{"id":29012,"date":"2019-09-18T11:03:45","date_gmt":"2019-09-18T10:03:45","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=29012"},"modified":"2019-09-20T11:11:21","modified_gmt":"2019-09-20T10:11:21","slug":"making-a-case-for-ot-cybersecurity-investment-how-to-present-to-the-board","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/09\/18\/making-a-case-for-ot-cybersecurity-investment-how-to-present-to-the-board\/","title":{"rendered":"Making a case for OT cybersecurity investment: How to present to the board"},"content":{"rendered":"\n<p>Operational Technology (OT) is at a growing\nrisk of cyberattack, bringing with it the danger of far-reaching and costly\nimpacts. But OT in most traditional heavy industries and infrastructure\nfacilities have been run in silos behind \u2018air gaps\u2019 for so long that the Board\nassumes they are safe from attack. <\/p>\n\n\n\n<p>\u201cTraditional approaches are no\nlonger enough to secure heavy industry and infrastructure from cyberattacks,\u201d said\nMike Bergen of GECI International, which specialises in advanced cybersecurity\nsolutions for both administrative (IT) and industrial environments.<\/p>\n\n\n\n<p>\u201cThe traditional \u2018air gap\u2019 between\nIT and OT is closing amid new business requirements associated with\ndigitalisation, and this is increasing the potential attack surface and hence\nthe cyber risk.<\/p>\n\n\n\n<p>\u201cWe see a growing trend for ransomware\nand crippling attacks launched against key systems that keep infrastructure and\nsocieties functioning worldwide.\u201d<\/p>\n\n\n\n<p>But motivating for additional spend\non top of existing, traditional cybersecurity budgets can be challenging.<\/p>\n\n\n\n<p>Bergen recommends outlining the\nsignificant risks the organisation could face in the event of an attack,\nincluding costly production outages leading to financial losses, catastrophic\nsafety failures and environmental damage leading to potential liability issues,\nor theft of corporate IP resulting in a loss of competitive advantage.<\/p>\n\n\n\n<p>GECI partner CyberX notes that the\ndiscussion with the Board around OT security should be framed as a strategic\none, rather than a technology issue. Key factors to be considered are risk\nmanagement and regulatory and compliance requirements \u2013 particularly in those\norganisations providing essential services such as energy, water, health care,\nbanking and financial services and digital infrastructure.<\/p>\n\n\n\n<p>Key metrics on system maturity and\nrisk should be presented to the Board in an unambiguous, comprehensive and\nunderstandable way. These metrics should be directly linked to enterprise goals\nand strategies and clearly measure the consequences of alternatives.\nImportantly, potential financial losses should be modelled to present a\nfinancially based position statement on the importance of securing industrial\nand OT assets.<\/p>\n\n\n\n<p>CyberX advises presenting to the\nBoard with a focus on facts, risks, the future, and actionable plans; including\na mapping of the current cybersecurity framework to an accepted maturity model.\nThe Board should also be alerted to any known threats and the potential\nbusiness risk of each.<\/p>\n\n\n\n<p>\u201cThousands of attacks are getting through even the best organisational defences,\u201d said Bergen.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"682\" height=\"1024\" src=\"https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/09\/Mike-Bergen-682x1024.jpg\" alt=\"\" class=\"wp-image-29014\" srcset=\"https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/09\/Mike-Bergen-682x1024.jpg 682w, https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/09\/Mike-Bergen-200x300.jpg 200w, https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/09\/Mike-Bergen.jpg 685w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><figcaption>Mike Bergen, from GECI International<\/figcaption><\/figure>\n\n\n\n<p>\u201cThe South African Banking Risk\nInformation Centre (SABRIC) states that South Africa has the third-highest\nnumber of cybercrime victims worldwide, losing about R2.2 billion a year to\ncyberattacks. &nbsp;<\/p>\n\n\n\n<p>\u201cIn the U.S. for example, 53 cities\nwere hit last year by ransomware attacks, usually demanding hundreds of\nthousands of dollars to reinstate the victim\u2019s systems. <\/p>\n\n\n\n<p>\u201cIn the first six months of this\nyear, 25 to 30 more U.S. cities were attacked, and in August, 23 cities in\nTexas alone were hit by ransomware. Dozens of large and small companies\nworldwide have also suffered costly attacks recently. In this country, a\nmuch-publicised attack on Johannesburg\u2019s City Power was met with shock,\nparticularly by electricity clients in that city. <\/p>\n\n\n\n<p>\u201cMore than a month after the attack,\nthey are still dealing with the damage caused. But that is just the beginning.\nSouth Africa is a wide-open cybersecurity target market. And as the doors close\nfor cybercriminals overseas, they will be heading to our shores. <\/p>\n\n\n\n<p>\u201cIt\u2019s no longer a matter of \u2018if\u2019,\nbut \u2018when\u2019 you will be attacked.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Operational Technology (OT) is at a growing risk of cyberattack, bringing with it the danger of far-reaching and costly impacts. But OT in most traditional heavy industries and infrastructure facilities have been run in silos behind \u2018air gaps\u2019 for so long that the Board assumes they are safe from attack. \u201cTraditional approaches are no longer [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":29013,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,134,5,136,275,19,9059,13,262],"tags":[7720,1696,387,9645,11073,745,9648,9352,9353,10902,453,11074],"class_list":["post-29012","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-blog","category-enterprise-security","category-industry-expert","category-intelligent-technology-newsletter","category-regional-news","category-south-africa","category-top-stories","category-used","tag-city-power","tag-cyber-risk","tag-cyberattack","tag-cyberx","tag-geci-international","tag-johannesburg","tag-mike-bergen","tag-operational-technology","tag-ot","tag-sabric","tag-south-africa","tag-south-african-banking-risk-information-centre"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=29012"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29012\/revisions"}],"predecessor-version":[{"id":29086,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29012\/revisions\/29086"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/29013"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=29012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=29012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=29012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}