It’s hard to think of an industry where a significant risk to public safety wouldn’t emerge should their networked systems become compromised. Networked systems could be fully digital, like a population-level dashboard hooked into an EHR platform, or a hybrid system composed of physical sensors and digital monitoring layer, like the factory network described in the case study, meaning few organizations are free of risk.
One recently networked industry that may be particularly vulnerable is construction. Companies like Versatile are using networks of sensors and digital controls to collect data about the usage of construction equipment while industry leader Procore digitizes project plans and financials. Start-ups like Built Robotics are even adding autonomous robots to the mix. Should players in this market experience a data breach, the infrastructure of projects could be compromised or building plans containing security details could be leaked which would pose a significant risk to public safety. Most concerning, and similar to the cheese factory case, it would be easy for these compromises to go undetected until it was too late.
Data security guidelines, like HIPAA for health data, offer a helpful framework for determining which data should be kept locally and which should have added protection. HIPAA directs organizations to send only the minimum necessary information needed for a task across a network. Similarly, the construction industry might consider a similar standard where they keep sensitive information that is non-essential for the entire jobsite, like security system plans, on a local drive. Similar to the treatment of PHI, they might also apply additional security to highly sensitive information like that about potential failure points in building plans that might be taken advantage of at a later point.
In Protecting the Cheddar, vulnerabilities like these might have gone unnoticed and unaddressed in the cheese factory if Sara hadn’t spoken up. The discussion would have likely revolved around the first suggestion, offered by a male executive, to increase the company’s investment in their intrusion-monitoring systems. If this had been the case, the CEO would have never embarked on a full audit of the security vulnerabilities introduced by the new digital controls and may not have mitigated any of these risks. Sara’s lack of seniority and gender made her an easy target in a room of more senior men but her decision to speak up saved the company significant risk.
While our concept, an improved group scheduling web app, has minimal risk to public safety should a takeover event occur, we do face a more significant risk of personal calendar information being compromised. We should carefully consider how to secure API endpoints between our application and calendar platforms along with any scheduling data that users provide within our app.
