Written by:

TL;DR

An Operational Technology Security Operations Center (OT SOC) provides dedicated security monitoring and threat detection for industrial environments such as manufacturing, energy and critical infrastructure.

As Operational Technology (OT) environments become more connected, they also become more exposed to cyber threats. Traditional SOC models are not sufficient for industrial environments, where safety, availability and operational impact come first.

With over 20 years of OT security experience, mnemonic is building a next-generation OT SOC to help organisations detect threats and protect critical operations.

Background

mnemonic Cyber Defence Center has been protecting critical entities from cyber attacks for more than two decades.

Many of our customers rely on operational technology, and protecting their core deliveries and most valuable assets has always been a priority.

The changing reality of OT security

Traditionally, OT has been protected by a strong perimeter with a strict separation between operational networks and the outside world, resulting in "air-gapped" networks with very few attack pathways.

Over the years, operational necessities and business requirements have led to a more connected world. Centralised monitoring and control, remote access, process optimisation, predictive maintenance and cross-site automation are just some examples of real-life use-cases that poke holes in the "air-gapped" design.

Such use-cases improve efficiency, production rates and reduce the need for local labour, which are valid reasons to implement them. That being said, the once strong perimeter is not that robust anymore. This modernisation of OT is also increasing the risk of cyber attacks by introducing new attack pathways.

Why OT faces greater cyber risk than before

The threat landscape is complicating things further at rapid speed. Rising geopolitical tensions are driving increased intelligence-gathering activities, while ongoing conflicts are lowering the threshold for disruptive and destructive actions against opponents, their supporters, and their supply chains.

AI is also lowering the barrier for threat actors to acquire knowledge of industrial systems and protocols that previously required specialised domain expertise. As a result, attacks against OT environments that once demanded highly skilled adversaries may become accessible to a broader range of actors.

As a result, organisations that deliver critical services, support essential infrastructure, or hold sensitive information are increasingly attractive targets for both intelligence operations and cyberattacks.

From niche to necessity

OT SOC used to be a niche market, with only the most critical or most mature entities adopting such services. A rapid digitalisation of OT in combination with an increasingly complex threat landscape requires better security measures.

Having the capability to detect unauthorised access, exploit attempts and abnormal activity is no longer optional; it is for many industries enforced by laws and regulations.

mnemonic's OT security journey

mnemonic has a long history with OT security. Being a service provider to some of the most critical entities, and some of the earliest adopters, we have more than 10 years of experience with SOC services in OT environments, and more than 20 years of OT security experience. We already have established partnerships with CERTs, OEMs and technology partners, and have come far in maturing our OT SOC capabilities. That being said, there still was (and still is) room for improvement. We needed an OT SOC.

Three years ago, the decision was made to invest heavily in developing a leading holistic SOC service covering both IT and OT. We saw the potential in our unique position to develop the next generation of OT SOC, and we have been committed to becoming a leading OT SOC provider in Europe since.

Why traditional IT SOC models don't work for OT 

Traditional SOCs, now also including cloud environments, are built for IT. The tools used to detect potential security threats are refined, and skilled security analysts know how to triage events efficiently with their understanding of how systems and users are supposed to behave. The criticality of events can often be deduced by class of malware, available threat intelligence and systems/applications involved. Mitigations can often be implemented through automated playbooks, and active countermeasures are becoming the norm. For instance, by revoking users' access or isolating devices from the network.

Security monitoring of OT is very different. Operational Technology is often purpose-built systems for the industrial tasks involved, and consist of vulnerable components with long lifecycles. Security features, data and telemetry are less available. SOCs often have to rely on passive network intrusion detection systems as the only source of information. Impact analysis and criticality assessments can be challenging given the diverse use of components and unknown dependencies. The use of automated playbooks and active countermeasures are rarely accepted due to the risk of physical damage or huge financial losses. Applying IT security logic to OT environments creates friction, blind spots and sometimes operational risk.

Building an OT-specific SOC approach in mnemonic

We use purpose-built tools for security monitoring of OT and apply OT-specific detections tailored to customer environments and threat intelligence received from our own security research and partners. Our service delivery is designed to address the challenges OT SOCs face.

We emphasise the importance of understanding the potential impact of security events in industrial contexts. Efforts are made to enrich security events with additional context, and we have OT security experts in the SOC analysing security events originating from OT. 

Pushing for OT security to match IT maturity

We strive to close the maturity gap between an IT and OT SOC, and retain a holistic approach that applies security where it matters.

mnemonic is committed to being a leading IT and OT security provider in Europe. As a highly reputed IT SOC provider, with a lot of OT security experience providing solid and proven IT and OT SOC services, we are at the forefront of OT SOC development. However, the OT SOC market is still young compared to IT, and service providers in this space will have to innovate and enhance their capabilities in the years to come. Significant developments are being made to both technology and services, and we are actively taking part in that.

The current state of the OT SOC (and what is missing)

The current generation of OT SOCs has some challenges to overcome, especially related to integrations, contextualisation and impact analysis at scale. Being an organisation of 400+ security specialists with a favourable culture for research and development of high-quality security solutions and services gives us a solid foundation to meet these challenges. Through close collaboration with academia, research partners, technology vendors and customers, we are defining what a future OT SOC should be.

How we are building a next-generation OT SOC

We chose a focused approach to build our OT SOC capabilities. A dedicated and consistent service development department for OT security was established, and a large team consisting of people with different backgrounds within cybersecurity, OT security and industrial automation came together.

The team started with a thorough analysis, interviewing key stakeholders, customers and partners to identify objectives for a combined IT and OT SOC.

We then recruited so-called "OT champions" in all relevant teams in mnemonic, ensuring that the whole organisation was on board with our ambitious plan.

Upskilling and knowledge-sharing became an integral part of our journey, and the interest for OT security across the whole company has grown far beyond our initial imagination. OT security has become one of the most popular topics for internal events, and more than a quarter of the company participates in knowledge sharing forums.

Great things happen when strategy, projects and people are aligned.

Lessons learned along the way

We have learned a lot during this process. Early on, we focused too much on detection engineering and research on known malware targeting OT. We soon realised that there are other priorities and needs in OT.

Understanding the industries and how they operate under normal conditions was far more valuable than knowing the tactics, techniques and procedures of adversaries.

The number one priority in OT is to lower the risk of physical accidents that could potentially harm humans or the environment. When applying security in OT, availability and integrity are more important than confidentiality.

OT SOCs need to understand the systems they are protecting, and be able to set the right priority based on the criticality of systems involved. Doing SOC triage efficiently at scale requires more than detection logic; it requires context and knowledge.

For us, that has been one of the most important lessons: building an OT SOC is not simply about adapting an IT SOC to industrial environments. It requires a fundamentally different mindset, built around the realities of operational technology.

Get in touch with our OT experts