Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 11 of 37

Principle 1: Balance the risk and opportunities

Before you undertake any design work for new or existing connections to your OT environment, you must ensure you are equipped to make risk-informed decisions about when, how, and where connectivity is permitted within OT systems and to external/third party systems. Ensure these decisions are thoroughly documented to allow the reasoning to be auditable.

The first step for all OT connectivity should be the documentation of a formal business case to support decision-making. This should be stored centrally and referred to regularly during the design process. At a minimum the business case should document the following:

  • Requirement:

    is the connection required and what does it aim to achieve?

  • Business Benefit:

    what benefits arise from the added connectivity?

  • Risk Tolerance:

    what cyber and operational risks are acceptable?

  • Potential Impacts:

    what are the potential impacts of a compromise to this connectivity?

  • Introduced Dependencies:

    will the connection make the system reliant on external services, making isolation harder in an incident?

  • Senior Accountability:

    who is the senior risk owner for the new connectivity?

Tip: Define risk thresholds in the business case so future design and review decisions can be measured against agreed limits.
Note: To be able to effectively assess introduced dependencies and impacts you will require a definitive view of your OT architecture. To achieve this, use the NCSC guidance on creating and maintaining a definitive view of your OT architecture. 

For OT environments it is critical to give additional consideration within the business case for both risks to obsolete products and operational risks that could arise from increased connectivity:

 

At each stage of the design process you should assess if the connectivity is able to meet the risk-thresholds defined in your business case and that it aligns with your organisational threat context. In order to do this effectively you will need to verify your organisation has existing knowledge and processes to support this.



Further reading

  • CISA’s Secure by Demand publication outlines priority considerations for OT owners and operators when selecting digital products, emphasising the importance of devices being secure by design.
  • ACSC’s secure by design publication on choosing secure and verifiable technologies can further assist procuring organisations to make informed, risk-based decisions within their own operational context. 
  • Additionally, IEC 62443-4-1 provides vendor-specific requirements for secure development practices in Industrial Automation and Control Systems (IACS), offering a robust framework for evaluating supplier security maturity.

Published

Reviewed

Version

1.0