The NCSC research problem book
Pages
Page 7 of 21
CC5 - How can we accelerate the adoption of modern security mitigations into OT?
How can we accelerate the adoption of modern security mitigations into Operational Technology?
Operational Technology (OT), such as the Industrial Control Systems (ICS) that operate factories, smart cities and our energy infrastructure, often lack many of the security controls and mitigations that we take for granted in Information Technology (IT). This means that if threat actors manage to reach OT systems, they may then be able to use relatively simple techniques to have a physical real-world impact. Research in the areas below could contribute to significantly improving the security of OT systems.
Strands or sub-problems
-
Security architecture
There are security architecture interventions which could reduce the risk to OT, such as developing templates for risk reduction to help manage the hazard of living with legacy or known vulnerable equipment. Another area to explore is how we can use cross-domain solutions or software-defined networking to provide stronger separation between IT and OT systems. This would allow visibility of data/management information from the OT environment to be accessible to business users, without undermining security. Proven examples of architectures which reduce the risk to OT environments, as well as templates to aid adoption of good practice, would also be welcome additions to support improvements in this area.
-
Platform security
Modern IT systems have many security controls (such as authentication or access control) and exploit mitigations that are rarely found in OT. Even when security controls exist, they are missing exploit mitigations like data execution prevention (DEP) and address space layout randomisation (ASLR), that make it harder to turn software vulnerabilities into working exploits, meaning security controls are easier to bypass when vulnerabilities are found. Beyond the software, hardware-based mitigations like Secure Boot, which we also take for granted in modern end-user computing devices, are also rarely found in OT. Widespread take-up of hardware-backed security controls would help improve confidence in supply chain integrity, and more generally support the detection of tampering. How can we speed up the take-up of all of these modern security controls and exploit mitigations? How can we accelerate the removal of vulnerable legacy systems, or better protect them from harm?
-
Incentives
How can we incentivise vendors and operators to rapidly improve the security of OT? How can customers better assess the security properties of what they are buying and be influenced to choose more secure products and systems?
-
Operational security
It isn’t common for OT environments to undergo the active security testing of IT environments. One reason often given is that OT equipment may be disrupted by common vulnerability scanning or penetration testing tools. Testing is instead carried out on reference environments, which may not always mirror production environments. Are the resilience concerns that prevent security testing of OT systems valid? If they are, how can we rapidly reach a position where they’re not, so that operational security testing can become the norm? And if they’re not valid, how do we quickly dispel this myth? Also, are there other options to explore for gaining assurance in OT environments?
Why this is important
“Although there has been a heightened focus on OT cyber security in the past decade, many modern OT components and systems still don’t include even baseline security features and capabilities. And those which do rarely have these features enabled by default. Our understanding of vulnerability and risk in these environments is rarely informed by testing to actually evidence the effectiveness of controls, and to gain confidence in overall security architecture. All of this often results in an illusion of security, where security capability is claimed, but not enabled, and the true vulnerability of a given system or architecture isn’t accurately understood or reflected in the end approach to managing risk.”
Ben R, NCSC Technical Director for Cyber-Physical Systems
“Modern mobile phone handsets have more technology to ensure the integrity of the system and data than the current or near-future operational technology that we rely on to provide essential services such as power and water. To date we have only scratched the surface of why this position persists and how we might remedy it.”
Mat P, NCSC CTO for Private Sector Critical National Infrastructure