The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years. Marco Ayala has spent more than two decades inside industrial control system security. He is technical director for global energy at ABS Consulting, and he puts the risk with the discipline he thinks owns it. “Reliability, uptime and safety are paramount. Cybersecurity affects all these outcomes, making it an engineering problem.” The bill for getting it wrong has grown. Cyberattacks on U.S. utility companies climbed nearly 70 percent over a single year. Dragos and Marsh McLennan put worst-case global OT cyber losses at $329.5 billion across all sectors. Waterfall Security counted a 146 percent year-over-year rise in OT sites hit by attacks with physical consequences. Operators spend the cybersecurity money elsewhere. OT security draws roughly 20 percent of it, and laptops and enterprise tools take the rest. Recovery is where the plans break Shankar Somasundaram runs Asimily, which inventories connected devices across industrial sites. He watches the restart expose what the recovery plan assumed. “I’ve seen plants with a backup of a controller, but the engineer who knew why it was configured the way it was is long gone. So the backup is restoring a state no one can confirm is actually still correct. Plants end up reverse-engineering their own process under immense pressure (mid-outage!), which is the worst possible time to
The energy sector's OT <b>cybersecurity</b> talent is retiring faster than it can be replaced
Read the original article
helpnetsecurity.com →