OT Cybersecurity: When a Cyber Event Becomes a Process-Safety Event
A cyber incident can affect alarms, control loops, visibility and safe operating decisions. Learn how to connect OT cybersecurity to your process-safety management system.
OT Cybersecurity: When a Cyber Event Becomes a Process-Safety Event
Operational technology controls physical processes. It includes the systems that monitor a tank level, start a pump, close a valve, display an alarm or support a shutdown function. When these systems are compromised or unavailable, the consequence can extend beyond lost data or office productivity. The facility may lose visibility, control, or confidence in the integrity of its safeguards.
Treat cyber scenarios as operating scenarios
The first question is not “can the network be hacked?” It is “what can the plant safely do if this system is unavailable, manipulated or untrusted?” Consider loss of historian data, unavailable operator screens, a disabled alarm, loss of remote access, incorrect set points, ransomware affecting engineering workstations, or a supplier connection that becomes a pathway into the control environment.
These are process-safety scenarios because they can affect prevention, detection, decision-making and emergency response.
Connect IT and operations
OT security cannot be owned by IT alone, and operations cannot solve it alone. Create a shared risk picture involving operations, engineering, maintenance, process safety and cybersecurity. Maintain an inventory of critical assets, their function, connection paths, owner, backup arrangements and safe state.
Prioritise systems connected to major-incident scenarios. A compromise of a business report may be inconvenient; a compromise of a shutdown, gas detection, fire-and-gas display or remote isolation function needs a tested response plan.
Build practical barriers
The exact controls depend on the facility, but the baseline usually includes network segmentation, controlled remote access, multi-factor authentication where workable, patch and vulnerability management, backups, supplier access management, logging, asset visibility and an incident-response plan that includes operations.
Avoid applying IT changes without understanding process consequences. A security patch that requires a restart, blocks a support path or changes controller communications needs management of change and a recovery plan.
Practise the loss-of-control response
Run scenario-based drills. Can operators establish the plant state without the usual display? Who decides whether to continue, reduce rate, stabilise or shut down? How is the site isolated from a suspect network? How will the team communicate with emergency responders and external support?
This is also an opportunity to review manual operating capability, procedure quality and operator workload. A cyber event often reveals weaknesses that existed before the attack.
Add cyber to the hazard-review agenda
Include cyber-enabled deviations in HAZOP, LOPA and emergency-planning reviews where the affected control or information system has a safety function. Link the outcome to BowTie barrier health so impaired digital safeguards are visible and managed.
South African professional activity around OT and industrial control security, together with current research into petrochemical-sector maturity, makes this a timely discipline for high-hazard operators. MMRisk can help bridge operational risk, hazard analysis and emergency planning with your OT-security programme. Contact us to start the conversation.