Preventing Cyberattacks from Derailing Your Net-Zero Goals

Net-Zero-Goals.png” alt=”” class=”wp-image-41875″/>

If your business is relentlessly reaching for net-zero status, you are certainly on the right track.The Fifth Annual Climate Survey has revealed that 82% of companies worldwide have reaped economic rewards from decarbonization, with 6% reporting a value that exceeds 10% of annual revenue. Moreover, the vast majority of companies surveyed are either maintaining or increasing their sustainability investments, which necessitates greater reliance on connected devices. Companies embracing greater online connectivity are therefore facing new cybersecurity risks that must be addressed proactively and strategically.

How Cyberattackers Cause Damage

Today’s net-zero systems rely on devices such as IoT sensors to measure energy consumption, temperature, and emissions. Many are also relying on smart meters, EV charging stations, and connected solar inverters, wind turbine controllers, and battery systems—all of which have software, firmware, and network access. Cyberattackers gain entry points that allow them to move through an organisation’s entire network. Say your company installs IoT energy sensors throughout your building. If one sensor has an enabled default password or other vulnerability, the cyberattacker would control that device. They could then install malicious software that connects back to their server, enabling them to control the sensor remotely. From this sensor, they could scan your internal network and discover your building energy management system, carbon reporting server, or shared internal databases. They might then capture network traffic or find stored credentials and move to more critical systems, including carbon-tracking and energy management systems. 

Causing Supply Chain Damage

Hackers could also mount supply chain attacks, compromising your trusted vendors rather than targeting your organisation directly. Your sustainability efforts undoubtedly rest on specific software or hardware, and key data may be stored in the cloud. Most companies rely on third-party apps, servers built with components from numerous manufacturers, cloud providers for data storage, and MSPs for security operations. Sustainable companies, however, also typically rely on third-party energy providers and sustainability-related software vendors, as well as cloud-based ESG platforms, smart grids, IoT devices, and operational technology (OT), such as wind turbines, battery systems, and solar farms. These multiple dependencies have changed the nature of the digital supply chain, making it one in which your organisation must trust partners with privileged access to data. Supply chain attacks have increased significantly in recent years, with approximately 15% of breaches involving third parties.

Embracing a Multifactorial Strategy to Avoid Cyberattacks

To stop cyberattackers from interfering with your sustainability efforts, organisations must start by using strong passwords and enabling multifactor authentication across all systems connected to their OT, energy management, and carbon-tracking systems. Networking is also key. IoT devices, OT systems, and other business systems should operate on separate networks. Security monitoring tools should be used to detect suspicious activity (including failed login attempts, new devices connected to the network, or unusual data transfers). In terms of the supply chain, organisations must limit third-party access to essential systems and monitor integrations to reduce the risk of supply chain compromise. Every user, device, and external connection must be verified before granting access. Vendor permissions must be regularly reviewed and updated, and vendor integrations and connections must be continually monitored for suspicious activity.

Investing in Staff Training

Sustainable companies should train employees to understand how cyberattacks occur and recognise threats such as phishing. Any staff members handling IoT devices, cloud-based carbon-tracking platforms, and smart infrastructure should receive training in secure handling and management. Staff and technical teams should also be trained to spot warning signs, such as unauthorised access alerts, unusual data changes on emissions-reporting platforms, and unexpected system behaviour. Holding regular drills and simulations can help employees learn how to respond to threats and identify and avoid common pitfalls. Companies can support these efforts by creating a documented incident response plan that outlines roles, responsibilities, and procedures for responding to cyberattacks.

Companies wishing to undertake their sustainability efforts smoothly must take cybersecurity seriously. Connected energy systems, cloud-based ESG platforms, and third-party integrations bring them closer to their environmental goals, but also expose them to vulnerabilities. A strong strategy must include goals such as strengthening access controls, managing supply chain risk, and preparing employees to respond effectively to external threats.

Issue 125

SBM 125

Sustainable Business Magazine