Bridging Cybersecurity Gaps in Operational Technology

Operational Technology (OT) manages systems that interact with the physical environment. These systems monitor and/or control devices, processes, and events.

Operational Technology (OT) manages systems that interact with the physical environment. These systems monitor and/or control devices, processes, and events.  Operational Technology is essential for the operation of critical infrastructure. Critical infrastructure refers to essential systems and assets—physical or digital—whose failure or destruction would seriously harm a country's security, economy, public health, or safety.  Industries such as utilities, defence, manufacturing, mining, chemical, and energy rely on OT to automate their industrial processes. While Information Technology (IT) deals with business applications  and data processing, Operational Technology manages processes embedded in the physical environment : a valve, a production line, water or oil flow.

Industrial control systems (ICS), such as Supervisory Control and Data Acquisition (SCADA), Programmable Logic Controllers (PLCs), Distributed Control Systems (DCS) are automated systems (hardware and software) designed for working in an OT environment.  

Operational Technology in Context

Industries such as utilities, defence, manufacturing, mining, chemical, and energy rely on OT to automate their industrial processes.

Operational Technology  & Information Technology Integration: Advantages and Threats 

The integration of IT and third-party software into Operational Technology drives efficiency but also increases cybersecurity risks by expanding the attack surface.As a result, cyberattacks targeting Operational Technology environments are becoming more sophisticated and deliberate.

Attacker’s techniques include MitM, denial-of-service (DoS), replay attacks, and others. Volt Typhoon, a Chinese-backed Advanced Persistent Threat (APT) group,  hit a Massachusetts power utility company in 2023, and is suspected to be still lurking around US-based critical infrastructure targets.  Common causes of vulnerabilities and threats to the OT environment arise from connection to the network, lack of awareness and training, disgruntled staff, lack of maintenance, unpatched system, collusion, lack of proper physical safeguards, upgrade of attackers skills, weak third-party software security. 

Severity and Consequence of an Attack to Operational Technology 

The consequences of a successful cyberattack to a water treatment plant, an oil refinery, or a power plant could be by far more devastating than the exposure of credit card information. This doesn’t mean that attacks to IT infrastructures and software could not be as lethal.  The severity of a cyberattack to Operational Technology and/or critical infrastructure depends on multiple factors, including the adversary’s intent, level of sophistication, capabilities, and familiarity with OT automated processes.  A publication by Michael Assante and Rober Lee highlights that attackers targeting OT/ICS  invest considerable time gathering sufficient intelligence to disrupt the full scope of the target’s operations (Assante & Lee, 2021).  The consequences of Operational Technology cyber attacks include injuries, loss of human and animal lives, long term environmental damage, community displacement. In short,  it could trigger a major disaster for a region or country. 

Protecting Operational Technology: Consequence-driven/ Cyber-informed Engineering Framework (CCE)

Effective intrusion prevention and detection systems are of utmost importance when working with Operational Technology. Furthermore, the  standard cyber hygiene recommended  to protect IT assets is not enough. The protection of an Operational Technology environment requires expertise beyond standard cybersecurity practice. And that is the essence of  The Idaho National Lab’s Consequence-driven/ Cyber-informed Engineering Framework (CCE): to protect critical infrastructure by combining engineering and cybersecurity controls with interdisciplinary collaboration.

The framework relies on 4 major steps as depicted in graph 1. 

Consequence-driven/ Cyber-informed Engineering Framework (CCE). Source: The Idaho National Lab

The  CCE approach is straightforward, realistic and practical. Moreover, the reliance on a framework drives accountability, avoiding the lack of processes and controls ownership - so common in organizations.  Needless to say that to reap the expected benefits, the application of the framework must be iterative, dynamic, and structured. The purpose is to capture the organization’s risk profile in a point in time to reduce those risks to the desired tolerance levels. For further references about the Idaho National Lab CCE Framework https://inl.gov/national-security/cce/

© 2025 Belkis Herrera, MBA, CISSP, CISA, CIA. The author has more than 10 years of experience in the mining industry across multiple companies in the Americas. 

References: 

  1. Idaho National Lab. https://inl.gov/national-security/cce/

  2. Cybersecurity. Harvard Business Review. 2019

  3. The Industrial Control System Cyber Kill Chain.  Michael J. Assante and Rober A. Lee. SANS Institute 2021. 

  4. Symantec Enterprise Blogs/ Threat Intelligence

  5. National Institute of Standardization. Guide to Operational Technology. www.nist.gov/nist-guide-operational-technology-ot-security

Previous
Previous

Navigate IT Audits Like a Pro