• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Situational awareness more important than traditional security in OT and ICS

by CXO Staff
August 29, 2022
in Opinions
Situational awareness more important than traditional security in OT and ICS

The current state of security for operational technology and industrial control systems is turning a corner. In today’s real-life scenarios, there has been an increase in related cyber incidents. In one week in May 2022, the Cybersecurity and Infrastructure Security Agency in the U.S. released 27 Industrial Control Systems Advisories.

The growing number of attack patterns has revealed three pitfalls in operational and industrial systems:

  • Companies are reacting to security incidents, rather than investing in reducing severity
  • Threat of sophisticated, nation-state level attacks, narrows focus to threat hunting at the expense of other indicators
  • Data science in theory is useful for security, but in practice does not solve challenges in operational and industrial systems

Industrial and operational technologies encompass a wide range of machines and configurations, pumps, compressors, valves, turbines, and similar equipment, interface computers and workstations, programmable logic controllers and diagnostics, safety, metering, and monitoring and control systems that enable or report the status of variables, processes, and operations.

A single programmable logic controller can be designed and produced by several different vendors, can be configured using different programming languages, and enable communications from hundreds of different protocols.

When simplified, any programmable logic controller from an average of 10 major vendors, utilising any of the top 5 most common programming languages, and one or more of the 12 most common communications protocols, has at least 600 possible operational configurations. This example demonstrates how quickly standardising the technologies and products to establish their attack scenarios will become an enormous task.

We need to build a deterministic nature of purpose-built systems in operational technology and industrial control systems, customised for every and any operation. This approach ensures no two attacks on operational and control systems are ever the same.

This is the next step in building security systems for operational technology and industrial control systems environments. The purpose-built systems and subsystems need to be translated into purpose-built systems for security.

In security we continue to amass knowledge in the form of indicators of compromise. Unfortunately, attacks on operational and industrial systems do not provide the volume of telemetry data to adequately derive threat actor objectives helping to identify novel attacks ahead of time.

Indicators of compromise do not capture indicators for misconfigurations, malfunctions, or accidental changes that go undetected. These limitations are only captured by monitoring actual processes and operations.

Most of the security companies doing intrusion detection in this space focus on network traffic capture and security monitoring that evaluates and scans for known threat activity. There are limitations to this type of collection, rule application, and analysis for operational and industrial systems.

Since there are no cut and paste tactics, techniques, procedures from incidents in operational and industrial systems, the only way to secure operations is to include plausibility checks for systems in play.

Security is relative to functioning of the entire process or critical operation worth securing. Systemwide frameworks for understanding risk and threat scenarios are a must for this field. A systemwide framework examines the largest-scale dynamics, and the inherent systemic risk of the Internet. This approach is necessary to secure operational and industrial systems and explore the full range of potential intrusions, espionage, attacks, disruptions, and accidents.

The more efficient we become at asset intelligence, process variable detections and plausibility checks for real-world outcomes, the better we will be able to augment threat intelligence. It is more efficient to spend resources in building intuition and bolstering situational awareness, rather than incident response capabilities.

The next wave of building intuition into monitoring for operational and industrial systems security is behavioural analytics that cover communications traffic and process variables simultaneously.

With an, assume a breach has happened mentality, the focus for security products must be on reducing the severity of potential impacts, not on responding to worst case scenarios after they unfold. Building intuition into security for purpose-built operations requires customising detections and prevention methods. That is the way forward.

 

Tags: featured3Nozomi Networks
ShareTweet

Related Posts

Work reborn: Accelerating digital workplace transformation in the UAE and Saudi Arabia
Opinions

Work reborn: Accelerating digital workplace transformation in the UAE and Saudi Arabia

As the UAE and Saudi Arabia continue to lead the Middle East’s digital evolution, the future of work is undergoing...

July 15, 2025
Five ways to balance AI innovation with sustainability 
Opinions

Five ways to balance AI innovation with sustainability 

As the AI landscape rapidly evolves, business and technology leaders face growing challenges in balancing immediate AI investments with long-term...

July 14, 2025

Discussion about this post

Latest Issue

UAE execs trust AI with ‘high-stakes’ decisions, says Endava

UAE execs trust AI with ‘high-stakes’ decisions, says Endava

July 17, 2025
Gartner predicts 40% of AI data breaches will arise from cross-border GenAI misuse by 2027

Okta, Palo Alto Networks team up to strengthen AI-driven security

July 17, 2025
Global PC shipments rise, enterprise leads the way: report

Global PC shipments rise, enterprise leads the way: report

July 17, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.