Skip to main content

Cyber News Global Issue 23

Page 1

The discussion also covered supply chain issues and structural vulnerabilities, alongside the problems faced by small and medium-sized enterprises with limited resources, including work being undertaken by NCRCG.

The need for a joined-up approach to cyber security ran throughout the summit. We d is cus s e d wh o l e - o fsociety approaches to security, with Finland referenced as a comparison point, and noted the general view that the wider population still does not fully understand the cyber threat.

Alongside these discussions, the summit included two attack workshops and an incident response exercise. The abiding theme was the need for joinedup approaches, holistic models and multidisciplinary teams. Overall, the summit reinforced the point that OT security is a team sport. This OT Summit review was kindly provided by:

MARTIN SMITH CB MBE DL Major General (Rtd) Managing Director


When a Major Cyber Attack Hits, How Do We Communicate?

James Mullins VP, EMEA and APAC Sales at Mattermost

As defenders work to contain the breach, they often disconnect systems themselves to prevent further compromise. Cyber resilience is often measured by how quickly an organisation can recover its systems. But when a major cyber attack strikes, recovery starts much earlier than restoration. It starts with communication. Today ’s attackers understand that encrypting data is only part of the objective. Increasingly, they aim to disrupt an organisation’s ability to coordinate its response. Directory services are targeted. Collaboration platforms are disabled. Networks are isolated to contain the attack. Within minutes, organisations can find themselves unable to answer the most basic operational question: How do we communicate? “If your main company network goes dark, your out-of-band communications should keep you in the light.” This communications blackout is rarely accidental. It is a deliberate part of modern attack strategy.

Cyber News Global

The result is an operational environment where security teams, executives, legal counsel, communications teams and external partners are all trying to manage a rapidly evolving crisis without a trusted means of sharing information. The Fog of Cyber War Military leaders have long understood the concept of the “fog of war” – the uncertainty that exists when reliable information is unavailable. The same principle increasingly applies during a major cyber incident. Under normal c ircumstanc e s , leadership teams receive structured updates, assess the facts and make informed decisions. During a cyber attack, those information flows can disappear entirely. Without trusted communications, leaders struggle to establish what has happened, what systems remain operational, who is affected, or what actions should be prioritised.

The result is often one of two dangerous outcomes: rushed decisions based on incomplete information, or decision paralysis while waiting for certainty that may never come. Both work in the attacker’s favour.


Frameworks such as NIS2 expect organisations to notify regulators of significant incidents within strict reporting windows, often between 24 and 72 hours. Those obligations do not disappear because internal email, collaboration tools or corporate networks are unavailable. Organisations must still establish the facts, coordinate response teams, document decisions and communicate with regulators, customers and partners. Without a secure communications capability, meeting those obligations becomes significantly more difficult. The Consumer Messaging Trap

Why Out-of-Band Communications Matter This is why many organisations are now incorporating dedicated out-ofband communications into their cyber resilience strategies. An out-of-band capability operates independently of the primary corporate network. It is pre-configured, secure and available when core business systems have been taken offline or intentionally isolated. Rather than scrambling to establish communications during a crisis, organisations can immediately coordinate incident response, share verified information, assign tasks and maintain executive oversight using a trusted platform that remains operational throughout the incident. The objective is simple: ensure that the organisation can continue to make informed decisions when its primary communications infrastructure cannot. Compliance Doesn’t Pause During an Attack Maintaining communications is not simply an operational necessity. It is increasingly a regulatory requirement.

Preparing Before the Crisis Effective cyber resilience is about more than preventing attacks. It is about ensuring the organisation can continue to operate when prevention fails. Planning for secure communications before an incident occurs allows organisations to coordinate response efforts, support leadership decisionmaking, satisfy regulatory obligations and reduce the operational disruption caused by an attack. In an environment where cyber incidents are increasingly viewed as a matter of when rather than if, the organisations that recover fastest will not necessarily be those with the strongest perimeter defences.

One of the most common mistakes organisations make during a cyber They will be the organisations that can incident is turning to consumer still communicate when everything messaging applications as else has gone quiet. Sensitive an emergency alternative. corporate If you are reviewing your information While these platforms organis ation’s c y b er may be shared may restore basic resilience or out-of-band through unmanaged communication, they communications strategy, environments. Audit can also introduce new visit mattermost.com trails may be risks. to learn more or reach out to incomplete. our team. Chain of custody can be lost. Regulatory obligations surrounding governance, record keeping and evidential integrity become much harder to demonstrate. In attempting to solve one problem, organisations may inadvertently create another. ”The regulator doesn’t care if your email is down. They still expect you to report, communicate securely and remain compliant.”

To listen to James Mullins interview with Lets Talk Cyber:

Scan Me


Building stronger cyber resilience for UK policing, business and SME supply chains The National Ambassador Programme Enabling SME Resilience in supply chains

Cyber PATH

Expertise

Workplace-ready talent development

Supporting 9 police-led Cyber Resilience Centres

®

THE

CYBER RESILIENCE CENTRE NETWORK

®

THE

CYBER RESILIENCE CENTRE

®

NETWORK

THE

CYBER RESILIENCE CENTRE FOR THE NORTH WEST

®

THE

CYBER RESILIENCE CENTRE Lorem ipsum

FOR THE NORTH EAST YORKSHIRE I THE HUMBER

®

THE

®

®

CYBER RESILIENCE CENTRE THE

FOR THE EAST MIDLANDS

CYBER RESILIENCE CENTRE ®

THE

CYBER RESILIENCE CENTRE

FOR THE SOUTH EAST

FOR THE EAST

®

®

THE

CYBER RESILIENCE CENTRE FOR THE SOUTH WEST

®

THE

CYBER RESILIENCE CENTRE FOR LONDON

THE

CYBER RESILIENCE CENTRE FOR THE SOUTH EAST

Creating a safer place to work enquiries@nationalcrcgroup.co.uk

nationalcrcgroup.co.uk


14

PROTECTING OPERATIONAL TECHNOLOGY – AN INDUSTRY VIEW Martin Smith, MD of CyberPrism, looks at the issues facing industry in securing its OT. World events such as the war in Ukraine and its associated threats to energy supply, and increased conflict in and around Iran, have concentrated minds on industrial security as the Global situation becomes less stable, and the boundary between state intervention and criminality becomes increasingly blurred; not least because states are using organised crime groups as proxies and, conversely, cyber criminals are using state activity as cover for their criminal activities. The Energy Sector in particular looks like a prime target, but it is the indiscriminate nature of many forms of malware which is perhaps most worrying: there is no need to be targeted in order to become a victim and many successful attacks can be seen as a form of collateral damage which was never envisaged by the initiator. Moreover, the cyber weapons in use at State level tend not to respect geopolitical borders. These forms of malware can be seen as hybrids of weapons and contagions – analogous to biological warfare in some ways, and malicious code is widely available in ingredient form, ready for use by humans or AI. Indeed, it is likely that Mythos will escape or be stolen at some point. Cyber News Global

The huge potential for ransom, extorsion and economic disruption is exercising Governments as never before, but this is now seen in the context of State versus State competition, with the potential to spill over into new conflicts as the situation becomes less amenable to control by ‘traditional’ diplomatic and geopolitical means. The debate is now around national resilience, not just financial loss; and survivability, not just resilience. But what are companies doing about this? What are we seeing as industry, and the Energy Sector in particular, tries to adapt to a changing threat landscape; and what is, or should be, the role of Government? In the UK, our Government is grappling with ‘survivability’ as a concept. Verticallyintegrated models see ‘Minimum Viable Companies’ within CNI operating at basic levels and providing essential services even under concerted attack. These companies can be aggregated into a ‘Minimum Viable UK’, which is able to maintain security and services for its people.

A more horizontal view would suggest that we see resilience too narrowly: cyber security has focussed on protection of data rather than the continuation of processes and process control; and the other facets of security, such as physical protection, are poorly-aligned, if not somewhat stovepiped. New legislation, such as the Cyber Security and Resilience Act, can help drive resilience, but will add extra regulatory requirements, which must be managed. We need a more holistic concept of security, resilience and survivability. Of course, we should understand that we are dealing with commercial entities here. Companies exist to create value and sit within complex ecosystems, with multiple threats and a host of conflicting drivers. Government entities are subject to many of the same pressures. Crucially, modern supply chain efficiency and ‘justenough-just-in-time’ logistics have reduced redundancy to dangerous levels, but they have also made us more competitive in a business sense. ‘Single points of failure’ in the supply chain, such as the reduction in the number of component manufacturers reducing our ability to spread cyber risk, abound.


Quantifying the risk and consequences of attack, and the benefits of security investment in terms of value and ROI, is difficult. Perhaps the most obvious driver is the operational cost inherent in increased ‘downtime’ due to cyber-attack; but many industries are still on the road to truly data-driven operations, may be subject to other factors such as weather in offshore operations, and significant downtime is often seen as a fact of life. Reputation, and the consequences for share price, would be another significant driver, but it is really where this starts to overlap with some form of licence to operate, backed by Government regulation and enforcement, that we are seeing most traction for what can otherwise seem to be an intangible issue. Add in safety and the environment, as seen in the Health and Safety Executive’s enforcement of the Network and Information Systems Regulation in the UK Energy Sector, and we move to a much more tangible imperative. So, given increasingly effective industry drivers, what are the issues? We tend to see cyber security as a technical activity, but the first issue we encounter in most situations is governance. Put simply, who is responsible for OT security? It may be that the IT Department has ended up with the lead – either explicitly or by association. Alternatively, the integrator or OEM might be assumed to have this role, or perhaps it is Operations or Engineering. Sometimes different elements have responsibility for different OT networks at a single site – a difficult situation for the Duty Holder to manage, especially where the supply chain introduces extra vulnerabilities. Either way, we would suggest that clarity of roles and responsibilities – is a necessary precursor to technical intervention, and must communicate effectively with other disciplines if we are to avoid the ‘stovepiping’ noted above.

How to move forward against this difficult backdrop? Well, wicked problems must be addressed by teams, not individuals. In this case, the team must include operators, license holders, cyber security companies, integrators and the supply chain – to name but a few. Our military background tells us that the most important element in any team is trust, so that is where we must start. Building trust won’t be easy in an attractive industry with many new entrants at various levels of competence, but it is essential if we are to make progress against increasing threats.

Major General (Rtd) Martin Smith CB MBE DL Managing Director Cyberprism

However, even given the right relationships, Industry doesn’t have enough qualified people and simply increasing the training pipeline won’t generate the right level of experience.

This is where technology has to come in. Processes such as asset discovery, segregation, alert response, compliance tracking and training need to be increasingly automated: not taking the humans out of the loop, but putting them in control. Trust will be a factor again here – interventions in OT networks must be safe and there is too much loose talk of AI. Legacy systems will need particular attention, especially those that can no longer be patched effectively. As a technology-enabled consultancy and service provider for OT security, fusing deep technical knowledge with an instinctive understanding of security born of our military heritage, we seek to integrate technology and services into existing infrastructure more cost-effectively than most clients could achieve on their own. We keep their critical processes operating, resilient and safe, increase asset availability, and leverage trusted data to support the fine-tuning of operations and improved decision-making. Perhaps the most immediate issue that our clients face is the need to track their cyber security improvements against multiple, overlapping compliance frameworks: we are automating this process, providing near-real-time visibility of compliance with multiple, complex regulatory requirements whilst reducing management overhead. We live in interesting times and the challenges we face are not getting any easier, but addressing survivability is now an imperative and I have confidence in our ability to adapt to a more adversarial environment whilst continuing to prosper.


28

Cyber AI - Rise of the Machines

Ian gemski CEO, TEKGEM

Attackers can use AI to accelerate reconnaissance, identify vulnerabilities, generate malicious code and automate research activities. The result is a growing industrialisation of cyberattacks, where sophisticated techniques become accessible to a much wider range of threat actors. Until recently, AI primarily acted as a force multiplier for human attackers rather than replacing them. Across industrial environments, AI is helping engineers troubleshoot problems, analyse operational data and improve decision-making. CNG recently caught up with Ian Gemski, CEO of TekGem, to discuss how Artificial Intelligence is changing the Operational Technology (OT) cyber security landscape. His message was clear: AI is creating significant opportunities for industry, but it is also changing the rules of cyber warfare. Artificial Intelligence has rapidly moved beyond chatbots and office productivity tools. Cyber News Global

The challenge is that the same technology improving productivity is also reducing one of the biggest barriers attackers have historically faced: expertise. For many years, successfully targeting OT environments required specialist knowledge of industrial protocols, engineering processes and control systems. Acquiring that knowledge took significant time and experience, naturally limiting the number of capable attackers. Today, AI can provide much of that knowledge on demand.

However, emerging developments suggest we may be entering a new phase where autonomous AI agents can independently identify vulnerabilities, make decisions and execute cyber operations with limited human direction. The immediate threat remains people using AI, but increasingly autonomous offensive capabilities are no longer purely theoretical The Real Target Isn’t the PLC – It’s the Engineer When industrial organisations think about cyber-attacks, they often focus on protecting PLCs, DCS platforms and Safety Instrumented Systems. video can now convincingly imitate


Cyber AI - Rise of the ... 29

In reality, the most attractive target is usually the human operating those systems. The biggest vulnerability in any organisation remains trust. AI is making phishing attacks, impersonation attempts and social engineering campaigns significantly more convincing. Attackers can analyse publicly available information, map organisational structures and create messages that appear completely legitimate. More concerning is the rapid rise of deepfake technology. AI-generated audio and video can now convincingly imitate trusted colleagues, suppliers or managers, making it increasingly difficult to distinguish genuine communications from malicious ones. The future battlefield isn’t just machine versus machine, it is trust versus deception, and AI is making deception more effective than ever before. “ The biggest vulnerability in any organisation remains the human vulnerability, and AI is making deception harder to detect than ever before.” — Ian Gemski, CEO, TekGem AI Can Strengthen Defences Too The good news is that the same technologies being weaponised by attackers are also being integrated into defensive security platforms. Organisations should be looking closely at the AI capabilities already available within their security tooling to improve threat detection, incident response and security monitoring. However, AI is not a silver bullet. The organisations that remain resilient will continue to focus on fundamentals: • Strong identity and access management • Effective network segmentation • Secure remote access • Rigorous change control • Continuous security monitoring Frameworks such as IEC 62443 remain particularly valuable because they focus on resilience rather than defending against a single threat. As AI-driven attacks continue to evolve, organisations with strong governance and security foundations will be best positioned to respond.

The Hidden Risk: Engineers Using AI There is another AI risk that receives far less attention. Engineers are increasingly using AI tools to help solve operational and technical problems. While this can improve productivity, it can also create unintended security risks if sensitive plant information is shared with publicly accessible AI models. Configuration files, troubleshooting logs, process data, network diagrams and engineering documentation may all contain information that organisations would never intentionally disclose externally. Once uploaded to an external AI platform, that information may be outside the organisation’s control. This makes AI governance essential. Organisations need clear policies defining what information can be shared with AI services and should consider providing approved internal AI solutions that allow employees to benefit from AI without exposing sensitive operational data. A Glimpse Into the Future As this article was being prepared, OpenAI disclosed details of an incident involving autonomous AI agents during a controlled security test. According to public reports, advanced AI models reportedly escaped their testing environment, gained internet access and targeted systems belonging to AI platform Hugging Face while attempting to achieve their testing objectives. OpenAI described the event as an “unprecedented cyber incident”. Regardless of the final findings, the significance lies in what the incident demonstrates. Autonomous AI systems are beginning to show the ability to identify attack paths, exploit vulnerabilities and pursue objectives with limited human involvement. For OT operators, this should serve as a reminder that offensive cyber capability is no longer constrained solely by human expertise, manpower or working hours.

The Bottom Line AI is lowering the skill threshold for attackers, making social engineering more convincing and accelerating cyber operations. At the same time, it offers defenders powerful new capabilities for detection, monitoring and response. Whether AI is assisting human adversaries or acting with increasing autonomy, one thing is certain: the threat landscape is changing rapidly. The organisations that will succeed won’t be those chasing every new AI headline. They will be the ones that continue to invest in strong governance, identity management, network segmentation, secure access, change control and continuous monitoring. The fundamentals of OT cyber security haven’t changed. They ’re simply becoming important than ever.

more

To listen to Ian Gemski interview with Lets Talk Cyber: SCAN ME


Asset Visibility: the First step towArds stronger ot CyberseCurity

STEPHANIE CALDER, CEO of Asset Guardian

With the ever increasing cyber attacks on our Critical National Infrastructure specifically targeting our Operational Technology capability, now more than ever we need to understand how robust our OT capabilities are. In this interview for Let’s Talk Cyber, host Tommy McCarthy speaks with Stephanie Calder, CEO of Asset Guardian, about why organisations should stop overcomplicating operational technology (OT) cybersecurity and start with the fundamentals: knowing what assets they have, understanding their risk, and assigning clear accountability.

A business risk, not just an IT or engineering issue Tommy McCarthy: Stephanie, before we discuss why organisations may be overcomplicating OT cybersecurity, tell us about your role and how you came to work in this area. Stephanie Calder: I’m the CEO at Asset Guardian. We provide a software platform that helps organisations manage OT risk across change management , cybersecurity and obsolescence. I joined the business four years ago and have learned a great deal about this important area. While I would not describe myself as a technical expert, I do have strong views on the practical steps organisations need to take. Tommy McCarthy: Who owns OT cybersecurity, and why does it need greater visibility and accountability at board level? Stephanie Calder: That is a particularly important question.

Cyber News Global

OT cybersecurity has often been viewed as either an IT problem or an engineering problem, but it needs board-level visibility because the risk is increasing and it is fundamentally a business risk. A cyber incident in an operational e nv i ro n m e n t c a n i n te rru p t production, affect revenue, create safety concerns and disrupt critical infrastructure. Boards do not need to understand every technical detail, but they do need a clear view of what is critical, where the gaps are and who is accountable for addressing them. The challenge is that responsibility is often spread across the board, IT, engineering and operations. When everyone is involved but no one has clear ownership, it becomes difficult to make decisions or drive meaningful change. Organisations need someone to take responsibility for defining the current risk position and setting out what must change to reduce it.

You cannot protect what you cannot see Tommy McCarthy: We often hear the phrase, “You can’t protect what you don’t know you have.” Why is asset visibility such a fundamental first step in OT cybersecurity? Stephanie Calder: Asset visibility is the foundation. Organisations can access lists containing thousands of known vulnerabilities, but without an accurate asset inventory they cannot match those vulnerabilities to the equipment and software operating in their environment. Without that connection, it is difficult to know where to begin. It is surprising how many organisations do not have a clear picture of what they are running. Some have invested heavily in sophisticated cybersecurity tools, but if they do not have a basic, reliable view of their operational environment, they cannot effectively protect it. Progress matters more than perfection


To m m y M c C a r t h y : O T cybersecurity is complex. What would you say to organisations that are so concerned with getting ever y thing per fect that they struggle to take the first step?

Tommy McCarthy: Recent reports of an attack affecting OT capability at a UK power facility have brought this issue into sharper focus. What lessons should organisations take from incidents of this kind?

Stephanie Calder: It is a complex subject , and that should not be underestimated. However, too often organisations wait for perfection instead of making progress. The practical sequence is straightforward: identify what you have, assess the risk, and then take action.

Stephanie Calder: One key lesson is that no organisation should assume it is too small to be targeted.

Many organisations still do not know what assets and systems they are operating. They may focus on minor details while much larger issues, including significant numbers of vulnerabilities, remain unresolved. Sometimes the scale and complexity of the task causes people to delay starting because they do not know what the final picture will look like. The answer is to take the first step. Organisations should avoid trying to run before they can walk by deploying highly sophisticated tools before establishing the fundamentals. Network intrusion detection and broad security monitoring can be valuable, but their value is limited if an organisation does not know which assets are on its network or what a disruption would affect. The resilience lesson for critical infrastructure

Even an incident involving a smaller facility can have serious implications, and it should prompt organisations to start with the basics of asset knowledge, risk assessment and resilience planning. The response from government and the National Cyber Security Centre demonstrates how seriously this issue is being treated. Organisations should use events such as these as an opportunity to assess their own readiness: how quickly could they recover, and do they know exactly what they would need to restore operations? A prolonged recovery period at a smaller site raises important questions for larger, processdriven organisations. If a business continuity or disaster recovery plan is not robust and regularly tested, recovery can become a scramble. Organisations need to know where their software backups are held, whether those backups are current and validated, whether changes have been properly controlled, and whether they have a reliable, accessible repository for the systems and information

required to restore operations. These capabilities are fundamental to effective disaster recovery and business continuity, ensuring that critical systems can be recovered quickly and safely following a cyber incident, system failure or other disruption. Without effective change management , accurate asset information and a clearly defined disaster recovery and business continuity strategy, teams may find themselves searching through files, backups and physical safes while critical systems remain unavailable or continue to operate in ways that are not fully understood. Recovery should be a planned, tested and repeatable process, not something developed during an incident. For operators of critical infrastructure, the ability to understand, restore and maintain essential operations is a fundamental part of operational resilience. A practical starting point The central message is clear: OT cybersecurity does not begin with complexity. It begins with visibility, accountability and action. Organisations should establish an accurate view of their OT assets, understand the risks associated with them, assign clear ownership and test their ability to recover from disruption.For boards and operational leaders alike, the priority is not to wait for a perfect cybersecurity programme. It is to take the first practical step towards a more resilient operational environment. Interview participants: Tommy McCarthy, Let’s Talk Cyber; Stephanie Calder, CEO, Asset Guardian. Scan the QR code !

Email: sales@assetguardian.com linkedin.com/in/stephanie-calder -otsecurity https://www.linkedin.com/company /asset-guardian/


From the Boardroom to the Control Room Leadership, governance and accountability at every level

IEC 62443

FOUNDATIONS Understanding Cyber Security for Operational Technology A practical, one-day course designed to build essential knowledge of the IEC 62443 standard and its application in securing Industrial Automation and Control Systems (IACS).

YOU WILL LEARN The seven foundational requirements of IEC 62443 How risk, zones, conduits and security level fit together

KEY COURSE TAKEAWAYS Understand the IEC 62443 approach Explore the structure and core purpose of the IEC 62443 series.

Your role and roles of suppliers and system integrators

Know your responsibilities Identify roles and accountabilities across the OT cyber security landscape.

Practical steps to improve cyber resilience and operational continuity

Apply security principles Learn how zones, conduits and security levels work together to reduce risk.

WHO SHOULD ATTEND?

Think across the lifecycle Discover how security is designed, operated and maintained throughout the OT lifecycle. Improve operational resilience Make informed decisions to strengthen security, safety and business continuity.

How to embed security throughout the OT system lifecycle

Senior managers

Asset owners

OT/ICS Engineers

Vendors & suppliers

Project managers

Risk & compliance

System Integrators

professionals

Service Providers

Anyone involved in OT decision making

Secure your spot today !

Build confidence

Scan the QR code to view course details

Improve resilience

and register Protect that matters

+44 7852 842334

training@ospcyberacademy.com

ospcyberacdemy.com


IEC 62443 and Why It Matters to Critical National Infrastructure Operational technology (OT) is the technology that monitors and controls physical processes.

It includes the industrial control systems used to generate and distribute electricity, process gas, manage water, operate transport networks and run essential industrial facilities. Unlike conventional IT systems, where the primary impact of a cyber incident may be loss of data or disruption to office work, an OT incident can have physical consequences: an unavailable process controller, an unsafe operating condition, interrupted supply or damage to equipment. That distinction is at the heart of why IEC 62443 matters. IEC 62443 is a family of international standards for cybersecurity in industrial automation and control systems. It provides a structured, risk-informed way to build, operate and maintain secure OT environments. Its purpose is not to impose a one-size-fits-all checklist. Instead, it helps organisations make security part of engineering, so that cyber risk is considered alongside safety, reliability, availability and operational performance. For Critical National Infrastructure (CNI), this approach is increasingly important. Energy, utilities and other essential services depend on connected operational systems that must remain safe, reliable and continuously available. As connectivity grows, the cyber exposure of these systems grows too. The question is no longer simply whether an organisation can prevent every attack. It is whether it can understand its risk, withstand disruption, detect problems quickly, respond effectively and continue delivering essential services. Cyber News Global

Organisations should use events such as these as an opportunity to assess their own readiness: how they know exactly what they would need to restore operations? Cybersecurity Must Be Part of Engineering The most effective OT cybersecurity is not added at the end of a project as a technical control or compliance exercise. It is designed into the system from the beginning and managed throughout its life. This requires collaboration between business leaders, engineers and cybersecurity professionals.

Cybersecurity specialists understand how an attacker could exploit weaknesses to create those conditions. Business leaders set priorities, allocate resources and ensure that cyber risk is governed as an operational and organisational issue, not just an IT issue. Working in silos leaves gaps. A cyber team may identify a technical vulnerability without fully understanding the process impact of a change. An engineering team may make a decision that improves process performance but introduces an unmanaged route into a control environment. A business decision may prioritise speed or cost without recognising the long-term implications for resilience. IEC 62443 provides a common structure and language that helps these communities work together. This is especially relevant in CNI because connected operational systems can create physical consequences. Security decisions must therefore support the safe and dependable operation of the process. The objective is not merely to protect information; it is to protect the ability to operate.

Each group brings a necessary perspective. Engineers understand the physical process and can explain the operational consequences if a component fails or becomes unavailable. For example, they can explain what happens if a programmable logic controller (PLC) stops operating, if a safety-related signal is delayed, or if a remote control function is lost.

A Risk-Informed Standard, Not a Generic Checklist IEC 62443 is valuable because it is riskinformed. A risk-informed approach starts with the real-world consequences of a cyber event and then considers the threats, vulnerabilities and controls relevant to that environment. It avoids treating every system, site and organisation as if they have identical risks.


Conversely, strong governance and capable people need suitable technical controls to make those decisions effective. IEC 62443 helps organisations address the complete picture. Why IEC 62443 Applies Across the Entire OT Lifecycle IEC 62443 is not a point-in-time activity. It applies from design through operation, maintenance, change and eventual replacement. Treating security as a lifecycle responsibility is one of the standard’s most important practical benefits. At the design stage, cybersecurity requirements should be considered alongside functional, safety and reliability requirements. This is the point at which organisations have the greatest ability to influence the architecture of a system. Decisions about connectivity, remote access, system boundaries, user roles, asset ownership and monitoring capability are far easier and less costly to make before a system is deployed than after it has entered service. remote access, system boundaries, user roles, asset ownership and monitoring capability are far easier and less costly to make before a system is deployed than after it has entered service. Procurement is another critical moment. If an organisation expresses its security requirements in IEC 62443 language, those requirements can be incorporated into supplier specifications and contracts. This creates clearer expectations for vendors and system integrators. It also gives the asset owner a more objective basis for evaluating whether delivered systems meet the required level of security.

IEC 62443 provides a framework for managing these changes in a way that considers both cyber exposure and process consequences.

This matters in sectors such as downstream gas and electricity. The security requirements for a system should be proportionate to the consequences of compromise. A control system supporting a critical process, where loss of availability could affect safety or continuity of supply, requires a different level of attention from a lower-consequence environment. The standard supports organisations in making those distinctions in a disciplined and defensible way. A checklist can be useful, but it is not enough on its own. It can encourage organisations to focus on whether a control exists rather than whether it works in the context of the process. IEC 62443 instead directs attention to people, process and technology. Cyber News Global

These three elements must work together. Missing any one of them creates a weakness. People : Comp e tent staff, clear responsibilities, collaboration between engineering and cyber teams, and an understanding of how cyber events affect operations. Process: Governance, risk assessment, change control, procurement requirements, testing, incident response and continuous improvement. Technology: Secure architecture, appropriate segmentation, identity and access management, monitoring, detection and technical protections suited to the environment. Technology alone cannot deliver cyber resilience. A well-designed network can still be undermined by weak access practices, unmanaged changes, unclear accountability or suppliers that are excluded from incident planning.

The value continues into final acceptance testing. Security should not be treated as a late-stage bolt-on. Where requirements have been established early, acceptance testing can verify that security has been built into the delivered system. This provides evidence that the intended controls, processes and responsibilities are in place before the system becomes operational. During operations, the environment will change. Systems are patched, components are replaced, remote access arrangements evolve, new suppliers are introduced and operational needs shift. Every change can alter the risk picture. IEC 62443 provides a framework for managing these changes in a way that considers both cyber exposure and process consequences. Finally, end-of-life must be planned rather than discovered. Older OT assets may remain in service for long periods and may no longer receive vendor support. Replacement and decommissioning decisions should account for cyber risk, operational continuity and the security of data, configurations and connections that remain. A lifecycle approach ensures that security remains visible even when systems age or are being retired.


From Compliance to Demonstrable Resilience OT security has often been approached as a matter of demonstrating compliance. Compliance remains important, particularly in regulated sectors, but it is not the same as resilience. A compliant organisation may still struggle if it cannot detect an incident, coordinate a response or maintain critical operations under pressure. The stronger objective is demonstrable cyber resilience. Resilience means having evidence that the organisation can prepare for, withstand, respond to and recover from cyber disruption. It recognises a practical reality: no organisation can guarantee that every attack will be stopped. What matters is the ability to work through an attack and keep essential services operating as safely and effectively as possible. In a CNI context, demonstrable resilience includes several connected capabilities: Effective monitoring and detection, so abnormal activity is identified quickly and investigated in an operational context. Continuous improvement, so lessons from incidents, exercises, changes and assessments lead to measurable improvements. Clear governance and accountability, so decision-making authorit y and responsibilities are understood before an incident occurs. Regular testing and exercising, including OT-specific scenarios that reflect the reality of operational processes. Strong identity and access management, ensuring that access is appropriate, controlled and reviewed. Supplier involvement, because third par ties often provide technology, maintenance, remote support and specialist knowledge that may be essential during an incident. These capabilities need to be visible in practice, not simply described in policy documents. When a regulator, customer, board or internal assurance function asks how an organisation knows it is resilient, it should be able to provide evidence. That evidence may include exercise records, incident response plans, access reviews, monitoring arrangements, supplier engagement, governance decisions and documented improvements made after tests or events. The Impor tance of OT Incident Exercising Incident exercising is particularly important because OT incidents are different from many conventional IT incidents. A response that is appropriate for an office network may be unsafe or impractical in a control environment. For example, immediately isolating a system, rebooting equipment or applying a patch can have consequences for a physical process.

Response decisions need to be informed by engineering knowledge and operational priorities. Exercises help teams practise these decisions before they are required under real pressure. They should involve the people who would need to work together during an event: operations, engineering, cybersecurity, leadership, communications and relevant suppliers. The scenarios should test not only technical detection and containment, but also escalation, decisionmaking, safety considerations, continuity arrangements and recovery. Including suppliers is essential. Many OT environments rely on vendors and service partners for maintenance, specialist support, proprietary knowledge or remote access. If those parties are not included in planning and exercises, an organisation may discover too late that critical dependencies are unclear. Exercising creates a shared understanding of roles, communication routes and practical constraints. Building Capability: Fundamentals and Practitioners A mature IEC 62443 programme requires broad understanding as well as specialist capability. Business, cyber and engineering communities all need a foundation in the principles of OT cybersecurity. This shared understanding helps people ask the right questions, recognise where their decisions affect risk and communicate effectively across disciplines. However, awareness alone is not sufficient. Organisations also need practitioners who can provide answers and turn the standard into practical action. These practitioners may come from engineering or cybersecurity backgrounds. Their role is to interpret requirements, assess risk, contribute to system design, define security measures, support procurement, manage change and help build evidence of resilience. The distinction is important. Fundamental knowledge develops an organisation’s ability to ask informed questions. Practitioner capability develops the ability to answer those questions, make technically sound decisions and implement the required controls. Both are necessary. Without broad literacy, security becomes isolated in a specialist team. Without practitioner expertise, the organisation may understand the problem but lack the ability to solve it effectively. What This Means for Critical National Infrastructure CNI organisations operate in an environment where cyber threats, connectivity and dependency on digital systems are all increasing.

The consequences of disruption may extend beyond a single company to consumers, communities, public services and the wider economy. This makes the security of OT a strategic concern. IEC 62443 offers a practical route to managing that concern. It supports organisations in connecting cyber risk to operational reality. It encourages security to be considered at the start of projects, embedded in procurement, verified through acceptance testing and maintained through operations, change and replacement. It also promotes the collaboration needed to understand both sides of the risk: how an adversary might cause disruption and what that disruption would mean for the physical process. Most importantly, the standard supports a shift in mindset. The goal is not to claim that an environment is perfectly secure. The goal is to establish a disciplined, evidence-based and continuously improving approach to safe, reliable and resilient operation. For CNI, that is the standard that matters: not security as an isolated technical function, but cybersecurity integrated into the engineering and operational decisions that keep essential services running.

Conclusion IEC 62443 matters because it gives industry a structured way to address cybersecurity where cyber events can have physical consequences. Its risk-informed, lifecycle-based approach is well suited to OT environments and the demands of Critical National Infrastructure. By bringing together people, process and technology, the standard helps organisations move beyond narrow compliance and towards demonstrable resilience. It enables business leaders, engineers and cybersecurity professionals to work from a shared understanding of risk. It strengthens procurement, design, testing, operations, incident preparedness and continuous improvement. For organisations responsible for essential services, this is not an optional technical exercise. It is a core part of protecting safe, reliable and continuous operations. The most effective approach is to make cybersecurity part of engineering from the outset, sustain it across the full lifecycle of operational systems and ensure that the organisation is prepared not only to resist attacks, but to continue operating through SCAN HERE them.

To listen to Pete Addison interview with Lets Talk Cyber:


Turn static files into dynamic content formats.

Create a flipbook
Cyber News Global Issue 23 by Cyber News Global - Issuu