Brian Sims
Editor
Brian Sims
Editor
THE NATIONAL Cyber Security Centre (NCSC) has witnessed the increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK. This targeting has been carried out by a range of threat actors and resulted in some limited real-world disruption.
The NCSC has stated: “Any organisation that uses, deploys or maintains OT systems should treat this development seriously and review their security posture accordingly.”
Any organisation with Internet-exposed OT could be affected by this activity.
Organisations should not assume that their OT is inaccessible from the Internet without verifying it, observed the NCSC, as unintended exposure can arise through misconfigurations, legacy connections or unmanaged assets.
National resilience
The NCSC has been engaging with sectors directly in response to this recent targeting and is now sharing an advisory to support national resilience efforts.
For some time, the NCSC has been warning about a broader pattern of disruptive cyber activity carried out by state and non-state actors affecting organisations in both the Critical National Infrastructure (CNI) and non-CNI sectors. Set against the backdrop of technology-enabled uplifts in cyber capability and increased geopolitical instability, the NCSC assesses that the threat from state use of offensive cyber – including outside of conflict – has almost certainly increased.
As a result of this wider context, it’s now deemed “essential” that all organisations take action immediately given the developing threat picture.
Actions to be taken
In response to the observed disruptive activity, organisations should take the following actions:
*build a definitive view of all OT assets and ensure that OT devices are not directly accessible from the public Internet
*replace default credentials and strengthen access controls for OT systems
*control access to OT networks and maintain secure and supported boundary devices
*adopt secure industrial and management protocols wherever possible
*ensure all connectivity to and within OT networks is logged and monitored
*ensure OT devices are operated in a state that prevents remote programming during normal operations
*separate OT, management and business networks to limit the impact of incidents
*maintain tested back-ups and recovery procedures for critical OT systems
Implications for non-OT organisations
While the NCSC has observed the direct targeting of OT, there continues to be a broader pattern of disruptive cyber activity targeting Internet exposed systems and edge devices affecting all sectors.
The NCSC has previously highlighted other activity such as that against poorly configured routers, published in July in conjunction with international partners. For non-OT organisations, such activity highlights the importance of maintaining visibility of Internet-exposed assets and edge network devices.
Key actions include maintaining an accurate inventory of Internet-facing systems, understanding the function and data flows of edge devices, applying vendor security updates promptly, retiring end-of-life equipment, disabling insecure management protocols such as SNMP v1, SNMP v2 and Telnet and monitoring for unexpected configuration changes or outbound connections.
Building long-term resilience
Effective cyber resilience requires organisations to be prepared before an incident occurs and capable of responding and recovering when one does.
Organisations should review their readiness for significant cyber incidents, taking account of the NCSC’s guidance on preparing for severe cyber threats, and ensure that arrangements for responding to and recovering from cyber attacks are established, maintained and regularly exercised in line with the NCSC's guidance on what to do when cyber attacks disrupt your organisation.
All organisations should register for the NCSC’s free Early Warning service to help identify publicly exposed vulnerabilities and other potential security issues affecting Internet-facing systems, supporting efforts to detect and address risks before they’re exploited.
Cyber Assessment Framework
Organisations that have embedded strong cyber resilience practices are better placed to prevent, detect and respond to cyber incidents before they cause operational disruption.
The Cyber Assessment Framework (CAF) provides a comprehensive framework for assessing how well an organisation is meeting expected security and resilience outcomes. Boards of Directors should seek assurance that the outcomes and principles described within the CAF are being achieved across all systems supporting essential functions.
Where the CAF isn’t appropriate, Cyber Essentials is an excellent first step in gaining assurance that systems are protected against the most common threats. It’s the minimum standard of cyber security recommended by the Government for organisations of all sizes.
*Further information is available online at www.ncsc.gov.uk
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM