Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • IT/OT Convergence or IT/OT Integration?
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

IT/OT Convergence or IT/OT Integration?

5 years ago Tripwire Guest Authors
IT/OT Convergence or IT/OT Integration?

IT/OT convergence is an oft-repeated term, and maybe it’s the wrong term.

From a technology standpoint, IT/OT convergence has been occurring since at least the 1990s when HMI/Operator Stations began running on Windows and when Ethernet began displacing deterministic custom LAN protocols in the OT realm. This technology convergence has continued with networking, cybersecurity, virtualization, edge, zero trust, etc. The biggest change since the 1990s is that the time lag between technology being common in IT and it becoming common in OT is shrinking, although this process is still measured in years.

Integration vs Convergence

The skill sets required to deploy and manage these computer-, TCP-/IP-, Ethernet-based systems are the same in both IT and OT. So we are seeing some workforce convergence, as well.

Outside the underlying technology, the term “integration” may be more appropriate than convergence when talking about OT and IT.

Even when we look at IT only, everything is not, or at least it should not, be converged into one large, flat system. Desktop management is not “converged” with the ERP system or e-commerce operations. They are different systems with different purposes and different requirements. They are deployed and maintained by different teams in large organizations.

The same is and will continue to be true for OT in relation to IT. The non-engineering portion of OT applications, systems, and services may be the responsibility of “IT,” but it will be a team dedicated to OT. This team’s customer will be Operations, just as the ERP team’s customer is typically Finance.

Integration for the benefit of the business

While we can quibble with the term “convergence,” there is no doubt that the trend to connect, or integrate, IT and OT together for significant business benefits is growing in importance. Originally this involved sending historical process data from OT to IT for a variety of business purposes including billing, regulatory data, and business process reporting. Increasingly, it is being sent for predictive maintenance, efficiency improvements, and other process performance reasons. The future also includes sending OT data to IT so that enterprise cyber asset management, including security and change management, comprises both IT and OT.

Tripwire is a good example of integrating OT and IT asset management along with vulnerability management. Asset owners have long been using Tripwire on the enterprise side of things. There has also been a Tripwire product for the OT world, not to mention the OT heritage and widespread deployments that parent company Belden brings. The Tripwire OT solution has particular traction in the power sector, as it plays a role not only in security and asset management but also in helping utilities meet NERC CIP compliance.

A CISO’s “Single Pane of Glass”

The widespread news of the growing threat and real consequences of cyber attacks on critical infrastructure have resulted in the Board of Directors and CEO wanting answers on cyber risk. And they typically look at the CISO for these answers. Most CISOs don’t want to have separate IT and OT systems with different terminology to show them current risk posture and key metrics. The modern CISO wants to look at the “single pane of glass” to see their cyber security posture and cyber risk. The distinctions of IT and OT are less important than understanding the cyber risk from a business perspective.

The simplest solution is to export the OT data to an IT system and display it. We are seeing this through OT interfaces and connectors from companies like Splunk and ServiceNow. The challenge is risk isn’t as simple, especially in OT, as counting up the number of missing patches. Issues such as exposure, process and safety criticality, as well as security posture need to be taken into account to properly show the business risk to the CISO.

Patching is the most common and simple example. A large number of OT cyber assets have no user or data authentication. For these cyber assets, applying security patches accomplishes little and can be resource-intensive to do on a monthly or quarterly basis. With the exception of immediate patching of exposed OT resources, resources are typically better applied to other OT cyber risk reduction activities rather than monthly or quarterly patching. This differs from IT where most cyber assets are exposed to connections from networks with a lower trust level.

So while the CISO wants to see OT and IT cyber risk in a single pane of glass, it will require the way the key metrics are presented to be different in IT and OT. Otherwise OT will always look like it is at greater risk even though the data for decades has shown that the likelihood of compromise is much greater on IT than OT. As IT/OT cyber risk management integrations increase, vendors will need to deal with these differences. And it is likely that the asset owners will need to have the ability to tune these risk metrics so the presentation of data to the CISO and others is consistent enough to make intelligent cyber risk decisions.


About the Author: For over 20 years, Dale Peterson has been on the leading/bleeding edge helping security conscious asset owners effectively and efficiently manage risk to their critical assets. He has pioneered numerous ICS security tools and techniques such as the first intrusion detection signatures for ICS that are now in every commercial product. In 2007, Dale created the S4 Events to showcase the best offensive and defensive work in ICS security and to build a community. S4 is now the largest and most advanced ICS event in the world. Dale is constantly pushing and prodding the ICS community to move faster and get better.

LinkedIn: https://www.linkedin.com/in/dale-peterson-s4/ 

Twitter: @digitalbond

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” IT/OT Convergence or IT/OT Integration?” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Critical Severity, TripWire

Continue Reading

Previous New Bill Could Force U.S. Businesses to Report Data Breaches Quicker
Next [eBook] A Guide to Stress-Free Cybersecurity for Lean IT Security Teams

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

10 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

12 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

13 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

15 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

17 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

20 hours ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT