Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 20 of 37

Secure Connectivity - Operational OT Data Export Example

Monty Rakusen via Getty Images

A fictional worked example exploring the application of our secure connectivity principles.

If you design or maintain an operational technology (OT) network, the scenario below will help you navigate the cyber security issues related to external connectivity for your cyber-physical system. 



Information requirements

As part of the high-level description, Admin Corp captures detailed information requirements using a process like the CDDB’s integrated approach to information management methodology.

Some of the questions Admin Corp address include:

  • What information is required, and why is it relevant?
  • Which parties are involved, and what decisions will this information support?
  • What data will be shared, and where will it come from and go to?
  • How critical and sensitive is the data in both a cyber and protective (that is physical and personnel) security context?
  • What is the sharing frequency, volume, and timeliness required?

Third-party involvement

Admin Corp follows the NCSC’s guidance on Creating and maintaining a definitive view of your OT architecture. As such they have a good understanding of existing third-party risks to their system. For each data sharing initiative, Admin Corp:

  • documents all third parties involved, whether receiving data or providing enabling technologies
  • records the existing security requirements applied to each third party, along with their current compliance status
  • assesses the organisation’s ability to further influence or enforce security standards with those third parties

Admin Corp ensures that no new operational dependencies on third parties are introduced as part of any initiative.

Stage 2: Risk assessment

Admin Corp has an existing risk assessment for their system. Given Adminox's cyber-physical production process, the risk analysis covers physical threats (such as damage or interference) and personnel risks (like insider threats), alongside cyber risks. The risk assessment is built upon a thorough understanding of their OT architecture and follows international standards like ISO 27001, IEC 62443-3-2, and the NCSC’s Risk management guidance.

The baseline risk model:

  • links each identified risk to its potential operational, safety, and regulatory impacts
  • identifies feasible mitigations for each risk
  • considers cross-system interdependencies and how these influence the scale and nature of potential impacts

Admin Corp’s senior leadership a define a set of risk thresholds for data sharing activities. These thresholds reflect the organisation’s appetite for operational and cyber risk, and set clear limits on acceptable exposure.

For each information requirement, within each data sharing initiative, the Admin Corp assessment team evaluates its impact on the established baseline risk model and determines whether any of the thresholds are breached. This ensures any new or expanded data flows remain within agreed tolerance levels. Examples of these thresholds include:

  • no data sharing arrangement will be approved if it introduces a point of failure that could cause unplanned production downtime
  • no new connectivity path created by data sharing may permit direct access to OT systems controlling Adminox production from outside the secure OT network
  • no shared dataset may contain operational, system configuration or site layout and security details that, if combined with publicly available or previously compromised information, could enable a threat actor to materially degrade, manipulate, or halt Adminox production processes

Through this structured review process, Admin Corp ensures that any expansion of data flows is aligned with their security, operational resilience, and safety objectives.

Stage 3: Governance framework

Each business case ends by assigning senior accountability, defining roles and responsibilities, setting governance arrangements, and noting relevant policies.

Admin Corp's governance framework for the sustainability transparency use case is shown below. Admin Corp is a medium-sized CNI organisation with separate members of staff for each role. In smaller organisations, one member of staff may fulfil multiple roles. 

RoleKey Responsibilities
Risk Owner
  • Acts as the accountable risk owner for all data sharing activities and represents the management board.
  • Ensures security, compliance, and assurance processes are embedded in all decisions.
Operational Lead
  • Provides expertise on OT systems and data.
  • Responsible for operational impacts, system constraints, and integration issues.
Technical Security Lead
  • Responsible for the design and implementation of secure data transmission, storage, and access controls.
  • Monitors for vulnerabilities and advises on mitigation.
Security Manager
  • Responsible for personnel and physical security of the organisation’s operations.
  • Responsible for developing and implementing corporate security strategy and policies.
  • Sets security standards for organisation’s supply chain.
Supplier Security Lead
  • Responsible for ensuring third-party products/services meet predefined minimum security standards, oversees supplier security audits, and manages contract enforcement.
Compliance & Policy Lead
  • Responsible for data governance policies and ensures alignment with corporate standards.
  • Oversees data classification, sensitivity assessments, and retention policies.
Compliance Support
  • Responsible for ensuring all data sharing meets applicable legal, contractual, and regulatory requirements.
Coordination & Oversight
  • Responsible for coordinating initiation, review, approval, and lifecycle monitoring of data sharing agreements.
  • Tracks actions, escalates issues, and reports to senior leadership.

Relevant policies include:

  • approval (defines authority levels and document sign-off procedures)
  • monitoring (outlines procedures for reviews to identify and address changes in scope, risk profile, or partner behavior)
  • change management (establishes procedures for modifying or terminating data sharing agreements)
  • issue resolution (defines escalation routes and assigns responsibilities for efficiently resolving disputes or incidents)

Managing exposure

After the team have identified and categorised exposure, they consider how they can manage exposure for each of the information requirements. The team identify a number of mitigation approaches:

Batch exports

For both information requirements there is a high latency tolerance, 24 hrs and 7 days respectively. As such, batch exports are scheduled to coincide with these limits. Due to network hardware limitations, Admin Corp cannot disable network paths outside of the designated export windows. Even so, a batch export approach still provides benefits. Restricting usage to standardised intervals reduces exposure (for example by limiting the time window during which interception could occur), and supports more effective monitoring for anomalies.

Isolation points

A structured flow‑control pattern is enforced through defined isolation points located at both the internal and external interfaces of the OT DMZ. Admin Corp has considered the overall posture of their network security and decided that hardware security controls such as data diodes would be undermined by weaker controls elsewhere. Instead, firewalls with tightly defined rule sets governing permitted traffic are used.

Push-only architecture

No listening ports are open on the OT side of the DMZ. All data must be pushed from the OT networks upward through the architecture. This design significantly limits the potential for a threat actor to traverse the network from higher‑tier systems back into the OT environment.

Connectivity bearer exposure

The IR cameras are on a wireless network explicitly for IIoT sensors. This network is treated as untrusted, and it therefore has limited access to anything else. To manage the connectivity bearer risk, Admin Corp ensures the wireless network uses WPA3 Enterprise with MAC allow-listing to restrict access to registered cameras only. They also limit power in wireless transmitters to reduce the likelihood of interception of RF traffic from outside the facility perimeter.

Internet exposure

Admin Corp’s core principle for managing internet exposure is that no OT asset is ever directly connected to the internet. The team ensure this principle is not violated. Existing monitoring practices focus on detecting and analysing any internet‑facing endpoints. For this monitoring to be effective it is necessary for Admin Corp to maintain an accurate IP asset inventory. The Admin Corp team note that third‑party endpoints used to receive OT data must also be included in this inventory. This ensures such endpoints are subject to the same monitoring as internal assets.

At this point the team create data export schematics for each of the information requirements:

Initial data export patterns for each information requirement with exposure management controls highlighted in red
Initial data export patterns for each information requirement with exposure management controls highlighted in red






Published

Reviewed

Version

1.0