0% found this document useful (0 votes)
18 views39 pages

Section 7

The document outlines key learning objectives related to ICS security fundamentals, focusing on incident response, network architecture, monitoring, secure remote access, and vulnerability management. It emphasizes the importance of timely detection and response in OT environments and the need for a dedicated ICS incident response plan. Additionally, it discusses the risks associated with shared Active Directory between IT and OT networks, advocating for separate identity management solutions to enhance security.

Uploaded by

Muhammad Ahmad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views39 pages

Section 7

The document outlines key learning objectives related to ICS security fundamentals, focusing on incident response, network architecture, monitoring, secure remote access, and vulnerability management. It emphasizes the importance of timely detection and response in OT environments and the need for a dedicated ICS incident response plan. Additionally, it discusses the risks associated with shared Active Directory between IT and OT networks, advocating for separate identity management solutions to enhance security.

Uploaded by

Muhammad Ahmad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

What You Will Learn

Section 6
Section 5 ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS
OT Threat Landscape & Threat Modeling Controls)

Cyber threats targeting OT: threat actors & malware You will learn:
origins 1. ICS Incident Response: Plan Why timely detection,
Understand the typical OT threat landscape across the response, and containment are essential in OT
Purdue model layers. environments.
Threat modeling in OT: Mapping assets, vulnerabilities, 2. Defensible ICS Network Architecture: Building segmented,
and potential attack paths. risk-aware architectures to protect critical operations.
3. ICS Network Visibility & Monitoring: Leveraging passive
monitoring tools for asset inventory, anomaly detection,
and continuous oversight.
4. ICS Secure Remote Access: How to enable secure, least-
privilege remote connectivity for vendors and operators.
5. Risk-Based ICS Vulnerability Management: Prioritizing
vulnerabilities, applying compensating controls, and
managing patching challenges in OT.

Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

SANS OT/ICS Incident Response Plan


#1

SANS
#2 Defensible OT/ICS Network Architecture

SANS
#3 OT/ICS Network Visbility & Monitoring

SANS
#4 OT/ICS Secure Remote Access

SANS
#5 Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 67
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

SANS OT/ICS Incident Response Plan


#1

Defensible OT/ICS Network Architecture

OT/ICS Network Visbility & Monitoring

OT/ICS Secure Remote Access

Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 68
SANS IT Incident Response vs OT Incident Response
#1 Same attack, very different consequences

Action: Isolate Infected Device (Laptop, Server, Desktop.. etc.) Action: Isolate Infected Device (PLC, HMI..etc)

Impact: Business ontinues with minor disruption Impact: Production halt, Equipment risk, Safety Hzard

Isolation & Containement


Isolation & Containement

Simone's CyberSecurity 69
16
ICS Incident Response: The Challenge of Timely Detection & Response
SANS Why SANS ranks Incident Response as the #1 ICS/OT Critical Security Control
#1

Availability of adequate logs: this is Qualifying the impact of the


often a challenge in the OT threat:
environment to assign adequate resources and
attention to it

Time taken to mitigate: this


refers to the time taken to
fully act on and block or
slow down a threat to limit
its impact on the
infrastructure.

Responsiveness to threats:
depends on the security
operation team’s ability to
immediately inspect an alarm

Time to qualify a threat:


after adequate inspection,
how soon can the team
classify/qualify a threat
Investigation time: how much time
does the team take to fully investigate
and classify a threat
These challenges highlight why a dedicated ICS Incident Response Plan is
essential. SANS ranks Incident Response as the first of the 5 Critical ICS
Source¹⁶: KPMG, Industrial Control System (ICS) or Operational Technology Simone's CyberSecurity Controls, ensuring organizations can detect, triage, investigate, and contain
(OT) Threat Landscape: A New Frontier for Cyber Attacks, April 2024 threats before they escalate into safety and reliability incidents.
SANS
Building OT-Specific Incident Response Plans
OT incident response must balance cybersecurity actions with safety and operational continuity
#1

Safe Containment Procedures

Roles & Responsibilities

Testing & Training

Runbooks & Playbooks

Simone's CyberSecurity 71
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

OT/ICS Incident Response Plan


SANS
#2
Defensible OT/ICS Network Architecture

OT/ICS Network Visbility & Monitoring

OT/ICS Secure Remote Access

Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 72
Maturity Levels of Defensible Network Architecture
Progression of Segmentation (Mapped to Purdue Model & ISA/IEC 62443 Zones/Conduits)

Level 3
Level 0: Flat, no segmentation
Level 2
Level 1: Basic Zone separation

Level 1
Level 2: Firewalls between IT/OT

Level 3: Micro-segmentation + dedicated


Level 0
OT services

Simone's CyberSecurity 73
Level 0: Flat IT/OT combined (No Segmentation)
Equivalent to ignoring Purdue zones — enterprise and control systems in one flat domain.
Scenario:
Demonstrates the current state of many industrial networks where IT and OT systems coexist in a flat, unsegmented environment. There is no separation between
enterprise and control assets.

Risks:
• No segmentation boundary between IT and OT
• Single broadcast domain increases exposure
• High lateral movement risk across systems
• Attackers gaining access to IT can easily pivot to OT
• Lack of network zoning complicates monitoring and containment

IT DMZ IT-OT flat network

Enterprise
Server
Public
OT data
Server
historian
PLC
Internet

Workstation

HMI

Simone's CyberSecurity 74
Level 1: Segmented IT/OT (Basic Segmentation)
Scenario:
Represents organizations that have begun their segmentation journey by separating IT and OT into two distinct zones. However, there is no dedicated OT DMZ for secure data
exchange, and the OT side lacks micro-segmentation — meaning environments like R&D labs, test benches, or engineering workstations are still grouped into a single flat OT
zone.

Risks:
• Single security boundary between IT and OT (single firewall).
• Limited visibility and control across zones.
• Potential for lateral movement if the IT zone is compromised.
• No additional buffer zone for secure data exchange.

IT DMZ IT network OT network

Enterprise
Server
Public
OT data
Server
historian
PLC
Internet

Workstation

HMI

Simone's CyberSecurity 75
Level 2: IT/OT Segmentation with Dedicated OT DMZ
Scenario:
Shows more mature segmentation where a dedicated OT DMZ exists between IT and OT, improving monitoring and control of data flows. While this architecture is
stronger, the OT network itself remains broadly zoned. There is still significant scope to introduce additional micro-segmentation of OT environments (e.g., separating
production, R&D, and test benches) to further reduce lateral movement risks..

Risks:
• If DMZ firewall rules are weak, attackers may pivot from IT to OT.
• OT DMZ often hosts data historians or jump servers, making it a high-value target.
• Misconfigured DMZ components can lead to data leakage or indirect access to OT assets.
• Segmentation improves security, but micro-segmentation is still missing.

IT DMZ IT network OT DMZ OT network

Enterprise
Server
Public
OT data
Server
historian
PLC
Internet

Workstation

HMI

Simone's CyberSecurity 76
General Shopfloor Layout

77
Level 3 Segmentation: Two Scenarios (Logical and Zone based segmentation)

Scenario 1 (Zone Based Segmentation) Scenario 2 (Logical VLAN based Segmentation)

Simone's CyberSecurity 78
Level 3: Scenario 1 (Firewall Zone Based Segmentation)
Purdue-aligned Architecture with OT Micro-Segmentation

Scenario:
Represents a more mature network security model with IT, OT, and OT DMZ all clearly separated, combined with micro-segmentation within the OT side. Critical sub-zones such
as R&D, test benches, production cells, and engineering stations are isolated, reducing lateral movement and supporting defense-in-depth..

Risks:
Complexity of firewall policies may lead to misconfigurations.
Rule sprawl and inconsistent updates can weaken security posture.
Higher operational overhead for maintaining multiple firewalls and policies.
Potential performance bottlenecks if firewall capacity is not sized correctly.
Legacy OT devices may still lack proper endpoint security.

IT DMZ IT network OT DMZ OT network

Enterprise
Server
Public
OT data
Server
historian
PLC
Internet

Workstation

HMI

Simone's CyberSecurity 79
Level 3: Mature Segmentation with OT Micro-Segmentation via Firewall Zone segmentation
IT DMZ IT network OT DMZ OT network

SCADA

Enterprise
Server
Public
OT data
Server
historian Process / Production
PLC
Line 1
Internet

Workstation

HMI

PLC Process / Production


Line 2

HMI

PLC Process / Production


Line 3

HMI
80
Level 3: Scenario 2 (Logical VLAN based Segmentation)
Purdue-aligned Architecture with OT Micro-Segmentation
Scenario:
Represents a more mature network security model with IT, OT, and OT DMZ all clearly separated, combined with micro-segmentation within the OT side. Critical sub-VLANs such
as R&D, test benches, production cells, and engineering stations are isolated, reducing lateral movement and supporting defense-in-depth..

Risks:
VLAN hopping attacks: Misconfigured switches may allow attackers to move between VLANs.
Shared infrastructure risks: VLANs are logical, not physical; they still run on the same switch fabric, so compromise at Layer 2 can bypass isolation.
Management complexity: Large numbers of VLANs can become hard to manage, leading to inconsistent policies.
Lack of true enforcement: VLAN segmentation depends heavily on correct ACLs and switch configuration — a misstep can collapse segmentation.
Insider or misconfigured port issues: If an access port is incorrectly assigned, a device could end up in the wrong VLAN.

IT DMZ IT network OT DMZ OT network

Enterprise
Server
Public
OT data
Server
historian
PLC
Internet

Workstation

HMI

Simone's CyberSecurity 81
Level 3: Mature Segmentation with OT Micro-Segmentation via Logical Segmentation (VLANs)
IT DMZ IT network OT DMZ OT network

Enterprise
Server
Public
OT data
Server
historian Process / Production
PLC
Line 1
Internet

Workstation

HMI

PLC Process / Production


Line 2

HMI

PLC Process / Production


Line 3

HMI
82
From Maturity Levels to Real Architectures
From Maturity Levels to Purdue-aligned Architecture

Level 3

Level 2

Level 1

Level 0
Concept to
Blueprint

Simone's CyberSecurity 83
Level 3: Scenario 1: OT Micro-Segmentation via Firewall Zone segmentation

Level 5 Web Servers Email Servers Ethernet


Internet DMZ
Hardwired
Instrumentation
Internal DBs,
Level 4 Authentication Servers Corporate AD File Servers
Enterprise Admin

Level 3.5 Patching AV Server


Jump Hosts Data Historian
Server
Industrial/OT DMZ

Alarming & Local AD in case


Engineering Quality
Level 3 Monitoring completely isolated
Workstation Management
MES
(Centralized) from Corporate AD
Operations Admin

ICS System #1 iCS System #2

Level 2
Local HMI Local HMI
Supervisory

Level 1
Control

Level 0
Process

Simone's CyberSecurity
Level 3: Scenario 2: OT Micro-Segmentation via Logical Segmentation (VLANs)

Level 5 Web Servers Email Servers Ethernet


Internet DMZ
Hardwired
Instrumentation
Internal DBs,
Level 4 Authentication Servers Corporate AD File Servers
Enterprise Admin

Level 3.5 Patching AV Server


Jump Hosts Data Historian
Server
Industrial/OT DMZ

Alarming & Local AD in case


Engineering Quality
Level 3 Monitoring completely isolated
Workstation Management
MES
(Centralized) from Corporate AD
Operations Admin

ICS System #1 ICS System #2

Level 2
Local HMI Local HMI
Supervisory

Level 1
Control

Level 0
Process

Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

OT/ICS Incident Response Plan


SANS
#2
Defensible OT/ICS Network Architecture
IT AD
OT AD

Further enhancing with


OT/ICS Network Visbility & Monitoring the segmented AD for OT
architecture
OT/ICS Secure Remote Access

Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 86
Active Directory in IT & OT: Why a Shared AD Weaknes Segmentation
Single AD = Expanded Attack Surface Accross IT and OT

The IT AD standard
Active Directory is the central identity management for most IT
environments. It's built for convenience and broad connectivity.
IT AD OT using
OT's unique constraints
IT AD
OT networks prioritize safety, reliability, and uptime. They often
include legacy systems incompatible with modern security practices.

The dangerous "flat" network


Connecting a standard IT Active Directory to the OT network creates
a single point of failure. An IT breach could give attackers a clear path
to control critical industrial systems, as shown by attacks like the
Colonial Pipeline incident. Shared AD forces multiple firewall ports
(DNS, Kerberos, LDAP, SMB, RPC, etc.) to be opened between IT and
OT. You generally need to open
the following firewall ports
from the client to the Domain
The solution Controller:

OT requires a dedicated, purpose-built identity and access TCP/UDP 53 for DNS,


management (IAM) solution. This means separating IT and OT Active TCP/UDP 88 for Kerberos,
TCP 135 for Microsoft RPC,
Directory to protect the OT network. TCP/UDP 139 for NetBIOS,
TCP 389 for LDAP,
TCP 445 for SMB, and
high-ports like TCP 49152-
65535 for dynamic RPC.
Simone's CyberSecurity 87
Case Study: Norsk Hydro Ransomware Attack (2019)
AD Compromise Escalated Into OT Disruption

OT
Initial AD Group Policy disruption $70M
Access Compromise Push Impact

Simone's CyberSecurity 88
Separate OT Active Directory – Enforcing True Segmentation
Isolating IT and OT Identities to Reduce Risk

IT AD Seperate
OT AD
A dedicated OT AD forest – no ports shared with IT AD.

Eliminates the need to open high-risk firewall ports (DNS,


Kerberos, LDAP, SMB, RPC).

Containment: IT compromise does not automatically


impact OT.

A completely separate Active


Directory forest for OT
infrastructure. With no ports
shared between the two.

This ensures that a compromise


of the IT forest does not
automatically grant access to OT
assets.

Simone's CyberSecurity 89
The segmented AD for OT architecture
Secure OT Identity: The Dedicated Forest Model

Dedicated OT AD forest
Create a completely separate Active Directory forest for OT
infrastructure. This ensures that a compromise of the IT forest
IT AD (Levels 4-5)
does not automatically grant access to OT assets.

One-way trust (Optional)


A limited, one-way trust can be established from the OT forest to
A jump Server for adminstrative
the IT forest. This allows IT staff to authenticate to OT systems access OT DMZ (Level 3.5)
for management, but crucially, it prevents OT from trusting IT
credentials.

Hardened domain controllers


A separate OT AD (Level 3)
All OT domain controllers must be hardened according to OT-
specific benchmarks and best practices (e.g., CIS or ISA/IEC
62443).

Industrial controls (PLCs, HMIs)


Jump servers and privileged access workstations (PAWs) on Levels 1-2
All administrative access to OT domain controllers and key
systems must go through dedicated, hardened jump servers. This
is part of a zero-trust approach.

Simone's CyberSecurity 90
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

OT/ICS Incident Response Plan

Defensible OT/ICS Network Architecture


SANS
#3
OT/ICS Network Visbility & Monitoring

OT/ICS Secure Remote Access

Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 91
16
OT/ICS Network Visibility & Monitoring
Develop capability for monitoring ICS environments

HMI IoT Controller Controller


HMI IoT Controller Controller
Industrial Printer
Industrial Printer

Building Automation CNC System


Building Automation CNC System Reporting Server Device
Reporting Server Device Remote Access
Remote Access
Gateway
Gateway

Small Power Meter


Small Power Meter Electrical Drive
Electrical Drive Building Automation Computer
Building Automation Computer
Controller
Controller

Temperature
Temperature Embedded PC
Embedded PC Sensor Gateway
Sensor Gateway
Industrial Workstation
Industrial Workstation
Remote I/O
Remote I/O

Network Attached Storage


Network Attached Storage Temperature Sensor
Temperature Sensor
PLC

Without an Asset Inventory tool: OT Visibility with a tool such as Nozomi,


Dark/Blind OT Environment Claroty xDome, Cybervision etc.

Simone's CyberSecurity
16
Building Visibility: Data Sources & Collection
From passive scanning to integerations: enabling full OT visibility

Connectors
Passive scanning Active Scanning integreating with
collection Collection several IT/OT tools

Switch Span port Edge Devices Integerations

Simone's CyberSecurity
16
Turning Visibility into Action
Leveraging OT visbility tools for classification, segmentation and risk reductions

Enterprise
Network
HMI IoT Controller Controller
Industrial Printer
Management:
ERP
Building Automation CNC System
Reporting Server Device
Remote Access Planning:
Gateway MES

Level 2
Small
Electrical Drive
Power Meter Supervisory:
Building Automation Computer
HMI / ENG / SCADA /
3 1

4 2

Controller
Historian
Temperature
Embedded PC Level 1
Sensor Gateway
Industrial Workstation Automation: PLC
/ RTU
Remote I/O Ethernet
Level 0 connectivity
Process: Field
Network Attached Storage
Temperature Sensor Devices
Hardwired
Safety Instrumented System Instrumnetation

OT Visibility with a tool such as Nozomi,


Claroty xDome, Cybervision etc.

Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

OT/ICS Incident Response Plan

Defensible OT/ICS Network Architecture

OT/ICS Network Visbility & Monitoring


SANS
#4 OT/ICS Secure Remote Access

Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 95
Introduction to OT/ICS Secure Remote Access
Why Remote Access is Critical (and Dangerous) for OT

The "Why"
Remote access allows for significant cost savings and
improved efficiency for maintenance, monitoring, and
troubleshooting of industrial systems. Internet

The "Danger"
Unlike IT breaches that cause data loss, a compromised
OT remote access session can lead to physical damage,
safety hazards, and major operational disruption. OT network

Traditional vs. Modern


Legacy OT systems were "air-gapped" (isolated), but the
demands of Industry 4.0 and remote work have made
secure external access a necessity.

Key takeaway
We must transition from ad-hoc, insecure remote access
to a purpose-built OT secure remote access solution that
integrates MFA, monitoring, and least privilege. Case Study: A Secure OT Remote Access Workflow
A maintenance engineer needs to update a PLC at a remote pump station.

Simone's CyberSecurity
96
The OT/ICS Remote Access Threat Landscape
Common Attack Vectors & Risks

Compromised Endpoints: An attacker can pivot from an infected


Lateral
laptop or contractor device to infiltrate the OT network. Compromised Movement
endpoint
Weak Authentication: Many OT systems use legacy technology with
limited security features and default or weak passwords.

Lateral Movement: If network segmentation is poor, an attacker can


move easily from a less critical system to more sensitive ones.

Unmonitored Third-Party Access: Vendors often need remote


access, but without proper controls, this can be a major security Weak
risk. Authentication
Unmonitored
Third-Party
Insecure Protocols: Many legacy industrial protocols (like Modbus) Access
were not built with security in mind and lack encryption or OT Network
authentication.

Insecure
Protocols
Key Controls for Secure OT/ICS Remote Access

Multi-Factor Authentication (MFA): Ensure all remote sessions


require MFA for strong identity assurance. Jump Server Role-Based Access
Control (RBAC)
in OT DMZ
Jump Servers in OT DMZ: Force remote connections to pass
Session Recording
through a hardened, monitored gateway.
& Supervision

Role-Based Access Control (RBAC): Grant the minimum level of


access required, aligned with job role.

Session Recording & Monitoring: Log and record all remote Secure OT
sessions for forensic visibility. Remote
Access
Multi-Factor Time-Bound
Time-Bound Access: Approve access only for the required Authentication Access
duration and revoke it automatically after. (MFA)

Vendor Access Governance: Ensure vendor/third-party access is


controlled, monitored, and revocable.

Vendor
Forensic Access &
Logging Device Posture
Governance
Check

Simone's CyberSecurity
98
Implementing a OT/ICS Secure Remote Access Solution

Request & Approval – Engineer submits remote access request


(system, reason, duration).
Internet
Authentication – MFA validation + identity verification.

OT DMZ
Connection via Secure Gateway – Access routed through jump
server in OT DMZ.
OT network

Policy Enforcement – RBAC, time limits, monitoring enabled.

Session Recording & Alerts – Continuous logging with real-time


alerting.

Access Revocation – Session automatically ends, credentials


revoked.

Case Study: A Secure OT Remote Access Workflow


A maintenance engineer needs to update a PLC at a remote pump station.

99
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)

OT/ICS Incident Response Plan

Defensible OT/ICS Network Architecture

OT/ICS Network Visbility & Monitoring

OT/ICS Secure Remote Access


SANS
#5 Risk-Based OT/ICS Vulnerability Management

Simone's CyberSecurity 100


Why Risk-Based Vulnerability Management in OT is Needed
The Sisyphean Struggle of Patching Everything

Patching in OT is slow and costly – requires downtime,


backups, and manual rollback.

Chasing every patch like IT does creates an endless


cycle of effort.

Unlike IT, downtime in OT means lost production, safety


risks, and high operational cost.

A risk-based approach focuses effort where it matters


most, instead of patching everything.

The Punishment of Sisyphus: An Endless Struggle

Simone's CyberSecurity
Breaking the Sisyphean Loop with a Risk-Based Approach
All vulnerabilities are not created equal and a savvy security team must prioritize its efforts.

Identify your "Crown Jewels." Understand context and exposure Analyze real-world threat intelligence Prioritize and Mitigate based on
risk.

Human-Machine Interface for downstream conveyor & Rugged


The Main Assembly Robot: The Paint Shop Automation:
Tablets for inventory logging
Has a critical CVSS 9.8 vulnerability in its controller Contains a medium CVSS 6.5 Windows SMB
The HMI software has a CVSS 8.5 vulnerability, and rugged tablets
software. vulnerability in its supervisory control software.
also run outdated OS versions with known flaws.
However, it’s on a highly isolated network segment with no It runs on a flat OT network where contractors
However, these devices are not continuously connected — tablets
direct external connectivity. occasionally connect laptops for troubleshooting.
sync intermittently, and the HMI controls only a downstream
conveyor.
Exploitation would require physical access or pivoting This increases the likelihood of lateral movement and
through multiple layers. exploitation, even if the vulnerability score itself is
A disruption would be inconvenient but not production-halting
not the highest.
(operators can reroute or buffer flow).
→ High impact, low likelihood. Patching deferred until major
maintenance; monitoring and physical safeguards are → Medium-high likelihood, high impact. Prioritize
→ High likelihood, low impact. Manage via hardening, regular
prioritized. patching/segmentation, as exploitation could ruin
updates before re-connection, and monitoring.
multiple vehicles at once.

Simone's CyberSecurity
Breaking the Sisyphean Loop with a Risk-Based Vulnerability Management Cycle
Identify, Assess, Prioritize, Mitigate, Monitor

Identify
Identify critical OT assets & processes
Monitor & Review
Continously monitor & update

Assess
Analyze vulnerabilities & threats

Mitigate
Apply controls & response plans

Priortize
Rank risks by likelihood & impact

Simone's CyberSecurity
End of Section 6
Section 6 Summary – Key Takeaways

#1
Incident Section 7
Response Plan

#3
5 Network Visibility
& monitoring
#2 SANS
Defensible Network Critical OT/ICS
Architecture Controls
#4
Secure Remote
Access

#5
Governance & Processess (Who
Risk-Based Vulnerability
Ensures OT Security Happens?)
Management

Simone's CyberSecurity

You might also like