As operational technology (OT) systems continue to be a rich target for cybercriminals, the one-size-fits-all approach to OT security is outdated. From manufacturing to utilities, oil and gas, to health care, each industry requires a verticalized and tailored security approach, said Anand Oswal, SVP and GM of network security at Palo Alto Networks.

OT networks typically combine hardware and software systems including high-value assets and machines, Oswal noted. Historically, many of these systems have been air-gapped, meaning they were not directly connected to the internet. But the lockdown of the COVID-19 pandemic forced them to accelerate digitalization.

Additionally, the growth in connected devices, driven by digitization, has increased the attack surface and risk significantly. This has led to incidents like the Colonial Pipeline attack, causing catastrophic disruption and economic impact.

“Making sure that the critical infrastructure [and] the OT systems are not attacked or are able to resist attacks is top of mind,” Oswal said.

However, security vendors shouldn’t “shift and lift” their enterprise security strategies and apply them to OT systems; instead, the strategies need to be verticalized — customized for each industry.

“I don't believe that what works for health care can work for manufacturing, what works for manufacturing can work for energy; because if you look at energy and utilities, they're more constrained or conservative in access to the outside world,” Oswal said. "We have a healthcare solution for medical customers, for hospitals. We have solutions now for manufacturing, energy, utilities, oil and gas."

Palo Alto Networks’ 4-step vertical-centric approach for OT security

Oswal explained a vertical-centric OT security offering should create solutions specific to the environment of the operator, and Palo Alto Networks’ approach comprises four key steps:

1. Gaining visibility into assets 

As the threat landscape continues to grow, achieving full visibility into the OT network is more critical than ever, Oswal noted. Security teams for those systems must understand what devices are connected to the network and the specifics about each one. This includes the make, model, version of software running, open vulnerabilities and whether it has been patched or not.

“It's cumbersome. You have new devices that come onto the network periodically, and you want to be precise and accurate,” he said. That’s why Palo Alto Networks uses artificial intelligence (AI) and machine learning (ML) to dynamically identify these devices by monitoring traffic patterns and performing deep inspections. And the vendor continues to improve the AI model as it encounters new and unique devices.

2. Using AI and ML to automate policy creation

Palo Alto Networks also uses AI and ML to automatically create security policies. These policies, driven by technical segmentation and based on zero-trust principles, dictate which device can communicate with which device, and which device can interact with the outside world. The asset owner or operator can then review the policies and decide whether to apply them.

This approach can help reduce the cyber risks, Oswal said, as “a majority of the cybersecurity breaches happen because of misconfigurations or because things are not configured properly.”

3. Monitoring device connections to the outside world

The next significant step in OT security involves monitoring the devices that connect to the internet. Oswal claims Palo Alto Networks’ solution is designed to ensure that all interactions are monitored and permissions are appropriately validated by checking for potentially harmful transactions, command-control connections, malware and links to phishing sites.

“We want to use the power of AI and machine learning to stop attacks that you have never seen before,” he said. “Then we want to do that on a continuous basis, not just one and done.”

4. Simplifying the security operations of the OT environment

In the past year, the vendor has been seeing a trend where customers are reducing the number of tools and vendors used for cybersecurity. This is particularly relevant for OT environments with legacy architectures and flat networks, as well as for organizations facing a security talent shortage. So, without the need for adding more point process solutions, Palo Alto Networks uses existing enforcement points such as firewalls as sensors to minimize the operational complexity.

The vendor also addresses the unique needs of each vertical, Oswal touted. “For example, with manufacturing, I will want to have asset utilization about how my assets are performing, how often they are being used, not used, etc. If you think of energy, many of the endpoints are very passive, so you need to do active probing in terms of what they are doing and what they're not doing.”

“So every single vertical has some nuances and what they need and do not need," he said. "We are creating vertical-specific products for these environments.”