Zoom out before you zoom in: why OT cyber security risk assessment should come first

Zoom out before you zoom in: why OT cyber security risk assessment should come first

By Valeriy Savinov, OT/ICS Cyber Security Sales Lead, ABB

Customers often come to us with a specific cyber security problem. "Can you help us protect this system?" they ask. It might be a system they want to protect, a vulnerability raised in an audit, or part of the network they are concerned about.

We can help with that individual issue, but it is usually worth looking at what sits around it as well. When only one part of the OT environment is protected, the overall risk remains unaddressed. This is why most organizations end up focusing on symptoms rather than addressing the root cause of their cyber risk. 

Why is OT cyber security difficult to address one system at a time? 

Industrial plants are rarely made up of one system, one supplier or even one generation of technology. A control system usually connects equipment from different vendors, with older and newer technologies connected through different networks, interfaces and protocols. While control systems play a central role in OT environment, they are not the only components. 

Consider a typical manufacturing facility: the main control system may connect with standalone PLCs, safety systems, data historians and analytics platforms, often from different vendors and different generations of technology. These are linked through networks, gateways and industrial communication protocols, creating dependencies that are not always immediately visible.  

That makes cyber security difficult to address in one system at a time. Industrial systems are interconnected, which means a weakness in one part of the operational technology (OT) environment can create risk elsewhere. Securing one component may reduce a particular exposure while another route remains open. This is where organizations can end up playing a game of whack-a-mole: one issue is fixed, another appears, and it becomes difficult to know whether the overall cyber security posture is actually improving. 

Why should a cyber security risk assessment come first?

A cyber security risk assessment provides a better starting point because it gives organizations visibility across the OT landscape, helps identify the risks with the greatest operational impact and supports a prioritized remediation plan. Repeated over time, it can also show whether risk is being reduced and whether security investment remains aligned with business and operational priorities.  

This wider view is becoming increasingly important as regulatory requirements evolve. NIS2, for example, requires organizations to establish policies for risk analysis and perform risk assessments on their systems.

Using a structured methodology based on recognized standards like ISA/IEC 62443 can also help organizations build a more robust cyber security program. 

How does a risk assessment help set priorities?

Not every vulnerability carries the same operational risk. Some vulnerabilities may be relatively easy to address but have limited operational impact. Others may sit in systems that are critical to production or safety and warrant attention sooner. Without that wider view, it's easy to spend time and budget on the problem that's most visible rather than the one that creates the most risk.

This is especially important in OT, where teams often have limited resources and where changes need to be made without disrupting operations. A cyber security risk assessment doesn't mean trying to solve every cyber security issue at once. Instead, it gives you a practical way to work through them in the right order, starting with the areas where action will have the greatest return.

In practice, this supports better investment decisions. Teams can direct budgets and resources towards the risks with the greatest potential operational impact, while tracking what has been addressed and what needs attention. 

So when a specific cyber security problem comes up, address it. But also take the time to understand how it fits into the entire OT environment. That wider view gives you a clearer basis for deciding what to address, and in what order. Before you zoom in on individual vulnerabilities, zoom out to see the complete picture.

Valeriy Savinov is OT/ICS Cyber Security Sales Lead at ABB. You can also read the accompanying piece, “Why OT cyber security needs its own roadmap, here

Links

Contact us

Downloads

Share this article

Facebook LinkedIn X WhatsApp