April: OT Security Perimeter And Segmentation

We have gone through the first three months of this weekly OT security calendar and have not discussed any classic cybersecurity controls. It’s time. 

April’s weekly tasks look at your security perimeters, segmentation strategy, and implementation. Restricting network access to OT is very important given the insecure by design (lacking authentication) nature of most deployed ICS protocols and many ICS applications. If an attacker is able to achieve and maintain access to your OT, what the attacker does to your physical process will most likely be limited by their engineering skills and the capabilities of your ICS.

While good security practice is to not rely solely on a security perimeter, it remains the most important protection security control for OT.

Week 14: Is Your OT Environment Accessible From The Internet?

Hopefully you believe the answer to this question is no. If any person or device on the Internet can access any of your OT environments you need to take immediate action. Note: “any person or device on the Internet” doesn’t include an employee or partner with...

read more

Week 15: Identify All OT Electronic Security Perimeters

Last week’s task identified, and initiated steps to remove, all unauthorized or insecure Internet access to OT. The remaining OT network access will come from your IT networks or business partner networks. The first step to evaluating the OT electronic security...

read more

Week 17: Evaluate Your OT Electronic Security Perimeters

Take the information gathered in Week 24 on your OT electronic security perimeters and evaluate the risk related to each communication allowed through the OT electronic security perimeter. This is typically a rule by rule analysis. If you have a well-documented...

read more