While it has not been a popular choice due to the risks involved, operational technology (OT) organizations are increasingly looking to move SCADA solutions to the cloud. As a result, the UK National Cyber Security Centre (NCSC) has provided guidance for managing the security elements of such a choice.
During engagement with industry, the NCSC has noticed a clear shift in the attitude towards using the cloud for industrial applications, with many operational technology (OT) organizations now looking to the cloud for solutions.
In ‘Cloud-hosted supervisory control and data acquisition (SCADA)’ identifies three critical areas that organizations need to assess before deciding on a SCADA cloud migration. These are:
- Understanding your business drivers and cloud opportunities.
- Organizational readiness.
- Technology and cloud solutions suitability.
Organizations also need to consider the impact of challenges OT organizations face such as the reliance on legacy equipment, on-premises solutions, and monolithic software packages.
Comment
Trevor Dearing, Director of Critical Infrastructure at Illumio told Resilience Forward:
“Operational downtime is now the driving force behind many cyber attacks. Cybercriminals know by targeting SCADA systems, they can cause operational downtime in key critical infrastructure sectors such as energy and manufacturing, which could cause mass societal chaos.
“It’s good the NCSC has recognised the risk posed to operational resilience when SCADA systems are connected to the cloud. Many SCADA systems were originally designed years ago without security in mind and were therefore never intended to be connected to the cloud. This of course means they are vulnerable to an attack and operational downtime.
“We fully endorse the NCSC’s message of ‘organisational readiness’ when it comes to migrating SCADA systems to the cloud. Organisations should look into a Zero Trust approach, one of the most effective ways to improve cyber resilience. Adopting a “never trust, always verify” approach can help organizations contain attacks at the point of entry and limit lateral movement to SCADA systems.”






