Why securing the OT environment against cyberattacks is vital

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Shunichi Miyanaga, Chairman of the Board, Mitsubishi Heavy Industries


  • Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases.
  • Risks can open up during Factory Acceptance Testing, Site Acceptance Testing, shutdown maintenance and brownfield services.
  • Here, we consider how these risks can be mitigated.

Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases, such as Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), shutdown maintenance, and brownfield services, increasing vulnerability to cyber threats. CISA’s 2022 report highlights a 30% increase in OT system cyberattacks, with over 800 incidents. ENISA’s findings corroborate this, showing that 63% of critical infrastructures faced cyber incidents, 55% targeting OT systems.

The early months of 2023 saw notable cyberattacks: a ransomware strike on a U.S. water plant in January; a European power grid disruption in February; and, an Asian transportation company’s operational halt in March. These incidents emphasize the importance of stringent cybersecurity throughout the OT system lifecycle, especially in critical stages

Risks during the FAT milestone and proposed controls

During FAT, a pivotal stage in the OT system lifecycle, the system is tested in a controlled environment to confirm adherence to design requirements. During FAT, however, cybersecurity controls often become less stringent, with emphasis primarily on design specifications over security, unless explicitly included in the scope. It’s crucial to integrate essential high-level cybersecurity controls at this stage to prevent transferring risks or threats to the site post-FAT. This proactive approach is key to maintaining robust security throughout the system’s lifecycle. These controls include, but are not limited to:

• Security of the staging area

Staging areas, designated for pre-deployment system testing, require secure measures to prevent unauthorized access, thereby avoiding the introduction of malware or other threats into production environments.

• People

People are always the weakest point in any security system. It is important to educate employees about best cybersecurity practices. This includes training on how to identify phishing activities, handling sensitive project information, complying with cybersecurity requirements and identifying and reporting a cybersecurity incident.

Discover

How is the World Economic Forum addressing rising cybersecurity challenges?

The Global Security Outlook 2023 revealed that 43% of leaders polled believe that a cyberattack will materially affect their organization in the next two years.

The World Economic Forum’s Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors.

Learn more about our impact:

Want to know more about our centre’s impact or get involved? Contact us.

• Asset lists

An asset list is a comprehensive list of all hardware and software assets used in a specific project. This list is the main pillar to detect and understand if any changes have occurred.

The asset list contains information about firmware versions, OS, IP addresses, MAC addresses, vulnerabilities, what was patched and what wasn’t, the latest updates to end-point security, etc. The list must be maintained and updated regularly to ensure that all assets are properly secured, as well as to enable effective vulnerability and patch management.

• Access controls

Access controls are essential to prevent unauthorized access to sensitive information and systems. This includes implementing strong password policies, multi-factor authentication and other mechanisms to ensure that only authorized personnel can access sensitive areas or functions.

• Secure configuration

Secure configuration involves implementing security best practices when configuring hardware and software systems. This includes disabling unnecessary services and ports, using strong encryption and implementing other security measures to reduce the attack surface of a system.

• Vulnerability and patch management

Vulnerability and patch management involves regularly scanning systems for vulnerabilities and deploying patches to fix known issues. This is critical to prevent attackers from exploiting known vulnerabilities to gain access to sensitive information or disrupt operations.

• Incident management

Incident management involves having a plan in place to respond to cybersecurity incidents when they occur. This includes identifying the scope of the incident, containing it and recovering from it, as well as conducting a post-incident analysis to identify areas for improvement.

All these controls must be implemented and documented during the FAT milestone to ensure that potential risks are not transferred to the site.

https://cdn.jwplayer.com/players/9psU3UfP-ncRE1zO6.html

Risks during the SAT milestone

Similarly, the SAT/shutdown maintenance window and brownfield services milestone also pose a cybersecurity risk to the OT system. During this milestone, the system is tested in its actual environment and any issues are addressed. These milestones, however, may require taking the system offline and cybersecurity controls may be relaxed to facilitate maintenance activities. Moreover, third-party contractors may not be familiar with the system’s cybersecurity controls, leading to potential cybersecurity problems with the completion of maintenance work and when the system/plant is brought online again to resume production. This can result in dozens of untraceable changes to the cybersecurity controls, which are either disabled or bypassed.

Proposed high-level controls

Apart from the high-level controls mentioned during the FAT milestone, additional controls need to be implemented during the SAT/shutdown maintenance window and brownfield services due to the dynamic SAT environment. These controls include:

• Environment integration

During SAT, the system is evaluated for its integration with the surrounding operational systems. This can identify vulnerabilities that might arise due to interactions with other systems or software.

• Network integration and firewalls

As the system is now in its intended network environment, SAT can assess how it interacts with firewalls, intrusion detection systems and other network security measures. It can uncover vulnerabilities, such as open ports, that shouldn’t be open or potential for unauthorized network access.

• Authentication and authorization

While these might be tested during FAT, during SAT, they’re tested in the context of the operational environment. For instance, how the system integrates with the enterprise’s identity and access management solutions.

• Red/blue team testing

Sometimes, organizations might choose to perform more aggressive penetration testing (red team exercises) during SAT to see how the system holds up against simulated cyberattacks in its actual environment.

• Incident response integration

During SAT, you might also test how incidents on the system integrate with the broader organizational incident response plan and tools.

How to mitigate these risks

To mitigate these risks, end-users, contractors, vendors and suppliers must establish and adopt a robust change management process that includes proper documentation, approval mechanisms, testing and validation procedures. This process should ensure that all changes, including those made during the critical and gap periods, are properly tracked, assessed for security implications and validated before the system’s commissioning. A more advanced and strict approach is to assign a dedicated cybersecurity officer to follow up and document all the changes made at different milestones.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com