Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 14 of 37

Principle 4: Use standardised and secure protocols

In addition to securing the networks and devices used to establish communications, your organisation must also consider the security of the protocols employed.

As outlined in Creating and maintaining a definitive view of OT architecture, it is common for industrial environments to prioritise availability over the confidentiality and integrity of communications. It is essential that all components of the confidentiality, integrity & availability (CIA) triad are considered. However, you may prioritise different aspects of CIA depending on the connection. For instance, in field networks, authentication and integrity are essential to limit an attackers' ability to send malicious traffic. Conversely, in north-south traffic at network boundary points, encryption becomes critical to prevent attackers from discerning information on how to impact the system.



Where your organisation has insecure industrial protocols in use, you should establish a roadmap for migration to secure industrial protocol variants. This will enable you to make considerations to enable this in asset uplifts and system maintenance. 

Tip: Use resources published by your manufacturer to support your development of a migration plan. This could include: 

  • direct support from engineers that understand your current deployment
  • use of public materials on migration or new solutions from vendors
  • evaluation of the manuals and specification products you already own to identify supported protocols

Industrial control protocols (Modbus, OPC DA, EtherNet/IP, etc.) should be restricted to isolated OT network segments. External connections for data exchange between OT and IT should be brokered through a DMZ and use secure, standardised protocols designed for interoperability (such as OPC UA over TLS, MQTT over TLS, HTTPS). Where operational data needs to be shared, replicate the OT historian to a historian instance in the DMZ via a unidirectional, secure transfer mechanism, ensuring no inbound connectivity from IT to OT. IT systems should query the DMZ historian via a secure HTTP-based API with strong authentication, rather than directly accessing OT systems.


Published

Reviewed

Version

1.0