Remote Approaches to Cybersecurity Assessments Can Reduce Costs and Risk

Author photo: Larry O'Brien
By Larry O'Brien

Summary

Assessments are the foundation of a good cybersecurity strategy. For end users, picking the right partner to do an OT level cybersecurity assessment can be a challenge. A wide variety of companies offer these assessments today. The OT level cybersecurity services market has been growing substantially, and many new companies have entered the ring Cybersecurity Assessmentswith their own approaches and their own strengths and weaknesses, from automation suppliers to large engineering service providers.

In today’s world of the long-term COVID pandemic, getting engineers and technicians on site to do a vulnerability assessment can be quite a challenge. Just as we have seen a surge in remote operations and other forms of remote work in the midst of COVID, the world of cybersecurity services is also embracing the concept and applying to various engineering services, including cybersecurity vulnerability assessments.

ARC recently discussed OT level cybersecurity assessments with engineering provider L&T Technology Services (LTTS). The company has been conducting OT level vulnerability assessments for years, and has developed a methodology for conducting remote assessments that incorporate standard methodologies.

What’s Different About OT Level Cybersecurity Assessments?

Cybersecurity assessments are a necessary part of the cybersecurity lifecycle. The first step in managing risk is to Cybersecurity Assessmentsunderstand the current level of risk within a system. The process for conducting a cybersecurity risk assessment is outlined in the ISA/IEC 62443-3-2 standard. Normal engagements include a review of control system architectures and equipment to identify potential gaps in defenses and a review of current cybersecurity programs and practices to identify people and process gaps that might limit the company’s ability to maintain its security posture. Final deliverables include a risk assessment and mitigation recommendations. Physical inventory of cyber assets is a common option, particularly for facilities with older equipment and immature change management programs.

Standards, Guidelines, and Best Practices

A good OT level cybersecurity assessment will conform to industry standards and best practices like the IEC/ISA 62443 standard and NIST Cybersecurity Framework (CSF), and will also perform key tasks like asset identification and risk evaluation.

While most service providers have their own cybersecurity guidelines, end users increasingly request that assessments be performed in line with generally accepted guidelines and standards. This includes the NIST Cybersecurity Framework, ISA99/IEC-62443, NERC-CIP, and NIST 800-52/53. In some cases, users may also expect assessments to include compliance with specific industry standards and practices.

A Unique Mix of Legacy and Cutting-edge Technologies

Industrial, energy, and critical infrastructure applications also contain a wide mix of proprietary legacy technologies and assets at the OT level that don’t always lend themselves to easy detection. These include distributed control systems Cybersecurity Assessments(DCSs), programmable logic controllers (PLCs), robotics, remote terminal units (RTUs), safety and shutdown systems, and more. Many of these legacy systems are also quite old and some are no longer supported by the vendor. Many of these assets also bring other liabilities and vulnerabilities with them, such as unsupported operating systems like Windows XP, outdated computing hardware and firmware, and older unpatched versions of various applications.

Conversely, many industrial sites combine these older unsupported or undocumented assets with newer innovative technologies and systems covered under the Industrial Internet of things (IIoT), including new edge computing devices, IoT-enabled sensors, cloud-based systems, wireless technologies, VLANs, and more.

IT/OT Cybersecurity Convergence

Lack of resources is arguably the biggest challenge for OT cybersecurity programs. It leads to poorly managed defenses and undetected compromises that provide attackers time to compromise critical assets and steal proprietary information. It is also one of the hardest problems to overcome. The global shortage and high cost of cybersecurity professionals makes it difficult to justify and recruit the necessary people.

Converging IT and OT cybersecurity programs can go a long way to resolving these issues. Most IT groups have access to a team of cybersecurity experts that can immediately fill the expertise gaps that plague facilities. This relieves the need for each facility to hire people with these unique skills. Existing OT cybersecurity resources can then be applied to tasks that need to be performed locally, for safety and operational reasons. As these tasks only require basic IT and OT skills, they can be performed by local technicians. IT cybersecurity experts can also provide any remote support that may be required to resolve specific issues that may arise.

IT and OT Still Have Different Cybersecurity Requirements

Despite the convergence of IT and OT approaches, the requirements for OT level cybersecurity are different from that of the IT world. The OT world is more time critical, often involving the control of hazardous process governed by safety or emergency shutdown systems. OT environments require high availability, have complex change management requirements, and numerous proprietary protocols. Patches and upgrades are deployed at less regular intervals and often require more special testing and in a much more controlled fashion compared to the IT world. With its large and varied installed base of systems, software, and controllers, the world of OT also presents more challenges when it comes to asset discovery. Many of the assets deployed at the OT level can also be quite old, with some systems dating back over 20 years.

Cybersecurity Assessments

A Broad Mix of Assessment Service Providers

Assessment is the most popular industrial/OT cybersecurity service. Most companies want to understand their potential exposure, even if they are not always able to address deficiencies. Many also require periodic reviews of the security of facilities. Not surprisingly, this market segment has the broadest mix of suppliers. These include automation suppliers, control system integrators, niche ICS cybersecurity service companies, and IT/OT cybersecurity service providers.

Cybersecurity Risk Assessment

Measurement of risk and the adoption of risk-based frameworks and models are coming to the forefront as a way to measure overall levels of cybersecurity preparedness and protection. Managing risk and adopting a risk-based approach to cybersecurity is increasingly necessary in the age of convergence. There is already a proliferation of risk-based services and risk-based approaches to cyber insurance, engineering, and design through the industrial and critical infrastructure segments.

Cybersecurity Assessments

LTTS Cybersecurity Services

A subsidiary of one of India’s largest engineering conglomerates Larsen & Toubro, LTTS provides engineering services across the entire “Design to Shop Floor” value chain, such as Product Conceptualization, Design & Development, Testing, Value Analysis & Value Engineering, Product Maintenance, Manufacturing Support, After Market Support, and Plant Engineering Services.

LTTS has been conducting cybersecurity assessments for manufacturing and the process industries for a decade now. The company conducts assessments based on NIST CSF and the ISA/IEC 62443 standards and has developed its own in-house security posture assessment framework that is custom built to tackle cyberthreats for connected products.

LTTS assessment services include a review of control system architectures and equipment to identify potential gaps in defenses and a review of current cybersecurity programs and practices to identify people and process gaps that might limit the company’s ability to maintain its security posture. Final deliverables include a risk assessment and mitigation recommendations. Physical inventory of cyber assets is a common option, particularly for facilities with older equipment and immature change management programs.

The goal of LTTS is to guide end users through the various phases of cybersecurity program maturity, which culminates in a proactive and managed cybersecurity state, where both the IT and OT layers are continuously monitored. After LTTS conducts the assessment, it has the capability to offer additional services, including remediation, passive monitoring, patch upgrades, firewall updates, and network segmentation services. LTTS has remote security monitoring and incident response capabilities.

LTTS has currently conducted over 50 vulnerability assessment and penetration testing (VAPT) projects around the world for global conglomerates. LTTS has domain expertise across multiple industries, from manufacturing to automotive, semiconductors, electronics, buildings, and smart cities. The company also has an innovation hub in Israel that works on cutting-edge security microservices.

Remote OT Network Assessments in the Age of COVID

In addition to on-site assessment, LTTS has also taken many steps to automate portions of the assessment and to conduct remote assessments. In this age of COVID, being able do a conventional on-site cybersecurity assessment has been hampered due to the pandemic and its associated travel restrictions. However, the chaos of COVID is spurring innovation, and service providers are coming with new ways to do more engineering tasks remotely than could ever be done before.

To address these increased requirements for remote work, LTTS has developed a remote OT vulnerability assessment methodology. Working with a single point of contact within the end user organization, LTTS can remotely execute an assessment from discovery and packet capture through inspection, analysis, and reporting. The company also has the capability to expand on these assessment capabilities to help the end user implement managed cybersecurity services for a more proactive and continuous threat monitoring posture.

Discovery Meeting

LTTS remote vulnerability assessments start with a discovery meeting, which includes project awareness presentations and a review of the OT network topology. The team reviews the overall OT process and its critical output and reviews any network tools that are already in place. The team then identifies required network tapping points and determines tapping duration time. Other information like OT network design, IP schema, a list of known automation vendors and systems in place, and a list of known OT protocols in place is also provided and reviewed.

Cybersecurity Assessments

Packet Capture

LTTS guides the plant team through the process of running packet captures on the relevant tapping points. Packet capture files are then uploaded to a secure location for retrieval by LTTS.

Inspect and Analyze

LTTS processes the packet captures and performs an analysis. A standard compliance audit is performed via a remote session.

Reporting

Once the packet analysis and standard compliance audit are performed, LTTS builds a comprehensive OT security assessment report to share any relevant insights and information from the assessment. The company also provides suggested remediations to identified issues.

Assessment reports include key insights from LTTS, including asset inventory lists and interaction maps per the Purdue Model. An asset communication protocol map is also provided along with type, firmware, and vendor details. Along with an asset breakdown by vendor, the report includes a list of known vulnerabilities with CVE details and highlights of major security gaps in the installation.

Lifecycle Capabilities Beyond Assessment

Assessments also don’t end after the assessment. LTTS offers many other cybersecurity services after the assessment that can guide end users to a more proactive cybersecurity posture. As part of its SOC as a Service offering, LTTS can continuously monitor and improve an organization’s security posture while preventing, detecting, analyzing, and responding to cybersecurity incidents.

Case Studies

Consumer Products

LTTS has implemented its remote assessment methodology at many customer sites. One recent success was at a large global consumer goods manufacturer. This assessment was both an IT and OT level assessment that identified assets and associated risks. LTTS conducted verification of network topology and IT and OT network segmentation.

Since this was a combined IT/OT audit, LTTS did audit scans on IT elements to identify major vulnerabilities. They also completed audit scans and manual verifications for critical OT entities like MES systems, control systems, and the ability of AGVs to identify major vulnerabilities. The OT portion of the assessment followed NIST guidelines. After the assessment, LTTS provided remediations to the end user for identified vulnerabilities and provided further recommendations for continuous monitoring and notification systems.

Food & Beverage

LTTS completed another recent remote vulnerability assessment for a global tobacco major. Like the consumer products project, this case study included an assessment of both IT and OT assets. Automated scans were conducted both for the IT assets and for selected OT assets during non-production hours. Passive network traffic monitoring of select OT subnets were conducted at the site, as well as site access point scan and verification.

This project also included access control list (ACL) verification and firewall architecture validation. LTTS also used active scanning techniques in this project for its IT network scans. Key recommendations for this project included implementation of continuous monitoring and notification systems.

Private 5G Network Assessment

Privately deployed 5G networks are already making inroads on the shop floor. LTTS recently completed an independent security assessment of one proposed private 5G network at a major electronics manufacturer to reduce the risks associated with operating these technologies and enable the customer to implement a robust and secure 5G network.

LTTS provided a security assessment of 5G network components and developed security test cases for each component of the 5G network. The company also reviewed the overall architecture of the network being deployed to ensure that it was inline with the end user’s overall cybersecurity requirements. LTTS also reviewed firewall requirements, maintenance and service contracts with suppliers, and recommended an end-to-end threat monitoring solution.

Cybersecurity Assessments

Recommendations

It’s important to evaluate the capabilities and expertise of potential partners to ensure that they understand the requirements of your industry and relevant standards and best practices, but it’s also important for end users to understand that assessments are the first step in a cybersecurity lifecycle. Assessments establish asset inventories, performance baselines, and really should provide a comprehensive picture of the end user’s overall cybersecurity posture.

Assessments are just one step in the overall cybersecurity lifecycle, and flows into the implementation and maintenance/operations phases. Any potential assessment partners should view it in this context and provide you with guidance about how to use the information gathered in the assessment to remediate issues, implement solutions, and provide value throughout the maintenance and operations phases of your plant or facility.

Remote assessments are a great way to take advantage of the current suite of technologies, pinpoint key vulnerabilities, and develop a more solid cybersecurity posture without the requirement and associated cost of on-site engineers. Good remote assessments require adequate coordination between the assessment provider and the end user, so ARC recommends that end users develop a full understanding of the remote service offering including what’s expected of the end user in terms of their project responsibilities and work processes required.

For more information about LTTS remote cybersecurity assessment capabilities you can visit their web site here

 

ARC Advisory Group clients can view the complete report at  ARC Client Portal

If you would like to buy this report or obtain information about how to become a client, please  Contact Us

Keywords: OT Level Cybersecurity Assessments, LTTS, Larsen & Toubro Technology Services, IEC 62443, Risk Management, NIST CSF, ARC Advisory Group.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients