Transicon's senior project engineer Niall Sephton offers SMEs a five-step strategy to break down the big issue of Operational Technology (OT) cyber security and strengthen cyber resilience.
OT cyber security can be an overwhelming and often worrying area for manufacturers and businesses in an ever-changing world.
It is a big subject that is not going away and is something you have to embrace and keep on top of.
According to ESET report, 78% of UK manufacturers experienced a cyber security incident in the last 12 months, with 95% reporting business disruption as a result.
However, despite the scale of the risk, the same research found that only 22% of manufacturing organisations assign cyber security responsibility to board or executive leadership.
With the threat landscape constantly evolving, it has become a real issue for UK manufacturing. However, despite it feeling overwhelming, there are things you can do to break down what may seem like a big issue.
Here is Niall's five-step approach to strengthening your cyber resilience:
Build the right team
The first key point is recognising that security should be a shared responsibility, rather than being down to one person or a department.
You need to have open communication between everyone involved, because each group has valuable knowledge that can contribute to identifying and reducing risks.
Identify enthusiastic people who have an interest in the area, even if they are not technical experts.
These 'site champions' should encourage good security practices, promote awareness and act as a link between staff and management.
If internal expertise is limited, you can also engage with external specialists for guidance and support, but ultimately cyber security begins with people and creating a culture around collaboration.
Know what you have
Before you can secure your OT environment, you must know what you own.
Creating a complete inventory of every connected device – from PLCs, sensors, drives, HMIs, servers, networking equipment and communication links – is key.
Older, undocumented or forgotten assets can become significant vulnerabilities and they also need to be included.
Another important point is to develop logical network diagrams that show how systems communicate and data flows, as well as considering physical security in terms of unsecured control panels and where cables and communication links are.
Automated asset discovery tools can simplify the documentation process by identifying devices and infrastructure.
Assess risk and develop a roadmap
Once you understand your assets, the next step is evaluating the risks they present and prioritising improvements.
Sometimes budgets can be limited, and you should focus first on systems where failure would have the greatest impact.
Protecting human safety should always be the highest priority, followed by systems that are critical to maintaining production.
It is important to recognise that cyber security is a long-term process, rather than one project – environments cannot be fully secured overnight.
The most important thing is to recognise that there are issues out there. We all know there are. Accept that and start chipping away.
Develop a realistic roadmap that breaks improvements into manageable phases over several years if necessary. This allows investments to be prioritised while ensuring continuous progress is made.
Design and implement security controls
Having put together an asset inventory and risk assessment, you should start putting in place appropriate cyber security controls.
One priority is segmenting networks by separating plant-level systems from historians and data management.
Physical resilience is equally as important and a robust back-up strategy should follow what is known as the 3-2-1 backup rule: three copies of data, on two different media types, with one copy stored off-site.
Back-ups must be tested regularly to enable you to restore them quickly and successfully when needed.
Keep going – always monitor
As has been mentioned already, cyber security is an evolving beast and keeping on top of it is an ongoing process that requires monitoring and improvement.
As equipment is upgraded, manufacturing sites are constantly evolving, processes change and new technology is introduced.
While this is going on, cyber threats continue to develop, meaning measures that were secure last year may no longer be adequate.
Regularly review and update your risk assessments to reflect changes and the external threat landscape.
Systems can be monitored using appropriate security technologies and, ultimately, cyber security should be viewed as a continuous improvement cycle rather than a project that ends.
Regular reviews and maintenance are essential to protecting long-term operations – so accept where you are, start chipping away and never stop.
If you’re still unsure where to start on improving your OT cybersecurity, then get in touch. We can help with initial assessments and help build a road map.
If you want further information on the five-step guide to OT Cyber Security, you can re-watch the webinar below.