Operational Technology
Pages
Page 10 of 37
Introduction
Driven by the need for increased efficiency, agility, and integration, these advancements offer significant operational benefits (such as real-time analytics remote monitoring and administration, and predictive maintenance), but they also introduce risks.
Organisations deploying or operating OT systems often face challenges in prioritising cyber security due to operational constraints, such as dependence on legacy technologies that were never designed for modern connectivity or security requirements. These challenges are compounded by the increasing use of third party vendors, remote access solutions, and supply chain integrations, which expand the potential attack surface. In an OT environment, risks are elevated since a cyber intrusion can lead to physical harm, environmental impact, or potentially the disruption of an operator of essential service (OES).
Exposed and insecure OT connectivity is known to be targeted by both opportunistic and highly capable actors. This activity includes state-sponsored actors actively targeting critical national infrastructure (CNI) networks. The threat is not just limited to state-sponsored actors with recent incidents demonstrating exposed OT infrastructure is opportunistically targeted by hacktivists.
Strengthening the cyber security of CNI, including securing OT connections, can challenge attackers' efforts and raise the threshold necessary to cause physical harm, environmental impact, and disruption.
Prioritising systems
Due to potentially limited resources, organisations may not be able to complete all mitigating steps at once. When prioritising systems within your organisation, some topics that should be considered are:
-
The role and impact of the device or process to your operations, including the ability to control and/or monitor key functions.
-
The presence of fail‑safe systems or redundant systems that maintain availability and reduce the risk of unsafe operating conditions or service outages.
-
The time it would take to implement the change, including currently available funds and complexity. Keep in mind that the cheapest option may not be the most impactful option to securing connectivity.
-
Active threat activity from attackers ranging in sophistication, including the consideration for current geo-political events and the potential national security significance of your organisation and/or your customers' organisations.
Principles-based guidance
This guidance outlines the desirable end-states that organisations should look to achieve when designing connectivity into OT environments. They are intended as goals rather than minimum requirements.
System owners should use these principles as a framework to design, implement, and manage secure OT connectivity, for both new and existing OT systems. These principles are particularly critical for operators of essential services.
Integrators and device manufacturers are encouraged to make these principles easier for organisations to achieve, through providing products that are secure by design, easy to implement and maintain. Integrators and manufacturers should ensure they are providing documentation to allow organisations to assess connectivity risks. It is especially important that this documentation is available for 'turnkey' solutions, allowing operators to understand the design and implement appropriate security controls throughout the system's lifecycle.


