Cybersecurity Crash Course, Pt 2 of 2: Zero Trust Ensures Plant Resilience During a Cyberattack
In the second edition of this two-part series on OT network security, the popular term “Zero Trust architecture” is fully broken down into individual devices that together take both an offensive and defensive approach to securing an OT network. Zero Trust Architecture: An All-Encompassing Term for a Defensible OT Network While the term “zero trust” has become popular within the field of operational technology (OT) network security, its meaning stems from the evolution of ever-increasing network security measures that have had to be implemented in response to increasingly complex threats. As the threat frequency and sophistication of a breach has increased, security measures have also had to increase in lockstep, assuming less and less trust for devices operating on the network. At this point in time, the most robust network design always assumes the worst – trusting absolutely nothing attempting to access an OT network until full authentication has occurred, and regularly interrogating devices currently on the network as if they’ve become malicious. Trust no device, at any point in time – zero trust. Simply put, when it comes to cybersecurity, you’ll find safety in skepticism. Zero Trust vs Safe Zones: Why Assuming the Worst is Best In the Zero Trust model, full identification and credentialing occurs on a continual basis for every single device attempting to access the network. Traffic monitoring is continual, access is limited, and no safe perimeter is assumed. This is a different, nearly inverse approach than that traditionally implemented within an IT network, which assumes a “safe zone” and primarily defends that zone at its perimeter. The Zero Trust approach requires a collection of network components and software solutions, each doing their own task, that work together to collectively keep the network secure. Some components monitor data; some log events; some actively interrogate existing devices using the … Continued