Operational Technology
Pages
Page 25 of 37
Organisational readiness
Before an OT organisation considers a cloud migration for any of their operational technology solutions, they first need to understand their organisational readiness. Organisational readiness in this context refers to understanding if you have the skills, people, and policies to support a shift to the cloud.
Note:
OT environments can face greater cloud migration challenges due to their reliance on physical systems which often contain legacy hardware not designed for a connected network. Cloud migration should not be executed in isolation, and needs to be considered as part of the organisation’s wider cyber security strategy.
Do you have access to cloud expertise?
Like all new technologies, cloud requires a special set of skills and expertise to design and deploy and maintain a secure solution. Where many OT organisations are moving from an on-premises environment, it is possible that these cloud-specific skills don’t yet exist in the organisation. OT organisations will need to consider what skills they need to build internally before starting a cloud migration strategy. Another option is to consider a managed service provider (MSP). The NCSC has established guidance on using a MSPs to administer cloud services.
If a cloud-hosted SCADA is being used only as a cold-standby, you should also ensure that regular exercising and training is conducted to ensure skills are maintained. Employees with developed cloud-hosted SCADA specific skills should have clearly defined responsibilities as part of your incident response plans.
Have you considered the policies and processes required?
A move to the cloud is a fundamental shift in the way that most OT organisations operate. Migrating from on-premises networks (that might traditionally have been air-gapped and kept away from internet connectivity) to an environment that's often internet-connected by default requires organisations to re-evaluate their cyber security policies and procedures.
Without re-assessing these policies, you are unlikely to cope with the pace of change, increased connectivity and new technologies that the cloud presents, while keeping security central to your planning. These policies should consider the principles of adapting to the cloud discussed in the NCSC's Using a cloud platform security guidance.
Have you considered the impact of shared services?
All external connections and shared services need to be carefully considered when designing a cloud-hosted SCADA solution. OT vendors routinely provide maintenance services and/or security functions directly (due to the technology’s proprietary nature). You should consider how connections out to shared services or third party solutions could affect the integrity of critical SCADA data.
As mentioned earlier, where cloud skills are missing within an organisation an MSP might be selected to deliver the solution. The organisation should also be aware that although an MSP will bring a large amount of cloud expertise, they may not always be experienced in SCADA systems. The organisation must ensure that their subject matter experts (SMEs) on OT are involved in the design process to address the nuances required by this sector.
A third party is a third attack surface and as such careful consideration should be taken to how the MSP is implementing their security controls. There is further advice on MSP considerations within the ‘Using MSPs to administer your cloud services’ blog. A key element to understand is how a chosen MSP will provide the cloud solutions, as this could include:
-
an MSP providing a limited set of services (such as maintaining IT functions or providing a service desk)
-
an MSP provisioning a tenancy on their underlying cloud infrastructure
-
an MSP provisioning an entirely separate cloud environment
Each of these different solutions changes the security posture of a delivered environment.
Ownership of the cloud environment and the root administrator account should be clearly understood by the organisation. If the MSP owns the underlying cloud accounts, then there is a much greater risk of an MSP compromise being able to affect customer environments that they service. CNI organisations are already an attractive target from advanced adversaries; a single MSP or third party service/integration, servicing multiple CNI organisations can further increase the risk.


