Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 10 of 37

Introduction

Operational technology (OT) environments - which have long been centred on safety, uptime, and operational continuity - are now more interconnected than ever.

Driven by the need for increased efficiency, agility, and integration, these advancements offer significant operational benefits (such as real-time analytics remote monitoring and administration, and predictive maintenance), but they also introduce risks.

Organisations deploying or operating OT systems often face challenges in prioritising cyber security due to operational constraints, such as dependence on legacy technologies that were never designed for modern connectivity or security requirements. These challenges are compounded by the increasing use of third party vendors, remote access solutions, and supply chain integrations, which expand the potential attack surface. In an OT environment, risks are elevated since a cyber intrusion can lead to physical harm, environmental impact, or potentially the disruption of an operator of essential service (OES).

Exposed and insecure OT connectivity is known to be targeted by both opportunistic and highly capable actors. This activity includes state-sponsored actors actively targeting critical national infrastructure (CNI) networks. The threat is not just limited to state-sponsored actors with recent incidents demonstrating exposed OT infrastructure is opportunistically targeted by hacktivists. 

Strengthening the cyber security of CNI, including securing OT connections, can challenge attackers' efforts and raise the threshold necessary to cause physical harm, environmental impact, and disruption.




Published

Reviewed

Version

1.0