News Security Technology

Integrating Cybersecurity With Business Strategy: A CISO’s Guide

CISOs and organisations must integrate a comprehensive industrial cybersecurity programme into daily operations, supported by a team of OT experts

A comprehensive industrial cybersecurity programme should include a dedicated team of OT cyber experts, says Harshad Mengle, Global CISO at Tata Chemicals. CISOs and organisations must integrate a robust industrial cybersecurity programme into their daily operations, ensuring that digitalisation and cybersecurity evolve hand in hand. As operations become more connected, data-driven, and autonomous, the exposure to cyber threats significantly increases. 

Hackers are aware of this growing vulnerability, strategically targeting both information technology (IT) and operational technology (OT) environments, which are becoming more interconnected. Through simple entry points, like a flash drive, they can potentially halt entire operations. Organisations can no longer afford to focus solely on the last cyber attack; CISOs need to build comprehensive cybersecurity frameworks that anticipate and mitigate future threats. 

With the convergence of OT and IT systems, and the deployment of newly designed cyber-physical systems (CPS), OT security is shifting from network-centric to CPS asset-centric security. Analysts indicate that only 8% of organisations have progressed beyond the awareness phase of cybersecurity, with most starting their journey by conducting discovery efforts. 

 Manufacturing Business & Mission Objectives 

Cybersecurity risks can have a direct impact on human safety in manufacturing. Therefore, personnel need to understand the interdependencies between cybersecurity and safety. Maintaining human safety, product quality, and production goals, alongside protecting trade secrets, are critical business objectives. Cyber risks, if not managed effectively, can potentially affect the safety of employees, the environment, product integrity, and production output. A comprehensive cybersecurity programme, executed by a team of OT cyber experts, should focus on assessing, planning, and developing OT network protections, as well as managing detection and incident response to minimise operational risks. 

 Top Industrial Cyber Threats 

 The most prevalent industrial cyber threats include ransomware, network compromise, distributed denial-of-service (DDoS) attacks, insider threats, and the growing use of unmanned aerial vehicles (UAVs). Legacy OT systems are increasingly interconnected with IT systems, while cyber-physical systems introduce new vulnerabilities and protocols. Managing these vulnerabilities demands specialised security skills and solutions, such as integrating plant interface systems (HMIs) with LDAP or directory services. 

 New Cyber Targets: Industrial Control Systems (ICS) & OT 

 Cyber attackers are evolving and now aim for more than just data theft; they seek control over operational technology. They aim to shut down, overspeed, overload, and disrupt operations. When vulnerabilities are exploited within an OT network, threats can easily spread to other devices, escalating risks. 

 As operations expand, so does the “attack surface,” offering more entry points for cyber attackers. Expanding operations often leads to cybersecurity becoming an afterthought, which leaves critical gaps. The addition of sensors, devices, and Industrial Internet of Things (IIoT) systems to the network can amplify these risks, particularly as organisations increasingly rely on remote monitoring and management. 

 Cyberattackers: Now Forming Businesses 

 Cyberattacks are now business enterprises in their own right, with threat actors forming well-organised entities. These actors range from terrorists to politically motivated hackers. Their tactics differ, but their goal remains consistent: to target organisations, waiting for the opportune moment to strike. 

 Steps To Strengthen OT Cybersecurity 

 Basic cyber hygiene can greatly reduce OT cyber risks. Key measures include investing in robust cybersecurity solutions, understanding what needs protection, managing vulnerabilities, and implementing security at the design phase of operations and expansions. Continuous 24/7/365 visibility and control are essential, ensuring that operations are not exposed to risks. Moreover, partnering with an experienced OT cybersecurity expert is crucial. 

Collaboration Between CISO & OT Plant Manager 

 A successful OT cybersecurity programme requires close collaboration between the Chief Information Security Officer (CISO) and the OT Plant Manager. Together, they should develop a comprehensive strategy that encompasses asset inventory, risk assessment, security policy implementation, network segmentation, access control, and incident response planning. Regular security awareness training is essential to ensure that all employees understand their role in safeguarding OT systems. 

 Asset inventory and classification are the first steps in this process, helping to prioritise critical assets for protection. Following that, a comprehensive risk assessment should be conducted, specific to OT systems, with a focus on understanding vulnerabilities and potential impacts on safety, production, and business continuity. Security policies, tailored to OT, must be developed, covering areas such as access control, patch management, and incident response. Network segmentation is vital, ensuring that critical systems are isolated from non-critical ones to limit lateral movement during an attack. 

 Strong access controls, including multi-factor authentication (MFA), should be implemented to protect privileged accounts. Vulnerability management processes need to be in place, enabling regular scans for vulnerabilities and ensuring that they are addressed promptly. A tailored incident response plan must be developed, involving both the CISO and OT Plant Manager in drills to test its effectiveness. Continuous monitoring of the OT network, along with real-time threat detection, is essential to detect and respond to any anomalies. 

 Moreover, regulatory compliance plays an important role in OT security. The CISO must stay informed about relevant regulations and prepare compliance reports as needed, while the OT Plant Manager provides the necessary documentation during audits. The integration of OT and IT systems and the advent of cyber-physical systems have significantly increased the cybersecurity risks faced by manufacturing organisations. CISOs and OT Plant Managers must work together to build a comprehensive industrial cybersecurity programme that not only addresses current threats but also anticipates future vulnerabilities. Through continuous monitoring, robust incident response plans, and security-by-design, organisations can protect themselves from cyber attackers who are constantly evolving their strategies. Cybersecurity is no longer just about protecting data—it’s about ensuring the safety, continuity, and resilience of industrial operations. 

Author: Harshad Mengle, Global CISO, Tata Chemicals 

Leave a Reply

Your email address will not be published. Required fields are marked *