top of page

Resolving the IT/OT Connection Paradox

  • May 21, 2021
  • 4 min read

Updated: Oct 22, 2024

Raj Sharma Sr, Operating Technology Security Director, GSK

Chris Sullivan, CEO, Nymi



The Colonial Pipeline breach of May 6 was the fourth attack on a US energy company in the last six months. Coincidentally, on May 12, the US government released its long-awaited Executive Order on Improving the Nation’s Cybersecurity. Together, these two events dramatically underscore the severity of the cyber threats we are facing today. More specifically, there is an urgent need to update our security strategies to enable digital transformation to continue. We see this clearly in the IT and OT environments of our public and private sector institutions as our nation wakes up to the critical need to address the dangerously growing IT/OT conundrum.


So, how did we get here?


Connections are good

Once upon a time, Operational Technology (OT) networks were segregated from all other networks (such as IT) — specifically to increase reliability. This made good sense, given that networks were not as reliable as they are today and like Christmas lights, companies didn’t want (or couldn’t afford) one blown fuse taking out the whole strand.


Fast forward to the present day and much has changed. Enterprise Resource Planning (ERP), Digital Transformation (DX), the Cloud, and most recently, the need to work remotely have combined to drive companies further along the path of connecting their OT networks with the goal of eliminating operational silos, increasing visibility, and making their employees’ lives easier. In this sense, connections are good.


Connections are bad

OT networks control critical operations and infrastructure like manufacturing plants, transportation networks (trains and planes), nuclear power plants, and so on. IT networks are used for email, cloud apps, legitimate web browsing and, as a result, are vulnerable to countless known and unknown attack vectors from virtually any place in the world. When we connect OT to IT, we make them equally vulnerable. So, connections are also bad.


Here are just three examples out of thousands where adversaries likely compromised credentials on IT networks, and then pivoted to OT through such a connection, resulting in catastrophic business and societal consequences:


June 2017 – An attack using Petya malware was directed at the Ukrainian government and spread into the IT networks of many global companies. In the case of pharmaceutical giant Merck, it quickly spread to the manufacturing lines (OT), taking them offline for weeks. The company reported $1.3 billion in losses.


February 2021 – A US city water department was breached, and attackers increased the amount of sodium hydroxide (NaOH) in the system by 11,100%. NaOH is used in very small quantities to control acidity, but at these massive levels, it becomes a highly caustic drain cleaner (check the Drano under your sink). Fortunately, the change was noticed and corrected immediately.


May 2021 – Colonial Pipeline suffered a ransomware cyberattack that shut down 45% of the fuel supply for the Eastern US for a week and caused extensive ripple effects including the panic buying of gas.


The trillion dollar question

So... What do we do? The obvious answer, being implemented around the globe, is re-segmentation.


In principle, this means:


• “Air Gapping” high-risk networks

• Prohibiting traffic between any secured (OT) environments and the Internet

• Restricting connections to only required systems and ports

• Prohibiting any trust relationships across network lines that would permit a compromise on an open (IT) network to a locked-down (OT) network

• Prohibiting password re-use across networks and/or domains


But in practice, these controls cannot be implemented in most environments:


• Data must flow for the enterprise to work

• There is no way to enforce password re-use restrictions


The reality of the matter is that enterprises and agencies are realizing that locking-down OT is not at all simple. How do you continue to take advantage of the benefits of IT/OT convergence? What do you do with shared printers? Cloud services? Remote access? Can workers function effectively in such an environment? How many strong and unique usernames and passwords can one person remember without re-use or writing them down?


As seen in the examples above and reported in the Verizon Data Breach Investigations Report (VDBIR) every year since its inception, lost, stolen, or compromised identities are at the root of the vast majority of OT breaches. In the words of Bret Arsenault, Microsoft CISO, “Hackers don’t break in. They log in.”


What we need is a safe, secure, and simple way to ensure that the user at the edge of the network (local or remote), is actually the person you need them to be. To do this, we need presence, non-repudiation (can’t be copied), and collusion/coercion prevention and detection (for example, biometrics to activate and on-body detection to continue use). From an employee perspective, this must all be wrapped in a beautiful and simple user experience that’s connected to everything (IT, OT, doors and floors, vending machines, printers, DX initiatives, health and safety). People have already experienced the ease and convenience of connection and when we take it away to make strong security their responsibility, they will get fatigued and fail.


As more and more operational technology (OT) devices are connected to IT networks, and as more and more threats attack our borders, the more we realize and must accept that we are caught in the middle of a connection paradox and the only way out is through a deliberate approach to connecting workers that prioritizes security, privacy, and best UX principles all at once.


A better way to manage IT/OT convergence

In conclusion, the old way doesn’t work. We know better than to live with unsecure connections between IT and OT. It’s time to replace the fragmented, risky, cumbersome, and reactionary approaches that are currently being used with an approach that’s built on a comprehensive connected worker platform. This will enable organizations to proactively resolve the IT/OT conundrum by managing and connecting their data, systems, and workers in a safe, secure, and simple manner. Take a look for yourself.


45 Comments


davidthom.a.s.282.55
7 hours ago

555win.tips mình ghé thử cho biết vì thấy tên xuất hiện mấy lần trên group, chủ yếu tò mò giao diện thôi. Vào trang chủ thấy bố cục khá gọn, kiểu chia từng khối nên kéo xuống không bị rối mắt. Có đoạn giới thiệu “555WIN - Trang Chủ 555WIN.COM…” đặt ngay đầu nên nhìn phát là biết họ muốn nói gì, trong đó có nhắc giấy phép Isle of Man với Cagayan nên đọc lướt cũng thấy họ cố trình bày rõ ràng. Mình không đào sâu, chỉ liếc phần “bài viết gần đây” thì thấy có bài về cách tính chi mậu binh, tiêu đề nổi bật nên dễ bấm nhầm vào xem. Nói chung nhìn qua là…

Like

uyenghomsoet.h.uy.e.n+abc123
3 days ago

https://79king.legal/ mình chỉ ghé thử vì thấy mấy người quen bàn tán, chứ không có tạo tài khoản hay tham gia gì. Lướt qua vài mục thì thấy thiết kế khá sạch sẽ, chia phần rõ ràng nên đọc không bị rối mắt. Mấy tab chuyển qua lại mượt, gần như không phải đợi load lâu. Thông tin giới thiệu cũng trình bày kiểu dễ hiểu, không nhồi nhét chữ. Có nhắc tới bảo mật SSL 256-bit nên cảm giác ít nhất họ cũng chú ý chuyện an toàn. Nói chung hợp kiểu ai muốn xem thông tin nhanh, gọn.

Like

terrancecart.e.r.36.0.7
Jun 01

hitclub mình mới ghé thử vì thấy mọi người bàn tán hoài, kiểu vào xem cho biết thôi chứ không định chơi gì. Ấn tượng đầu là giao diện nhìn sáng sủa, chia từng khối nội dung rõ nên lướt xuống khá nhẹ đầu, không bị rối. Mình có đọc lướt phần giới thiệu, thấy họ ghi ra mắt từ 2015 nên cũng yên tâm hơn chút, cảm giác không phải trang làm vội. Mấy mục trên menu đặt ngay chỗ dễ thấy, bấm qua lại không phải đoán xem thông tin nằm đâu. Nói chung mình thích kiểu họ tách tiêu đề và nội dung thành các box riêng, nhìn phát là biết đang ở đoạn giới thiệu lịch…

Like

elsiebre.we.r1.6.921
May 29

https://nk88.gg/ hôm trước mình lướt thấy bạn share nên mở thử xem sao, kiểu tò mò giao diện thôi chứ chưa đăng ký hay chơi gì. Vào trang cái thấy thiết kế khá hiện đại, nền nhìn sạch và chữ dễ đọc nên không bị ngợp. Mấy mục nội dung được chia theo khối rõ ràng, kéo xuống là biết mình đang ở đoạn nào, không phải đoán. Mình cũng để ý họ có nhắc đến hệ sinh thái game khá phong phú, nhưng mình chỉ đọc lướt qua phần giới thiệu cho biết. Điểm mình thích là menu đặt dễ thấy, bấm qua lại không bị lạc, load cũng ổn. Nói chung nhìn qua đã thấy họ sắp xếp…

Like

melaniemarshall6592
May 29

game tài xỉu dạo này thấy bạn bè nhắc hoài nên mình cũng bấm vào xem thử trang đó ra sao. Mình không rành mấy cái này, chủ yếu tò mò cách họ sắp xếp nội dung thôi. Vào cái là thấy họ để mấy bài kiểu “tìm hiểu game tài xỉu online là gì” với phần “luật chơi đơn giản” khá nổi, nên người mới như mình biết đọc từ đâu luôn. Cách trình bày nhìn thoáng, chữ không bị dồn một cục, kéo xuống là từng khối nội dung tách ra rõ nên đỡ mỏi mắt. Mình cũng thích mấy tiêu đề dạng “TOP 10 Trang Game Tài Xỉu – Tải App Tài Xỉu APK iOS Mới Nhất”…

Like
bottom of page