Setting Goals and Benchmarks for Cybersecurity Improvement

Hillstrong Group Security ·

Author: Roger Hill

The journey to OT cybersecurity maturity is a multi-faceted and continuous process. In the first blog of this series, we discussed how to assess your current OT cybersecurity posture. Now, we move to the next critical step: setting goals and benchmarks for cybersecurity improvement. This phase is essential for guiding your organization toward enhanced security resilience and operational excellence. By establishing clear, measurable goals and benchmarks, you can systematically improve your OT cybersecurity posture, ensuring alignment with industry best practices and regulatory requirements.

Why Set Goals and Benchmarks?

Setting goals and benchmarks is akin to establishing a roadmap for your cybersecurity journey. With them, efforts to enhance security can become cohesive, reactive, and ultimately effective. Goals provide direction and purpose, while benchmarks allow you to measure progress and make data-driven adjustments.

Key reasons to set goals and benchmarks include:

Strategic Alignment: Ensuring that cybersecurity initiatives align with broader business objectives.

Resource Optimization: Efficiently allocating resources to areas with the highest impact.

Risk Management: Prioritizing actions that mitigate the most significant risks.

Compliance: Meeting industry standards and regulatory requirements.

Continuous Improvement: Establishing a culture of ongoing enhancement and resilience.

Defining Clear Cybersecurity Goals

When defining cybersecurity goals, it’s crucial to consider your organization’s unique needs and challenges. Goals should be Specific, Measurable, Achievable, Relevant, and Time-bound (SMART). Here are some example goals for an OT environment:

Enhance Network Segmentation: Achieve complete segmentation of critical OT networks from IT networks within 12 months.

Increase Patch Management Coverage: Within the next 18 months, ensure 95% of OT systems are in scope for regular risk mitigation and/or remediation.

Improve Incident Response: Develop and test incident response plans for all major OT systems within six months.

Conduct Regular Risk Assessments: Perform quarterly risk assessments and adjust security measures accordingly.

Enhance Employee Training: Provide cybersecurity training to 100% of OT staff within the following year.

Establishing Benchmarks

Benchmarks serve as reference points against which performance and progress can be measured. They provide the data needed to assess the effectiveness of cybersecurity measures and inform strategic decisions. Here are steps to establish effective benchmarks:

Identify Key Performance Indicators (KPIs): Determine the metrics that best reflect your cybersecurity performance. Examples include the number of detected incidents, time to respond to incidents, percentage of systems mitigated or patched, and compliance scores.

Set Baseline Measurements: Conduct an initial assessment to understand your current state. This baseline will serve as a comparison point for future measurements.

Define Target Levels: Set target levels for each KPI based on industry standards, regulatory requirements, and organizational goals.

Regular Monitoring and Reporting: Continuously monitor KPIs and report on progress at regular intervals. Use this data to adjust strategies and improve performance.

Common Benchmarks in OT Cybersecurity

Incident Response Time: The average time taken to detect, respond to, and mitigate a cybersecurity incident.

OT Vulnerability Management Compliance: The percentage of OT systems with vulnerabilities mitigated or remediated with the latest security patches.

Network Segmentation Effectiveness: The extent to which OT and IT networks are correctly segmented to prevent lateral movement by attackers.

User Training Participation: The percentage of OT personnel who have completed cybersecurity awareness training.

Vulnerability Management: The number of vulnerabilities identified, mitigated and/or remediated within a specified timeframe.

Case Study: Setting and Achieving Goals in a Manufacturing Environment

Consider a global manufacturing company that aims to enhance its OT cybersecurity posture. Here’s how they might set and achieve their goals:

Goal: Improve OT Vulnerability Management

Current State: Only 50% of OT systems are in scope for the OT vulnerability management program.

Target: Achieve 95% OT vulnerability management coverage within 18 months.

Steps:

–              Conduct a comprehensive inventory of all OT assets.

–              Develop an OT vulnerability management process and risk methodology

–              Develop and implement an OT risk register

–              Train OT staff on the importance and procedures of the OT vulnerability management process.

–              Monitor and report OT vulnerability management progress monthly.

Benchmark: Track the percentage of systems having mitigated and/or remediated vulnerabilities, aiming for incremental improvements.

Goal: Enhance OT Incident Response

Current State: OT Incident response plans need to be updated and tested.

Target: Develop, test, and refine OT incident response plans for all critical OT systems within six months.

Steps:

–              Review and update existing incident response plans.

–              Conduct tabletop exercises to simulate potential incidents.

–              Establish a dedicated incident response team.

–              Invest in advanced detection and response technologies.

Benchmark: Measure the time to detect and respond to incidents during simulations and actual events.

Aligning with Industry Standards

To ensure your goals and benchmarks are robust and comprehensive, align them with established industry standards such as IEC 62443, NIST SP 800-82, and the NIST Cybersecurity Framework (CSF) 2.0. These frameworks provide guidelines and best practices tailored to OT environments, helping you build a resilient cybersecurity posture.

For instance, the NIST CSF 2.0 includes categories like Identify, Protect, Detect, Respond, and Recover, which can serve as a foundation for setting goals and benchmarks. You ensure a holistic approach to cybersecurity improvement by aligning your initiatives with these categories.

Continuous Improvement and Adaptation

Cybersecurity is not a one-time effort but a continuous process. Regularly review and adjust your goals and benchmarks to adapt to evolving threats, technological advancements, and organizational changes. Foster a culture of continuous improvement by encouraging feedback, conducting regular training, and staying informed about the latest cybersecurity trends and best practices.

Conclusion

Setting goals and benchmarks is crucial in the journey to OT cybersecurity maturity. It provides direction, facilitates resource optimization, and ensures continuous improvement. Manufacturing organizations can significantly enhance their cybersecurity resilience by establishing clear, measurable objectives and aligning them with industry standards. Remember, the path to cybersecurity maturity is ongoing, and staying committed to these principles will help you navigate the ever-changing cybersecurity landscape.

For more insights and guidance on OT cybersecurity, stay tuned for the next blog in this series, which will discuss implementing and monitoring cybersecurity controls.

If you need assistance setting and achieving your cybersecurity goals, contact Hillstrong Group Security today. Our experts are here to help you navigate your journey to cybersecurity maturity with tailored solutions and strategic guidance.

Want this as a playbook?

Every guide we publish has a companion eBook with templates you can use today.