Cybersecurity Risk in Industrial Control Systems in Industry 4.0
Industrial control systems (ICSs) are the operational technology that monitors and directs physical processes across critical infrastructure. They sit at the core of Industry 4.0. Once these systems are connected to digital platforms and service chains, a flaw in one component is no longer confined to that component. Conventional practice still treats disclosed vulnerabilities as isolated events to be patched, which leaves an open question: does the way vulnerabilities accumulate across ICS infrastructure amount to systemic risk, a property of the system rather than of any single flaw? We examine this using the ICS-CERT Vulnerability Dataset, analysing 60,378 vulnerability-product records that cover 2327 unique Common Vulnerabilities and Exposures (CVE) entries, 416 vendors and 14,577 affected products from 2012 to 2020. We construct a System Risk Index (SRI) that aggregates vulnerabilities to the vendor-year level, weighted by severity and exploitability. An ordinary least squares (OLS) model with heteroscedasticity-robust standard errors explains vulnerability severity (R2 = 0.99). A second model explains system-level risk (R2 = 0.91). Vulnerability-type diversity, measured through the Common Weakness Enumeration (CWE) taxonomy, is the strongest driver of SRI (β = 1.25, p < 0.001), ahead of mean exploitability (β = 0.29, p < 0.001) and product breadth (β = 0.06, p = 0.001). Annual ICS disclosures rose from 115 in 2012 to 503 in 2019, an increase of 337 per cent. Risk is concentrated: the five largest vendors account for 33.3 per cent of disclosed CVEs and more than 60 per cent of the cumulative SRI, with one vendor carrying over twice the cumulative SRI of the next. Quantile regression confirms the severity findings at the median. The pattern indicates that digital transformation redistributes risk into a connected, vendor-level property of the infrastructure beneath product–service delivery. Oversight should therefore track the diversity and exploitability of a vendor’s vulnerabilities rather than severity alone, concentrating scrutiny on the small set of vendors that carry most of the systemic exposure.