AI and ICS Cybersecurity: New Principles for Secure Integration

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Technology Trends

Everybody in industry is talking about AI, but very few are talking about the need to secure this technology for OT and ICS applications. Last week, CISA introduced a new document that was created jointly with several other cybersecurity agencies around the world, titled Principles for the Secure Integration of Artificial Intelligence in Operational Technology. This document provides guidance for critical infrastructure owners and operators on safely integrating AI into operational technology (OT) systems.

AI offers benefits such as efficiency, cost savings, and improved decision-making but also introduces risks such as model drift, safety bypasses, and cybersecurity vulnerabilities. The document outlines four principles to mitigate these risks. 

  1. Four Principles for Secure AI Integration:

    • Understand AI: Recognize AI-specific risks, educate personnel, and follow a secure AI system development lifecycle (design, procurement, deployment, and maintenance). 

    • Consider AI Use in the OT Domain: Assess the business case for AI, manage data security risks, evaluate vendor roles, and address integration challenges such as interoperability and latency. 

    • Establish AI Governance and Assurance Frameworks: Implement governance mechanisms, integrate AI into existing security frameworks, conduct thorough testing, and navigate regulatory compliance. 

    • Embed Oversight and Failsafe Practices: Ensure human oversight, monitor AI systems, establish failsafe mechanisms, and incorporate AI into incident response plans. 

  2. AI Techniques and Applications:

    • Covers traditional statistical modeling, machine learning (ML), large language models (LLMs), and AI agents. 

    • Discusses AI applications in OT environments using the Purdue Model, including predictive maintenance, anomaly detection, workflow optimization, and behavioral analytics. 

  3. Risks and Mitigations:

    • Identifies risks such as cybersecurity vulnerabilities, data quality issues, model drift, lack of explainability, operator cognitive load, regulatory compliance challenges, and AI dependency.

    • Provides mitigation strategies such as secure development practices, personnel training, data protection, and regular testing.

  4. Vendor and Integration Considerations:

    • Emphasizes transparency from OT vendors regarding AI features, data usage policies, and software supply chains.

    • Highlights challenges such as system complexity, cloud security risks, and compatibility issues.

  5. Regulatory and Compliance:

    • Discusses the lack of OT-specific AI standards and the need for auditability, safety certifications, and adherence to evolving regulations. 

  6. Monitoring and Safety Mechanisms:

    • Recommends human-in-the-loop decision-making, anomaly detection, explainable AI tools, and failsafe mechanisms to ensure safe operation and cybersecurity.  

This document is definitely worth a read and stresses the importance of balancing AI's benefits with its risks in OT environments. By following the outlined principles, critical infrastructure owners and operators can securely integrate AI while maintaining safety, security, and reliability. The document also provides links to additional resources, including guidelines, frameworks, and best practices from organizations such as CISA, NSA, NIST, and international cybersecurity agencies.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients