{"id":1337,"date":"2022-06-20T09:45:11","date_gmt":"2022-06-20T02:45:11","guid":{"rendered":"https:\/\/dt-corp.com.vn\/?p=1337"},"modified":"2022-06-20T09:45:11","modified_gmt":"2022-06-20T02:45:11","slug":"what-is-the-value-of-ot-cyber-risk-assessment","status":"publish","type":"post","link":"https:\/\/dt-corp.com.vn\/?p=1337","title":{"rendered":"What is the Value of OT Cyber-Risk Assessment?"},"content":{"rendered":"<section class=\"resource-inner-main bg-white\">\n<div class=\"grid\">\n<div class=\"row the-content\">\n<div class=\"two-third-div\">\n<p>The viability of any project or task is directly linked to the value it produces, i.e. if value exceeds costs, the project is worthwhile; otherwise, it\u2019s a losing proposition.<\/p>\n<p>Applying this simple model to cyber-security, and namely to OT-security, presents the problem: how do you determine the value of an OT-security system that successfully protects the industrial network? The costs of securing the OT network are known, but what are they measured against?<\/p>\n<p>One solution is to rely on industry and regional benchmarks: find out what equivalent companies (by industry, size, locale, etc.) had invested in, and replicate their system. While this crude method of planning (and obviously I\u2019m over-simplifying) leaves out many of the network and the company\u2019s unique characteristics \u2013 no two industrial networks face the same threats or employ the same devices \u2013 it allows you, with just the right amount of customization, to bring your OT security \u201cwithin the (very large) ballpark\u201d of your reference group\u2019s OT systems\u2019 value. Plus, in lieu of a better option, it\u2019s the best you got.<\/p>\n<section class=\"resource-inner-main bg-white\">\n<div class=\"grid\">\n<div class=\"row the-content\">\n<div class=\"two-third-div\">\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"third-div\">\n<div class=\"more-content\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2086\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/CIARA-dashboard-082321.jpeg\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/CIARA-dashboard-082321.jpeg 1024w, https:\/\/www.radiflow.com\/wp-content\/uploads\/CIARA-dashboard-082321-300x169.jpeg 300w, https:\/\/www.radiflow.com\/wp-content\/uploads\/CIARA-dashboard-082321-768x432.jpeg 768w\" alt=\"\" width=\"1024\" height=\"576\" \/><\/p>\n<p>Radiflow\u2019s CIARA industrial risk assessment and management platform enables OT organizations to maximize the value of their OT security by matching expenditure with the highest-value risk mitigation controls. The result is more and better OT security per dollar spent.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<p>In time, and as the field of OT security matured, better ways to calculate the value of OT security were developed. The\u00a0<a role=\"link\" href=\"https:\/\/www.arcweb.com\/\">ARC Advisory Group\u2019s<\/a>\u00a0formulation of the\u00a0<a role=\"link\" href=\"https:\/\/www.arcweb.com\/blog\/arcs-industrial-cybersecurity-maturity-model-evolves#:~:text=ARC%20Advisory%20Group%20released%20its,the%20coverage%20of%20supplier%20products.\">different stages of cyber-security maturity<\/a>\u00a0describes this evolution as transitioning from\u00a0<em>Vulnerability Management<\/em>\u00a0\u2013 installing passive defence systems that identify vulnerabilities in the OT network along with effective matching protections, to\u00a0<em>Threat Management<\/em>\u00a0\u2013 installing active defence mechanisms that react to the entire security environment, including threat agent capabilities, the user organization\u2019s security needs, per-business unit security, and more. (Much of the principles of Active Defence and its implementation as Risk Management are embedded into the\u00a0<a role=\"link\" href=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/WP-62443-compliance-051120-1.pdf\">IEC 62443 standard<\/a>, which in many ways represents the maturing of OT security).<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-4126\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/ARC-maturity-model.jpg\" sizes=\"(max-width: 427px) 100vw, 427px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/ARC-maturity-model.jpg 427w, https:\/\/www.radiflow.com\/wp-content\/uploads\/ARC-maturity-model-300x188.jpg 300w\" alt=\"\" width=\"600\" \/><\/p>\n<p>The ARC Advisory Group\u2019s model for OT security maturityThe introduction of\u00a0<a role=\"link\" href=\"https:\/\/www.radiflow.com\/white-papers-and-ebooks\/risk-assessment-management-for-industrial-organizations\/\">Risk Management<\/a>\u00a0as an overarching method of benchmarking, planning and monitoring the effectiveness (read: value) of the OT security system allows for a much higher level of optimization, meaning that you get the most security for every dollar spent.<\/p>\n<p>This is done by re-defining the role of the OT security system: from merely identifying vulnerabilities and installing protections that prevent them from materializing as cyber-attacks, to minimizing the impact \u2013 the damages to the organization and its people \u2013 of a successful cyber-attack.<\/p>\n<p>This is based on a number of underlying assumptions and guidelines:<\/p>\n<ol>\n<li>You can\u2019t and shouldn\u2019t try to protect your network against all known vulnerabilities. You need a method of prioritizing threats and prioritizing their (often costly) corresponding mitigation measures.<\/li>\n<li>There\u2019s no need to protect against an identified vulnerability if it had been deemed irrelevant to your industry and locale.<\/li>\n<li>If a successful (debilitating) cyber-attack on a specific business unit (or Zone, as defined in IEC 62443) is expected to cause little or no damage, there\u2019s no point of mitigating its underlying threat.<\/li>\n<li>How and what to protect depends in part on the user organization\u2019s preferences, including risk aversion, compliance status with various security standards, budget, etc.<\/li>\n<li>Due to the sheer volume of variables involved (see next section) it is impossible and counter-productive to \u201ceyeball\u201d OT risk. There\u2019s an absolute need for an objective, dedicated risk assessment platform.<\/li>\n<\/ol>\n<h2><strong>Model and inputs<\/strong><\/h2>\n<p>Given the above, a network\u2019s total risk can be formulated as the aggregate of the impact of a successful attack on each business unit, weighted by probability of each such attack materializing.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-medium wp-image-4125\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/risk-equation.jpg\" sizes=\"(max-width: 628px) 100vw, 628px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/risk-equation.jpg 628w, https:\/\/www.radiflow.com\/wp-content\/uploads\/risk-equation-300x73.jpg 300w\" alt=\"\" width=\"800\" \/><\/p>\n<p>This equation relies on multiple inputs, both intrinsic and extrinsic to the OT network:<\/p>\n<h3>Intrinsic values:<\/h3>\n<ul>\n<li>User organization\u2019s locale<\/li>\n<li>User organization\u2019s industry\/sector<\/li>\n<li>Device and vendor-specific vulnerabilities introduced by networked devices (e.g. PLCs, HMIs, etc.) Device-specific vulnerabilities are usually derived from\u00a0<a role=\"link\" href=\"https:\/\/en.wikipedia.org\/wiki\/Common_Vulnerabilities_and_Exposures\">CVEs (Common Vulnerabilities and Exposures)<\/a>\u00a0issued by research bodies such as the US\u00a0<a role=\"link\" href=\"https:\/\/en.wikipedia.org\/wiki\/National_Cyber_Security_Division\">National Cyber Security Division<\/a>of the US Department of Homeland Security<\/li>\n<li>Topology-related vulnerabilities caused by inter-zone lateral movement of threats, use of certain communication protocols, etc.<\/li>\n<li>Groupings of devices into business units\/zones that share the same security profile<\/li>\n<li>Impact of a debilitating attack on each business unit (calculated in collaboration with the network owner, accounting for financial, competitive, reputation and compliance damages)<\/li>\n<li>Mitigation measures already installed<\/li>\n<\/ul>\n<h3>Extrinsic values<\/h3>\n<ul>\n<li>Attacker capabilities for known threats relevant to the specific OT network (derived from Threat Intelligence sources such as\u00a0<a role=\"link\" href=\"https:\/\/attack.mitre.org\/\">MITRE ATT&amp;CK<\/a>)<\/li>\n<li>Modeling of mitigation measures\u2019 effectiveness<\/li>\n<li>Changes to attackers\u2019 assumed motivation to attack (e.g. heightened risk of state-sponsored attacks as a result of international conflicts)<\/li>\n<\/ul>\n<p>Given these multiple, vast datasets, there\u2019s an obvious need for a methodological risk management process that\u2019s able to produce actionable decision-making information for CISOs and other business stakeholders (CRO, OT manager) responsible for business continuity. This includes key indicators, comprehensive security reports, and a highly optimized OT security roadmap that mitigates the most risk per dollar spent.<\/p>\n<p><strong>The added value of risk assessment (using Radiflow CIARA)<\/strong><\/p>\n<p><a role=\"link\" href=\"https:\/\/www.radiflow.com\/products\/ot-risk-managment\/\">Radiflow\u2019s CIARA<\/a>\u00a0is the first-of-its-kind automated, fully-IEC 62443 compliant risk assessment and management platform for industrial networks.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-medium wp-image-1327\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Product-page-Screens_CIARA-uses-geo-location.png\" sizes=\"(max-width: 882px) 100vw, 882px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Product-page-Screens_CIARA-uses-geo-location.png 882w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Product-page-Screens_CIARA-uses-geo-location-300x235.png 300w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Product-page-Screens_CIARA-uses-geo-location-768x602.png 768w\" alt=\"\" width=\"600\" \/><\/p>\n<p>To assess the risk posture of an OT network, CIARA uses a self-learned, non-destructive digital image of the OT network, rather than running analyses on the OT network itself, to ensure that no damage is done to the network. This is made possible thanks to the complete accuracy of the Radiflow-generated digital image of the OT network and the slow rate of changes to the network, so that a days-old digital image can still be used for analysis.<\/p>\n<p><a role=\"link\" href=\"https:\/\/www.radiflow.com\/white-papers-and-ebooks\/breach-attack-simulations-bas-in-ot-environments\/\">CIARA\u2019s breach-and-attack (OT-BAS) simulation engine<\/a>\u00a0uses the thousands of data points listed above for numerous breach and attack iterations on each and every business process and Zone, to prioritize the most impactful threats \u2013 not necessarily those with a higher probability of materializing \u2013 and prioritize the corresponding mitigation controls for these threats. Network owners are able to further customize CIARA\u2019s mitigation plans by accounting for available security budgets over time (by quarter) and by setting additional criteria, such as preference to beef up security for high-risk zones at the expense of low-risk zones, ensuring compliance as high priority, etc.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-medium wp-image-2089\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows.jpg\" sizes=\"(max-width: 1933px) 100vw, 1933px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows.jpg 1933w, https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows-300x113.jpg 300w, https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows-1024x386.jpg 1024w, https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows-768x290.jpg 768w, https:\/\/www.radiflow.com\/wp-content\/uploads\/ciara-process-diagram-ZCR-1-5-arrows-1536x579.jpg 1536w\" alt=\"\" width=\"600\" \/><\/p>\n<p>At the same time CIARA provides network owners with high-level key risk indexes for monitoring changes in risk posture. This include overall risk level, overall threat level (subject to detection of new threats and changes in attackers\u2019 motivation) and control level, for completion of prescribed mitigation measures. Alongside these KPIs CIARA provides a host of customizable security reports used for threat mitigation and budgeting.<\/p>\n<p>It\u2019s clear to see that any project of setting up a new OT security system or improving an existing one could benefit from, and should start with a thorough risk assessment. Beyond producing a highly-optimized security plan, custom-tailored to minimize the impact of cyber-incidents by prioritizing the threats and mitigation measures most relevant to the OT network, regularly assessing and monitoring the changes in network risk allows tweaking mitigation plans based on new developments, and allows for better understanding of the organization\u2019s threat environment by both technical personnel and decision makers.<\/p>\n<p>We welcome you to schedule a personalized live demo of CIARA and of Radiflow\u2019s entire OT security suite.<\/p>\n<p>Source: <a href=\"https:\/\/www.radiflow.com\/blog\/what-is-the-value-of-ot-cyber-risk-assessment\/\">Radiflow team<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p class=\"tx-excerpt\">The viability of any project or task is directly linked to the value it produces, i.e. if value exceeds costs, the project is worthwhile; otherwise, it\u2019s a losing proposition. Applying this simple model","protected":false},"author":3,"featured_media":1338,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-1337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/dt-corp.com.vn\/wp-content\/uploads\/2022\/06\/value-risk-blog.jpg","_links":{"self":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1337"}],"version-history":[{"count":1,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1337\/revisions"}],"predecessor-version":[{"id":1339,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1337\/revisions\/1339"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/media\/1338"}],"wp:attachment":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}