Körber’s CISO on Securing Manufacturing’s Expanding Cyber Attack Surface

Written by

The manufacturing sector is a tempting target for threat actors, with successful compromises providing the potential for valuable data theft and the ability to cause significant economic damage by disrupting production activity.

Growing OT-IT convergence, and reliance on legacy technology often provides threat actors relatively easy access points into these lucrative environments.

As a global provider of software and machinery products for the manufacturing industry, German-based firm Körber finds itself at the heart of an industry that is in the crosshairs of this malicious activity.

As such, it must ensure it has a mature security strategy to both protect itself and help customers’ cyber resilience levels.

Infosecurity spoke to Körber’s CISO, Andreas Gaetje, to discuss this topic, including strategies to keep software products secure, working with downstream customers to reduce the impact of supply chain attacks and the growing role of AI in security operations.

Infosecurity Magazine: With Germany being a major manufacturing hub, are there any industry-wide initiatives/collaborations taking place in the country to help tackle these threats?

Andreas Gaetje: There are many different organizations in Germany that are talking about cybersecurity for different purposes. The most important one for us is the VDMA, Germany’s principal association for the mechanical and plant engineering industry. They’re active in sharing information, best practices and advise on how to comply with regulations.

We also have others in Germany. For example, the BSI, the authority for information security in Germany and the Alliance for Cyber Security – we are part of this Alliance and that’s a very important place to share information.

It is also very important is that we look beyond Germany. We are very well connected within Europe and are in the European Cyber Security Organisation (ECSO), and this is again a very important organization to share best practices within.

At Körber, we have our own cybersecurity center and own threat intelligence where we get information from around the world. This is the fastest and most important way we collect information and manage our threat intelligence.

IM: How does Körber manage cybersecurity risks in its role as both a supplier and a third-party supply chain partner?

AG: Supply chain security is really important to us and we have invested a lot of money to tackle this topic. On the one side we have thousands of different suppliers where we need to understand the potential damage that could be caused to us if they are attacked.

On the other side are supply chain attacks that could affect software in our own products. A lot has been done in recent years to improve our security practices in this area. For example, we’ve introduced our own Product Security Incident Response Team (PSIRT), something we’ve never had before. This is really important if you are active in the software area.

IM: What more should technology providers be doing to better protect downstream customers from the impact of compromises of their systems?

AG: Most importantly, they should be doing better with communication and transparency to their customers. If they suffer an attack – which is quite normal today – then what we want to have is a transparent conversation, but getting the right information is sometimes a struggle.

The second part is what you can do to make your product safe, to make your environment safe and, as mentioned, we’re making a lot of effort to improve this area in our company. Körber is a tech company delivering products worldwide and it is important that our software is secure and our customers can rely on that.

This area is seeing fast changes. There was a lot of debate in the past about software being airgapped – this is no longer true. It is connected, and when its connected, we need to have the same standard of security that software companies have.

IM: Körber has previously highlighted the significant benefits of IT-OT convergence to enabling real-time data flow across the entire manufacturing ecosystem. How can such benefits be retained while addressing the cyber risks that come from IT-OT convergence?

AG: For us, it depends very much on the individual customer setup. We need to understand how close our customers want us to be to their operations, what level of connectivity they already have and what security and maintenance capabilities are in place on their side.

"They should be doing better with communication and transparency to their customers. If they suffer an attack – which is quite normal today – then what we want to have is a transparent conversation, but getting the right information is sometimes a struggle"

If you have connectivity, you need to update your machine, so you need to maintain that, but customers often don’t have maintenance people, because they were never needed in the past.

Now we are having discussions with customers about whether they want to change the way they operate.

As a provider, we have access to certain machines, which allows us to deploy updates and security patches on their behalf. I think we will see some shifts there in how we operate machines and the applications on the machines in the future.

IM: What are the most effective deployments of AI in cybersecurity you are seeing to date? What are the biggest implementation challenges?

AG: I think we will see a quick evolution when it comes to AI. For me it’s clear that the biggest impact AI has in cybersecurity is on the security operations center (SOC) side. This is very important because vulnerabilities can be exploited within minutes, which means we need to react within minutes. This is more than what the human can do.

Machines need to react and not rely on people anymore. I believe the SOC analyst will move into the engineering level, to run things. This is the most important area where AI can help in cybersecurity.

We’ve recognized the need in this area and are already ahead of many others in the market. We’ve invested significantly, and it’s exciting to see what AI is enabling in the SOC today.

IM: What are your biggest concerns in cybersecurity today?

AG: The biggest concern from my point of view is the maths problem. There are a massive amount of threats, attack vectors, vulnerabilities – everything has now doubled or even more. Are we able to manage this? The amount of data, the amount of connectivity, it’s difficult. The likelihood that you’ll miss something, somewhere is so high.

IM: What are your biggest successes in cybersecurity today?

AG: At Körber, in the last six-to-nine months we were able to harmonize our entire continuous integration and continuous deployment (CI-CD) pipeline. We used to have several development units, they had several approaches, and we were able to create one platform for everyone.

Now, I can see everything that is in our environment, what we develop, and we can scan for vulnerabilities and react to that – and that’s amazing.

Software developers will always have their own opinion because they’re knowledgeable, but we were able in a very short space of time to harmonize that process which is a bit of a miracle.

That drives the overall maturity level of the security processes in the organization, which led to us winning the Platinum Medal in the CyberVadis cybersecurity rating in 2025 and in 2026. This is recognition that we’re doing something well there.

IM: If you could give one piece of advice to fellow CISOs, what would it be?

AG: Be honest to your board. What I can see after incidents like WannaCry and NotPetya is that we need a paradigm shift when it comes to security.

If you don’t prepare today, you will not be ready for tomorrow. That’s a message that you need to bring to your board.

What’s Hot on Infosecurity Magazine?