Hyppää sisältöön
    • Suomeksi
    • In English
Trepo
  • Suomeksi
  • In English
  • Kirjaudu
Näytä viite 
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
JavaScript is disabled for your browser. Some features of this site may not work without it.

Product cyber security impacting business and processes for IACS embedded device providers

Honkasaari, Anniina (2026)

 
Avaa tiedosto
HonkasaariAnniina.pdf (728.0Kt)
Lataukset: 



Honkasaari, Anniina
2026

Tietotekniikan DI-ohjelma - Master's Programme in Information Technology
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2026-07-29
Näytä kaikki kuvailutiedot
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202607298610
Tiivistelmä
Due to the global political instability and the increased connectivity of operational technology, the cyber security of embedded devices is very topical. The legislation is changing, most notably at European Union level, where the Cyber Resilience Act (CRA) will step into power fully on 12/2027. CRA will bring requirements to all software and hardware products with cyber elements, which has driven many industrial automation and control (IACS) companies to strengthen their product cyber security. Many companies create a stable base for CRA with the standards IEC 62443-4-1 and 62443-4-2. Due to this, these standards have been inspected closely in the thesis.

The aim of the thesis is to find out how product cyber security effects the business and internal processes of an IACS embedded device provider company. The thesis is done with a case company that is also an IACS embedded device provider company. There were three research questions formulated, first concerning internal processes, the second business impact, and the third whether raising the product cyber security level above the mandatory is feasible.

The answers to research questions have been answered via existing theory, literature review, analysing the standards and unstructured interviews within the case company. Additionally, a model for assessing security level (SL) 4 business case is created.

The impact of product cyber security on internal processes is analysed based on IEC 62443-4-1 and 62443-4-2 standards, the difference between security level 1 and 4, and finally in a general context as well. IEC 62443-4-2 SL 1 is described as the device being protected from accidental or casual misuse, and SL 4 as the device being protected from what could be nation state actors attempting to attack it. There were several indirect process impacts found when analysing the standards, some also overlapping.

The business impact of product cyber security is analysed from customer value viewpoint as well as from the viewpoint of potential risks/costs. Additionally, a cyber security business case theory is introduced. There were several customer values established, although it remained partly unclear based on this thesis research how many customers would be ready to prioritize product cyber security in their decision-making. This is due to many companies refraining from publishing their cyber security status clearly because of fears such as litigation or negative company image. Another reason for the unclarity is that the product cyber security in embedded devices has been developing a lot in recent years.

The feasibility of raising the IEC 62443-4-2 security level to 4 is not a simple yes or no question. A model for cyber security business case is developed using Channaveerappa’s “Cyber Security and Business Analysis” (2024) as a basis. The model can be used by IACS embedded device provider companies to determine whether it is feasible for them to raise their security level to 4.
Kokoelmat
  • Opinnäytteet - ylempi korkeakoulututkinto [43231]
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste
 

 

Selaa kokoelmaa

TekijätNimekkeetTiedekunta (2019 -)Tiedekunta (- 2018)Tutkinto-ohjelmat ja opintosuunnatAvainsanatJulkaisuajatKokoelmat

Omat tiedot

Kirjaudu sisäänRekisteröidy
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste