Operational Technology
Pages
Page 24 of 37
Understanding the business drivers and cloud opportunities
One of the first things you need to identify is what your organisation means by ‘cloud-hosted SCADA’. This can cover several use cases including:
-
a full migration
with control and telemetry both being actioned from the cloud environment
-
hybrid deployments without cloud-based control to enable the use of advanced data analytics
where only telemetry data is ingested for processing, but control remains in an on-premises SCADA solution
-
hybrid deployments with cloud-based control
where the cloud is used for part of the functionality or the resiliency designed into the overall solution
-
using the cloud as a cold standby and/or recovery solution
where this is deployed as an addition to an on-premise SCADA solution as part of a business continuity and disaster recovery plan
It is vital that the use case is clearly understood so that adequate controls can be put in place for the unique risks each one presents.
An OT organisation should also aim to identify what is driving them to adopt a cloud solution. The NCSC's white paper ‘Security benefits of a good cloud service’ outlines the key security benefits. Any planned migration should be looking to leverage these benefits, rather than ‘lifting and shifting’ an on-premise solution to the cloud. Additionally, organisations should use NCSC guidance to help select a suitable cloud provider.
In OT organisations, change cycles typically operate at a slower pace, with large systems that are expected to be in service for 20 or more years. A cloud migration offers an opportunity to re-architect the OT system to be more secure. However, if not designed correctly, this can also introduce risks, with legacy infrastructure becoming more exposed to external threats.
Gaining flexibility
A common benefit of migrating to a cloud-based solution is the flexibility to adopt new technologies and solutions. This could present great opportunities for speeding up adoption of security solutions in OT organisations.
OT organisations should look to architect their solution to leverage this flexibility by using cloud native services where possible. This will allow you to establish a clear single ‘pane of glass’ view of hosted services, and effectively maintain security of the platform over time.
A cloud migration will also introduce software defined networking (SDN) to your solution. SDN is flexible and reconfigurable, allowing you to quickly define how virtual networks can (and cannot) communicate with each other. Monitoring to detect unauthorised changes to the SDN should be a priority in all new cloud environments. The NCSC talks further about technically enforced separation in the cloud in its cloud security guidance.
Resilience and scalability
Configured correctly, cloud services can greatly increase the resilience of your overall architecture with automated scaling and failovers, DDoS protection and integrated disaster recovery and backup solutions. However, as noted in the NCSC's lift and shift guidance, not all these benefits will be realised unless they’re designed into the architecture.
OT organisations will need to consider how critical functions would be recovered in the event of a cloud (or cloud connectivity) outage. As with safety critical functions, organisations will need to consider break glass recovery solutions to ensure local control can be regained. OT organisations that are ‘operators of essential services’ (OES) will also need to specifically consider their requirements under The Network and Information Systems Regulations 2018, and guidance from their competent authorities.
Where OT organisations are planning on using cloud for cold-standby use cases they should also consider how they will use cloud-native features to add to the resilience of this solution. In particular this should look to use infrastructure as code and automation to bring systems online, and to establish critical connectivity to the network as part of your disaster recovery plan. This environment should be periodically tested to ensure it will function correctly during an incident.
Remote access improvements
Granular authentication, maintenance access and third-party remote access have all been hard to integrate into legacy OT estates. These often result in large volumes of external connections and exposed services which can present challenges to monitor and maintain visibility.
The cloud presents an opportunity to centralise remote access into one solution. This allows a 'single pane of glass view' of what both internal maintainers and third parties are executing remotely against the OT network. You should also consider the opportunity to integrate a privileged access management (PAM) solution, for managing access and permissions for users, accounts, processes, and systems across your environment.
The NCSC's guidance on secure system administration should be considered in these implementations. Specifically on the use of PAM and gaining trust in your management devices.
Centralising authentication, secrets, and key management
IT and OT both face challenges in managing identity, authentication, secrets, and keys. However, this challenge is often even greater in OT organisations due to segregated and legacy systems, often requiring the use of local authentication rather than centralised role based access. A move to a cloud is a valuable opportunity to assess how existing processes can be improved and centralised.
Centralising identity in this guidance document relates solely to OT identity and does not include guidance for OT/IT convergence programs.
OT systems should not rely solely on systems in a lower trust domain for authentication and authorisation. The reasons for this are outlined in the NCSC guidance Introduction to identity and access management.
One of the most important steps in designing a cloud solution is deciding how users will be authenticated. The NCSC's using a cloud platform securely guidance discusses best practice on authenticating users, services and how to apply access controls in detail. Administrator access should be protected as described in our secure system administration guidance.
Where single sign-on (SSO) or centralised role-based access control (RBAC) are not possible (due to legacy devices within your estate), centralised secrets management may be considered. Cloud-native secrets management can play a key role in ensuring that you take a consistent approach to protecting your secrets across the organisation. Secrets management is a major issue in the OT sector due to the number of local accounts that are required in existing infrastructure. Cloud secrets managers should allow RBAC to manage users access to individual keys and secrets. The NCSC's using a cloud platform securely guidance discusses protecting secrets in more detail.
A common mistake in cloud deployments is to avoid trusting the clouds key management service (KMS), as discussed in the NCSC blog ‘Myth busting cloud key management services’. A KMS is a fundamental part of the cloud and the integrated KMS will provide the best possible security. The NCSC have published detailed guidance on choosing and configuring a KMS for secure key management in the cloud. Organisations should consult this guidance before architecting how keys will be managed within your cloud and wider estate.


