CyberSecurity SEE

CISA Offers OT Recovery Guidance via CI-Fortify

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity Management / Disaster Recovery,
Critical Infrastructure Security,
Governance & Risk Management

Agency Tells Operators to Test Recovery Plans End-to-End for Real Life Conditions

CISA Offers OT Recovery Guidance via CI-Fortify
Image: Shutterstock

The U.S. government, in collaboration with its Five Eyes partners, is set to release a new set of guidelines aimed at helping operational technology (OT) owners and operators effectively recover from cyberattacks. This initiative is an extension of the CI-Fortify program, which is focused on enhancing the resilience of critical infrastructure against digital threats. Officials reported these developments this week, indicating a significant advancement in the state of the program.

One of the core messages that will emerge from this forthcoming guidance is the necessity for OT operators to conduct comprehensive tests of their response and recovery plans. According to Matt Rogers, an OT security specialist with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), these tests should cover the entire organization to ensure robust preparedness. “You might think things are working as intended with these short, isolated little tests, but until you test it for real on your whole system, you still don’t know,” Rogers stated during a CISA Live webinar on Monday.

Rogers emphasized the real-world impact of such preparedness initiatives, stating that many organizations in sectors such as energy, natural gas, and water have utilized CI-Fortify to advocate for proactive measures within their entities. He recounted instances where professionals successfully appealed to their boards, insisting on conducting “IT/OT disconnect exercises.” These exercises entail severing the business network from operational technology to identify potential failures in the system. “And something always does break, right?” he remarked, underscoring the importance of thorough testing.

In one illustrative case, Rogers referenced a power utility that performed a disconnection drill, asserting that everything was functioning correctly. However, the utility soon discovered that the browser had “cached all of the pages,” which produced an illusion of functionality. Consequently, when operators attempted to refresh the page, nothing worked as expected. “It’s little tips and tricks like that we’ll hopefully include in the upcoming guidance,” he added, showcasing the critical nature of experiential learning in disaster recovery strategies.

In addition to offering practical advice, CISA is currently hosting a technical exchange group where operators preparing for testing can share insights with those who have already executed similar drills. This collaborative effort is designed to help participants assess potential vulnerabilities within their systems before conducting tests. “Ideally, they’ll figure out what breaks before they do the test for themselves,” noted Rogers, reflecting on the proactive steps organizations can take for better preparedness.

However, Rogers also pointed out that understanding the risks associated with disconnection from network systems can be particularly challenging, especially for those accustomed to constant connectivity. He observed that individuals of a younger demographic are often familiar with technology at an intimate level, leading to some disjointed conversations regarding emergency protocols. This generation tends to use multiple platforms for communication—often assuming that if one is down, another will suffice. “When asked what happens if the phone is out, they respond, ‘Well, then I call them up on Teams,'” he elaborated. This disconnect reveals a lack of awareness about the real-life scenarios that can occur during a critical point of failure.

Rogers illustrated this point further using an emergency communications plan that depends on satellite phones. He posed relevant questions: “Well, do you have everybody’s sat phone number? Have you tried communicating with them from where you realistically would need to?” He ultimately advised organizations to closely examine their contingency plans, especially regarding the logistics of communication in emergencies.

The guidance on recovery will build upon previously issued advice regarding the isolation of critical operational technology systems. This earlier issuance came in July from the Five Eyes alliance, comprising Australia, Britain, Canada, New Zealand, and the United States. The continued collaboration between these nations highlights a commitment to fortifying the security of critical infrastructure and ensuring that operational technology remains resilient against evolving cyber threats.

Source link

Exit mobile version