Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 24 of 37

Understanding the business drivers and cloud opportunities

Identifying and understanding your organisation's use case for ‘cloud-hosted SCADA’ so that adequate controls can be put in place.

One of the first things you need to identify is what your organisation means by ‘cloud-hosted SCADA’. This can cover several use cases including: 

  • a full migration

    with control and telemetry both being actioned from the cloud environment

  • hybrid deployments without cloud-based control to enable the use of advanced data analytics

    where only telemetry data is ingested for processing, but control remains in an on-premises SCADA solution

  • hybrid deployments with cloud-based control

     where the cloud is used for part of the functionality or the resiliency designed into the overall solution

  • using the cloud as a cold standby and/or recovery solution

    where this is deployed as an addition to an on-premise SCADA solution as part of a business continuity and disaster recovery plan

It is vital that the use case is clearly understood so that adequate controls can be put in place for the unique risks each one presents. 

An OT organisation should also aim to identify what is driving them to adopt a cloud solution. The NCSC's white paper ‘Security benefits of a good cloud service’ outlines the key security benefits. Any planned migration should be looking to leverage these benefits, rather than ‘lifting and shifting’ an on-premise solution to the cloud. Additionally, organisations should use NCSC guidance to help select a suitable cloud provider.

In OT organisations, change cycles typically operate at a slower pace, with large systems that are expected to be in service for 20 or more years. A cloud migration offers an opportunity to re-architect the OT system to be more secure. However, if not designed correctly, this can also introduce risks, with legacy infrastructure becoming more exposed to external threats.





Centralising identity in this guidance document relates solely to OT identity and does not include guidance for OT/IT convergence programs.

OT systems should not rely solely on systems in a lower trust domain for authentication and authorisation. The reasons for this are outlined in the NCSC guidance Introduction to identity and access management.

One of the most important steps in designing a cloud solution is deciding how users will be authenticated. The NCSC's using a cloud platform securely guidance discusses best practice on authenticating users, services and how to apply access controls in detail. Administrator access should be protected as described in our secure system administration guidance.

Where single sign-on (SSO) or centralised role-based access control (RBAC) are not possible (due to legacy devices within your estate), centralised secrets management may be considered. Cloud-native secrets management can play a key role in ensuring that you take a consistent approach to protecting your secrets across the organisation. Secrets management is a major issue in the OT sector due to the number of local accounts that are required in existing infrastructure. Cloud secrets managers should allow RBAC to manage users access to individual keys and secrets. The NCSC's using a cloud platform securely guidance discusses protecting secrets in more detail. 

A common mistake in cloud deployments is to avoid trusting the clouds key management service (KMS), as discussed in the NCSC blog ‘Myth busting cloud key management services’. A KMS is a fundamental part of the cloud and the integrated KMS will provide the best possible security. The NCSC have published detailed guidance on choosing and configuring a KMS for secure key management in the cloud. Organisations should consult this guidance before architecting how keys will be managed within your cloud and wider estate. 

Published

Reviewed

Version

1.0