ANACAM MAGAZINE - n. 3 luglio | settembre 2024

• la macchina deve individuare e fornire informazioni sul software necessario per il suo funzionamento sicuro in modo accessibile. IL PROGETTO CYBERLIFT SECURITY In occasione della 53ª Assemblea nazionale Anacam a Monte Carlo, abbiamo avuto l’opportunità di presentare il progetto CyberLift Security, che ha lo scopo di innescare la condivisione di buone pratiche e strategie per migliorare la protezione dei prodotti attuali e futuri rivolgendosi sia alle aziende di manutenzione o servizi in generale, sia alle aziende produttrici di sistemi connessi (come tool di telecontrollo remoto, prodotti connessi o quadri di manovra). Il progetto, il primo in Italia finalizzato alla sensibilizzazione delle PMI del settore ascensoristico in tema di sicurezza dei sistemi informatici, ha avuto un’ottima accoglienza ed alcune delle più importanti aziende italiane leader nella produzione di quadri di manovra connessi e sistemi per il telecontrollo sono già state coinvolte e stanno avviando con successo importanti attività di “penetration test” e “bug bounty”, attacchi hacker simulati con lo scopo di portare velocemente ai propri clienti prodotti più sicuri e affidabili. Con il supporto di UNGUESS Security, leader innovativo nel crowdtesting (l’utilizzo di community controllate), CyberLift Security utilizza, infatti, una comunità di centinaia di hacker etici che, attraverso le loro differenti competenze, possono identificare e risolvere le vulnerabilità degli ascensori in ambito IoT. Le attività principali che vengono svolte sui sistemi connessi sono: 1. penetration test: test da remoto su sistemi connessi, simulando un attacco in ambiente reale, con successiva presentazione dettagliata dei risultati e indicazione di rimedi; 2. bug bounty program: testing da remoto continui durante l’anno su quadri di manovra connessi, simulando l’ambiente reale, da parte della comunità di ethical hackers, con la definizione di “taglie” e relative ricompense per le diverse tipologie e livelli di criticità dei bug trovati. Il bug bounty CyberLift Security partnered by Unguess prevede una gestione in totale autonomia del programma attraverso: • una piattaforma proprietaria, flessibile e con facile accesso • il contatto diretto con hacker etici certificati • un team di figure esperte selezionate e profilate e un supporto continuo 3. on-site penetration test: test on-site su un impianto reale installato, con lo scopo di valutare il grado di protezione locale; 4. formazione: offerta di corsi e seminari su tutti i temi di cybersicurezza sopra esposti, per garantire che il personale sia adeguatamente preparato a fronteggiare le minacce informatiche; we had the opportunity to present the CyberLift Security project, which aims to trigger the sharing of good practices and strategies to improve the protection of current and future products by targeting both maintenance or service companies in general, and companies producing connected systems (such as remote control tools, connected products or switchboards). The project, the first in Italy aimed at raising the awareness of SMEs in the lift sector with regard to the security of computer systems, has been very well received, and some of the most important Italian leading companies in the production of connected switchboards and remote control systems have already been involved and are successfully launching important ‘penetration test’ and ‘bug bounty’ activities, simulated hacker attacks with the aim of quickly bringing safer and more reliable products to their customers. With the support of UNGUESS Security, an innovative leader in crowdtesting (the use of controlled communities), CyberLift Security utilises a community of hundreds of ethical hackers who, through their different skills, can identify and solve IoT lift vulnerabilities. The main activities that are performed on connected systems are: 1. penetration testing: remote testing on connected systems, simulating a real environment attack, with subsequent detailed presentation of the results and indication of remedies; 2. bug bounty program: continuous remote testing during the year on connected control panels, simulating the real environment, by the community of ethical hackers, with the definition of ‘bounties’ and relative rewards for the different types and levels of criticality of the bugs found. The CyberLift Security bug bounty partnered by UNGUESS provides for a totally autonomous management of the programme through: • a proprietary, flexible and easily accessible platform • a direct contact with certified ethical hackers • a team of selected and profiled experts and continuous support 3. on-site penetration testing: on-site testing on a real installed system, with the aim of assessing the degree of local protection; 4. training: offering courses and seminars on all the cybersecurity topics outlined above, to ensure that staff are adequately prepared to deal with cyber threats; 5. VDP - Vulnerability Disclosure Programs: a VDP is, in simple terms, a system through which a company invites external people, such as computer security experts or ethical hackers, to report any vulnerabilities or weaknesses in its systems, software or websites; 6. Phishing simulation: a phishing simulation is a test that a company uses to check how prepared its employees are to recognise and handle phishing e-mails, which are scam e-mails designed to steal sensitive information such as passwords or personal data. 44 SICUREZZA DEI SISTEMI INFORMATICI DI PAOLO TATTOLI*, GIANLUCA IARUSSI** E LUCA MANARA***

RkJQdWJsaXNoZXIy NDUyNTU=