Article by Nozomi Networks cybersecurity strategist and regional sales director APAC, Vincent Liu.
This article is the second of a three-part series on the operational technology (OT) digital transformation journey for Asian organizations (see here for parts one and three).
In the past, industrial systems were not considered to have high cyber-risk because they were isolated without connectivity to enterprise systems or the internet. They were also securely protected through obscurity and typically considered of low interest to cyber-attackers.
That reality simply doesn’t exist anymore, and now industrial cyber-risk is much higher due to an increase in:
According to Gartner, “to reduce risk, security and risk management leaders should eliminate IT and OT silos by creating a single digital security and risk management function. This function should report into IT but should have responsibility for all IT and OT security.”
As threats to OT systems in Asia intensify, there are several reasons to include OT in an enterprise-level security operations center (SOC). With a combined approach, companies can:
The US Government has gone some way to addressing some of these points – through the Continuous Diagnostics and Mitigation (CDM) program, led by the Cybersecurity and Infrastructure Security Agency (CISA).
This program is both a resource from which organizations across Asia can learn, and an example of the type of formal institution that can be created to integrate OT into SOCs and broader cybersecurity initiatives.
Aside from implementing a continuous diagnostics and mitigation program (CDM) like in the US, there are several best practices organizations here can implement to better unify IT and OT. Here are some suggested programs to consider to prepare for a digital transformation:
These activities can identify strengths and opportunities for improvement, and ultimately provide a clear roadmap on what each unit brings – or can bring – to provide a more resilient, cyber-secure organization.
Stay tuned for part three of this series.