Roadmap to OT Cybersecurity Maturity: How to Assess Your Current OT Cybersecurity Posture to Identify Strengths and Weaknesses

Hillstrong Group Security ·

**Author: Roger Hill
**

Aug 8, 2024

How to Assess Your Current OT Cybersecurity Posture to Identify Strengths and Weaknesses

Preventing Operational Technology (OT) cyberattacks against manufacturing systems starts with an organization’s firm grasp of its current security posture. Assessing your organization’s cybersecurity protective capabilities, including adaptive controls, security operations capabilities, incident response, threat modeling, and personal security, is essential to stopping potential threats.

Manufacturing companies depend on OT systems like Industrial Control Systems (ICS), such as SCADA and PLCs, to run production and collect valuable data telemetry. However, these systems should never be connected directly to the Internet, which raises the risk of cyberattacks, malware, and ransomware attacks. For this reason, a robust network segmentation architecture is recommended.

Cyberattacks on ICS can cause severe problems in industries such as electric power, water, nuclear, manufacturing, infrastructure, transport, and oil and gas. Organizations should consult global standards like IEC 62443 and NIST SP 800-82 before moving forward with OT assessments.

Are you concerned about threats against your OT environment or long overdue for an assessment identifying potential vulnerabilities?

Contact the team at Hillstrong today to schedule your initial consultation.

Why Perform OT Risk Assessments?

Cyberattacks on manufacturing systems can lead to safety and operational issues. Attackers can manipulate control systems to cause physical impacts, such as explosions or the release of hazardous materials. These attacks can be widespread during military conflicts. Hackers, whether from nations or acting patriotically, may target critical infrastructure like water facilities and power plants to disrupt operations or cause chaos.

Organizations operating in global manufacturing must know regional regulatory requirements for manufacturing security, which require them to comply with various mandates. Failure to meet these mandates often leads to fines and possible suspension from operating in a specific marketplace.

OT assessments provide valuable insight into creating supporting artifacts for the senior leader team to invest in or hold off on robust security measures. Assessments help offer measurement outputs to executives to make a well-informed decision to invest in new OT technology or present the level of risk if the decision is not to move forward. Ultimately, a 3rd party security assessment can be the most effective tool in building a case for investment in OT security.

Understand The Threat To Your Current OT Cybersecurity Posture.

Outdated manufacturing systems are vulnerable to cyber-attacks because they lack secure design security features, are difficult to patch, lack incident response capabilities, and lack vulnerability management programs. Cyberattacks on automated manufacturing and industrial operations facilities can cause significant revenue loss and downtime, making companies vulnerable targets.

Case Study – China and Taiwan CyberAttacks Against Critical Infrastructure

Tensions between China and Taiwan led to a rise in cyber espionage targeting industrial organizations in the Asia-Pacific region and the United States. These targets included chip manufacturing facilities in Taiwan, a military base in Guam, and industrial systems in the Philippines.

Case Study – Clorox Security Breach

In September 2023, a US-based consumer and professional products manufacturer, Clorox, announced that a cybersecurity attack that damaged its IT infrastructure and caused widespread disruptions to its manufacturing operations may significantly affect its first-quarter results.

Assessing Critical Components Within Your OT Cybersecurity Infrastructure.

Under IEC 62432-3-2, there are seven sections to completing an assessment for OT environments.

1. System Under Consideration (SUC)

The first step is to map out all the systems in the OT environment and identify how they are connected. This step involves conducting asset discovery, inventory, and mapping the system’s architecture and network components. Considering company policies, regulations, and acceptable risk levels is essential.

2. Perform Cybersecurity Risk Assessment.

The company will assess its cyber risks by reviewing OT risk assessments and using an enterprise risk matrix to identify vulnerabilities and threats. This step is critical for establishing a reference point for future actions.

3. Divide the Various SUCs Into Zones and Conduits.

Break down the system into smaller parts and pathways for better risk management. Understand standards, policies, and supplier guidelines and analyze critical elements.

4. Evaluate the Current State of Risk.

This step checks if the risk is okay for the company. We must take more steps to lower it if it’s too high.

5. Execute a More Detailed Cybersecurity Risk Assessment.

If there’s a high risk, we need to do a detailed assessment to determine where risks could occur and devise ways to deal with them.

6. Continuous documentation is a must.

Document the system’s cybersecurity requirements. This document includes all assumptions, issues, and results and is a reference for security measures and audits.

7. Submit requests to the Change Control Board for Remediation Approval.

Forward recommendations for implementing measures to resolve discovered vulnerabilities and exploits that lead to a cybersecurity breach in the OT environment of the business or asset owner.

Defining The Tolerance for Risk.

Understanding your organization’s unique risks is the first step to building a solid security posture.

Organizations defining their various levels of concerns from current or future cyber attacks against your OT environment start with breaking down the risk consideration into separate categories:

  • Operational Safely Risk (Preventable): What would affect the organization’s employees if a cyberattack shut down the various control units, including PLCs, SCADAs, and other critical infrastructure?
  • Production Impact Risk (Strategic): What is the risk if a cyberattack disrupts production operations, material processing, and automation controls?
  • Environmental Impact Risk (External): What is the risk to the facility and local environment if hackers successfully breach the various protection layers for chemicals, temperature controls, and other critical environmental systems?

What Risk Method Aligns With an OT Environment?

The NIST CSF 2.0 Manufacturing Profile helps industrial manufacturers manage cybersecurity risk in line with industry goals and best practices. It offers a voluntary, risk-based approach to cybersecurity for manufacturing systems, meant to work alongside existing standards and guidelines.

Manufacturing plants are vulnerable to cyber-attacks. Implementing strong cybersecurity measures is essential to protect against disruptions and theft, and CSF 2.0 can help manage these risks effectively.

The CSF 2.0 framework is broken into six categories:

A. Identify – Enhance your knowledge to effectively handle cybersecurity risks related to systems, assets, data, and capabilities.

B. Protect – Establish and place necessary measures to guarantee the provision of essential infrastructure services.

C. Detect – Create and carry out activities to detect cybersecurity incidents.

D. Respond – Create and execute activities to respond to a cybersecurity incident.

E. Recover – Keep plans to bounce back from a cyber attack.

F: Govern—Adding governance to the CSF 2.0 framework will help resolve past disconnections between aligning the framework’s enablement and the organization’s much-needed commitment to a management structure with tighter alignment to CSF 2.0 and validating the relevance of their security policies.

The manufacturing profile complements existing cybersecurity standards and industry guidelines, not replace them. It helps manufacturers prioritize cybersecurity investments to reduce and manage risks. It works alongside the Cybersecurity Framework but is not a one-size-fits-all solution. Each manufacturer will have unique risks and will implement security practices differently.

Manufacturing facilities should follow ISO 55000, 55001, and 55002 for asset management. It helps meet standards, reduce downtime, and boost productivity.

Remediation and Go Forward CyberSecurity Operations Strategy for OT Environments.

By 2025, cyber attackers could harm people through OT environments, making CEOs responsible. Yet, most OT systems go unpatched for an extended period. Manufacturers continue to deploy digital twins to help provide a mirroring production system, extending the organization’s ability to apply critical security patches without causing an operations failure.

Patching and other post-assessment remediation steps are necessary to stop cyberattacks. However, these steps are classified as reactionary, not proactive. OT organizations should proactively implement additional layers of control and processes to move their current security posture.

Here are some recommendations to help.

Threat Modeling and Detection.

Detection and threat modeling are at the core of preventing cyberattacks against converged OT environments. Manufacturers continue to invest in network detection and response (NDR), security information and event management solutions (SIEM), and extended detection and response (XDR) solutions powered by AI. Even with these solutions, manufacturing firms must assess to determine if they are working as expected. OT SecOps teams will burn considerable time and effort chasing false positives and negatives without accurately reporting the detections.

Effective Incident Response.

Manufacturers will continue to become even bigger targets as more infrastructures become IP-enabled and globally accessible, and their data telemetry is processed with cloud-based analytics.

Even with sophisticated threat detection, reference architectures, and encryption, incident response is the most critical function converged OT manufacturing firms must assess. How OT organizations respond will either deter a hacker or encourage them to increase their velocity. Incident response is crucial in responding to future attacks and limiting impact.

Why Hillstrong?

Want to move your organization forward into a proactive OT cybersecurity posture? Hillstrong Group Security has the expertise and experience to assist with this journey. Starting an assessment through remediation and enabling new security protection layers and processes, Hillstrong’s proven method and expertise in OT security will help your organization meet the various compliance frameworks with a go-forward security operations model.

Ready to get started? Click here to schedule your initial consultation.

Want this as a playbook?

Every guide we publish has a companion eBook with templates you can use today.