A power generation company was looking to take a step towards their IT/OT convergence and wanted a review and recommendations for their existing security controls in both these spaces.
Challenges
The organization wanted to understand the following aspects as a part of their review
Vulnerability assessment of existing assets facing the public infrastructure
IT-OT Operations’ – Assessment and Physical Audit
OT Visibility and Cyber Risk Assessment of the OT from IT-OT Surface
Cybersecurity Threat Modelling
The Solution
The security audit report was prepared after detailed site visits, consultation with IT and OT executives and a day long cyber threat modelling workshop. The report covered observations and a risk score for some of the challenges mentioned above as well as a detailed update based on the VA/PT results.
The OT report addressed issues mentioned below
Automation Assets and their existing anomalies that needed an immediate fix, a risk score on a scale of 5
Existing blind spots in OT infrastructure and potential threat surface for each of the blind spots
Security posture assessment based on existing coverage
Security Score for each of the existing security controls
Risk map and remediation plan
Outcomes
The outcome of the consulting exercise was a detailed security roadmap plan with special emphasis on “nice to have” and “must have controls” aligning with security compliances that are required in order to be prepared to adopt Industry 4.0 standards