Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

OT operators urged to map networks or risk major blind spots

(marcin049 / Pixabay)

By Chris Riotta

Global cybersecurity agencies are urging critical infrastructure operators to build a full picture of their operational technology environments, although analysts caution that mapping every corner of sprawling, decades-old networks may prove harder in practice.

Guidance backed by the United Kingdom’s National Cyber Security Centre and the U.S. Cybersecurity and Infrastructure Security Agency and other allied partners’ cyber agencies details a principles-based framework for creating and maintaining a “definitive record” of OT environments. It calls on operators of power grids, waters systems and factories to catalogue their assets by criticality, while documenting system connectivity, validating and maintaining records through structured change management and rigorously managing third-party access and contractual risks.

Implementing and maintaining a definitive record of OT environments is feasible and necessary, OT security experts told Information Security Media Group. But the process demands a major shift in how operators approach asset visibility, since legacy systems make real-time inventory difficult. Still, the growing sophistication of cyber-physical threats means organizations can no longer afford to operate without a dynamic record of who is accessing what and when, analysts said.

Read more at Gov Info Security

Click to listen highlighted text!