Cybersecurity has increasingly become top-of-mind with events such as the recent ransomware attack on supply chain management software provider Blue Yonder serving as constant reminders of its pertinence. With OT becoming more and more looped into this concern, the mission to protect such networks from evolving threats will certainly continue to be a priority throughout the rest of 2024 and into the future.
A New OT Cybersecurity Framework
The threat to OT cybersecurity is especially apparent when you consider ongoing risks associated with actors such as Volt Typhoon. As MeriTalk reported, Volt Typhoon reflects “a large interest by adversaries in not just knowing where our OT is, but also in taking a living-off-the-land approach to encamping themselves on those networks,” according to Matt Hayden, GDIT vice president for cyber and emerging threats for intelligence and homeland security.
With trends like this becoming more commonplace, security organizations from around the world have partnered to publish a new guide for OT operators. Titled “Principles of Operational Technology Cybersecurity,” the guide was put together by the Australian Cyber Security Centre (ACSC) in collaboration with CISA and other international entities to help those impacted by the potential of OT cybersecurity threats, particularly those in critical infrastructure fields. It is based on six key principles, including safety in OT environments, the protection of OT data, network segmentation, securing OT supply chains, business knowledge, and staff training.
What Changed in NIST CSF 2.0
OT operators are measured against more than one framework, and the NIST Cybersecurity Framework is the other one most will meet. NIST released version 2.0 in February 2024, built from feedback gathered across a range of industry participants. The revision adds a sixth function, Govern, to the five the framework already carried, which are Identify, Protect, Detect, Respond and Recover.
The stated goal was to provide direction for all organizations rather than only critical infrastructure enterprises. Cherilyn Pascoe, the framework’s chief creator, said the CSF “was developed for critical infrastructure like the banking and energy industries.” She noted it has proved useful “everywhere from schools and small businesses to local and foreign governments,” and that NIST wants a tool useful to every sector.
The 2.0 revision also took the changing threat picture into account, offering additional information on ransomware and supply chain risk. Risk management runs through the document as a central theme. An operator can start by testing a current OT program against Govern, since ownership and accountability decide whether the other five functions get executed.
The Important Role of OT Training
Angel Coker Jones at Commercial Carrier Journal reports that, “The NSA and other agencies recommend OT decision makers apply these six principles to help determine if a decision being made is likely to adversely impact the cybersecurity of an OT environment.” While all of the principles are essential, the last two listed above are foundational. Business knowledge ensures that companies truly understand why OT cybersecurity is worth the attention and investment, and staff training emphasizes a focus on the people in control of executing the plans to protect OT networks.
Education as amplified in the guide is necessary across the board, whether working in the private or public sector. It was the central point of a recent initiative introduced by the CISA, which launched a new platform to replace its internal education platform and Federal Virtual Training Environment. The new offering features a range of cybersecurity classes, General Services Administration webinars on artificial intelligence, and more.
Sector Rules Arrive One at a Time
Requirements have reached OT operators sector by sector rather than as one rule.
- The Transportation Security Administration issued an updated set of standards for pipeline operators. The emphasis shifted from developing plans to testing them, while requirements such as reporting and identifying roles remain.
- United States senators introduced the Food and Agriculture Industry Cybersecurity Support Act. The bill would create a National Telecommunications and Information Administration hub to help agricultural producers secure technology, equipment and hardware.
- Senators also introduced the Cybersecurity for Rural Water Systems Act, aimed at flaws in rural water systems. Only 20% of water and wastewater systems in the United States have adopted proper cybersecurity protections.
Christian Vasquez wrote for CyberScoop that the White House took on “a dizzying task,” described as “trying to harmonize the exceedingly broad number of cybersecurity-related regulations and technical standards set by industry that corporations and critical infrastructure operators must abide by.”
Sixteen critical infrastructure sectors sit inside that work, and several agencies may require reporting from a single organization. Operational technology is largely left out of rules written with information technology in mind, so each requirement needs a check for where it stops short of the plant floor. Listing every agency that can request a report is work an operator can start now. The same list shows what an OT cybersecurity program already covers.
Sources
- “As Supply Chains Go Digital, Cybersecurity Must be Strongest Link” – PYMNTS https://www.pymnts.com/cybersecurity/2024/as-supply-chains-go-digital-cybersecurity-must-be-strongest-link/
- “OT Threats Rise as Government, Industry Fight Back” – MeriTalk https://www.meritalk.com/articles/ot-threats-rise-as-government-industry-fight-back/
- “ACSC and CISA Launch Critical OT Cybersecurity Guidelines” – Alessandro Mascellino, InfoSecurity Magazine https://www.infosecurity-magazine.com/news/acsc-cisa-launch-ot-guidelines/
- “Cybersecurity Framework” – National Institute of Standards and Technology https://www.nist.gov/cyberframework
- “TSA Updates Pipeline Cybersecurity Requirements” – Dark Reading https://www.darkreading.com/ics-ot/tsa-updates-pipeline-cybersecurity-requirements
- “U.S. Senators Introduce Bills to Enhance Rural Cybersecurity” – Government Technology https://www.govtech.com/security/u-s-senators-introduce-bills-to-enhance-rural-cybersecurity
- “White House grapples with harmonizing thicket of cybersecurity rules” – Christian Vasquez, CyberScoop https://cyberscoop.com/cybersecurity-strategy-harmonization-critical-infrastructure/
- “National Security Agency publishes OT cybersecurity guidance” – Angel Coker Jones, Commercial Carrier Journal https://www.ccjdigital.com/technology/cybersecurity/article/15708230/national-security-agency-publishes-ot-cybersecurity-guidance
- “CISA debuts new cybersecurity training platform” – Justin Doubleday, Federal News Network https://federalnewsnetwork.com/cybersecurity/2024/11/cisa-debuts-new-cybersecurity-training-platform/




