FEBRUARY: High Consequence Event Risk Reduction
The tasks in February are the most important, and the most rarely done, tasks in OT security and cyber risk management. This should be clearer after February when you learned about your company and its risk management program.
In a perfect world, systems would work 100% of the time. There would be no unscheduled outages. No integrity, quality, or yield issues. Many Operations groups run their OT impressively near this level of perfection year after year.
What you hopefully learned last month is the company regularly lives with imperfect operations across all areas of the company. If these faults are of a limited size and frequency, it is a risk and loss that the company accepts. Patrick Miller has an applicable quote in the OnRamp training:
“It’s not their (executives) job to manage risk. It’s their job to take risk. It’s their job to take as many risks as they can and hopefully nothing bad happens. Because that makes them more profitable.”
What executives shouldn’t and won’t accept are risks that could lead to high and catastrophic consequence events. Well, they won’t accept them if they know about these risks. OT cyber related risk has remained hidden or at best poorly stated in most asset owner companies. You’re going to help change that this month.
You will begin by understanding how Operations uses safety and protection systems to prevent high consequence events. Next you will determine if a cyber attacker on OT could disable the systems that should prevent high consequence events (hint: the answer is often yes).
Once you identify OT cyber failure scenarios that can lead to high consequence events, we will step you through finding the solution and presenting it to executive management. It’s a busy and important month.
Week 5: Understand Your Safety And Protection Systems
Last week you identified the high consequence events related to the industrial process being monitored and controlled in OT. This week you learn what is in place to prevent these high consequence events. The engineers who designed the process are again your primary...
Week 6: Identify OT Cyber Incidents That Could Cause High Consequence Events
This week’s task builds on the information collected in the previous five weeks and provides a key output for your OT security program. It identifies the high consequence events that could be caused by a cyber incident if an attacker gains access to and control of OT....
Week 7: No High Consequence Events If (When?) OT Is Compromised
Last week you identified failure scenarios that could cause a high consequence event when OT is compromised. This week’s task is simple and important. For each failure scenario from Week 15, identify a solution that would prevent the high consequence event if OT were...
Week 8: Prevent OT Compromise From Affecting Safety And Protection
If any of your failure scenarios from last week required isolating the safety and protection devices and systems from OT, then this week you will design your solution. Note: Even if you don’t need to isolate your safety and protection you should read this section. The...
Week 9: Develop The Cost / Risk Reduction Package To Get Funding
Common complaint in OT security: the company won’t spend money on OT security. This week you begin to experience the joy of getting funding for your OT cyber risk reduction project. Let’s review this month’s activities: You’ve identified and understood the safety and...