top of page

Resolving the IT/OT Connection Paradox

  • May 21, 2021
  • 4 min read

Updated: Oct 22, 2024

Raj Sharma Sr, Operating Technology Security Director, GSK

Chris Sullivan, CEO, Nymi



The Colonial Pipeline breach of May 6 was the fourth attack on a US energy company in the last six months. Coincidentally, on May 12, the US government released its long-awaited Executive Order on Improving the Nation’s Cybersecurity. Together, these two events dramatically underscore the severity of the cyber threats we are facing today. More specifically, there is an urgent need to update our security strategies to enable digital transformation to continue. We see this clearly in the IT and OT environments of our public and private sector institutions as our nation wakes up to the critical need to address the dangerously growing IT/OT conundrum.


So, how did we get here?


Connections are good

Once upon a time, Operational Technology (OT) networks were segregated from all other networks (such as IT) — specifically to increase reliability. This made good sense, given that networks were not as reliable as they are today and like Christmas lights, companies didn’t want (or couldn’t afford) one blown fuse taking out the whole strand.


Fast forward to the present day and much has changed. Enterprise Resource Planning (ERP), Digital Transformation (DX), the Cloud, and most recently, the need to work remotely have combined to drive companies further along the path of connecting their OT networks with the goal of eliminating operational silos, increasing visibility, and making their employees’ lives easier. In this sense, connections are good.


Connections are bad

OT networks control critical operations and infrastructure like manufacturing plants, transportation networks (trains and planes), nuclear power plants, and so on. IT networks are used for email, cloud apps, legitimate web browsing and, as a result, are vulnerable to countless known and unknown attack vectors from virtually any place in the world. When we connect OT to IT, we make them equally vulnerable. So, connections are also bad.


Here are just three examples out of thousands where adversaries likely compromised credentials on IT networks, and then pivoted to OT through such a connection, resulting in catastrophic business and societal consequences:


June 2017 – An attack using Petya malware was directed at the Ukrainian government and spread into the IT networks of many global companies. In the case of pharmaceutical giant Merck, it quickly spread to the manufacturing lines (OT), taking them offline for weeks. The company reported $1.3 billion in losses.


February 2021 – A US city water department was breached, and attackers increased the amount of sodium hydroxide (NaOH) in the system by 11,100%. NaOH is used in very small quantities to control acidity, but at these massive levels, it becomes a highly caustic drain cleaner (check the Drano under your sink). Fortunately, the change was noticed and corrected immediately.


May 2021 – Colonial Pipeline suffered a ransomware cyberattack that shut down 45% of the fuel supply for the Eastern US for a week and caused extensive ripple effects including the panic buying of gas.


The trillion dollar question

So... What do we do? The obvious answer, being implemented around the globe, is re-segmentation.


In principle, this means:


• “Air Gapping” high-risk networks

• Prohibiting traffic between any secured (OT) environments and the Internet

• Restricting connections to only required systems and ports

• Prohibiting any trust relationships across network lines that would permit a compromise on an open (IT) network to a locked-down (OT) network

• Prohibiting password re-use across networks and/or domains


But in practice, these controls cannot be implemented in most environments:


• Data must flow for the enterprise to work

• There is no way to enforce password re-use restrictions


The reality of the matter is that enterprises and agencies are realizing that locking-down OT is not at all simple. How do you continue to take advantage of the benefits of IT/OT convergence? What do you do with shared printers? Cloud services? Remote access? Can workers function effectively in such an environment? How many strong and unique usernames and passwords can one person remember without re-use or writing them down?


As seen in the examples above and reported in the Verizon Data Breach Investigations Report (VDBIR) every year since its inception, lost, stolen, or compromised identities are at the root of the vast majority of OT breaches. In the words of Bret Arsenault, Microsoft CISO, “Hackers don’t break in. They log in.”


What we need is a safe, secure, and simple way to ensure that the user at the edge of the network (local or remote), is actually the person you need them to be. To do this, we need presence, non-repudiation (can’t be copied), and collusion/coercion prevention and detection (for example, biometrics to activate and on-body detection to continue use). From an employee perspective, this must all be wrapped in a beautiful and simple user experience that’s connected to everything (IT, OT, doors and floors, vending machines, printers, DX initiatives, health and safety). People have already experienced the ease and convenience of connection and when we take it away to make strong security their responsibility, they will get fatigued and fail.


As more and more operational technology (OT) devices are connected to IT networks, and as more and more threats attack our borders, the more we realize and must accept that we are caught in the middle of a connection paradox and the only way out is through a deliberate approach to connecting workers that prioritizes security, privacy, and best UX principles all at once.


A better way to manage IT/OT convergence

In conclusion, the old way doesn’t work. We know better than to live with unsecure connections between IT and OT. It’s time to replace the fragmented, risky, cumbersome, and reactionary approaches that are currently being used with an approach that’s built on a comprehensive connected worker platform. This will enable organizations to proactively resolve the IT/OT conundrum by managing and connecting their data, systems, and workers in a safe, secure, and simple manner. Take a look for yourself.


58 Comments


TemuulenErdenesaikhan
Jul 17

I came across MelBet while looking for a place to follow international football and basketball in one app. A post on a local forum mentioned the promo code PICKEM, so I decided to give it a try during registration. What surprised me most wasn't the offer itself but how polished the whole platform felt. Match statistics load quickly, the live section is easy to follow, and finding different leagues takes only a few taps. I also like that the interface doesn't feel cluttered, even with so many features available. Melbet promo code free spins has stayed on my phone because it makes keeping up with sports simple, and the PICKEM code was a nice bonus when I first joined.

Edited
Like

katrinacha.vez.52.0.2
Jul 17

https://ee88.photography/ mình ghé thử vì thấy bạn bè nói qua, kiểu vào xem giao diện là chính chứ không định đọc kỹ. Trang mở ra nhìn khá thoáng, mấy mục tiêu đề nổi như “KHUYẾN MÃI HOT” với “BÀI VIẾT MỚI NHẤT” đặt ngay chỗ dễ thấy nên khỏi phải mò. Mình thích cách họ chia nội dung theo từng khối, cuộn xuống vẫn gọn, không bị dồn chữ hay banner loạn lên. Lướt sơ cũng thấy có vài bài dạng kinh nghiệm/đọc nhanh, nhìn phát biết nó thuộc nhóm nào vì bố cục tách bạch. Nói chung cảm giác dùng ổn, và phần “BÀI VIẾT MỚI NHẤT” hiển thị dạng block nên nhìn một cái là thấy danh sách…

Like

billy24barne.s7.8.3.5
Jul 10

7p777 showed up in my feed a few times, so I poked around out of curiosity to see what the site looks like. I didn’t dive deep into the actual stuff on there, but the layout made sense pretty fast. The main menu is right where you’d expect it, and I didn’t have to hunt around to figure out where things were. What I noticed most is how everything’s spaced out—info isn’t jammed together, so it’s easy to skim without your eyes glazing over. It feels like someone actually thought about making it readable on a normal scroll, not just cramming text everywhere. The headings are clear, and the content is split into neat blocks that keep the page looking…

Like

hoachtungbuang.l.y.nh
Jul 07

hz88 game mình thấy bạn bè nhắc suốt nên cũng bấm vào coi thử cho biết, kiểu tò mò giao diện thôi chứ chưa chơi gì nhiều. Vào trang đầu thấy họ chia nội dung theo từng mảng rõ ràng nên lướt trên điện thoại khá nhẹ, không bị rối mắt. Mình thích cái cảm giác chuyển qua lại giữa mấy khu trong cùng hệ thống nhanh, bấm vài cái là tới chứ không phải vòng vo. Có mục giải đáp FAQ để ngay chỗ dễ thấy, đọc lướt cũng hiểu cơ bản nên người mới chắc đỡ hoang mang. Nói chung nhìn thân thiện, chữ không dồn dập, và mấy khung thông tin tiêu đề được căn theo từng…

Like

luciand.urha.m.584
Jul 03

https://vnew88.net/ hôm trước thấy bạn bè nhắc nên mình bấm vào coi thử cho biết thôi. Mình không đọc kỹ nội dung hay ngồi mò từng mục đâu, chủ yếu xem giao diện có dễ nhìn không. Vào cái là thấy trang chia khối khá rõ, khoảng trắng vừa đủ nên lướt nhanh không bị ngợp. Mình cũng thích kiểu họ trình bày thông tin theo dạng cột/bảng gọn gàng, nhìn một cái là bắt được ý chính chứ không phải kéo qua kéo lại nhiều. Thanh menu để ngay chỗ dễ thấy nên chuyển qua lại cũng tiện, không phải đoán xem nút nằm đâu. Nói chung cảm giác dùng vài phút là quen tay vì các khung nội…

Like
bottom of page