Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 12 of 37

Principle 2: Limit the exposure of your connectivity

Exposure refers to where an asset sits within the wider system architecture, and how accessible it is to external or adjacent networks, taking into account defence in depth controls. Ultimately, the more assets exposed at the network edge, the broader your attack surface becomes.

To manage this risk, organisations should adopt an exposure management approach. This involves proactively identifying, assessing, and mitigating risks associated with digital assets and their connectivity. This includes evaluating the asset’s placement in the network, the type of connectivity implemented, and the strength of cyber security controls. The NCSC Netherlands exposure management guidance defines categories such as ‘internet or external facing’  and ‘adjacent network-facing’ assets, helping organisations assess exposure levels systematically. 

It is especially critical to ensure that you are managing the exposure of your admin interfaces. Where possible limit administration of devices or systems to only be achievable through privileged access workstations (PAW), which provide secure and trusted endpoints for system management. When administering critical security controls or obsolete systems via a PAW it may be appropriate to limit administration to only be achievable via local physical access to further reduce the exposure of these interfaces. 

Note: Network edges in OT can be hard to identify. For example, an unsecured radio link inside an OT network may not appear on network diagrams but still forms part of the network edge. Ensure you identify all data flows within the OT network and the components that facilitate this connectivity.




Any device found through a EASM, or other internet-facing asset discovery tool should be deemed at risk and promptly investigated. This should include establishing: 

  • Was the system originally designed to be connected for direct internet access? 
  • Was this system designed to be exposed temporarily or permanently, and how long has it been exposed for? 
  • Are there any additional services/ports/protocols exposed by the system to those expected? 
  • Does the system have security controls implemented that are appropriate to its exposure?  
  • Is the system is updated and hardened? 
  • Does this systems exposure cause additional risk to other connected OT systems? 
  • Does the system need to be exposed directly to the public internet, or can connectivity be restricted to only those who need it? 
  • Is the asset and/or its internet connectivity critical to the delivery of your OT process? 

Where these factors highlight that an asset is not designed or lacks sufficient security controls to operate in the threat context of the public internet, remediation actions should be immediately taken. Depending on your operational constraints this could include:

  • disconnecting the asset 
  • reconfiguring/Updating the asset 
  • adding compensating controls to manage the exposure risk 

Managing wireless networks exposure

It is easy to think of exposure only at a device level, but the communication medium also needs to be considered. Devices that use wireless communications or send traffic using wireless signals can be exposed to a greater level of risk. 

A wireless network is not constrained by the boundary of your site. This means physical controls can't be relied on to protect this network. If a wireless network is not configured with security in mind, it is trivial for an attacker to intercept and capture signals, as well as to potentially inject traffic into these networks. 

Understanding the factors that impact security of your signals is critical to enabling you to build appropriate and proportionate controls.


Published

Reviewed

Version

1.0