AhnLab
Understanding Operational Technology Security
Pages
19
Time to read
30 mins
Publication
Language
English
Pages
19
Time to read
30 mins
Publication
Language
English
This white paper provides a detailed analysis of operational technology (OT) security, focusing on its definition and the essential differences between OT and information technology (IT) security. The document outlines the unique aspects of OT security, emphasizing the priority of availability over confidentiality. It describes the types of devices found in IT and OT environments and discusses the increasing security risks as digitalization interconnects these environments. The paper also presents various security breach cases, illustrating the vulnerabilities in OT systems, particularly in the manufacturing sector. Through specific examples like the WannaCry ransomware incident and the hacking of a water treatment facility, the paper explains the methods used to infiltrate OT networks. Additionally, it outlines potential attack pathways, including IT network breaches, direct access through third parties, and supply chain vulnerabilities. The document concludes with a discussion on establishing effective OT security frameworks, referencing the Purdue Model as a guideline for understanding OT architecture.