WhoshouldIsee Tracks

Contents

Building OT Resilience in an Era of Increasing Risk 

By Steve Wood, CNI Lead, BlueFort Security 

For those working in IT security, and especially operational technology (OT) security, the shifting geopolitical sands are a constant and increasing concern. 

In the last month alone the National Cyber Security Centre (NCSC) issued its starkest warning yet about the dangers posed by internet exposed systems and edge devices. This follows increased targeting of operational technology (OT) systems across multiple sectors in the UK and globally. The advisory warns that the overall threat of cyber attacks with state sponsorship or involvement has almost certainly increased, driven by geopolitical instability and technology-enabled (ie AI) capability increases. 

And in May of this year, the NCSC’s CEO, Richard Horne, delivered a speech at the Royal United Services Institute’s (RUSI) Annual Security Lecture during which he told the audience that it managed more than 200 incidents affecting UK critical national infrastructure (CNI) and the supporting ecosystem in the preceding 12 months. Around 75% of those are believed to be linked to state actors. 

I do not think it’s an over-exaggeration to say that globally our nations’ critical assets are under siege. As a case in point, in August it was reported that the water and waste water facilities in at least seven US states were hit by cyber attacks. Although, in this instance, the disruption was relatively minor (low water pressure, for example), the potential for serious harm is not an unrealistic scenario. 

The combination of increased external connectivity, legacy technology and the aforementioned volatile geopolitical situation, has created the perfect storm for cybersecurity attacks to be a clear and present danger for OT systems. 

The Technology Issue 

One of the key issues underpinning the challenge of securing OT systems today is that of the legacy infrastructure that’s still in play.  

Many sites continue to operate systems that pre-date modern cybersecurity practices, requiring specialists who can improve security without introducing operational instability or downtime.  

Connecting these older systems to an organisation’s modern digital enterprise is often risky as they have been built on operational efficiency, rather than security, 

The Supply Chain Issue 

In today’s uber-connected world, third party integrators, vendors and partners routinely access OT networks, often remotely. This exponentially increases the attack surface, and introduces risk that’s difficult to see, and therefore almost impossible to mitigate. 

Traditionally, OT networks were air-gapped from the internet and external systems. However, modern operational demands have led to increased connectivity and as a result, OT systems are now vulnerable to many of the same cybersecurity challenges as an organisation’s IT supply chain environments. 

Routine entry points such as USB sticks, portable devices, external docs, and software updates are all major security blind spots. (Remember Stuxnet?) And devices connecting remotely can easily deliver hidden malware directly to your OT system, creating the risk of serious organisational compromise. 

Ultimately, an organisation is only as secure as its weakest link.  

The Obligatory (and Changing) Regulation Issue 

The Cyber Security and Resilience Bill (CSR), which is on track to achieve Royal Assent at the end of this year, expands regulatory oversight across critical national infrastructure, managed service providers, and industrial supply chains.  

Under this legislative framework, OT assets are explicitly treated as elements of national resilience, giving regulators enhanced powers to enforce compliance and penalise non-resilient operators. In short, supply chain resilience will become a statutory obligation. 

Compliance is no longer just an IT audit item, it is a legal prerequisite for doing business. A comprehensive and robust risk mitigation strategy is the name of the game and as part of this organisations must ensure that all incoming files are thoroughly validated, sanitised, and verified as safe before they interact with critical operational systems. 

Three Issues, One Point of Exposure 

Look closely at these three issues and they all lead to the same problem -  legacy OTs are extremely vulnerable. They cannot be patched or run an endpoint agent and as  a result it’s left to the network boundary to do the work instead.  

However, that boundary was never meant to be air-tight. Vendors, engineers and contractors still need a sanctioned way in, and that entry point is almost always a file – a firmware update, a USB stick, an emailed drawing. And now regulation is starting to rule explicitly what security teams have long known informally -  that file is not someone else’s problem to verify. 

An unpatched programmable logic controller (PLC),  a vendor’s USB drive, and a compliance auditor’s checklist are three very different concerns. But each one arrives at the same question: has this file actually been checked, or are we simply trusting that it is what it claims to be?” 

Applying Zero Trust Thinking to OT Cybersecurity 

Our partner, OPSWAT’s advanced threat prevention platform, MetaDefender, layers an array of market-leading technologies like Deep Content Disarm and Reconstruction (CDR) to help operators remove threats from any file that could be infected, or attempting to exploit a vulnerability to compromise a network. 

At this month’s CS4CA conference, OPSWAT’s Steven Broadwell, Director of Solutions Engineering and Stefan Liversidge, Solution Engineer will be delivering a presentation challenging the idea that every file wanting to connect to your network should automatically be trusted to be ‘the real deal’. They will demonstrate that the question security teams should be asking is not “do we trust the source?” but “have we verified the content?”. 

This session will draw on real-world incidents where seemingly benign files (firmware updates, PDFs, engineering drawings) became attack vectors and it will explore how organisations can extend Zero Trust thinking down to the file level — verifying content, not just credentials or network position. 

Can’t Make the Event but Want to Know More? 

Catch up on our recent webinar Understanding the Data Risks of Supply-Chain: How to Protect Critical Infrastructure from Emerging Threats, where BlueFort and OPSWAT discussed best practices for implementing policies and processes that meet the specific needs of OT supply chains. 

Or drop me a line! steve.wood@bluefort.com 

Get in touch with BlueFort

Related articles