Welcome
 | 
My Account

CyberHealth News

Cybersecurity has become a critical topic to PMMI members and the packaging industry in today’s business environment.

As a result, PMMI has created CyberHealth, to assist you with your cybersecurity needs and keep you up to date on current business practices, key trends, and imminent threats. Check this page often as we will be updating the information and resources on a regular basis.

Get cybersecurity updates straight to your inbox by opting in to receive CyberHealth emails.

What You Need to Know about Recent Industrial Cybersecurity

April 10, 2024

Recent findings reveal a stark reminder of the ever-present cyber threats in the industrial sector. A survey by Palo Alto Networks has shown that out of nearly 2,000 industrial organizations, spanning across 16 countries, a significant 25% experienced operational technology (OT) shutdowns due to cyberattacks within the last year​ (SecurityWeek)​​ (OODA Loop)​. 

CISA recommends getting rid of default passwords

January 19, 2024

Following our recent blog post about vulnerabilities in Programmable Logic Controllers, the Cybersecurity & Infrastructure Security Agency (CISA) is urging manufacturers to change or even get rid of default passwords altogether on equipment and software they manufacture. The agency went on to say that “studies by CISA show that the use of default credentials, such as passwords, is a top weakness that threat actors exploit to gain access to systems, including those within U.S. critical infrastructure”. 

CISA Warns of Unitronics PLC Exploitation

December 19, 2023

You may have seen the news last week that multiple municipal water authorities declared themselves under cyber attack. How did they get in? The answer is quite simple: by using the default credentials on Unitronics PLCs. The specific controllers that were compromised were equipped with HMIs and did not have their default passwords changed. While the attack has a multitude of geopolitical ramifications, ultimately it highlights the need to revisit security measures around interconnected devices, especially those that have not had proper security controls implemented or changed from their default settings.

Cybersecurity Threat Intelligence – Should I have one?

October 20, 2023

Cybersecurity threat intelligence services are comprehensive offerings that collect, analyze, and provide real-time insights on potential cybersecurity threats, vulnerabilities, and risks to your organization. These services monitor diverse data sources, detect threats, and identify vulnerabilities, including malware…

Tabletop Exercises – How to conduct a cybersecurity preparedness exercise

September 22, 2023

Tabletop Exercises – How to conduct a cybersecurity preparedness exercise We all know that Cybersecurity is paramount to ensuring the continuous operation of any business in today’s digital world, and responding to any type of cybersecurity incident at some point is only question of when. To safeguard your…

Internet-of-Things Device Attacks

June 15, 2023

The Internet of Things (IoT) continues to transform the way we approach manufacturing, but it also brings increased risks of cyberattacks. With the growing volume of IoT devices and sensors, the potential attack surface for manufacturers grows with it, as does the amount of data needed to protect.

Exploring the Power of ChatGPT and Artificial Intelligence

May 22, 2023

If you’ve read the news lately, you’ve probably heard that Artificial Intelligence tools powered by language models like ChatGPT are taking the world by storm and have the potential to revolutionize the ways we all work, especially in the manufacturing industry. Manufacturers are increasingly exploring the potential of AI tools to enhance their operations and gain a competitive edge.

Watering Hole Attack and How To Prevent Them

April 19, 2023

What is a “watering hole” attack and how do I prevent it from happening to my company? A watering hole attack targets a specific company by infecting their website with malware which proceeds to then further infect everyone that visits your website.

Denial of Service Attacks

March 24, 2023

A Denial of Service (DoS) attack is a type of cyber-attack that attempts to make a website, online service or computer network unavailable by overwhelming it with a flood of traffic or requests, causing it to crash or become extremely slow and unresponsive.. It can be targeted at a single system or an entire network, and can range from minor disruption or slowness to a complete shut down.

Bring Your Own Device Policies – What do you need to have?

March 10, 2023

Bring Your Own Device, or BYOD, has become an important technology topic over the past ten years as mobile devices have increased their capability and sophistication. But how should your company deal with employees using their personal devices for work? What company services do you allow employees to connect to from their personal devices, and what should you restrict to only corporate-issued computers? The answer is: it depends!