TECH & AI from the comfort of their sofa, using the IT equipment to which the OT has been connected. These often decadesold systems aren’ t designed for these environments, they lack“ secure by design” thinking and they often don’ t have segmentation or risk controls.
On top of all that, there’ s a fundamental mismatch in risk and cybersecurity understanding between the physical OT engineers and IT workers on the one hand, and the cybersecurity SMEs on the other. When something digital fails, the engineers on the ground often don’ t know how to fix it themselves, while your typical IT support team would fail to fully grasp the context of the risk – which can create immediate problems or even a threat to life( not a common problem in IT).
Q. WHY ARE ENERGY AND UTILITIES FIRMS PARTICULARLY VULNERABLE RIGHT NOW?
» They’ re dealing with risks they simply haven’ t had to manage before and, in many cases, they don’ t yet have the in-house capability to respond quickly. At the same time, boards are rarely security specialists. Traditional security assessments might flag where controls are missing, but they don’ t always surface the risks that really matter.
energydigital. com 79