, adaptive strategy that aligns people, processes and technologies around a shared goal of resilience. By working with third-party experts, organisations can concentrate on their core business without having to worry about integrating capabilities such as real-time network monitoring, tailored endpoint protection and behavioural anomaly detection.

    Expert guidance, research and incident response services further enhance fault tolerance and reduce recovery time when the unexpected occurs. Ultimately, cyber resilience is not a static goal but a continuous journey – one that empowers industrial enterprises to operate safely, sustainably and with confidence in an increasingly hostile digital landscape.

    To learn more about industrial cyber resilience and ways to protect critical infrastructure, visit Kaspersky’s interactive page.

    • The author, Moses Munguti, is technical expert and team lead in Africa at Kaspersky
    • Read more articles by Kaspersky on TechCentral
    • This promoted content was paid for by the party concerned
    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Kaspersky Moses Munguti
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleVisa, FNB and RMB take aim at corporate cash
    Next Article Datatec CEO lifts hedge ceiling as shares surge

    Related Posts

    Kaspersky on how to secure a supply chain you do not control

    Kaspersky on how to secure a supply chain you do not control

    13 August 2026
    Hackers are hiding malware behind AI agents that antivirus cannot see - Sergey Lozhkin

    Hackers are hiding malware behind AI agents that antivirus cannot see

    27 July 2026
    Finding focus: a strategic approach to cybersecurity for SMBs - Kaspersky

    Finding focus: a strategic approach to cybersecurity for SMBs

    6 July 2026
    Add A Comment

    Comments are closed.

    Company News
    The stuff that doesn't fit on the quote - Graham Millar SevenC

    The stuff that doesn’t fit on the quote

    28 August 2026
    Can you trust the AI speaking to your customers? - 1Stream

    Can you trust the AI speaking to your customers?

    27 August 2026
    Telviva launches Viva, a digital agent built for South African businesses - Telviva CEO David Meintjes

    Telviva launches Viva, a digital agent built for South African businesses

    27 August 2026
    Opinion
    The fragile joint in the Capitec machine - Pambos Soteriades

    The R197-billion market the banks can’t reach

    25 August 2026
    South African tech's compounding debt problem - Jannie van Zyl

    Management consulting as we know it is over

    21 August 2026
    South African tech's compounding debt problem - Jannie van Zyl

    The most dangerous customer is the quiet one

    10 August 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Nvidia's biggest customers are becoming its biggest threat - Jensen Huang

    Nvidia’s best customers are becoming its biggest threat

    30 August 2026
    Nasa launches telescope that will map two billion galaxies

    Nasa launches telescope that will map two billion galaxies

    30 August 2026
    Chinese car makers go after South Africa's EV and bakkie buyers

    Chinese car makers go after South Africa’s EV and bakkie buyers

    30 August 2026
    South African talk radio is now searchable - Locl.co.za

    South African talk radio is now searchable

    28 August 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}