Energy Monitoring System
for manufacturing companies

Cyber Security statement and Responsible Disclosure

 hea headAnalytics For Industry takes our clients Cyber Security seriously. The Energy Management Solution (EMS) adheres to current best practices regarding (Industrial) Cyber Security. The safety and security of your data is our top priority. We recognize that your industrial data demands a rigorous set of operating standards compared to other information domains. We are committed to ensuring the highest standards of cyber security throughout our codebase and across our ecosystem of customers, partners and employees. We work hand-in-hand with our customers and partners to ensure leading data security and risk mitigation principles are embedded throughout our software and systems.

 

Cyber Security is part of our DNA

 

Components

The cloud-based EMS solution consists of software components provided by AVEVA (AVEVA Connect, AVEVA Insight and AVEVA BI Gateway) which run in Microsoft Azure and/or Amazon AWS, which are two of the leading public cloud service providers. Each company provides a robust global cloud platform that incorporates strong security practices as well as ensuring high availability.

The visualization layer is offered by Salesforce (Tableau) or Microsoft (PowerBI), depending on your personal preference.

 

Data at rest

All sensitive customer data is encrypted, logically segregated and segmented in a multi-tenant architecture. These measures offer the best assurances that customer data is safe from unauthorized access, and limit the risk of data being compromised in any meaningful manner while protecting the privacy, control and autonomy of each customer’s data independently from any other.

 

Data in motion

All data flow communications to and from AVEVA cloud services are encrypted using SSL/TLS over HTTP (i.e., HTTPS) on the industry standard and well defined Port 443 using Advanced Encryption Standard (AES) 256-bit encryption with secure 2048-bit X.509 certificates.

Data is always pushed out of your network (adhering to the ISA95/Perdue network model).

 

Read more

AVEVA’s Cloud Security
https://www.aveva.com/en/legal/trust/security/

AVEVA publishes all Security advisories
https://www.aveva.com/en/support-and-success/cyber-security-updates/

Microsoft about PowerBI security
https://powerbi.microsoft.com/en-us/security/

Salesforce about Tableau security
https://compliance.salesforce.com/en/services/tableau

 

System Architecture

The predefined EMS solution handles the data flow and transformation from the AVEVA Insight component to the Tableau or PowerBI dashboards. Read more about the architecture in our datasheet.

 

Responsible Disclosure

If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

Please do the following:

  • E-mail your findings to info@analyticsforindustry.com ,
  • Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people’s data,
  • Do not reveal the problem to others until it has been resolved,
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties, and
  • Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.
  • Please note that we do not consider an unset X-Frame-Options header to be a cyber security vulnerability 

What we promise:

  • We will respond to your report within 7 business days with our evaluation of the report and an expected resolution date,
  • If you have followed the instructions above, we will not take any legal action against you regarding the report,
  • We will handle your report with strict confidentiality, and not pass on your personal details to third parties without your permission,
  • We will keep you informed of the progress towards resolving the problem.

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.