Overview
Cybersecurity remains a major concern for industrial companies. Sophisticated attacks are penetrating conventional defenses and digital transformation is adding new challenges.
ARC research shows that most industrial companies are aware of the need for OT cybersecurity and have made investments in basic security measures. But many have not invested in the people and supporting technology to maintain these defenses.
New developments are also undermining the adequacy of current OT cybersecurity strategies. Increased use of remote access, particularly from personal devices, has expanded ways for attackers to compromise critical systems. Digital transformation has also weakened OT system defenses through broad connectivity with cloud apps and external systems, as well as through the introduction of potentially insecure, unmanageable IoT devices.
A more challenging threat environment is further pushing the limits of what is required to protect industrial systems. Nation-state attackers and cyber criminals are using sophisticated techniques and malware that overcome traditional defenses. Every company needs a strategy to minimize the impact of these attacks.
The safety and operational risks of operating facilities with these kinds of cybersecurity gaps shouldn’t be accepted. Smart companies will invest in people, processes, and technologies to ensure that defenses are properly maintained, new developments are properly addressed, and the impacts of sophisticated attacks are minimized.
IT/OT Cybersecurity Convergence Addresses Security Gaps
While companies increasingly appreciate the serious gaps in conventional industrial cybersecurity programs, addressing these issues is challenging. The global shortage of cybersecurity professionals, particularly those with OT experience, makes it difficult to hire additional staff. Operating constraints limit access that security teams need to keep defenses updated. Emphasis on isolation as the primary defense constrains visibility of vulnerabilities and abnormal system behaviors.
An onslaught of new cybersecurity challenges also diverts everyone’s attention from existing problems. Today, security teams have to develop security strategies for cloud data, in-motion and at-rest; apps that are being moved to the cloud; remote access users and all their devices; the security of new IoT devices and embedded systems; and, provide secure environments for edge compute platforms. The fluidity of all of the deployment options make it impossible for companies to maintain security, unless they have:
- End-to-end security solutions that span every endpoint and communication pathway
- Centralized management of consistent security policies
- Zero trust security for every step of every system interaction
Plants and facilities will clearly struggle to make the needed investments in OT cybersecurity people, processes, and technologies to address existing gaps and new challenges. But most companies already have IT security teams with the people, processes, and technologies in place to deal with these issues. Those that don’t will certainly need to make investments in IT security. Converging IT and OT cybersecurity programs provides a way to leverage these capabilities and investments to improve OT cybersecurity.
There will always be core OT-specific cybersecurity issues that require unique people, processes and technologies. But this doesn’t mean that they can’t be addressed as part of a converged cybersecurity program. Trying to maintain siloed IT and OT cybersecurity programs will only frustrate efforts to address existing and emerging security challenges and increase the risks of deploying new business strategies that integrate traditional IT and OT systems with cloud, IoT, and mobile solutions.
ARC Advisory Group clients can view the complete report at ARC Client Portal
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Industrial Cybersecurity, IT/OT Cybersecurity Convergence, ARC Industry Forum, ARC Advisory Group.