September 27, 2021 By David Bisson 2 min read

Digital security incidents involving operational technology (OT) can have big impacts on the physical world. Why are these OT security incidents happening? A lack of understanding of how the different elements of DevSecOps fit together can contribute. This also shows the importance of crossover between engineering and cybersecurity.

In March 2021, for instance, Fortinet found over 90% of organizations with OT assets admitted to having suffered at least one security incident in the past year. 12% said that their employers had faced a minimum of 10 incidents in that period. Those events disrupted work for more than half of respondents, the study found. Meanwhile, public safety became an issue in 45% of cases.

Facing IT-OT Challenges with DevSecOps

One problem facing OT security is the convergence of industrial environments with information technology (IT) assets. Both IT and OT suffer from similar types of security threats in some respects. Unwanted access, password reuse, malware attacks and other problems can hit both. But the two often have conflicting needs due to the nature of their business. OT sees availability as a means of preventing physical danger and ensuring public safety. Meanwhile, IT puts secrecy first in the ongoing fight against data breaches.

IT and OT don’t always know where their counterparts stand. Nor do they have a reference point to start to understand each other. This lack of teamwork complicates the task of extending security across both. In response, attackers might exploit a lack of integration and/or visibility between IT and OT. By targeting assets in one, they can pivot to the other. For example, threat actors can use IT security weaknesses to disrupt industrial control systems, make changes to OT assets and/or interfere with safety equipment. So, where does DevSecOps come in?

Cybersecurity Education for Engineers Matters to DevSecOps

So, how do you defend against OT attacks and account for the challenges of the ongoing IT-OT convergence? One way is to focus on providing engineers with cybersecurity education. Getting engineers involved in development helps further secure the DevSecOps collaborative system.

Critical infrastructure organizations need engineers more than others. After all, engineers operate on the front lines. These personnel help design, implement and maintain industrial environments. They’re in a position to help those environments evolve with and stay safe amid the IT-OT convergence. But, in order to do so, they need to understand the threats confronting them.

More on cybersecurity training

How to Provide Cybersecurity Education to Engineers

When it comes time to provide engineers with cybersecurity education, it’s important not to approach their security awareness training the same way as you would with non-tech employees on the IT side. A one-size-fits-all approach will not work. Those two groups confront different threats on a daily basis, after all. Learning about problems that don’t pertain to their jobs will waste their time or even make them more complacent.

Knowing that, cultivate engineers’ awareness of threats that are relevant to them. Use training modules in tandem with threat intelligence to emphasize new attack campaigns confronting critical infrastructure, for instance. In addition, conduct tests that highlight secure OT system design as those principles evolve with the changing threat landscape. This way, your engineers will find their own place in the DevSecOps framework.

More from Risk Management

How will the Merck settlement affect the insurance industry?

3 min read - A major shift in how cyber insurance works started with an attack on the pharmaceutical giant Merck. Or did it start somewhere else?In June 2017, the NotPetya incident hit some 40,000 Merck computers, destroying data and forcing a months-long recovery process. The attack affected thousands of multinational companies, including Mondelēz and Maersk. In total, the malware caused roughly $10 billion in damage.NotPetya malware exploited two Windows vulnerabilities: EternalBlue, a digital skeleton key leaked from the NSA, and Mimikatz, an exploit…

ICS CERT predictions for 2024: What you need to know

4 min read - As we work through the first quarter of 2024, various sectors are continuously adapting to increasingly complex cybersecurity threats. Sectors like healthcare, finance, energy and transportation are all regularly widening their digital infrastructure, resulting in larger attack surfaces and greater risk exposure.Kaspersky just released their ICS CERT Predictions for this year, outlining the key cybersecurity challenges industrial enterprises will face in the year ahead. The forecasts emphasize the persistent nature of ransomware threats, the increasing prevalence of cosmopolitical hacktivism, insights…

How I got started: Ransomware negotiator

4 min read - Specialized roles in cybersecurity are proliferating, which isn’t surprising given the evolving threat landscape and the devastating impact of ransomware on many businesses.Among these roles, ransomware negotiators are becoming more and more crucial. These negotiators operate on the front lines of cyber defense, engaging directly with cyber criminals to mitigate the impact of ransomware attacks on organizations.Ransomware negotiators possess a unique blend of technical expertise, psychological insight and negotiation skills that allow them to navigate the high-stakes environment of ransomware…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today