Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 33 of 37

Principle 5. Implement robust encryption

Encryption options present within the RF layer should be:

  • robust and provide sufficient protection to the underlying data being transmitted OTA
  • proportionate to the application itself

OTA data transmission provides a wide attack surface to an adversary encompassing threats such as RF spoofing, and replay. Unencrypted OTA transmissions are easily eavesdropped by others listening to the RF environment, which can enable the reconnaissance phase of an attack.

Use modern encryption modes (such as AES) with strong confidentiality and integrity protection on the RF links to protect the underlying data against both passive and active attacks. This encryption should encrypt the whole payload in the radio packet to decrease the likelihood of analysing the underlying protocol structure, and limit the information broadcast to a potential adversary.

Note:

Basic encryption (that is encryption without authentication mechanisms) at the RF interface will not mitigate all threats, especially in relation to replay attacks. It will however limit a malicious actor’s ability to understand the information being sent OTA, and thus increase the difficulty of packet modification or command injection.

Do not discard encryption as a security method, or substitute it with other means of securing the network (such as segregation or other access control measures). Although data within the network may not be considered confidential, encryption can also offer data integrity protection. More information on data-in-transit protection can be found in the NCSC’s Technology Assurance guidance. 

Published

Reviewed

Version

1.0