Why securing the OT environment against cyberattacks is vital

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Shunichi Miyanaga, Chairman of the Board, Mitsubishi Heavy Industries


  • Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases.
  • Risks can open up during Factory Acceptance Testing, Site Acceptance Testing, shutdown maintenance and brownfield services.
  • Here, we consider how these risks can be mitigated.

Despite existing frameworks to secure operational technology (OT) environments, cybersecurity controls often ease or are overlooked during key lifecycle phases, such as Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), shutdown maintenance, and brownfield services, increasing vulnerability to cyber threats. CISA’s 2022 report highlights a 30% increase in OT system cyberattacks, with over 800 incidents. ENISA’s findings corroborate this, showing that 63% of critical infrastructures faced cyber incidents, 55% targeting OT systems.

The early months of 2023 saw notable cyberattacks: a ransomware strike on a U.S. water plant in January; a European power grid disruption in February; and, an Asian transportation company’s operational halt in March. These incidents emphasize the importance of stringent cybersecurity throughout the OT system lifecycle, especially in critical stages

Risks during the FAT milestone and proposed controls

During FAT, a pivotal stage in the OT system lifecycle, the system is tested in a controlled environment to confirm adherence to design requirements. During FAT, however, cybersecurity controls often become less stringent, with emphasis primarily on design specifications over security, unless explicitly included in the scope. It’s crucial to integrate essential high-level cybersecurity controls at this stage to prevent transferring risks or threats to the site post-FAT. This proactive approach is key to maintaining robust security throughout the system’s lifecycle. These controls include, but are not limited to:

• Security of the staging area

Staging areas, designated for pre-deployment system testing, require secure measures to prevent unauthorized access, thereby avoiding the introduction of malware or other threats into production environments.

• People

People are always the weakest point in any security system. It is important to educate employees about best cybersecurity practices. This includes training on how to identify phishing activities, handling sensitive project information, complying with cybersecurity requirements and identifying and reporting a cybersecurity incident.

Discover

How is the World Economic Forum addressing rising cybersecurity challenges?

The Global Security Outlook 2023 revealed that 43% of leaders polled believe that a cyberattack will materially affect their organization in the next two years.

The World Economic Forum’s Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors.

Learn more about our impact:

Want to know more about our centre’s impact or get involved? Contact us.

• Asset lists

An asset list is a comprehensive list of all hardware and software assets used in a specific project. This list is the main pillar to detect and understand if any changes have occurred.

The asset list contains information about firmware versions, OS, IP addresses, MAC addresses, vulnerabilities, what was patched and what wasn’t, the latest updates to end-point security, etc. The list must be maintained and updated regularly to ensure that all assets are properly secured, as well as to enable effective vulnerability and patch management.

• Access controls

Access controls are essential to prevent unauthorized access to sensitive information and systems. This includes implementing strong password policies, multi-factor authentication and other mechanisms to ensure that only authorized personnel can access sensitive areas or functions.

• Secure configuration

Secure configuration involves implementing security best practices when configuring hardware and software systems. This includes disabling unnecessary services and ports, using strong encryption and implementing other security measures to reduce the attack surface of a system.

• Vulnerability and patch management

Vulnerability and patch management involves regularly scanning systems for vulnerabilities and deploying patches to fix known issues. This is critical to prevent attackers from exploiting known vulnerabilities to gain access to sensitive information or disrupt operations.

• Incident management

Incident management involves having a plan in place to respond to cybersecurity incidents when they occur. This includes identifying the scope of the incident, containing it and recovering from it, as well as conducting a post-incident analysis to identify areas for improvement.

All these controls must be implemented and documented during the FAT milestone to ensure that potential risks are not transferred to the site.

https://cdn.jwplayer.com/players/9psU3UfP-ncRE1zO6.html

Risks during the SAT milestone

Similarly, the SAT/shutdown maintenance window and brownfield services milestone also pose a cybersecurity risk to the OT system. During this milestone, the system is tested in its actual environment and any issues are addressed. These milestones, however, may require taking the system offline and cybersecurity controls may be relaxed to facilitate maintenance activities. Moreover, third-party contractors may not be familiar with the system’s cybersecurity controls, leading to potential cybersecurity problems with the completion of maintenance work and when the system/plant is brought online again to resume production. This can result in dozens of untraceable changes to the cybersecurity controls, which are either disabled or bypassed.

Proposed high-level controls

Apart from the high-level controls mentioned during the FAT milestone, additional controls need to be implemented during the SAT/shutdown maintenance window and brownfield services due to the dynamic SAT environment. These controls include:

• Environment integration

During SAT, the system is evaluated for its integration with the surrounding operational systems. This can identify vulnerabilities that might arise due to interactions with other systems or software.

• Network integration and firewalls

As the system is now in its intended network environment, SAT can assess how it interacts with firewalls, intrusion detection systems and other network security measures. It can uncover vulnerabilities, such as open ports, that shouldn’t be open or potential for unauthorized network access.

• Authentication and authorization

While these might be tested during FAT, during SAT, they’re tested in the context of the operational environment. For instance, how the system integrates with the enterprise’s identity and access management solutions.

• Red/blue team testing

Sometimes, organizations might choose to perform more aggressive penetration testing (red team exercises) during SAT to see how the system holds up against simulated cyberattacks in its actual environment.

• Incident response integration

During SAT, you might also test how incidents on the system integrate with the broader organizational incident response plan and tools.

How to mitigate these risks

To mitigate these risks, end-users, contractors, vendors and suppliers must establish and adopt a robust change management process that includes proper documentation, approval mechanisms, testing and validation procedures. This process should ensure that all changes, including those made during the critical and gap periods, are properly tracked, assessed for security implications and validated before the system’s commissioning. A more advanced and strict approach is to assign a dedicated cybersecurity officer to follow up and document all the changes made at different milestones.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

UN News Moreira da Silva (right), Executive Director of UNOPS on a visit to the Gaza Strip.

Strait of Hormuz: With hunger looming, life-saving fertiliser shipments cannot wait, head of UN task force says

This article is published in association with United Nations. As the Persian Gulf crisis continues, time is ticking for farmers who rely on fertilizer shipped via the Strait of Hormuz – and millions worldwide who depend on their crops, particularly in vulnerable countries such as war-torn Sudan.  In normal times, one third of global fertiliser trade […]
UN News A popular market in Khan Younis, southern Gaza Strip.

Economic collapse pushes highly educated Gazans into the ‘survival economy’

This article is published in association with United Nations. Young Palestinians in Gaza with university-level educations are setting aside dreams of putting their hard-won skills into practice and doing whatever they can to survive.  Abdullah al-Khawaja, an electrical engineering graduate displaced from Rafah to Khan Younis, now stands behind a small spice stall, having lost the […]
MONUSCO/Didier Vignon Dossou-Gbakon MONUSCO peacekeepers protect civilians in Ituri, eastern DRC.

World News in Brief: AI diagnostics, humanitarian deal for DR Congo, rights abuse allegations in Belarus, Ukraine children bear heaviest burden

This article is published in association with United Nations. New data shows that nearly three in four countries in Europe now use Artificial Intelligence in their health services to make a diagnosis. According to the UN World Health Organization (WHO) joint report with the European Union, 74% of countries in the bloc use AI tools in medical […]
© WFP The conflict in the Middle East is impacting the cost of food in many parts of the world.

Time running out on development goals as finance dries up, UN warns

This article is published in association with United Nations. Rising conflicts, the climate crisis and shrinking development finance are putting growing pressure on the poorest and most vulnerable countries – pushing development goals further off track. The warning comes in the Financing for Sustainable Development Report 2026 (FSDR), a new UN report launched on Monday, which finds […]
Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

World News in Brief: Myanmar amnesty, rising needs in Afghanistan, another power loss at Ukraine nuclear plant

This article is published in association with United Nations. Authorities in Myanmar released the country’s ousted president from prison on Friday, along with some 4,000 other people, as part of an amnesty to mark the traditional New Year festival. President Win Myint had been in jail since February 2021 when the military overthrew Myanmar’s democratically elected […]
UN Photo/Eskinder Debebe Siobhán Mullally, Special Rapporteur on Trafficking in Persons, especially women and children, one of the UN independent human rights experts calling for more accountability for the alleged trafficking victims in the Epstein files.

The Epstein files: Rights experts demand accountability, call for probe into trafficking allegations

This article is published in association with United Nations. UN independent human rights experts called on Thursday for justice and accountability for young women and girls who were trafficked systematically as part of allegations contained in the so-called Epstein files. The Human Rights Council-appointed experts also issued a general warning over the “continuing violence of patriarchal power systems” revealed […]
© World Bank A ship offloads its cargo at the port in Nuku'alofa, Tonga.

Middle East conflict chokes end of supply chain as lights go out in the Pacific

This article is published in association with United Nations. For Pacific Island countries, the Middle East crisis is not a distant geopolitical event. It is already showing up in higher fuel prices, electricity uncertainty and fears that communities sitting at the far end of global supply chains could be pushed into deeper economic insecurity. “We are […]
© UNICEF/Fouad Choufany The Basta neighbourhood in Beirut, Lebanon, lies in ruins.

‘Time for diplomacy over escalation’ in Middle East war: Guterres

This article is published in association with United Nations. As the war in the Middle East continues, the United Nations Secretary-General issued a passionate call for “serious negotiations” between the US and Iran to resume, warning that respect for international law “is being trampled” underfoot.  Addressing journalists at UN Headquarters in New York outside the Security […]
© IFAD/GMB Akash Prolonged disruptions to fuel and natural gas supplies could affect the global availability of fertilizers and impact crop yields. (file photo)

‘Clock is ticking’: Hormuz disruption raises fears of global food crisis

This article is published in association with United Nations. The clock is ticking for global food systems as disruptions in the Strait of Hormuz threaten to choke off the flow of fuel and crucial fertilizers needed for the next planting season – also raising the risk of higher food prices and a new wave of inflation.  […]
This article is published in association with United Nations.

Lebanon airstrike casualties ‘still under the rubble’ as ambulances, hospitals face new threats

This article is published in association with United Nations. With Lebanon still reeling from Israel’s devastating airstrikes on 8 April, UN humanitarians reported new fears of attacks on ambulances and looming food shortages in the south of the country on Friday. Speaking from Beirut, where he witnessed Wednesday’s attacks first-hand, the World Health Organization (WHO)’s representative […]
This article is published in association with United Nations.

Lebanon: Health system overwhelmed following a ‘horrific’ day of Israeli strikes

This article is published in association with United Nations. The scale and speed of destruction from the wave of airstrikes in Lebanon which began just hours after the US-Iran ceasefire announcement, has left the country’s already strained health system struggling to cope, according to the World Health Organization (WHO). WHO Representative in Lebanon Dr. Abdinasir Abubakar […]
© NASA/Jeff Schmaltz A satellite image shows the Strait of Hormuz. (far right)

Iran ceasefire raises hopes for reopening key Strait of Hormuz

This article is published in association with United Nations. The announcement of a shaky two-week ceasefire between the US and Iran, will it is hoped, lead to the opening of the strategically important Strait of Hormuz, a vital waterway through which one fifth of the world’s oil and gas passes. The strait has become a global […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

Global Health Priorities for the Year Ahead: Why the Next Generation Must Lead

This article was exclusively written for The European Sting by Mr. Sharif Mohammed Sadat, a medical student from Bangladesh and serves as the Regional Director for Asia-Pacific of the International Federation of Medical Students’ Associations (IFMSA). He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this […]
© IOM Families returning to Khartoum face the mounting task of rebuilding their lives and livelihoods amid damaged homes and limited access to basic services (file).

World News in Brief: ‘Skyrocketing’ needs outpace Sudan funding, Ukraine strikes update, global water security

This article is published in association with United Nations. The UN is significantly scaling up its presence in the Sudanese capital, Khartoum, to expand life-saving operations as the conflict between rival militaries approaches its third year. UN Resident and Humanitarian Coordinator Denise Brown has returned to the city with a core team, marking a renewed commitment […]
© UNHCR Smoke and debris from a building in the Bashura neighbourhood of Beirut, Lebanon, after an airstrike.

MIDDLE EAST LIVE 6 April: Strikes persist across region as humanitarian needs rise

This article is published in association with United Nations. Strikes and counter-strikes continue across the Middle East, with dozens of casualties reported over the weekend in Lebanon following Israeli strikes targeting the south and the capital, Beirut. Meanwhile, humanitarian needs are rising, critical infrastructure remains under strain, and the wider economic and global impacts of the […]
This article is published in association with United Nations.

UN nuclear agency chief ‘deeply concerned’ by reports of latest attack on Iran power plant

This article is published in association with United Nations. Reports of yet another projectile strike near the Bushehr nuclear power plant prompted Rafael Grossi, head of the International Atomic Energy Agency (IAEA), to register his deep concern on Saturday. The IAEA was informed of the strike – the fourth such incident in recent weeks – by […]
This article is published in association with United Nations.

Guterres warns of ‘wider war’ as Middle East conflict enters second month

The Middle East crisis has lurched into its second month, prompting UN Secretary-General António Guterres to issue a stark warning on Thursday morning that the world is “on the edge of a wider war” with catastrophic global implications. Speaking to the press outside the Security Council in New York, the UN chief painted a grim picture of the rapidly […]
This article is published in association with United Nations.

Middle East war: Energy crunch hits vulnerable nations

The war in the Middle East and the near halt to shipping in the Strait of Hormuz has amplified the energy crunch facing developing nations in Africa and South Asia that rely heavily on imported liquid gas, food and fertilizers.  And with Brent Crude still trading at more than $100 per barrel, many workers and households have reverted to […]
© WHO UN officials in Cyprus oversee the loading of emergency humanitarian supplies for Gaza.

Breaking the Gaza aid bottleneck: 106-tonne delivery arrives via new sea route

This article is published in association with United Nations. The World Health Organization (WHO) has facilitated the delivery of some 106 metric tonnes of lifesaving nutrition supplies to the Gaza Strip – the first shipment via a mechanism to deliver aid by sea, in line with a UN Security Council resolution and amid the ongoing war […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com