OT cyber resilience: looking beyond individual controls

OT cyber security is often discussed in terms of technical controls. Network segregation, access control, monitoring, secure configurations and backups are all important, particularly where compromise of an industrial control system could have physical consequences. However, the presence of individual controls does not, by itself, demonstrate that an organisation has the capability to maintain the operational functions that matter.

An industrial operation depends on much more than its control system. Operators and engineers need information and communications, maintenance activities may depend on engineering records and specialist suppliers, and changes to systems may require support from IT, engineering, operations and equipment vendors. These dependencies are not equally time critical either. Loss of some maintenance information might be manageable for hours or days during normal operation, while loss of communications, contact information or specialist support could become significant within minutes during an incident.

Technical boundaries therefore do not necessarily define the boundaries of operational resilience. The more useful question is what operational capabilities need to be maintained or restored, what they depend upon, what happens if those dependencies are lost and how long that loss can be tolerated.

Controls and management capability

Individual controls are essential, but a control and a management capability are not the same thing. A firewall is a control. Multi-factor authentication is a control. Personnel screening, monitoring, contractual requirements and backups can all be controls. Each contributes to a particular outcome, but none demonstrates on its own that the organisation can achieve and sustain that outcome.

Management capability is broader. It is the organisation’s ability to bring together the people, processes, information and technologies needed to achieve the required outcome, understand whether the arrangements remain effective and respond when circumstances change.

The distinction becomes clearer when we consider how controls and management capability contribute across the progression from prevention and detection through mitigation and emergency response to recovery.

Consider remote access to an OT system. Prevention might include personnel screening, contractual requirements, strong authentication, network segregation, access restrictions and appropriate authorisation. Detection might include logging and monitoring to identify unexpected or unauthorised activity. These controls are important, but their effectiveness depends on the management arrangements around them. Access needs to be justified, responsibilities need to be clear, supplier personnel changes need to be captured, monitoring needs to be acted upon and access needs to be removed when no longer required.

The controls contribute to the required outcome; the management capability provides the structure through which they are selected, coordinated, operated and kept effective.

If suspicious activity is identified, the emphasis moves towards mitigation. Access may need to be withdrawn or connections isolated to prevent further compromise, but those decisions can have operational consequences. IT may understand the identity services, connectivity and monitoring information, while engineering understands the control system and the consequences of isolation. Operations understands the condition of the plant and what can safely continue to operate. Effective mitigation requires those perspectives to be brought together quickly enough to support informed decisions that take account of both cyber security and operational consequences.

If the event threatens safe or continued operation, emergency response can extend those dependencies further. Communications, procedures, engineering information, specialist suppliers and management decision-making may all become important, but not necessarily with the same urgency. Their time criticality can also change as the event develops. Information that could be unavailable for a day during normal operation may be needed immediately when people are trying to understand an abnormal situation and decide what to do.

Recovery makes the distinction between controls and capability particularly clear. Having backups is important, but having backups is not the same as having the capability to recover. Backups may be incomplete, unavailable or no longer trusted, and systems may need to be rebuilt rather than simply restored. Configurations and information may need to be verified, supporting IT and communications services restored in the right sequence, specialist suppliers mobilised and competent people available to decide when systems are fit to return to service.

Recovery exercises therefore need to demonstrate more than whether a backup can be restored. They can establish whether the right people can be contacted in time, whether suppliers are available, whether essential information can be accessed, whether dependencies and recovery sequences are understood and whether decision authority is clear. In doing so, testing turns assumptions into evidence.

Bringing IT, people and OT together

This progression illustrates why operational resilience cannot be divided neatly into separate IT and OT concerns. Technical separation may be entirely appropriate, but the operational capabilities required to prevent, detect, mitigate, respond and recover frequently depend upon IT, people and OT working together. Controls provide protection, detection and recovery mechanisms, while management capability provides the structure through which responsibilities are coordinated, dependencies are understood, information is shared, decisions are made and competent people can adapt when events do not follow the plan.

For senior management, the assurance question is therefore broader than whether the right cyber controls are in place. It is whether the organisation has the management capabilities needed to bring IT, people and OT together when normal arrangements are challenged, and whether there is sufficient evidence to provide confidence that the operational capabilities that matter can be maintained or restored within the time available.

That is ultimately what operational resilience needs to deliver.