Risks and Mitigations in OT Cybersecurity
Details
Come and learn about OT security in our September meetup!
OT cybersecurity differs fundamentally from traditional cybersecurity - unlike traditional IT environments, compromises industrial control systems (ICS) can result in physical consequences that affect operations, production, equipment, the environment, and the safety of personnel. Effective defence requires five foundational controls:
- ICS-Specific Incident Response: Tailor response plans to prioritize physical safety and operational continuity, as standard IT playbooks can cause dangerous disruptions if applied blindly to industrial environments.
- Defensible Control System Network Architecture: Implement logical segmentation, such as industrial Demilitarized Zones (DMZs), because modern industrial networks are deeply interconnected and traditional air gaps no longer exist.
- ICS Network Visibility and Monitoring: Use passive monitoring tools to safely gain continuous visibility into proprietary OT protocols without disrupting sensitive field devices.
- ICS Secure Remote Access: Restrict and monitor vendor and employee remote connections using multi-factor authentication (MFA) and jump hosts, as unmanaged remote access is a primary target for attackers.
- Risk-Based Vulnerability Management: Prioritize patching and remediation based on real-world operational risk and potential safety impact rather than standard IT severity scores (CVSS).
Register to put it in your calendar.
Doors Open 5.00pm
Presentation Starts at 6.00pm
Networking 7.00pm
Doors Close 7.30pm
