{"id":116095,"date":"2024-09-23T13:00:45","date_gmt":"2024-09-23T12:00:45","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=116095"},"modified":"2024-10-07T11:34:08","modified_gmt":"2024-10-07T10:34:08","slug":"west-burton-energy-enhances-ot-security-with-tenable","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2024\/09\/23\/west-burton-energy-enhances-ot-security-with-tenable\/","title":{"rendered":"West Burton Energy enhances OT security with Tenable"},"content":{"rendered":"\n<p><strong><em>UK-based West Burton Energy reduces threat-detection alerts by 98% and improves efficiency by 87% using Tenable OT Security.<\/em><\/strong><\/p>\n\n\n\n<p>In 2022, nearly 11% of\u00a0cyberattacks targeted energy companies, so for power plants, healthy OT systems are crucial for high uptime and safety, as they control and monitor essential equipment, such as generators, turbines and transformers.<\/p>\n\n\n\n<p>As an important part of the UK\u2019s critical infrastructure,\u00a0West Burton Energy\u00a0takes a proactive approach to secure its OT network and assets. The InfoSec team uses\u00a0Tenable OT Security\u00a0for in-depth asset visibility, asset inventory and OT vulnerability management to ensure the safety of its employees, while guaranteeing reliable energy generation and delivery to its customers.<\/p>\n\n\n\n<p>West Burton has reduced the time and resources needed to manually manage their asset inventory, saving more than 200 hours per year. Additionally, they were able to create efficiencies in identifying, mitigating and remediating OT vulnerabilities.<\/p>\n\n\n\n<p>Proper OT security\u00a0requires a proactive approach to asset and network safety in order to stop cyberattacks before they start. West Burton chose Tenable OT Security for OT asset visibility, OT vulnerability management and threat detection \u2013 a set of use cases that have proven challenging for so many companies in the power industry.<\/p>\n\n\n\n<p>West Burton has reduced the number of threat detection alerts by more than 98% compared to their previous solution \u2013 a time savings of more than 87%. Rather than chasing false positives, the team can focus on remediating the security alerts that put operations at the greatest risk.<\/p>\n\n\n\n<p>\u201cWe are a critical infrastructure organisation, so although our InfoSec team is relatively small, we have to minimise risk and harden our cyber-resilience,\u201d said Tom Keyworth, C&amp;I Engineer. \u201cTenable OT Security gives us comprehensive visibility without burdening us with labour-intensive workloads.\u201d<\/p>\n\n\n\n<p><strong>Error-prone processes had InfoSec team looking for a better way<\/strong><\/p>\n\n\n\n<p>Keeping the lights on in the UK, West Burton Energy is an advanced and efficient Combined Cycle Gas Turbine (CCGT) plant and 49 MW battery energy storage facility that delivers 1,333 MW of power to the National Grid; enough electricity to power 1.5 million homes and businesses.<\/p>\n\n\n\n<p>In 2021, West Burton spun off from EDF Energy resulting in a three-member security team responsible for securing their entire OT environment with a product alerting on far too many false positive threat notifications. They had to handle engineering changes in the OT environment, new projects and the decommissioning of older systems, leaving the team with a significant workload.<\/p>\n\n\n\n<p>Dealing with original equipment manufacturers (OEMs) was especially painful. The InfoSec team relied on the knowledge of the plant engineers and various OEMs to keep track of assets, which involved a laborious, error-prone and spreadsheet-driven process.<\/p>\n\n\n\n<p>\u201cBetween waiting on OEMs to perform preventative maintenance and patches, and with status reports lagging by days or even weeks, we spent several hours per week just managing asset lists,\u201d notes Keyworth.<\/p>\n\n\n\n<p>\u201cWe relied on the OEM issuing technical advice letters and alerts to make us aware of CVEs that might be relevant to a specific asset,\u201d adds James Cartwright, C&amp;I Engineer. \u201cIt wasn\u2019t unusual for us to spend several hours investigating the issue only to discover that we didn\u2019t even have the equipment in question.\u201d<\/p>\n\n\n\n<p>Keeping the front office informed about the OT vulnerabilities, and remediation statuses and overall cyber-risk is also paramount, but it wasn&#8217;t always easy to deliver in a way that was both timely and user friendly in the past.<\/p>\n\n\n\n<p>\u201cWe struggled to safely and securely move data from the OT environment and display it to corporate IT users in a way that makes sense,\u201d said Cartwright.<\/p>\n\n\n\n<p>To overcome these challenges and bolster its cyber-resilience, West Burton wanted to check several important boxes, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Visibility of OT assets on the OT network without impacting uptime and availability<\/li>\n\n\n\n<li>A centralised asset inventory to move away from a time-consuming manual process, without disrupting the operation of modern and legacy systems<\/li>\n\n\n\n<li>Ability to demonstrate compliance to regulators with confidence<\/li>\n\n\n\n<li>Clear remediation and mitigation strategies to adhere to the company\u2019s acceptable level of risk<\/li>\n\n\n\n<li>Using the most up-to-date OT vulnerability database to reduce false positives<\/li>\n<\/ul>\n\n\n\n<p>That\u2019s when Keyworth and the team set out to find a new solution to secure its OT environment and ensure leadership had a complete understanding of the plant\u2019s complexity and associated risks.<\/p>\n\n\n\n<p><strong>Tenable OT Security \u2013 purpose built to safeguard converged IT\/OT industrial environments without disrupting productivity<\/strong><\/p>\n\n\n\n<p>Tenable OT Security\u00a0brings visibility, security and control to industrial environments, critical infrastructure and more, helping organisations maintain productivity, meet compliance requirements and stay safe from cyberattacks.<\/p>\n\n\n\n<p>Using a patented hybrid discovery approach to safely gain visibility into devices and cyber-physical systems without causing disruption, Tenable OT Security delivers a complete asset inventory along with deep situational awareness across all global sites, all in a single interface.<\/p>\n\n\n\n<p>Tenable OT Security lets organisations prioritise action and enables their IT and OT security teams to work better together.<\/p>\n\n\n\n<p><strong>Plant team manages remediations and delivers actionable data to front office<\/strong><\/p>\n\n\n\n<p>Tenable OT Security was initially deployed in 2022, providing Keyworth and Cartwright with complete visibility and control over the West Burton B\u2019s operations, which includes countless assets which may or may not be supported by the many OEMs charged with maintaining the plant\u2019s equipment.<\/p>\n\n\n\n<p>\u201cWe use Tenable OT Security to identify vulnerabilities and maintain a complete asset list, sometimes surfacing issues that our OEMs either don\u2019t know exist or no longer support,\u201d said Keyworth. \u201cThen as part of our workflow we import everything into Tenable Security Center for scoring, prioritisation and to track how we are reducing vulnerabilities asset by asset as we remediate.\u201d<\/p>\n\n\n\n<p>When facing a situation where a vulnerability simply can\u2019t be remediated, such as on a piece of legacy OT equipment that is no longer supported, the team uses Tenable to assess the acceptable level of risk. The team can then implement measures to prevent access to those systems and keep leadership informed.<\/p>\n\n\n\n<p>\u201cWith Tenable OT Security, the data is visible on the wall,\u201d said Cartwright. \u201cVulnerabilities are fed into an alerting system, and if we install a new device the asset list is updated in an automated way.\u201d<\/p>\n\n\n\n<p>\u201cThe front office has the data they want, they understand where it came from, and more importantly, they know what it means,\u201d added Keyworth.<\/p>\n\n\n\n<p><strong>InfoSec team optimises OT Security, saves time and streamlines compliance<\/strong><\/p>\n\n\n\n<p>Most organisations view any opportunity to increase efficiency as a win, but for a small team spread thin, process and time-savings improvements mean even more. Today, West Burton actually spends more time on vulnerability management than ever before. And that\u2019s a good thing.<\/p>\n\n\n\n<p>Prior to implementing Tenable, the InfoSec team didn&#8217;t have a complete picture of what was vulnerable, often waiting months for an OEM to issue technical advice letters and alerts to make the team aware of CVEs that might be relevant to a specific asset. What\u2019s more, it wasn\u2019t unusual for the team to spend hours investigating an issue only to discover that they didn\u2019t even have the equipment in question.<\/p>\n\n\n\n<p>\u201cUsing Tenable OT Security we can identify vulnerabilities early in the process, review the published CVE documentation and implement remediation and security restrictions without waiting for the OEMs,\u201d said Keyworth. \u201cNot only can we challenge the OEM guidance from an informed position, but we\u2019ve taken the 200-plus hours per year saved by eliminating manual asset management and applied them to the time we spend on critical vulnerability management efforts.\u201d<\/p>\n\n\n\n<p>West Burton uses Tenable Nessus, built into Tenable OT Security, within one of its OT environments to scan Windows servers and network switches and other IT equipment. Simply initiating a scan across the entire Windows environment helps the team discover vulnerabilities, for example, from the impact of an OEM\u2019s latest release or a version of software that is out of date.<\/p>\n\n\n\n<p>\u201cFrom patch level through to programs and everything installed on a machine, Tenable Nessus highlights vulnerabilities that the OEM probably never thought to look for,\u201d said Keyworth. \u201cTenable has earned our confidence to embed Tenable Nessus within our OT environment. From a vulnerability management perspective this puts us far above what we\u2019d have been able to achieve without it.\u201d<\/p>\n\n\n\n<p>\u201cTenable OT Security plus the Tenable Nessus scanner provides far richer data than we had before,\u201d added Cartwright. \u201cIt allows us to use Active Query to communicate with and discover OT assets, and IT assets as well \u2013 all in one solution, which eliminates additional costs and saves time. It would\u2019ve saved our team many hours of effort during Log4j.\u201d<\/p>\n\n\n\n<p>Fewer false positives also provides new freedom for the team. The passive tool that was in place prior to the corporate separation was alerting on more than 500 possible vulnerabilities per day \u2013 some 182,000 per year. Today that number clocks in at only 50 per day.<\/p>\n\n\n\n<p>\u201cWith Tenable OT Security tuned and trained to prevent false positives we\u2019ve reduced the number of reported events by 98%, resulting in tremendous time savings,\u201d said Keyworth. \u201cWhat used to take two days per week to manage now takes only a few hours, and we\u2019ve improved efficiency by 87%.\u201d<\/p>\n\n\n\n<p>\u201cTenable OT Security does a lot, but it isn\u2019t a \u2018fit-and-forget\u2019 solution \u2013 nor should it be,\u201d added Cartwright. \u201cYou have to invest the time and effort to configure the product to understand what \u2018normal\u2019 looks like on your network, because that\u2019s where you\u2019ll derive true business value.\u201d<\/p>\n\n\n\n<p>Keyworth agrees: \u201cHow do you see the woods for the trees if you don\u2019t condition the solution to understand your OT environment? I think many people buy these bits of kit, install them and it ticks loads of boxes from a compliance perspective, but the results that are returned aren\u2019t worth the digital paper it\u2019s written on.\u201d<\/p>\n\n\n\n<p>Speaking of compliance, West Burton and the auditors are confident in the results reported by Tenable OT Security versus manual processes. Keyworth explains that the accelerated pace of the OT and IT environment no longer allows for spreadsheets and handwritten records to be a viable source of truth.<\/p>\n\n\n\n<p>\u201cIt would be very difficult to demonstrate compliance without a tool like Tenable OT Security. The time savings is virtually immeasurable,\u201d said Keyworth. \u201cIt gives auditors a level of assurance that you are doing the correct things. From the asset list to risk scoring, Tenable makes the whole compliance piece so much easier.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UK-based West Burton Energy reduces threat-detection alerts by 98% and improves efficiency by 87% using Tenable OT Security. In 2022, nearly 11% of\u00a0cyberattacks targeted energy companies, so for power plants, healthy OT systems are crucial for high uptime and safety, as they control and monitor essential equipment, such as generators, turbines and transformers. As an [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":116099,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17482,33,27,6617,93,24],"tags":[21221,10485,5006,21222],"class_list":["post-116095","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-energy","category-intelligent-technology-newsletter","category-research","category-top-stories","category-used","tag-ot-security","tag-tenable","tag-uk","tag-west-burton-energy"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=116095"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116095\/revisions"}],"predecessor-version":[{"id":116643,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/116095\/revisions\/116643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/116099"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=116095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=116095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=116095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}