Anyone who carries the security methods of the IT world into a production facility discovers quickly that they cannot be used as they are. An update cannot be rolled out on a Tuesday. A system cannot be restarted to try something. And an incorrect action has consequences that concern not data but equipment and people. The order of priority is simply a different one.
The chapter opens by explaining what OT is and how it differs from IT in both purpose and construction. In an office environment, information is protected first. In a facility, availability and personal safety come first, and that difference governs every decision that follows. Then comes IT and OT convergence, what happens when previously isolated systems are connected to office networks and cloud services to enable remote monitoring and analysis. The benefit is real, but the routes in multiply and are rarely surveyed in full by either side alone. The threat picture for Swedish OT gets its own section, with the sobriety the question deserves. After that come the basic security measures, with segmentation and access control at the centre, since equipment with a twenty year service life cannot be updated at the pace of office systems. A review of IEC 62443 shows how the framework complements ISO 27001 rather than replacing it. One section deals with what the Cybersecurity Act requires of OT environments, and the chapter closes with an incremental path forward for anyone starting in systems that are not allowed to stop. How incidents are handled when the physical consequences are immediate is covered in chapter 17 on incident response.
The question is current because several of the sectors named in the Cybersecurity Act, such as energy, water and transport, rest on exactly this kind of system. The requirements therefore reach environments that have rarely had a security function in the IT sense, and where the competence sits with operations staff rather than with anyone who has read a standard.
This page shows what the chapter covers and why OT demands its own approach. The measures, the framework and the incremental path are in chapter 20 of the book.
Where security and safety meet, they have to speak the same language. That is where OT security begins.
Key insights
- In IT, information is protected first. In OT, availability and human safety come first, and that difference governs everything.
- Convergence between IT and OT creates routes in that neither side alone has a full view of.
- Equipment with a twenty year service life cannot be updated at office system pace, which shifts the weight to segmentation.
- IEC 62443 is the framework for OT and complements ISO 27001 rather than replacing it.
- The work has to be incremental. Systems that cannot stop will not tolerate a rollout that assumes they can.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Glossary and resource catalogue
OT, SCADA, PLC and IEC 62443 explained.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.