Analyst Comment

Why the mining sector should prioritise investment in cybersecurity

Credit: Bert van Dijk/Getty images.

Powered by

M​​​​​​​ining companies must prioritise investments in cybersecurity. Without proficient security and protection, companies are exposed to a greater risk of cyberattacks. And, so far, no company’s system is immune. 

Looking back just one year, Rio Tinto was hit by one of the biggest cyberattacks in the history of the mining industry in March 2023. The attack saw hackers leaking employees’ family information on the dark web, as well as company data such as payroll information. 

Later, in May 2023, Fortescue Metals was targeted by a Russian ransomware group claiming credit for the theft of data. In December 2023, Anglo American had its email distribution channels compromised, resulting in a crudely worded message and an inappropriate graphic sent to company subscribers.

Impacts can be disastrous

Impacts on daily business operations can be disastrous: operational shutdowns, equipment damage, health and safety risks, but also financial loss, intellectual property theft, competitive advantage loss, and reputation damage. 

Moreover, since cyberattacks have become important weapons in geopolitical battles, geopolitics, and cybersecurity tend to go hand in hand. The mining industry finds itself in the crossfire, given its strategic position in global supply chains.

The current state of cybersecurity in mining

Global cybersecurity revenues are headed for strong growth, reaching $290bn by 2027, having grown at a compound annual growth rate (CAGR) of 13% between 2022 and 2027. In the mining vertical, GlobalData estimates that the total cybersecurity market will be worth $3.6bn in 2027, having grown at a CAGR of 15% between 2022 and 2027. 

But cyber threats are escalating and mining companies need to prioritise cybersecurity investments. For example, 50% of organisations from all industries do not have a strategy to protect from cyberattacks, says GlobalData. In addition to this, the employment of chief information security officers (CISOs) by businesses is patchy, despite the importance of cybersecurity. 

However, the number of cyberattacks is rising as is their complexity. As the digital transformation of mining companies continues, a CISO on the company board should be a priority to minimise cyber risks and implement resilient cybersecurity policies consistently across a company to guard against growing cyber threats.

The increased exposure of the mining industry to cyberattacks

Once hit by a cyberattack, the most straightforward option for a mining company would be to shut down access to the network and switch parts of the operations to manual, but this would lead to a downgrade in efficiency and often a significant downtime. Neither solution is feasible, especially in the long run. 

However, malicious cyberattacks are increasingly more difficult to identify and nullify, making the incidents costly and difficult to manage. The increased exposure of the mining industry to cyberattacks can be attributed to the progressive digitalisation of the sector, due to the bigger volume of data that companies handle. 

This—coupled with more connected devices, the adoption of cloud, artificial intelligence (AI), internet of things (IoT), and robotics—creates fertile ground for hackers. Notably, the widespread availability of generative AI tools such as OpenAI’s ChatGPT, enhances the sophistication and personalised nature of attacks from bad actors. Therefore, investments in cybersecurity providers are extremely beneficial for the sector.

GlobalData, the leading provider of industry intelligence, provided the underlying data, research, and analysis;used to produce this article.

GlobalData’s Thematic Intelligence uses proprietary data, research, and analysis to provide a forward-looking perspective on the key themes that will shape the future of the world’s largest industries and the organisations within them.

Go to article: Home | Cybersecurity in the age of AIGo to article: ContentsGo to article: BriefingGo to article: Foreword: Cybersecurity in the age of AI Go to article: Navigating the AI-driven cybersecurity landscapeGo to article: Key trends impacting cybersecurity Go to article: Timeline: a history of cybersecurity Go to article: Explainer: The most common types of cyberattacks Go to article: AI attacks now ‘the main cybersecurity concern’ for businesses across sectors Go to article: The state of cybersecurity: AI and geopolitics mean a bigger threat than ever Go to article: Companies’ own AI applications are ‘a huge cybersecurity problem’ Go to article: Regulators must protect the cybersecurity market from a private equity takeover Go to article: HealthcareGo to article: The impact of cybersecurity on healthcareGo to article: Case studies: cybersecurity in healthcare Go to article: Leading cybersecurity adopters and providers in healthcareGo to article: How healthcare cybercrime is predicted to escalate Go to article: Healthcare cybersecurity risk ‘higher than ever’ due to pandemicGo to article: Industry takes: Keeping healthcare businesses cybersecure Go to article: Rubrik’s Richard Cassidy on cyberattacks and resilience in healthcare organisationsGo to article: Cyberattacks on healthcare: Russia’s tool for mass disruption Go to article: Traceability technologies tighten supply chain fakery Go to article: Could brain-computer interfaces be hacked? Go to article: Deal activity related to cybersecurity in the pharma industry since 2021 Go to article: Deal activity related to cybersecurity in the medical industry since 2021 Go to article: EnergyGo to article: The impact of cybersecurity on the energy sector Go to article: Case studies: cybersecurity in energy Go to article: Leading cybersecurity adopters and providers in power Go to article: Cyberattacks on critical energy infrastructure ‘have increased dramatically’ Go to article: Report: Nuclear industry faces acute cybersecurity threats Go to article: The energy transition means increased attack surfaces for hackers Go to article: Deal activity related to cybersecurity in the power industry since 2021  Go to article: Cyber threat to oil and gas driven by geopolitics, extortion Go to article: How has cybersecurity changed since the Aramco hacks? Go to article: Deal activity related to cybersecurity in the oil and gas industry since 2021  Go to article: MiningGo to article: The impact of cybersecurity on miningGo to article: Case studies: cybersecurity in miningGo to article: Leading cybersecurity adopters and vendors in miningGo to article: Proactive approach to cybersecurity key for minesGo to article: ‘Operational disruption’ the main cybersecurity threat in miningGo to article: Why the mining sector should prioritise investment in cybersecurityGo to article: Will the Northern Sea Route become commercially viable in the near future?Go to article: Deal activity related to cybersecurity in the mining industry since 2021Go to article: DefenceGo to article: The impact of cybersecurity on defence Go to article: Case studies: cybersecurity in defence Go to article: Leading cybersecurity adopters and providers in defence Go to article: Latest news: Ukraine war dominant in cyber operationsGo to article: Sweden’s Nato accession: a cyberattack-filled saga Go to article: Germany recalls ambassador to Russia over cyberattacks Go to article: Why have cyberattacks in Poland spiked since Donald Tusk’s election? Go to article: How did China hack the UK Ministry of Defence? Go to article: Will IoT in defence continue to grow amid cybersecurity concerns? Go to article: AI Innovations wants to use semi-autonomous drones to save lives in Ukraine Go to article: Deal activity related to cybersecurity in the aerospace & defence industry since 2021  Go to article: Consumer GoodsGo to article: The impact of cybersecurity on the consumer goods sector Go to article: Case studies: cybersecurity in the consumer sector Go to article: Leading cybersecurity adopters and providers in consumer goodsGo to article: Latest news: Cybersecurity in packagingGo to article: Cybersecurity rising concern for packaging firms as digitalisation raises threat Go to article: Packaging companies must protect production lines from cyberattacks –analyst Go to article: Cybersecurity boost: Packaging learns from recent IT outages Go to article: Deal activity related to cybersecurity in the packaging industry since 2021  Go to article: Latest news: Cybersecurity in drinks Go to article: Drinks industry faces cybersecurity challenges from smart manufacturing Go to article: Brown-Forman chief talks cybersecurityGo to article: Modern supply chains open up cyber weak spotsGo to article: BankingGo to article: The impact of cybersecurity in banking and payments Go to article: Case studies: cybersecurity in banking Go to article: Leading cybersecurity adopters and providers in banking & payments Go to article: Latest news: cybersecurity in bankingGo to article: AI needed to tackle AI fraud – cybersecurity expert Go to article: What are the main cybersecurity trends of 2024? Go to article: What does the Economic Crime Act mean for foreign investors to the UK? Go to article: Regulators make crypto more attractive to institutions – NYU professor Go to article: Finance firms and ex-spies: strange bedfellows in a war-torn world Go to article: Monzo adds friction to fight fraud—but the features may not be popular with customers Go to article: Looking to stop payment fraud? Modernise your approach to bank validation Go to article: Governments must intervene on anti-fraud funding for real-time payments Go to article: Knowledge sharing puts finance sector among best for cybersecurity Go to article: Deal activity related to cybersecurity in the retail banking industry since 2021  Go to article: Sponsorship opportunitiesGo to article: GlobalData Thematic IntelligenceGo to article: Next issue