CyberElements
Back

Secure Industrial Control Systems

CyberElements,

Share via

This article addresses the concerns of CISOs and their partners with regard to the Industrial Control Systems (ICS) security challenge.

It is crucial to control access to industrial Operational Technologies (OT), as it can have a high impact on real life. When we talk about ICS security, that includes supervisory control and data acquisition (SCADA) systems and distributed control systems (DCS), which rely on programmable logic controllers (PLC).

Industrial systems must comply with new usages which greatly increase the attack surface.

  • Greater connectivity with remote access needs — remote on-call interventions, third-party contractor access, vendor remote activity — especially where the accounts used have special privileges such as admin rights or software update.
  • Globally spread maintenance teams.
  • Spread infrastructures.
  • Scattered tools for remote access to the OT systems, by vendor or by subsidiary and site.

Industry relies more and more on IT components to improve performance and savings, but those components may be vulnerable. Most industrial protocols are now based on TCP/IP, and even programmable logic controllers and remote terminal units run on operating systems from the IT world such as Windows and Linux.

At the same time, the cyber threat has never been so present, with an increase in and a professionalisation of cyber criminality — ransomware, worms and the rest.

Consequences may have massive impact in the real world

Unlike administrative enterprise networks, which manage information, ICS manage physical operational processes. A cyber incident could have the following impacts.

  • Impossibility of planning production.
  • Blocking or stopping of the production chain.
  • Impossibility of delivering and billing.
  • Disconnection of industrial systems as a precaution.

And beyond the operational impact, the financial impact can lead to a huge loss.

Case study: changing the parameters of a water treatment plant

In its cybersecurity guide for industrial operations, the CLUSIF association reports the following case.

In 2021, an attacker managed to gain access to the industrial network of a water treatment plant in a Florida city through TeamViewer. The attacker then gained access to a human-machine interface to control the concentration of sodium hydroxide used by the plant, and increased that concentration from 100 particles per million to 11,100 particles per million. At that concentration, the water could have been dangerous to anyone in contact with it.

The following measures would have prevented this attack.

  • Avoiding the exposure of an access protocol to the internet.
  • Prohibiting direct flows between the internet and the OT network.
  • Setting up a secure remote access mechanism where remote control is required.
  • Raising operators’ awareness of the need to authenticate people wishing to access workstations.
  • Monitoring what is being done on the most critical resources.

Case study: Colonial Pipeline, a credentials management default

The Colonial Pipeline case made headline news. In May 2021 the American oil pipeline operator Colonial Pipeline was attacked by ransomware, causing a petrol shortage that immobilised cars and planes. A state of emergency was declared by Joe Biden, and the company paid a ransom of four million dollars.

The contamination was possible because an employee used the same passwords for their personal and professional activities.

The following measures would have prevented this attack.

  • Prohibiting direct flows between the internet and the OT network.
  • Avoiding the disclosure of credentials by managing them in a vault and ensuring rotation with managed policies.

On a path towards Zero Trust, it is fundamental to control the identity of the user — and just as fundamental to monitor administrators’ actions on the administration IT and OT networks.

Bringing value to the business with accountability

How do you guarantee individual accountability for actions taken during maintenance of OT systems? Traditional ICS components were designed for reliability rather than security.

  • No authentication.
  • No integration into a directory.
  • Direct connection.

How can you assign responsibility for actions on industrial equipment that does not require user authentication?

Only one organisation out of two is equipped with a PAM solution.

OpinionWay for CESIN, 2022

That is where Privileged Access Management brings all its value.

By operating as a proxy, it authenticates admins with a personal account — with multi-factor authentication as needed — and gives them access only to the devices and SCADA systems on which they are authorised to work, which is least privileged access.

Once authenticated, all actions can be audited and recorded, and the logs exported to whatever SOC or SIEM solution is in place. Passwords are stored in a vault, on which policies can be enforced.

What if you had a single solution for both IT and OT access, for both internal access from within the network and external access from the internet? PAM for OT is not so different from PAM for IT.

What we suggest doing to secure an industrial control system

You cannot protect what you cannot control. The following measures can protect facilities.

  • Delete or disable the accounts of administrators no longer working on the industrial system.
  • Conduct a review of third-party service providers’ access rights to OT systems.
  • Ensure that high-privilege actions require strong authentication (MFA).
  • Tier privileged accounts to dissociate them according to their needs — Tier 1, 2 and 3, for example, separating administration accounts from maintenance accounts.
  • Control external access to industrial systems with strong authentication and local validation or approval workflows.
  • Monitor sessions to detect abnormal behaviour.
  • Watch for reconnaissance. Most complex intrusions are preceded by a reconnaissance phase, so the operator’s control of legitimate actions on its industrial network must make it possible to identify abnormal activity.

Making compliance easy, with security, visibility and reporting

We and the major national security agencies — CISA, NCSC, ANSSI, BSI — recommend starting the Zero Trust journey by managing identities and implementing a PAM solution as soon as possible, whether for IT or OT networks and infrastructures.

PAM projects are not known for being plug and play. But new next-generation PAM-as-a-service solutions accelerate the time to value and allow a good security-to-cost ratio to be reached quickly.

Tags

  • Articles
  • ZTNA
  • PAM
  • Industrial & Manufacturing
  • OT & Industrial Security

Let’s secure your access together