Debunking Air Gap Myths: Essential OT Security Realities
The air gap is a myth and other OT security truths Benjamin Bachmann, Director Group Information Security at Bilfinger, discusses critical insights into securing industrial environments during an interview.
The air gap is a myth and other OT security truths
Benjamin Bachmann, Director Group Information Security at Bilfinger, discusses critical insights into securing industrial environments during an interview. He addresses misconceptions about threat models, containment strategies, and the evolving nature of ransomware attacks. Bachmann emphasizes the importance of redefining security priorities to align with operational resilience rather than traditional data protection frameworks.
Threat models and operational control
Executives often assume that cyber threats in industrial settings revolve around data theft, but Bachmann highlights that attackers target operational control rather than information. He explains that in industrial plants, the primary objective of adversaries is to disrupt physical processes, not access digital files. This shift in perspective requires organizations to focus on availability and physical safety as core security principles.
Air-gapped systems are not foolproof
A common misunderstanding is the belief in air-gapped systems as a foolproof security measure. Bachmann dismisses this notion, stating that air gaps are rarely effective in practice. He notes that even systems designed to be isolated can be compromised through overlooked vulnerabilities, such as unsecured peripheral devices. Instead of relying on theoretical isolation, security strategies must account for real-world scenarios where connectivity is inevitable.
Containment vs. operational continuity
During incidents, the conflict between security containment and operational continuity is inevitable. Bachmann clarifies that containment is not the ultimate goal but a tactical method to ensure safe plant operations. He stresses that security teams must collaborate with engineers to establish predefined protocols for isolating zones and managing downtime. These plans are documented, tested, and refined to avoid last-minute decisions during crises.
Legacy equipment and network traffic analysis
Legacy equipment poses unique challenges due to its lack of authentication and logging capabilities. Bachmann describes a shift in approach, treating network traffic as a reliable source of visibility rather than relying on the devices themselves. By analyzing the predictable patterns of operational technology (OT) traffic, security teams can detect anomalies that indicate potential threats.
Ransomware and financial impact
The rise of ransomware targeting physical operations has altered security priorities. Bachmann explains that cybercriminals now calculate ransom demands based on the financial impact of production downtime. This trend forces organizations to focus on rapid recovery and segmentation strategies that minimize disruption. By designing systems to allow independent restarts of unaffected zones, companies can reduce the leverage of attackers.
Human error vs. system design
A widely held belief that human error is the primary vulnerability in OT security is also challenged. Bachmann argues that the issue lies in system design rather than individual actions. He points out that a single malicious link can halt critical processes if the architecture allows it. This perspective shifts the focus from user awareness campaigns to securing the pathways that connect endpoints to operational systems.
Outdated principles and proactive approaches
Another outdated principle, “never touch OT, you will break it,” is criticized for discouraging necessary security measures. Bachmann warns that excessive caution can lead to complacency, leaving systems vulnerable. He advocates for a proactive approach that balances risk management with operational needs.
Conclusion
The interview underscores the need for industrial organizations to adopt security frameworks that prioritize resilience, adapt to evolving threats, and integrate with operational realities. By redefining traditional concepts like air gaps and human vulnerabilities, companies can better protect critical infrastructure against sophisticated attacks.
“Executives often assume that cyber threats in industrial settings revolve around data theft, but Bachmann highlights that attackers target operational control rather than information.”
