Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 26 of 37

Technology and cloud solutions suitability

Understanding if your technology is suitable for migration and how your cloud solution should be architected with considerations for its new environment.

A key part of the decision to move to the cloud is understanding if your technology is suitable for migration. Your cloud solution should be architected with considerations for its new environment and should avoid following a lift-and-shift pattern where possible. Organisations should also seek expertise internally (including from the staff that operate the SCADA solution) to inform these design decisions.

In IT this can be difficult due to the cost and time constraints of re-architecting. However, in OT this can form a major blocker due to legacy solutions and large applications suites that only have on-premises deployment options.

OT vendor engagement is an essential part of the cloud migration process. This should be done at an early stage when you are considering the cloud so you can gauge what is possible from each vendor's specific solution.



If you intend to deploy legacy protocols (or protocols with insufficient encryption) to the cloud, then these should be wrapped with additional protections such as a VPN to protect the data in transit.

You should ensure you explicitly identify which risks to the protocol each of the protections mitigate. For example, using a VPN to protect the control traffic will add protections to the integrity and confidentiality of the data in traffic. However, the addition of a VPN still leaves you vulnerable to rogue commands being sent to the field device from within the cloud or local network when using a legacy un-authenticated protocol. You should consider how established standards such as IEC 62351 could be used enforce security within your industrial protocols.

The NCSC has published guidance that will assist you if designing a VPN-based solution in both the published device security guidance and the IPsec guidance. You might also want to consider the Zero Trust architecture principles as part of the design process for integrating existing field devices to a cloud solution.



Published

Reviewed

Version

1.0