Why securing the OT environment against cyberattacks is vital

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Shunichi Miyanaga, Chairman of the Board, Mitsubishi Heavy Industries


  • Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases.
  • Risks can open up during Factory Acceptance Testing, Site Acceptance Testing, shutdown maintenance and brownfield services.
  • Here, we consider how these risks can be mitigated.

Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases, such as Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), shutdown maintenance, and brownfield services, increasing vulnerability to cyber threats. CISA’s 2022 report highlights a 30% increase in OT system cyberattacks, with over 800 incidents. ENISA’s findings corroborate this, showing that 63% of critical infrastructures faced cyber incidents, 55% targeting OT systems.

The early months of 2023 saw notable cyberattacks: a ransomware strike on a U.S. water plant in January; a European power grid disruption in February; and, an Asian transportation company’s operational halt in March. These incidents emphasize the importance of stringent cybersecurity throughout the OT system lifecycle, especially in critical stages

Risks during the FAT milestone and proposed controls

During FAT, a pivotal stage in the OT system lifecycle, the system is tested in a controlled environment to confirm adherence to design requirements. During FAT, however, cybersecurity controls often become less stringent, with emphasis primarily on design specifications over security, unless explicitly included in the scope. It’s crucial to integrate essential high-level cybersecurity controls at this stage to prevent transferring risks or threats to the site post-FAT. This proactive approach is key to maintaining robust security throughout the system’s lifecycle. These controls include, but are not limited to:

• Security of the staging area

Staging areas, designated for pre-deployment system testing, require secure measures to prevent unauthorized access, thereby avoiding the introduction of malware or other threats into production environments.

• People

People are always the weakest point in any security system. It is important to educate employees about best cybersecurity practices. This includes training on how to identify phishing activities, handling sensitive project information, complying with cybersecurity requirements and identifying and reporting a cybersecurity incident.

Discover

How is the World Economic Forum addressing rising cybersecurity challenges?

The Global Security Outlook 2023 revealed that 43% of leaders polled believe that a cyberattack will materially affect their organization in the next two years.

The World Economic Forum’s Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors.

Learn more about our impact:

Want to know more about our centre’s impact or get involved? Contact us.

• Asset lists

An asset list is a comprehensive list of all hardware and software assets used in a specific project. This list is the main pillar to detect and understand if any changes have occurred.

The asset list contains information about firmware versions, OS, IP addresses, MAC addresses, vulnerabilities, what was patched and what wasn’t, the latest updates to end-point security, etc. The list must be maintained and updated regularly to ensure that all assets are properly secured, as well as to enable effective vulnerability and patch management.

• Access controls

Access controls are essential to prevent unauthorized access to sensitive information and systems. This includes implementing strong password policies, multi-factor authentication and other mechanisms to ensure that only authorized personnel can access sensitive areas or functions.

• Secure configuration

Secure configuration involves implementing security best practices when configuring hardware and software systems. This includes disabling unnecessary services and ports, using strong encryption and implementing other security measures to reduce the attack surface of a system.

• Vulnerability and patch management

Vulnerability and patch management involves regularly scanning systems for vulnerabilities and deploying patches to fix known issues. This is critical to prevent attackers from exploiting known vulnerabilities to gain access to sensitive information or disrupt operations.

• Incident management

Incident management involves having a plan in place to respond to cybersecurity incidents when they occur. This includes identifying the scope of the incident, containing it and recovering from it, as well as conducting a post-incident analysis to identify areas for improvement.

All these controls must be implemented and documented during the FAT milestone to ensure that potential risks are not transferred to the site.

https://cdn.jwplayer.com/players/9psU3UfP-ncRE1zO6.html

Risks during the SAT milestone

Similarly, the SAT/shutdown maintenance window and brownfield services milestone also pose a cybersecurity risk to the OT system. During this milestone, the system is tested in its actual environment and any issues are addressed. These milestones, however, may require taking the system offline and cybersecurity controls may be relaxed to facilitate maintenance activities. Moreover, third-party contractors may not be familiar with the system’s cybersecurity controls, leading to potential cybersecurity problems with the completion of maintenance work and when the system/plant is brought online again to resume production. This can result in dozens of untraceable changes to the cybersecurity controls, which are either disabled or bypassed.

Proposed high-level controls

Apart from the high-level controls mentioned during the FAT milestone, additional controls need to be implemented during the SAT/shutdown maintenance window and brownfield services due to the dynamic SAT environment. These controls include:

• Environment integration

During SAT, the system is evaluated for its integration with the surrounding operational systems. This can identify vulnerabilities that might arise due to interactions with other systems or software.

• Network integration and firewalls

As the system is now in its intended network environment, SAT can assess how it interacts with firewalls, intrusion detection systems and other network security measures. It can uncover vulnerabilities, such as open ports, that shouldn’t be open or potential for unauthorized network access.

• Authentication and authorization

While these might be tested during FAT, during SAT, they’re tested in the context of the operational environment. For instance, how the system integrates with the enterprise’s identity and access management solutions.

• Red/blue team testing

Sometimes, organizations might choose to perform more aggressive penetration testing (red team exercises) during SAT to see how the system holds up against simulated cyberattacks in its actual environment.

• Incident response integration

During SAT, you might also test how incidents on the system integrate with the broader organizational incident response plan and tools.

How to mitigate these risks

To mitigate these risks, end-users, contractors, vendors and suppliers must establish and adopt a robust change management process that includes proper documentation, approval mechanisms, testing and validation procedures. This process should ensure that all changes, including those made during the critical and gap periods, are properly tracked, assessed for security implications and validated before the system’s commissioning. A more advanced and strict approach is to assign a dedicated cybersecurity officer to follow up and document all the changes made at different milestones.


Trending now:


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]

This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]

© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]

WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

© UNOCHA/Ximena Borrazas Kateryna and her two children warm up at a heating point and use rhe available electricity to charge their devices.

Keeping people warm amid hostilities and harsh winter weather in Ukraine

This article is published in association with United Nations. As people in war-torn Ukraine face the coldest winter in more than a decade, authorities and humanitarians are working to help them stay warm, particularly the most vulnerable residents.  Russian forces continue to attack Ukraine’s energy grid, leaving families without electricity and heating as temperatures plummet to -20° Celsius.  Since 2022, the Government has established so-called “Invincibility Points” – located in tents or public […]

UN News A UN emergency shelter set up amid the ruins of Gaza.

Gaza: War crimes probe pledges to continue work for justice and accountability

This article is published in association with United Nations. As President Trump launched the international Board of Peace plan for Gaza on Thursday, top independent rights experts tasked by the UN Human Rights Council with investigating grave abuses linked to the Hamas-Israel war pledged to continue their work seeking justice and accountability for all. “The Board […]

© WFP/Maxime Le Lijour Children wait for a hot meal at a kitchen in Khan Younis, Gaza, supported by the World Food Programme.

Cold kills another infant in Gaza as West Bank displacement intensifies

This article is published in association with United Nations. Another child in the Gaza Strip has died from hypothermia as winter weather continues to whip the enclave, the UN said on Wednesday, citing information from the health authorities.  The baby girl – just three months old – was found frozen to death on Tuesday morning at her home in […]

Critical medicines: EU measures to boost competitiveness and tackle shortages 

Critical medicines: EU measures to boost competitiveness and tackle shortages 

This article is brought to you in association with the European Parliament. On Tuesday, Parliament adopted proposals to enhance the availability and supply of essential medicines in the EU. The report, adopted with 503 votes in favour, 57 against and 108 abstentions, aims to ensure a high level of public health protection for EU citizens by […]

Europe Was Warned: Why the Next Pandemic Could Be  Worse 

This article was exclusively written for The European Sting by one of our passionate readers, Dr Taimoor Ahmed Shumail , MD | Dr Ahmed Bilal , MD , Vice  President Global Health and Diplomacy Wing – Pakistan International Medical Students  Association. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position […]

UN News Many Palestinian families are living in poorly equipped shelters that are highly vulnerable to flooding, leaving people inevitably exposed to harsh, stormy weather..

Gaza humanitarian crisis ‘far from being over,’ UN aid coordination office warns

This article is published in association with United Nations. Three months into the ceasefire in the Gaza Strip, the UN and partners have delivered tonnes of assistance items and carried out critical repairs, but this is only a temporary “Band-Aid” solution, a veteran aid worker has warned. “The humanitarian situation and crisis in Gaza is far […]

This article is published in association with European Investment Bank.

Will AI kickstart a new age of nuclear power?

This article is published in association with United Nations. The rapidly expanding use of artificial intelligence worldwide is putting electrical grids under huge pressure and many believe that, to meet that need without contributing to the climate crisis, a full-scale expansion of nuclear energy is essential. The global demand for electricity is growing at a vertiginous […]

UN Photo/Loey Felipe Martha Ama Akyaa Pobee, Assistant Secretary-General for Political Affairs briefs the Security Council meeting on the situation in Iran.

Iran: UN urges ‘maximum restraint’ to avert more death, wider escalation

This article is published in association with United Nations. As nationwide protests in Iran appear to ease after nearly three weeks of unrest and bloodshed, a senior UN official called on Thursday for action to prevent further escalation.  Assistant Secretary-General Martha Pobee briefed an emergency meeting of the Security Council in New York called by the […]

UNRWA UNRWA Headquarters in East Jerusalem

East Jerusalem: Forced shutdown of UN clinic signals escalating disregard for international law

This article is published in association with United Nations. The temporary closure of a UN-run health centre in East Jerusalem is the latest phase in “a pattern of deliberate disregard” for international law, the head of the UN agency that assists Palestine refugees, UNRWA, said on Wednesday.  Israeli forces stormed the UNRWA-operated health centre on Monday and ordered it […]

Unsplash

Iran: ‘The killing of peaceful demonstrators must stop,’ UN rights chief says

This article is published in association with United Nations.  As anti-government demonstrations continue across Iran, the UN human rights chief said on Tuesday that he was horrified at the mounting violence directed by security forces against protestors, with reports of hundreds killed and thousands arrested.  Volker Türk urged the authorities to immediately halt all forms of violence and repression against peaceful […]

© UNHCR/Yevheniia Kozun The bombing of residential buildings in Saltivka, Kharkiv, has left many Ukrainians without power.

Ukraine: Deadly Russian strikes push civilians deeper into winter crisis

This article is published in association with United Nations. Ukraine has entered the new year under intensifying and deadly Russian attacks which have crippled energy systems and left millions without heating, electricity or water amid freezing temperatures, senior UN officials told the Security Council on Monday. Under-Secretary-General for Political Affairs Rosemary DiCarlo told ambassadors the start […]

UN Photo/Eskinder Debebe UN Secretary-General António Guterres. (file photo)

UN chief ‘shocked’ by reports of excessive force against protesters in Iran

This article is published in association with United Nations. The UN Secretary-General is shocked by reports of violence and excessive use of force by Iranian authorities against protesters across the country, urging restraint and the immediate restoration of communications as unrest enters its third week. “All Iranians must be able to express their grievances peacefully and […]

Ukraine: New strikes disrupt basic services for millions

Ukraine: New strikes disrupt basic services for millions

This article is published in association with United Nations. Several parts of Ukraine were hit by a new wave of Russian strikes between Wednesday and Thursday morning. The attacks over the last 24 hours left civilians reportedly killed and injured in the port city of Odesa, interrupting power and water supplies there, as well as in […]

©WFP/Sayed Asif Mahmud Oleg Kemin from the UN World Food Programme (WFP) stands in front of his vehicle in Kherson, Ukraine.

Drones, fear and exhaustion: The daily reality of providing aid to Ukraine

This article is published in association with United Nations. Almost four years since Russia’s full-scale invasion of Ukraine, aid teams continue to adapt to the lethal reality of working in a modern war zone.  For frontline workers like Oleg Kemin from the UN World Food Programme (WFP), this involves travelling deep into disputed territory along the […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading