Skip to main content

Creating a Shared Risk Vocabulary: The Shifting Narratives of Operational Technology (OT)

Dr. James Stanger, Chief Technology Evangelist

I think we’ve all read about the increased attacks on critical infrastructure around the world. We’ve seen successful attacks on water systems and medical equipment in the United States to frozen food chains in Japan. Techniques for profiling and attacking Operational Technology (OT) devices have proliferated over a decade now; AI-based toolkits have only made it easier to wage attacks. I suppose that’s enough Fear Uncertainty and Doubt (FUD) for one blog entry! Instead, I’d like to talk about how the IT and OT industry are actually shifting their mindsets and, therefore, changing the narrative.

Heated debates and solutions

It’s not all that easy. Just last week, a 15-year veteran in OT cybersecurity told me about how he witnessed a conversation between a group of IT and OT workers spiral downward into a shouting match. The topic? Applying two-factor authentication on a Programmable Logic Controller (PLC) – a device that controls physical systems such as pipelines, HVAC systems, power-generating windmills, conveyor belts, and centrifuges. To an IT worker, implementing 2FA is expected. To an OT worker, it could be unthinkable.

Why do things like this happen?

Traditionally, IT and OT workers have had radically different mindsets and motivations, as shown in the table below.

Mindset differences

Principle IT mindset OT mindset What an OT worker might say
Uptime In some situations, the “five nines” might be possible, but not probable due to the nature of equipment, protocols, procedures and cost. Reboots often occur. Nothing can affect uptime. 100% uptime is a given. Systems are built with simplicity in mind. Redundancy is a given. Reboots are rare. “A simple reboot? That’ll mean disastrous loss of life, or loss of productivity.”
Latency tolerance Can tolerate various delays, jitter, and even time-based issues. Packetization trumps all. Strict timing requirements make for extremely low tolerance. “If I experience latency, people can die, or the factory floor will descend into chaos.”
System control/access control Various factors, from 2FA to access control features, must first be met before an individual or entity can control a system. Interdependency and interconnected systems are a fact of life. Systems must respond instantly to controls. Otherwise, human safety is compromised and equipment failure can occur. Encryption and authentication can become liabilities. Isolation is common – and often desired. “When I punch that emergency stop button, nothing gets in the way. Not 2FA, not anything.”
Longevity An older system is often considered a liability, or a form of technical debt. Component lifetimes of 3-5 years are common.     Systems are designed for longevity; 15-year lifespans are common. Success is defined in terms of stability and an extended lifecycle. “Wait – you’re age-shaming a system for doing its job reliably over its expected lifespan?”
Patching and maintenance A fact of life. Regularly-scheduled. Downtime is often tolerated. Relatively low cost of systems allows the existence of staging servers, networks, and platforms for testing before the patch goes to a live system. Patches must be tested and verified beyond a doubt. Little to no downtime tolerance. The cost and uniqueness of an OT system often interrupts or eliminates typical patching cycles. Often conducted by the manufacturer or a dedicated contractor, rather than the OT or IT team. Typically, there is no “patch Tuesday.” Legacy systems require a thoughtful, documented, and approved approach. “It’s working. Don’t fix it.”
Protocols TCP/IP-based systems use HTTP, HTTPS, DNS, and so forth. Modbus, ICCP, CIP, DNP3, and PROFINET; TCP/IP is relatively new.      

Both are right... and wrong.

And it’s important to realize that these different mindsets exist for good reasons; it’s not accurate – or useful – to simply say, “OT systems are old” and that OT workers need to change their thinking. It’s not a question of updating systems. No side is completely right or wrong. Though mindsets and processes are changing, these traditional differences still remain a factor.

What has changed?

The primary reason why both IT and OT workers need to change their mindsets is that attackers are exploiting the traditional IT/OT disconnect. Second, it’s important to realize that both IT and OT workers are being held to high standards: Laws and directives around the world, such as NIS2 and DORA in Europe, have led organizations to conclude that even OT devices need separate oversight and governance.

Also, there are technical reasons: OT devices are now using TCP/IP. Second, there are more ways to get into remote devices; yesterday’s devices had limited remote access options. Today’s devices have the same interconnection methods as IT devices: Secure Shell (SSH), web interfaces, and virtual private networks. Some even use the Remote Desktop Protocol and Virtual Network Computing (VNC).

We’re all in the same boat now: Creating a shared risk vocabulary

So, what does all of this mean? First, IT and OT leaders can no longer work in isolation. Second, understanding OT and ICS systems can no longer be a niche skill. This is something many IT and cybersecurity workers need to know, from compliance analysts to pen testers to security analysts.

What we’re doing about it at CompTIA

Nothing is more transformative to a culture than education. If we want to change the narrative and create a shared risk vocabulary, then everyone needs to understand each other’s language. If we want to address the OT attack surface with fresh eyes, then let’s make sure everyone knows how OT systems behave. That’s why we created CompTIA SecOT+. When was the last time you saw an IT worker control an OT system? Well, with our labs, we make that happen.

screenshot of a lab exercise on Datacenter PLC Integrity

 
Now, IT and OT workers can work together to understand what it means to increase monitoring and observability. They can work together to understand how to model uptime and budget for patching systems without affecting uptime. This way, it requires people to understand both narratives. That way, workers can understand the nuances and conundrums involved.

 


Dr. James Stanger is CompTIA's Chief Technology Evangelist and an award-winning author, blogger and educator. He has consulted with corporations, governments, and learning institutions on cybersecurity, exponential technologies, data analytics and upskilling programs for over 30 years. He works on advisory councils around the world and is a recognized speaker, consultant, author, security analyst, threat hunter and penetration tester.