What makes the cyber security situation in a typical mid-sized company so much harder than "install a firewall"?
Because a company is not one system: several business areas with different requirements, many people acting, many IT and OT applications, often several IT departments, and estate spilling further out into cloud and IoT — all of it tied to suppliers and customers.
* Not one system to secure but a distributed, multi-owner construction — the risk lives in the connections. *
Picture a manufacturer as the whole flow: purchasing draws on a supply chain of suppliers; production runs the plant; logistics stores and ships; sales and distribution partners reach the customers; administration and management sit across all of it. Every one of those areas carries its own cyber systems and its own idea of what "secure enough" means.
The compounding factors:
- Different requirements per area. Production cannot tolerate downtime; administration cannot tolerate data loss; sales cannot tolerate friction for customers. One uniform security level is wrong for all three.
- Many people as actors — employees, partners, customers, suppliers — each with different access needs, and each one a legitimate identity to be stolen.
- Many IT and OT applications, typically of very different ages and technical generations.
- Distribution. Often several IT departments (grown or acquired), and beyond them cloud services and IoT devices — so there is no single place where the estate is administered, and no single place to enforce anything.
- The perimeter runs through other companies. Supply-chain connections and customer-facing systems mean parts of the estate are shared with organisations whose security you do not control.
That is the situation the discipline exists for: not a single system to secure, but a distributed, heterogeneous, multi-owner construction where the interesting risk usually lives in the connections.
Go deeper:
ENISA — Threat Landscape for Supply Chain Attacks — what happens when the part of the estate you do not control is the way in.