Protect

From CyberWiki
Jump to navigation Jump to search

Protection Overview

Protection is a cyber security focus area that addresses technology, methods, and best practices for protecting generation OT networks and digital equipment against cyber-attacks (e.g., hardening, encryption, identity and access management, etc.). The objective of protection is to prevent an attacker from gaining access or minimize the chance that it occurs. This includes identity and access management, data security, platform security, and the resiliency of the architecture and assets. Protective measures like hardening may also be implemented with existing tools.

Key protection topics include:

  • Security Architectures and Segmentation
  • Vulnerability Management
  • Hardening
  • Secure Remote Access
  • Transient Cyber Assets and Removable Media
  • Identity and Access Management

Segmentation and Security Architectures

Vulnerability and Patch Management

Vulnerability Management is an ongoing process of identifying, assessing and addressing security vulnerabilities. It involves the systematic discovery, assessment and remediation of vulnerabilities to reduce the risk of cyber attacks and data breaches.

Challenges with vulnerability and patch management in power generation facilities include:

  • Many companies utilize a manual process of identifying, prioritizing, and remediating vulnerabilities in OT systems. This process is time-consuming and error-prone.
  • Companies implement automated vulnerability scanning tools and threat intelligence feeds – prioritizing vulnerabilities based on their potential impact on operations. These tools typically require manual effort to review and disposition OT impact.
  • Dependencies on third parties can introduce delays in the process of vulnerability remediation. Vendors validating the patches before the release can leave systems exposed for longer durations. To overcome this, a streamlined process should be established for validating and deploying the patches promptly.
  • Vulnerability advisories are not entirely accurate. In 2022 approximately 34% of vulnerabilities were found to be inaccurate. (Source: Dragos)
  • Adversaries interested in attacking old and unpatched vulnerabilities – The most exploited vulnerability of 2022 (Product - FortiOS and FortiProxy) was discovered in 2018

Current vulnerability and patch management key practices include continuous monitoring, automated patch deployment, and vendor patch support and outsourcing:

  • Continuous Monitoring. Deploying automated tools to assess and monitor. Proper configuration and management of data should be done to avoid a significant backlog of data and alerts.
  • Automated Patch Deployment. Cautiously deploy automated tools using test environments, change management, and rollback plans to avoid accidentally disrupting operations.
  • Vendor Support. Collaborate with vendors/suppliers to test and deploy patches promptly.

Relevant EPRI Resources

Hardening

Hardening is the process of securing systems and devices by reducing their attack surface and minimizing vulnerabilities. It involves configuring OT components with security best practices like limiting unnecessary access, disabling the ports and services not in use, and implementing strong authentication controls and encryption.

Hardening.png

Challenges with hardening in power generation facilities include:

  • Diverse & Legacy Systems makes it difficult to apply uniform hardening measures
    • Comprehensive asset inventory, prioritizing critical assets and gradually replacing legacy devices
  • Customized devices are not designed to handle traditional security configurations and can be too resource-intensive
  • Lightweight and critical controls should be implemented first.

Current hardening key practices include vendor hardening, company-specific baselines, and asset configuration management:

  • Hardening is often performed during installation. Vendors typically have security hardening standards and images that are followed.
  • Address regulatory requirements, industry standards, and company-specific baselines.
  • Documentation asset configurations in conjunction with hardening.

Relevant EPRI Resources

Secure Remote Access

Secure Remote Access (SRA) enables authorized personnel, vendors, and support organizations to securely access cyber assets from external networks for monitoring, administration, troubleshooting, and maintenance activities. SRA capabilities help reduce cybersecurity risk by controlling access paths into operational technology (OT) environments through authentication, authorization, encryption, monitoring, and session management. Remote access solutions are commonly used to support geographically dispersed facilities, specialized vendor support, and operational continuity while maintaining security controls.

Secure Remote Access Current Practices and Challenges in energy power generation:

  • Remote access is commonly provided through virtual private networks (VPNs), jump hosts, terminal services, and vendor-managed remote access platforms.
  • Multifactor authentication is increasingly used for remote access connections but may be limited by legacy systems, vendor capabilities, or operational constraints.
  • Utilities and generation operators often rely on dedicated intermediary networks or demilitarized zones (DMZs) to separate external connections from critical OT environments.
  • Third-party and vendor remote access remains a significant cybersecurity concern due to expanding operational support requirements and software supply chain dependencies.
  • Organizations continue to improve monitoring, logging, and approval processes to provide greater visibility into remote access activities and privileged sessions.
  • Cloud-connected assets, distributed energy resources, and remote operations increase the need for secure, scalable, and centralized access management capabilities.

Relevant EPRI and Industry Resources

Transient Cyber Assets and Removeable Media

Transient Cyber Assets (TCAs) and Removable Media (RM) are commonly used to support maintenance, software updates, diagnostics, data collection, and vendor support activities in operational technology (OT) environments. While these technologies provide operational benefits, they can introduce malware, unauthorized software, and other cybersecurity risks if not properly managed. Effective controls focus on reducing the risk associated with temporary device connections and the transfer of files into or out of critical environments.

Transient Cyber Assets and Removable Media Current Practices and Challenges in energy power generation:

  • TCAs and RM can bypass traditional network-based security controls and introduce risk to air-gapped or segmented OT environments.
  • Organizations commonly implement malware scanning, device inventories, media approval processes, and usage restrictions before connecting assets to OT environments.
  • Managing third-party devices remains challenging because organizations may have limited visibility into device configuration, patching status, and cybersecurity posture.
  • Air-gapped and isolated control system environments often require removable media for operational activities, creating an ongoing balance between operational needs and cybersecurity risk.
  • Some legacy OT assets depend on dedicated maintenance laptops running outdated software, limiting an organization's ability to apply security updates and standard endpoint protections.

Relevant EPRI and Industry Resources

Identity and Access Management

Identity and access management (IAM or IdAM) cyber security controls for authentication, authorization, and auditing only allow access when and where required to perform required operations. This includes verifying that the user is who they say they are. Identity and access management restricts unnecessary access and provides proper authentication and authorization methods for operation and maintenance.

IAM Capabilities, per EPRI Identity and Access Management Guideline

IAM Current Practices and Challenges in energy power generation:

  • Control systems utilize traditional methods such as Active Directory and local passwords. Multifactor authentication is implemented in some cases through IT/OT use cases, such as remote access through IT infrastructure.
  • Regulatory requirements for remote access users rely on coordinating notifications when roles change.
  • Password may eventually obsolete as passkeys and other forms of authentication seem to provide more security in verifying a human and/or device identity in a system.
  • The incorporation of cloud computing and digitalized assets, such as IoT devices and mobile devices, increases the need for more protection around understanding who a person is or what a device is and whether should it have access to perform a task. There has been an increase in phishing attacks leading to a greater need for protection beyond passwords.

Relevant EPRI and Industry Resources