No one wants to do what everyone else is doing, and no one wants to be told what to do. Certainly not in a competitive market. Standing out with innovation, by showing how much better you can do something than the rest, can bring in substantial income and clout and motivates customer loyalty…sometimes.As a cybersecurity research engineer, I have spent considerable time immersed in IEC standards, whose influence I have seen spread into the United States through acquisitions of utilities by foreign companies. While there might be some good arguments for ignoring industry requirements, whether regulatory or voluntary, I have also witnessed significant opportunities missed due to a lack of adherence to regulatory standards. To an extent, these standards cannot be ignored—and I would argue they shouldn’t be.This article will explore the delicate balance between compliance and innovation across various industries, with a focus on cybersecurity compliance. By examining real-world examples, such as Volkswagen’s emissions issue, Theranos’ regulatory challenges, and Boeing’s 737 MAX situation, we will illustrate the significant consequences of not meeting industry requirements. By analyzing these cases, we can gain valuable insights on how to manage regulatory responsibilities while encouraging innovation.The Importance of Adherence to StandardsWhy are standards important? In the context of industrial control systems, IEC 62351-8 and -9 provide effective guidelines for secure access control. These standards are voluntary and describe best practices; however, lack of certification or adherence to these standards can lead to barriers in B2B relations and reputational damage. Regulations like the NERC CIP cybersecurity standards, which aim to ensure the reliability, safety, and efficiency of power systems, are legally binding. Noncompliance can result in penalties such as operational restrictions and fines. Industries can also be bound by laws; for example, NIS2 in the European Union aims to enhance cybersecurity across various sectors, including power systems, and requires the implementation of measures to protect critical infrastructure from cyber threats. Each of these industry requirements have penalties for nonadherence, but the benefits of following them can also bring opportunities and enhanced safety and security.The Pitfalls of NoncomplianceInnovation Before ImplementationOne of the most common mistakes organizations make is prioritizing innovation before ensuring proper implementation. Companies may rush to create innovative products or services, ones that go above and beyond what the requirements ask for. This can lead to several issues, including:
- Loss of Opportunities—Attempting to develop a highly innovative product without adhering to considering basic solutions that fit the industry can result in missed short-term opportunities.
- Reputational Damage—Noncompliance can tarnish a company’s reputation, leading to the loss of customer trust and loyalty.
- Operational Disruptions—Regulatory breaches can halt operations, affecting overall business continuity.
- Inconsistent Quality—Without considering industry requirements, the quality of products or services can vary, leading to customer dissatisfaction.
- Increased Risk—Noncompliance with safety-related requirements can pose significant risks to consumers and employees, potentially leading to accidents and liabilities.
- Market Rejection—Products that do not meet industry standards may be rejected by the market, resulting in financial losses.
Additional Posts by Contributor
Contribute to the conversation
We want to hear from you. Send us your questions, thoughts on ICS and OT cybersecurity, and ideas for what we should discuss next.