DCS; Industrial control system
NameDescriptionContent
NEW CENTER
Current Location:

Ensuring Cyber Resiliency for OT Systems

来源:THOMAS | 作者:H | 发布时间 :155 days ago | 88 次浏览: | Share:

Ensuring Cyber Resiliency for OT Systems

Cyber resilience is the ability for an entity to continuously deliver the intended outcome despite cyber-attacks. In this case, the “entity” could likely be your plant and the “intended outcome” is the results produced by your operational technology (OT) efforts. Stated simply, being cyber resilient means your operations stay in operation even though they may be under cyber-attack.

“Cyberworthiness” is an assessment of the resilience of a system from cyber-attacks. It is applicable to software and hardware elements like standalone software, code deployed on an Internet site, browsers, manufacturing equipment or Industrial Internet of Things (IIoT) devices.

Whether intentional—as in a cyber-attack—or unintentional—as in a failed software update—adverse cyber events negatively impact the availability, integrity, or confidentiality of networked OT and information technology (IT) systems and associated services.
 

Cybersecurity versus cyber resilience

Cyber resilience is designed to prevent systems and networks from being derailed in the event that security is compromised. The manufacturing line, refinery or pipeline “stays” operational. Cyber resilience means that cybersecurity is effective without compromising the usability of OT systems (Figure 1).

Figure 1: Cyber resilience means that cybersecurity is effective without compromising the usability of OT systems.

According to Phil Tonkin, field CTO at Dragos, cybersecurity is concerned with the protection of digital systems, whereas cyber resilience considers the real-world implications of cyber events—extending beyond the digital defense perimeter to encompass the ability of an organization to maintain its core functions and recover swiftly from any form of cyber disruption. “In the world of OT, infrastructure owners as asset managers are concerned with the integrity and reliability of their assets. An electric company needs to worry about keeping a reliable, efficient and clean energy supply to its customers, how they achieve that is resilience. It’s not just protecting the system against compromise but managing the risks of downstream effects.”

Greg Hale, editor and founder of ISSSource, said that resiliency is a plan to find ways to keep the plant/network/system up and running despite an ongoing attack. It is related closely to the business continuity plan. “Cybersecurity, on the other hand, is the overall general idea of protecting assets. The government says resilience entails the ability of a system to anticipate, withstand, recover from and adapt to cyberattacks and natural or accidental disruptions,” he said.

Hale wrote in a recent article in The Source: “A core meaning behind cybersecurity is keeping systems up and running and secure against any kind of attack. But when an organization does suffer a hit, the next step in the ladder of protection needs to be resilience—how to stay up and running no matter the type of assault.”

“Cybersecurity focuses on the implementation of capabilities and controls such as identification, detection, protection and so on, whereas resilience relates to the ability to withstand attacks, bring appropriate response and ability to recover swiftly,” said Mansur Abilkasimov, vice president of Cyber and Product Security Strategy and Governance at Schneider Electric.



Need for cyber resilience is real

Hale points out that one of the classic cases of a lack of cyber resilience is the Colonial Pipeline incident a few years back (Figure 2). “There was a ransomware attack on the company’s IT department and while OT systems remained up and capable of running, the company shut down completely for about four or five days ‘out of an abundance of caution.’ The real reason was the company’s billing system was run on the IT side and if that was held for ransom, the company could not bill its customers and therefore not make any money, so they had to shut everything down. Even though OT was not affected, they had no plan on what they should do to stay running in case of an attack.”

Figure 2: One of the classic cases of a lack of cyber resilience is the Colonial Pipeline incident.

Roy Kok, senior partner and Alliances specialist CLPA at Mitsubishi Electric Automation Inc. said that cyber resilience becomes an interesting challenge for Mitsubishi Electric going forward “because we’re the only company that’s offering combined networking. Most industrial automation companies have a control network and an information network, the control network being focused on deterministic performance and also being dedicated to doing the control. And then of course, the information network is open to the IT world, performance management, quality and so on.”

With combined networking, cyber resilience is increasingly important. “Our protocol is called CC-Link IE TSN. IE stands for ‘industrial Ethernet.’ TSN [time-sensitive networking] is the enhancement to the Ethernet spec that happened back in 2016, which allows you to have deterministic performance. It’s like setting up a private channel on Ethernet that guarantees that your control will have deterministic performance regardless of anything else on the network. The spec has been enhanced to allow scheduling of communications, which means that means devices on a network know when they have an opportunity to speak—traffic shaping.”

The tie-in with cyber resilience is Mitsubishi Electric’s push to bring these security efforts to CC-Link and TSN. “By combining the networks” Kok continued, “there are little things that we take for granted. When you make a device that is compliant with our protocol, you get SNMP [simple network management protocol] support in the device as well. And SNMP lets IT systems ping and communicate with all kinds of endpoint devices. Those endpoint devices used to be isolated on a control network but are now exposed because they’re on a combined network.”

There is greater access to information. “It gives you greater ability to manage all the devices on your network,” said Kok. “Cybersecurity tends to be more important in that world. We're creating the opportunity for smarter machines because you have better communications with every aspect of the machine from its control devices to its PLCs [programmable logic controllers.

Abilkasimov  said the cybersecurity threat landscape is continuously evolving, and as a next step organizations should validate if their cybersecurity controls can respond to their current environment or threat landscape. Schneider Electric’s cybersecurity resiliency approach is multifaceted. “This strategy starts at the top. The cybersecurity objectives are set by the Global CISO [Chief Information Security Officer], and the implementation of the strategy is carried out by the executive management team as a whole. A key element of the initiatives are the employees, so the resilience strategy includes robust training and education of all its employees. The strategy company-wide, risk-informed approach that has preventative (breach readiness) and response (breach resilience) measures in place for potential incidents,” he said.

Schneider’s program includes:


  • Employee training and awareness: The company aims to raise employee cybersecurity awareness, provide relevant training and create a culture to empower employees across IT and OT to act in a secure manner. The training includes an annual baseline awareness course for all employees and role-based trainings for specialized populations including cybersecurity site leaders.

  • Enterprise risk management (ERM) framework: Schneider Electric categorizes and translates cybersecurity risks into business and operational scenarios and exposure. This exposure is communicated with the C-suite to drive investments in risk mitigation initiatives. This framework is aligned to National Institute of Standards and Technology (NIST) Cybersecurity Framework and increases the company’s overall level of cyber resilience.

  • Incident response capabilities: Schneider Electric is constantly testing and improving its capacity to respond to operational disruption, damage to customers, compliance issues and IP theft. Its incident response plans are defined, and stress-tested routinely to ensure preparedness. The Security Operations Center (SOC) operates 24/7/365 and is staffed with security analysts leveraging security incident and event management (SIEM) capabilities with OT scenario-based playbooks and responders.

  • Crisis simulation exercises: Crisis simulations aim at training senior executives through operational roles, enhancing external collaboration and internal coordination and reviewing internal processes around crisis resolution. The company’s simulation activities follow a comprehensive framework with realistic and risk-based scenarios for the best outcomes and learning. The goal is for simulations go beyond testing and training and focus on examining and improving operational processes while enhancing readiness for future crises through experiential learning.

The combination of these programs ensure that cybersecurity risk is not an afterthought for the organization but rather an intentional practice to ensure cybersecurity resilience.

“Dragos emphasizes the importance of understanding the specific threats and vulnerabilities that could impact critical systems and assets and ensures that important context is built into its technology,” said Tonkin. “This begins with a thorough assessment to identify the ‘crown jewels’ or most critical components of an organization’s operations. Based on this assessment, Dragos advocates implementing controls that are proportionate to the actual threats and vulnerabilities identified.”

For example, a prominent water utility, responsible for managing 20 dams and 2,000 kilometers (1,243 miles) of pipelines, recognized the critical nature of its infrastructure and took steps to adopt a proactive cybersecurity stance to get ahead of potential threats. Audits pinpointed areas that needed improvement, raising leadership’s awareness of the importance of OT cybersecurity.

When seeking a cybersecurity provider, the utility prioritized OT-specific expertise and reputable providers. The water utility adopted the Dragos OT cybersecurity platform to streamline and advanced its cybersecurity programs to ensure the secure delivery of water to more than 5,000 commercial customers and enable critical projects in collaboration with industry, mining and government agencies.

The partnership with Dragos has resulted in increased efficiency, productivity and cybersecurity readiness. The utility is prepared to counter evolving cyber threats and plans to expand the footprint of the Dragos Platform in the future by adding sensors at prioritized sites.


Automate—with caution

In an ISAGCA blog post, titled “The Danger of Overreliance on Automation in Cybersecurity,” Zac Amos, features editor at ReHack, and frequent contributor to the ISAGCA Blog wrote: “Automation is critical in enhancing cybersecurity efforts, and speed is one of its key benefits. Most cyberthreats spread quickly, such as ransomware or worm attacks, and automated systems can detect and respond to them much faster than humans can. AI [artificial intelligence] also ensures consistency because it can do repetitive tasks with high accuracy. However, it’s easy to rely too heavily on automation to provide cybersecurity. The volume of logs, alerts, and incidents is multiplying exponentially, and automated tools can analyze vast amounts of data without getting overwhelmed. This can be a double-edged sword, though. Companies should have a healthy balance of tech and human talent when keeping systems safe.”

Amos warns that some of dangers of being overly dependent on automation in cybersecurity include a false sense of security, false positives and/or negatives, lack of context, reduction in human expertise and reliability concerns to name a few. “Believing that automated systems will catch every threat can make organizations complacent. No system is perfect, and new, unforeseen threats are always emerging,” he said.

“Automated systems can generate false positives, which can desensitize security teams if they happen frequently,” Amos said. “Conversely, false negatives, where a genuine threat goes undetected, can have severe implications.” In addition, “automated systems lack the human intuition and context needed to evaluate the risk and importance of a particular alert. A seasoned security expert can differentiate between a benign activity that looks suspicious and a genuine threat. Over-relying on automation reduces the need for human experts, which means an organization might have fewer experts who fully understand the system. This can be dangerous if things fail or are compromised.”

Reliability is always a concern when using automation to bolster cyber resilience. “Like any technology, automated systems can fail. Overreliance without redundancy can lead to exposure when these systems experience downtimes,” Amos said.


Becoming cyber resilient: awareness

When it comes to cyber resilience, the biggest difference now from three or four years ago is awareness. “Companies understand they can’t fight off all attacks and some will get in. Depending on what kind of plan they have and how they approach it, remains up to the individual company,” said Hale.

Hale said that organizations’ approach must shift from a futile quest for absolute invulnerability to a more realistic strategy of resiliency in which they can control the impacts of failures. Resilience means organizations need to identify the most critical assets and determine what they find as an acceptable return to operations. “Today, organizations are more aware and more tuned into the idea that attacks are going to happen so they better be protected and then understand—and have a plan—as to what they should be doing and what should happen if an attack makes it in and starts to create issues. This is also where quality segmentation and micro segmentation come into play… Three years ago, they were running around putting out fires and trying to ward off attacks. Today, companies have realized attacks are going to happen, so let’s figure out what are the most important areas we need to protect and then create a plan around that.

“Industry is maturing in its understanding of cybersecurity. Gone are the days of lacking broad attention for the topic when it was viewed as a technical issue rather than a strategic one,” said Tonkin. “Today, the subject of managing cyber risks to improve operational integrity and resilience is becoming much more aligned with the overall risk management of organizations. This maturation in approach reflects a deeper understanding of the interconnectedness between cybersecurity and business continuity. Organizations are now more proactive in identifying and protecting critical assets, assessing vulnerabilities and implementing comprehensive cybersecurity measures that support resilience. This includes not just technological solutions but also organizational and procedural changes to enhance the ability to withstand and recover from cyber incidents.”


  • GE Fanuc - IS200EXHSG3A High-Speed Relay Driver Terminal Board for Exciters
  • GE IS200TRLYH1BGF - Advanced Relay Termination Circuit Board for Industrial Control
  • GE A06B-6151-H075 - Spindle Amplifier Module High Precision Control for Industrial Applications
  • GE DS200TBQDG1A - Advanced Extension Analog Termination Board for Industrial Control Systems
  • GE IC697CMM742-HK - Advanced Ethernet Module for Industrial Automation
  • GE IC200CHS002 - Box-Style Input/Output Carrier
  • GE VME-MB-Z004 - MODULE Advanced Industrial Control Solutions
  • GE IS200ERDDH1ABB - High-Performance Circuit Board for Speedtronic System
  • GE IS210AEBIH3BE - Printed Circuit Board
  • GE MIWII - 1000E00HI00 High Precision Counter Module
  • GE Electric - IC693MDL931 Isolated Relay Output Module
  • GE Fanuc - IS215UCVEH2AE Advanced Gas Turbine Control System
  • GE 531X111PSHARG3 - Industrial Power Supply Card
  • GE DS200TCQCG1RJD - Power Supply Board for Industrial Control Systems
  • GE IC693PRG300 - G300 Hand-Held Programmer
  • GE FANUC - 78004654B High Performance Industrial PLC Module
  • GE A06B-6093-H101 - Servo Amplifier Unit Precision Control for Advanced Applications
  • GE DS200TCPDG2BEC - A Comprehensive Power Distribution Board for Industrial Control Systems
  • GE DS3800NPSJ1B1B - High-Performance Power Supply Board for Industrial Control Systems
  • GE GE - IS200GFOIH1A High-Performance Control Module for Industrial Automation
  • GE IS215ACLEH1AB - Original Equipment Manufacturer Control Module
  • GE Fanuc - F650BABF2G0IHI PLC Module High-Performance Control Core
  • GE DS200ADPBG1ABB - Precision Engineered Genius Adapter Module for Advanced Control Solutions
  • GE IS210HSLAH1ADE - High-Speed Serial Link Interface Circuit Board
  • GE IS215GFOIH1A/IS215GFOIH1AB/IS200GFOIH1A - Industrial Control Systems for Enhanced Performance & Reliability
  • GE CM415REBKH1B - Tuning Fork Crystal Unit for Industrial Control Systems
  • GE Fanuc - IC694MDL916 Advanced Programmable Automation Controller
  • GE Fanuc - SR469-P5-HI-A20 Motor Protection System Comprehensive Control for Large Motors
  • GE Electric - IC693ALG221 Affordable Industrial Control Module
  • GE Electric - DS200TCQRG1RFC Circuit Board Advanced IO Expansion Module
  • GE FANUC - IC694MDL740 Modular Control System Module
  • GE IC697MDL753 - Industrial Output Module Precision Control for Your Operation
  • GE DS3800HAFA1D - Industrial Control Module for Power Generation
  • GE DS200TCDAG1A - Advanced Digital I/O Board for Industrial Control
  • GE UR6TH - Module Digital Input/Output
  • GE FANUC - DS200SNPAH1ABB Advanced Gas Turbine Control Module
  • GE IS220PSCAH1A - IO Pack for Serial Communications
  • GE Fanuc - IC698PSA100E Durable Industrial Power Supply Module
  • GE IC693PWR322 - High-Performance Power Supply for Industrial Control Systems
  • GE FANUC - IC697CPM925 CPU MODULE Industrial Control Solution
  • GE IC3600SSLB1H1B - Gas Turbine Control Module
  • GE DS3800HPRB1A1A - Precision Pulse Rate Card for Industrial Control Systems
  • GE DS4820R20 - Relay Module (194B5704G1) Reliable Industrial Control Solution
  • GE IC698CHS009 - Rear Mounted Rack Industrial Control Module
  • GE IC694ALG392 - Analog Output Module for Industrial Control Systems
  • GE DS200TCDAH1BGD - Advanced I/O PC Board for Industrial Automation
  • GE Electric - DS200TCEAG1BTF Emergency Overspeed Board
  • GE IS420YAICS1B - Analog I/O Module for Industrial Control Applications
  • GE Fanuc - IC693PWR331CA High-Efficiency Power Supply for Industrial Control Systems
  • GE UR9NH - CPUUR PLC CPU Module
  • GE SR735-5-5-HI-485 - Relay
  • GE Fanuc - 0285A7595 MGM115 Programmable Logic Controller Module
  • GE Fanuc - IC200MDL102 Input Modules Advanced Control Solutions
  • GE M60K03HKHF8LH4CM8NP6EUXXW5C - Industrial Control Module
  • GE Industrial - Systems IS200BICIH1ADC PCB Board
  • GE IC200CPU001 - Advanced Microcontroller Module
  • GE DS200TCQCG1BJF - PLC Overflow Board
  • GE Fanuc - IS200TRPGH1B Terminal Board Advanced Control Solution for Industrial Automation
  • GE IC693CPU313LT - Advanced Series 90-30 PLC Controllers
  • GE Industrial - Controls 8601-FT-NI Field Terminal Module
  • GE IC200CHS001 - Industrial Control System I/O Carrier
  • GE IC693CHS397M - High-Performance Programmable Logic Controller Module
  • GE 0552N1QLG132A-01 - Control Module Advanced Industrial Automation Solution
  • GE A20B-1006-0270 - Keyboard Panel High-Performance Control Module
  • GE IS210AEAAH1BKE - Industrial Strength Mark VI PCB for Enhanced Turbine & Excitation Control Systems
  • GE Fanuc IC200UAL005 Versamax PLC - Industry-Leading Control Solution
  • GE IC693PWR330 - Industrial Power Supply
  • GE IC200ALG620 - Industrial Input Module
  • GE DS200SLCCG3ACC - & DS215DENCG3AZZ01A | Industrial Communication Board
  • GE DS3800HPIB - Industrial Grade Panel Interface Board for Turbine Control
  • GE DS200SDCIG2AFB - High-Performance SDCI Board for Industrial Automation
  • GE IS200MVREH1AAB - Advanced Control Board for Industrial Automation
  • GE DS3820RDMB - Control Card Precision in Automation
  • GE FANUC - VMIVME-7671-421000
  • GE DS200SLCCG3AGH - Advanced Industrial Control System
  • GE IC695CPE330 - Dual-Core Microprocessor Industrial Control Module
  • GE Fanuc - DS200LDCCH1A Advanced Mark V PLC for Industrial Control
  • GE IS200XDIAG1A-DD - Advanced Circuit Board PLC for Industrial Automation
  • GE IS200ACLAH1A - Advanced Control Assembly
  • GE Fanuc - IC697CPM790 PLC Control Module
  • GE UR6EH - I/O Module for Advanced Industrial Automation
  • GE Fanuc - IC693CPU374HW PAC Systems RX3i
  • GE Electric - IS220YDOAS1AK Analog I/O Pack Industrial Automation Solutions
  • GE FANUC - VMIPCI-5565-110000 Advanced Reflective Memory Node Card for Industrial Automation
  • GE Fanuc - HE693STP311 Indexer Stepper Motor High Performance for Industrial Control Systems
  • GE Fanuc - IS230SNAIH4A/IS200STAIH2ACB Precision Control for Industrial Automation
  • GE IC200MDL740J - Output Module Advanced Control Solutions for Industrial Automation
  • GE FANUC - 745-W2-P5-G5-HI-A-L | Advanced Transformer Protection System
  • GE Electric - DS200TCDAH1 Digital I/O Board Control Systems
  • GE FANUC - IC660BBR101 Relay Block High Performance Modular PLC Component
  • GE FANUC - DS200ADMAH1AAC Precision Digital-Analog Module for Industrial Control Systems
  • GE Fanuc - IC697VAL314 Programmable Automation Controller
  • GE HE693RTM705C - RTU Master Module
  • GE DS200FCSAG2ACB - Advanced Control System Module for Industrial Automation
  • GE Fanuc - IC200TBM002 | Versamax PLC Modular Control Heart
  • GE VMIPMC-5565 - Memory PMC Modules
  • GE IC687BEM744 - High-Performance Bus Controller
  • GE Electric - IS215ACLEH1AB
  • GE HE700GEN100 - Advanced VME Interface Module for Industrial Control Systems
  • GE IS200HFPAG2ADC - Precision Circuit Board for Industrial Control Systems
  • GE Electric - 0621L0431-G001 Armature Interface Card
  • GE FANUC - DS303A6A01KXA003XT Advanced Direct Current Contactor
  • GE Electric - IC641HBR302 Programmable Logic Controller Module
  • GE UR9WH - Multilin Ur Relay Module Advanced Control
  • GE IC200MDL240 - AC Input Module
  • GE Electric - IS420UCSCH2A-C-V0.1-A Unique Turbine Control System Module
  • GE IS200EXHSG3AEC - High-Speed Relay Driver for Turbine Control Systems
  • GE IC697ALG320 - Analog Output Module for Industrial Control Systems
  • GE IC200CHS002M - Industrial Control Module by GE-FANUC
  • GE IS200AEPCH1BAA - High-Performance Printed Circuit Board Module for Industrial Automation
  • GE IC693DSM302-RE - Digital Signal Processor Module
  • GE DS200SIOBH1ABA - High Performance Signal Input Module for Industrial Automation
  • GE Electric - IC660BBA026 Analog Input Module
  • GE Electric - DS200FCGDH1B DSP Drive Control Module
  • GE DS200TCEAG1BTF - Advanced Processor Card for Industrial Control Systems
  • GE FANUC - IC698CPE020-JU CPU MODULE Advanced Control
  • GE IC694MDL931 - RX3i AC/DC Voltage Output Module
  • GE IS420UCECH1B - Industrial Control System for Precision Applications
  • GE IC200ALG240 - Industrial Control Module
  • GE 8103AI-TX - Analog Input Module
  • GE FANUC - IC695PSD140 Power Supplies Industrial Control Solutions
  • GE DS200TCQCG1AFC - Relay Board for Industrial Control Systems
  • GE IS230SNAIH4A - & IS200STAIH2ACB Industrial PLC Circuit Board
  • GE FANUC - IC697VAL348 Digital to Analog Converter Board for Industrial Control
  • GE IS200WETCH1AAA - Precision Converter Power Module for Industrial Control Systems
  • GE IC695CPU320 - CF High Performance Modular Control CPU
  • GE FANUC - IC697MDL671 Interrupting Module Advanced Control
  • GE DS3800HSAA1T1M - Servo Amp