Editor's Choice


Cybersecurity for operational technology: Part 4: Practical recommendations to reduce cybersecurity risks for OT systems

November 2021 Editor's Choice

According to the latest report from Clatory, it is critical that defenders understand the attack vectors threat actors may take to compromise industrial networks. Having proper visibility into potential weak spots helps organisations prioritise patching and other risk management activities[1]. It is therefore essential that IT professionals can clearly articulate cybersecurity risks to management. According to the World Economic Forum: “The board as a whole takes ultimate responsibility for oversight of cyber risk and resilience”. This means developing a command of the subject[2].

The first step is to adopt a best practice cybersecurity framework, which provides an holistic view of what is needed and will establish your organisation’s current level of maturity and provide a prioritised risk-based roadmap for improvement going forward. This roadmap is like a nautical chart. Without one, an organisation is adrift in the cyber-sea, without knowing where they are or where they are going. This increases the chances of panic when an incident occurs.

Figure 1 illustrates the key steps and processes required. A comprehensive security assessment is performed against a best-of-breed security framework, generating a prioritised, actionable security roadmap.

Table 1 lists some examples of best practice frameworks.

Care needs to be taken when selecting frameworks as industrial control systems (ICS) have different performance, availability and equipment lifetime requirements to IT systems. It is difficult to apply traditional cybersecurity controls to ICS systems, since they are often a combination of legacy and newer systems.

Often, a single security product or technology cannot adequately protect an ICS. The benefit of a best practice framework is that the IT and ICS components in the business will be evaluated holistically. Defences need to be based on a combination of effective security policies and a properly configured set of cybersecurity controls. This includes the organisation and operations. Figure 2 shows a big picture view of all the areas that need to be addressed.

Table 2 shows an overview of some recommendations mapped to the NIST Cybersecurity Framework specific to ICS environments.

Note: The final step ‘Recovery’ has been left out due to space constraints. Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to cybersecurity. I will cover this in a future article.

One of the best ways to demonstrate commitment to reducing cybersecurity risk is to work towards a recognised security certification of your environment. This will provide stakeholder assurance that reasonable steps have been taken to mitigate cyber threats. One of the best frameworks is ISO 27001, which can be assessed locally by the BSI (British Standard Institution)[8] with assistance from cybersecurity professionals such as Wolfpack[9].

References

[1]Claroty, 2021 Claroty biannual ICS risk & vulnerability report: 1h 2021, https://claroty.com/annual-report/

[2]W.E.F, 2017 Advancing Cyber Resilience Principles and Tools for Boards https://www.weforum.org/whitepapers/advancing-cyber-resilience-principles-and-tools-for-boards

[3]https://www.nist.gov/cyberframework

[4]https://www.iso.org/isoiec-27001-information-security.html

[5]https://www.bsigroup.com/en-ZA/ISOIEC-27001-Information-Security/

[6]https://www.cisecurity.org/

[7]https://www.iec.ch/blog/understanding-iec-62443

[8]https://www.bsigroup.com/en-ZA/

[9]https://wolfpackrisk.com/


About Bryan Baxter


Bryan Baxter.

Bryan Baxter has been in the IT Industry since 1992 in various roles before recently joining Wolfpack Information Risk. He has helped customers successfully manage and deliver IT infrastructures to around 7000 users in several countries, where, of course, the recurring theme has been keeping customers secure from cybersecurity threats. For more information contact Bryan Baxter, Wolfpack Information Risk, +27 82 568 7291, [email protected], www.wolfpackrisk.com


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Swiss watchmaking meets hypercar power
Horne Technologies Editor's Choice
The display of Bugatti’s upcoming luxury model, Tourbillon will be something truly special. Instead of a digital version, the driver will see a genuine Swiss timepiece behind the steering wheel.

Read more...
Reinventing the wheel
Editor's Choice
Once a curiosity in the early automotive age, in-wheel motors are now re-emerging with real promise. From electric cars to commercial vehicles and even aircraft, they are on the verge of transforming transportation engineering.

Read more...
Creating new magnets for electric motors
Editor's Choice
Innomotics, a global specialist in electric motors and large drive systems, is coordinating a consortium for a research project on ‘Integrated Product and Process Innovation for Electric Drives’.

Read more...
Sustainability is transforming fluid power
Editor's Choice Motion Control & Drives
Sustainability is reshaping the future of fluid power. With the growing demand for cleaner, more efficient technologies and tightening global regulations, fluid power systems are being re-engineered for higher efficiency, lower emissions and reduced material usage.

Read more...
The power of water
Editor's Choice Electrical Power & Protection
The Alpenglow Hy4 is the world’s first water-based hydrogen combustion engine, offering a convincing alternative to traditional battery-electric vehicles and established hydrogen fuel cell designs.

Read more...
Optimising purification for green hydrogen production
Parker Hannifin - Sales Company South Africa Editor's Choice Electrical Power & Protection
Parker Hannifin delivers advanced purification and thermal management components that enhance green hydrogen production.

Read more...
A new chapter in geothermal engineering
Editor's Choice Electrical Power & Protection
The town of Geretsried in southern Germany has become a focal point in the global shift toward renewable energy. While the world’s attention often turns to wind turbines and solar panels, a quieter but no less powerful force is at work deep beneath the surface, geothermal energy.

Read more...
Harnessing the ocean with wave energy
Editor's Choice Electrical Power & Protection
Wave energy is emerging as one of the most promising yet underutilised renewable sources. Tapping into the rhythmic, predictable power of ocean waves, this technology offers a clean, reliable alternative to fossil fuels and a valuable complement to wind and solar energy.

Read more...
Leading the way to the all-electric mine
ABB South Africa Editor's Choice IT in Manufacturing
Decarbonising the mining sector requires more than just new technology. ABB eMine provides a strong portfolio of electrification and automation solutions, consulting, partnerships and technology applications to support mining operations to reduce emissions and achieve operational cost savings and superior efficiency.

Read more...
Speeding up warehouse automation
Rockwell Automation Editor's Choice Motion Control & Drives
Bastian Solutions designs and delivers world-class material handling systems. The company was engaged by a high-end global fashion brand to implement a new warehouse system. Bastian used Rockwell Automation Emulate3D digital twin software to test the system before it was installed and went live.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved