Critical industrial operations during a pandemic

Those tasked with securing OT environments must understand the extended threat landscape to keep things running smoothly, explains Maher Jadallah, Regional Director – Middle East at Tenable.

The current unprecedented public health crisis has impacted nearly all populated nations. Governments all over the globe have mandated citizens to stay at home, working remotely where possible in an effort to curb the spread of infection. However, when it comes to our essential services and critical infrastructure, these large-scale industrial and production plants face the unenviable challenge of maintaining uptime and efficient production, irrespective of external factors.

Automation within industrial environments is now commonplace, due largely to the convergence of the data side of the business (traditionally the realm of IT) and the operational technology (OT) side (used to manage industrial control systems (ICS)). However, the more OT environments are integrated and connected to IT systems, the more closely both sides need to be managed. A security incident on either side — IT or OT — can compromise both systems and, if left unchecked, could impact production or even change a product significantly enough to make it dangerous.

The frequency and severity of attacks specifically targeting OT networks has been increasing each year. Clearly, there is a need to secure OT networks as we have in IT.

It’s imperative that those tasked with securing critical operations in these challenging times fully understand the new threat landscape, and particularly which security measures are needed to keep things running smoothly and safely. Here are some areas to consider and address:

OT vulnerabilities: With the number of malware threats to industrial systems on the rise, further extending the vulnerable attack surface in an OT environment, production and operational managers need to ensure they are aware of the threats faced. A further consideration is the risk of lateral movement, where an attacker gains a foothold in one infrastructure and then traverses across to the other – from OT to IT and vice versa. Organizations must pay attention to keep OT networks secure, as has been practiced in IT environments for years.

Errors and delays: A skilled or managerial worker should be onsite at all times in case of an unplanned, or emergency, situation. The reason for this is that there is greater risk of an error being overlooked, or negative knock-on caused by configuration changes, if someone unfamiliar with these complex environments alters settings. Automatic snapshots of the initial and changed state, or an automated trail of the configuration resets, must accompany any actions taken to rectify a situation. This will allow the changes to be reversed if required. It should also capture the identity of the personnel initiating the action, and the date and time stamp of the incident, to verify it was correctly authorised.

Another fallout could be a delay in responding to an alarm, triggering a chain of events with unknown consequences. Given OT / IT convergence, any delays and/or errors could impact either side.

Monitor for dubious activity: Following on from the points above, it’s also important to check for any unexpected changes that could be an indicator of compromise, or an active attack, at both the network, and device level.

Planned remediation: With remote working policies activated, the team responsible for remediation must be identified so they are ready to respond, should an alarm be triggered. This could be based on proximity, skill levels, planned escalation, and so on. The channel for alerts also needs to be worked out beforehand, whether it is SMS, phone, email or others.

Dashboard monitoring: All networks, devices, systems, and plants need to fall back into an integrated dashboard that allows full-scale monitoring of behavior. In case of alerts on the dashboard, the team can isolate the fault or intrusion and deep dive at a granular level to identify the nature of the compromise or threat.

We’re living through unprecedented times and the pandemic can create any number of challenging macro environment situations. But, at the end of the day, critical businesses must continue, operations must deliver, and the fabric of a nation must survive.

A deep macro and micro level understanding of how the operations are managed will provide the most sustainable solution to surviving to avoid security making the situation worse.

 

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

FLIR - security buyer

New FLIR camera for Perimeter Security

FLIR, a Teledyne Technologies company, today released its newest high-resolution visible/thermal security camera for commercial..
Contacta - Security Buyer

Contacta launches Level 8 ballistically-resistant window intercom

Assistive listening specialist, Contacta, has launched the world’s first window intercom system with a Level 8 UL752 approval.
Big Interview Abdullah Tanoli

Big Interview – Hero of Leicester Square

Rebecca Spayne of Security Buyer has the privilege of speaking with a real-life hero, Abdullah Tanoli, the hero of Leicester Square..
SentinelOne & AWS - Security Buyer

SentinelOne Teams with AWS to bring Cloud Security Protection

SentinelOne announced that it is a launch partner for the new AWS Security Hub. The new collaboration builds on a long standing..
Genetec - Security Buyer

Genetec and Hanwha Vision

The latest in our ongoing series introducing Hanwha Vision’s pioneering partners, leads us to Ben Durrant, Account Executive at Genetec Inc.
Altronix - Security Buyer

Altronix POE367 Delivers 277VAC Support

Altronix has expanded its power product line with the new POE367 power supply/charger designed specifically for 277VAC input environments.
IFPO x GSA - Security Buyer

New Corporate Members for IFPO

The Global SecurAlliance (GSA)summer meeting on 16 June was held again at the stunning Château de Méry-sur-Oise on the outskirts of Paris.
SB Awards register now advert - Security Buyer

Launching Security Buyer Awards

Honouring innovation, leadership, and success across the global security industry at the Security Buyer Judges’ and Readers’ Awards 2025 
Product Spotlight - HID

Product Spotlight – HID

Access control is evolving into a smart, responsive platform—integrating embedded apps, IoT, and cybersecurity to deliver…
Genetec

Genetec brings new capabilities to Security Center SaaS

Genetec announced new updates to Security Center SaaS, the company’s enterprise-grade Security-as-a-Service (SaaS) solution..
Scroll to Top