{"id":14577,"date":"2025-02-04T14:15:54","date_gmt":"2025-02-04T08:15:54","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14577"},"modified":"2025-02-04T14:15:54","modified_gmt":"2025-02-04T08:15:54","slug":"plant-wide-global-or-local-it-ot-access-control-at-industrial-scale","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/plant-wide-global-or-local-it-ot-access-control-at-industrial-scale\/","title":{"rendered":"Plant-wide, global, or local IT\/OT access control at industrial scale"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-14578 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2025\/02\/13906054246094798606.jpg\" alt=\"\" width=\"500\" height=\"261\" \/><\/p>\n<p>IT-OT convergence is the integration of <strong>Information Technology (IT)<\/strong> and <strong>Operational Technology (OT)<\/strong> systems, enabling seamless data exchange between business and industrial operations.<\/p>\n<p>Traditionally, <strong>IT systems<\/strong> manage business-critical data, including databases, networks, and applications. In contrast, <strong>OT systems<\/strong> oversee physical processes in industries like manufacturing, energy, and utilities, controlling devices such as <strong>SCADA systems, PLCs, and industrial control systems<\/strong>.<\/p>\n<p>While this convergence enhances efficiency and decision-making, it also introduces security risks\u2014especially for legacy OT systems not originally designed for internet connectivity. To address these challenges, cybersecurity frameworks such as <strong>ISA\/IEC 62443<\/strong> and <strong>NIST cybersecurity guidelines<\/strong> are being widely adopted to safeguard IT-OT environments from emerging threats.<\/p>\n<hr \/>\n<p><span data-contrast=\"auto\">IT-OT convergence is basically integration of\u00a0<\/span><strong><span data-contrast=\"auto\">People, Process and Technology\u00a0<\/span><\/strong><span data-contrast=\"auto\">(<\/span><strong><span data-contrast=\"auto\">PPT<\/span><\/strong><span data-contrast=\"auto\">) requiring the following:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><strong>A\u00a0<span data-contrast=\"auto\">Governance Structure\u00a0<\/span><\/strong><span data-contrast=\"auto\">to determine how does the organization moves about solving cyber challenges<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Tools Implementation<\/span><\/strong><span data-contrast=\"auto\">\u00a0that enables monitor, measure and manage the cyber security threats<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Managed security\u00a0<\/span><\/strong><span data-contrast=\"auto\">portfolio which does continuous monitoring<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">An awareness program<\/span><\/strong><span data-contrast=\"auto\">, which provides continuous awareness to the users.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Key Benefits of IT-OT Convergence<\/strong><\/p>\n<p>The integration of IT and OT is designed to enhance <strong>operational efficiency, data-driven decision-making, and cybersecurity resilience<\/strong>. Some key aspects include:<\/p>\n<p>&#x1f539; <strong>Unified Data Analytics<\/strong> \u2013 Combining IT and real-time OT data enables deeper insights, improving productivity, predictive maintenance, and resource optimization across digital and physical operations.<\/p>\n<p>&#x1f539; <strong>Stronger Cybersecurity<\/strong> \u2013 As traditionally isolated OT systems connect to broader networks, IT-OT convergence supports a more <strong>comprehensive security strategy<\/strong> to protect against cyber threats.<\/p>\n<p>&#x1f539; <strong>Improved Operational Efficiency<\/strong> \u2013 Integration enables <strong>automation, predictive maintenance, and streamlined workflows<\/strong>, reducing downtime and optimizing industrial performance.<\/p>\n<p>&#x1f539; <strong>Compliance &amp; Governance<\/strong> \u2013 A unified approach simplifies <strong>regulatory adherence<\/strong> by applying consistent cybersecurity and policy standards across IT and OT environments.<\/p>\n<p>By aligning IT and OT strategies, organizations can drive innovation while maintaining security and compliance in an increasingly connected industrial landscape.<\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<hr \/>\n<h2><strong><span data-contrast=\"auto\">Overview of Convergence of IT-OT: Emergence of Industry 4.0<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><strong><span data-contrast=\"auto\">Convergence of IT and Industrial Automation historical steps are\u00a0 shown in the following picture (Source: IoT Analytics).<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span role=\"presentation\"><img decoding=\"async\" src=\"https:\/\/www.ssh.com\/hubfs\/undefined-Dec-03-2024-08-37-47-0272-AM.png\" alt=\"A diagram of a company's company's company's company's company's company's company's company's company's company's company's company'\n\nDescription automatically generated\" \/><\/span><\/p>\n<hr \/>\n<h2><strong><span data-contrast=\"auto\">How IT-OT Convergence current and future states look like?<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The next picture will show how the current and future stare look like and what are the most important gaps and remediation steps are needed to transform and converge IT and OT data and systems.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span role=\"presentation\"><img decoding=\"async\" src=\"https:\/\/www.ssh.com\/hubfs\/undefined-Dec-03-2024-08-37-24-5792-AM.png\" alt=\"A diagram of a transformation\n\nDescription automatically generated\" \/><\/span><\/p>\n<hr \/>\n<h2><strong><span data-contrast=\"auto\">IT-OT Convergence best practices<\/span><\/strong><\/h2>\n<p><span data-contrast=\"auto\">Here are listed the most common IT-TO Convergence best practices based on standards, regulations, frameworks etc:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">The\u00a0<\/span><strong><span data-contrast=\"auto\">vision, strategy and execution of the business plan\u00a0<\/span><\/strong><span data-contrast=\"auto\">need to include security, reliability and safety. These should be part of the business planning process at all levels of the organization (regardless if you are an IoT solution provider or a customer)<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Security should be \u201cowned\u201d\u00a0<\/span><\/strong><span data-contrast=\"auto\">by one person at the executive level who is responsible for both IT and operations. Security policy, governance and end-user education need to extend across the IT and OT environments as systems are interconnected<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Technologies and threats across the IT and OT environments\u00a0<\/span><strong><span data-contrast=\"auto\">should be clearly understood<\/span><\/strong><span data-contrast=\"auto\">. Technologies that work in the IT environment may not necessarily work in the OT environment. Additionally, threats may be different in the IT and OT environments<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">A threat intelligence framework\u00a0<\/span><\/strong><span data-contrast=\"auto\">needs to be set up so that the organization can be up to date on the latest information on threats and be prepared to deal with them<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Baseline security controls\u00a0<\/span><\/strong><span data-contrast=\"auto\">should be deployed across all layers of the organization\u2019s environments<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"6\" data-aria-level=\"1\"><span data-contrast=\"auto\">Regular risk assessments across all environments must be performed to identify vulnerabilities and ensure that the appropriate security controls are in place<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"7\" data-aria-level=\"1\"><span data-contrast=\"auto\">The organization and customers should consider\u00a0<\/span><strong><span data-contrast=\"auto\">NIST 800-5310 for IT and NIST 800-8211 and ISA\/IEC 6244312\u00a0<\/span><\/strong><span data-contrast=\"auto\">for ICS and OT<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"8\" data-aria-level=\"1\"><span data-contrast=\"auto\">Establish or update the security patch process to better address vulnerabilities. Follow the recommendations laid out in IEC\u00a0<\/span><strong><span data-contrast=\"auto\">62443-2-3<\/span><\/strong><span data-contrast=\"auto\">, which describes requirements for patch management for control systems<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"9\" data-aria-level=\"1\"><span data-contrast=\"auto\">Develop\u00a0<\/span><strong><span data-contrast=\"auto\">ICS-specific policies and procedures\u00a0<\/span><\/strong><span data-contrast=\"auto\">that are consistent with IT security, physical safety and business continuity<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<hr \/>\n<h2><strong><span data-contrast=\"auto\">Most common access management challenges<\/span><\/strong><\/h2>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">Access management<\/span><\/strong><span data-contrast=\"auto\">\u00a0is essential for securing systems, applications, and data within an organization, but it comes with several common challenges:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><strong><span data-contrast=\"auto\">Balancing Security with Usability<\/span><\/strong><span data-contrast=\"auto\">: Striking the right balance between security and usability is difficult. If access controls are too strict, users might seek workarounds that can introduce security risks. On the other hand, if access is too lenient, it increases the risk of unauthorized access<\/span><span data-contrast=\"auto\">\u200b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Managing Diverse Access Levels<\/span><\/strong><span data-contrast=\"auto\">: Organizations often need to manage a variety of access levels for employees, third-party contractors, and partners. Ensuring that each user has the correct level of access based on their role and responsibilities, and promptly updating or revoking access as roles change, can be challenging.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Password Fatigue and Complexity<\/span><\/strong><span data-contrast=\"auto\">: Users frequently experience password fatigue due to the need to remember multiple complex passwords across systems. This can lead to insecure practices like password reuse or storing passwords in insecure ways, which may compromise security.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Monitoring and Auditing Access<\/span><\/strong><span data-contrast=\"auto\">: Continuously monitoring who has access to what resources and auditing access logs to detect suspicious activity is vital but can be difficult to implement effectively. Many organizations struggle to keep up with access reviews, especially in large or complex IT environments.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Managing Access in Multi-Cloud and Hybrid Environments<\/span><\/strong><span data-contrast=\"auto\">: As organizations move to hybrid or multi-cloud environments, managing access across these diverse platforms becomes a challenge. Consistent policies and controls are required to manage access across on-premises, cloud, and third-party applications.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Identity Sprawl<\/span><\/strong><span data-contrast=\"auto\">: With more applications, systems, and third-party integrations, organizations often experience &#8220;identity sprawl&#8221; where identities proliferate across multiple platforms, making it difficult to centralize identity and access management (IAM) practices and creating potential gaps in security coverage.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><strong><span data-contrast=\"auto\">Compliance Requirements<\/span><\/strong><span data-contrast=\"auto\">: Different industries and regions have unique compliance and regulatory requirements (such as GDPR, HIPAA, and SOX), which require strict access controls. Meeting these requirements often demands significant resources and close collaboration between security and compliance teams.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span data-contrast=\"auto\">Organizations commonly address these challenges by implementing solutions like single sign-on (SSO), multi-factor authentication (MFA), privileged access management (PAM), and identity governance and administration (IGA) tools. These approaches help streamline access management processes while maintaining security across diverse systems and user roles<\/span><span data-contrast=\"auto\">\u200b.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">Most common<\/span><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">\u00a0c<\/span><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">hallenges for interactive and A2A access are shown in the next picture.<\/span><\/p>\n<p><span role=\"presentation\"><img decoding=\"async\" src=\"https:\/\/www.ssh.com\/hubfs\/undefined-Dec-03-2024-08-40-02-0601-AM.png\" alt=\"A close-up of a diagram\n\nDescription automatically generated\" \/><\/span><\/p>\n<hr \/>\n<h2>Major risks of access management in OT systems<\/h2>\n<p><span data-contrast=\"auto\">Managing access to OT (Operational Technology) systems is critical for maintaining the security and integrity of industrial processes. Here are listed the major risks associated with OT security access management:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">OT Security de-facto risks:<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"5\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Physical Security<\/span><\/strong><span data-contrast=\"auto\">: Inadequate physical security measures can allow unauthorized individuals physical access to OT systems, enabling them to tamper with or sabotage equipment.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"5\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Legacy Systems<\/span><\/strong><span data-contrast=\"auto\">: Many OT environments still rely on legacy systems with outdated security measures, making them more vulnerable to attacks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"5\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Inadequate Monitoring<\/span><\/strong><span data-contrast=\"auto\">: Lack of real-time monitoring and auditing of access attempts and activities can result in delayed detection of unauthorized or suspicious behaviour.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<h3><strong><span data-contrast=\"auto\">OT Security technical risks:<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Unauthorized Access:\u00a0<\/span><\/strong><span data-contrast=\"auto\">Unauthorized individuals gaining access to OT systems can disrupt operations, steal sensitive information, or even cause physical harm to equipment and personnel.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Unsecure Remote Access:\u00a0<\/span><\/strong><span data-contrast=\"auto\">Remote access to OT systems, if not properly secured, can be exploited by attackers. This is especially relevant with the increasing connectivity of industrial control systems to the internet.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Weak Authentication:\u00a0<\/span><\/strong><span data-contrast=\"auto\">Weak or compromised authentication methods, such as default passwords or easily guessable credentials, can provide an entry point for attackers.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Lack of Segregation of Duties:\u00a0<\/span><\/strong><span data-contrast=\"auto\">Inadequate separation of duties can lead to individuals having excessive privileges, increasing the risk of abuse or errors.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Failure to Revoke Access<\/span><\/strong><span data-contrast=\"auto\">: Failure to promptly revoke access when an employee changes roles, leaves the organization, or when access is no longer needed can leave systems vulnerable to unauthorized use.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"6\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Insider Threats<\/span><\/strong><span data-contrast=\"auto\">: Employees or contractors with legitimate access to OT systems may abuse their privileges intentionally or unintentionally, either through negligence or malicious intent.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"7\" data-aria-level=\"1\"><strong><span data-contrast=\"auto\">Supply Chain Risks<\/span><\/strong><span data-contrast=\"auto\">: Third-party vendors or suppliers with access to OT systems can introduce security vulnerabilities if their own systems are compromised.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<hr \/>\n<h2><strong><span data-contrast=\"none\">IT-OT Common language via Purdue model<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"none\">Traditionally OT networks have adopted various Models, Architectures and Systems to secure the OT Infrastructure.\u00a0<\/span><strong><span data-contrast=\"none\">An example is the Purdue Model for Control Hierarchy.<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The\u00a0<\/span><strong><span data-contrast=\"none\">Purdue Enterprise Reference Architecture (PERA)<\/span><\/strong><span data-contrast=\"none\">, often referred to as the\u00a0<\/span><strong><span data-contrast=\"none\">Purdue Model<\/span><\/strong><span data-contrast=\"none\">, is a hierarchical framework used to structure industrial control systems (ICS) and networks in manufacturing and critical infrastructure environments.<\/span><\/p>\n<p><span data-contrast=\"none\">Developed in the 1990s at Purdue University, this model categorizes industrial systems and networks into distinct layers, from physical equipment on the factory floor to enterprise-level information systems. The Purdue Model provides guidelines to separate systems by function and security zone, which is essential for cybersecurity and operational efficiency.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The Purdue Model for Control Hierarchy is a common and well understood Model in the Manufacturing Industry that provides a Blueprint to segments Devices and Equipment into hierarchical functions.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><strong><span data-contrast=\"none\">What are the 5 Purdue model levels?<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 5 (corporate network)\u00a0<\/span><\/strong><span data-contrast=\"none\">covers the enterprise IT systems that cover connections with the public internet.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 4 (IT systems)\u00a0<\/span><\/strong><span data-contrast=\"none\">consists of IT networks such as enterprise resource planning (ERP) systems, database servers, application servers, and file servers that enable the enterprise to drive business logistics systems.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 3 (manufacturing execution systems<\/span><\/strong><span data-contrast=\"none\">) is where the production workflow is managed on the manufacturing floor using customized systems for various functions, including batch management, record data, and manage operations and plant performance. These systems also put together lower-level data that gets pushed up to the higher-level business systems.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 2 (control systems)\u00a0<\/span><\/strong><span data-contrast=\"none\">houses the ICS including HMI and SCADA systems in order to supervise, monitor, and control physical processes.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 1 (basic control)\u00a0<\/span><\/strong><span data-contrast=\"none\">hosts the control devices such as sensors, pumps, and actuators, which sense and manipulate the physical processes in order to drive efficiencies.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"6\" data-aria-level=\"1\"><strong><span data-contrast=\"none\">Level 0 (physical process)\u00a0<\/span><\/strong><span data-contrast=\"none\">is where the physical equipment that defines the actual physical processes is found.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\">The Purdue model is shown in the following picture.<\/span><\/p>\n<p><span role=\"presentation\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=800&amp;height=853&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png\" sizes=\"(max-width: 800px) 100vw, 800px\" srcset=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=400&amp;height=427&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 400w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=800&amp;height=853&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 800w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=1200&amp;height=1280&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 1200w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=1600&amp;height=1706&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 1600w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=2000&amp;height=2133&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 2000w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-42-45-2390-AM.png?width=2400&amp;height=2559&amp;name=undefined-Dec-03-2024-08-42-45-2390-AM.png 2400w\" alt=\"A diagram of a software system\n\nDescription automatically generated with medium confidence\" width=\"800\" height=\"853\" \/><\/span><\/p>\n<hr \/>\n<h2><strong><span data-contrast=\"none\">What is the Remote Access flow recommended for IT-OT Convergence in the Purdue model?<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong><span data-contrast=\"none\">As part of IT-OT convergence activities we recommend the following way for remote access:<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"none\">Remote access GW is placed to a DMZ in level 3.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"none\">Remote access clients are authenticated against enterprise AD and they get an IP address from DMZ.<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"none\">Clients use RDP\/VNC\/Citrix to connect to jump hosts in level 3. These connections are authenticated against a separate ICS AD.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"none\">Jump hosts are dedicated per role \/ task that needs to be performed. They are hardened and have all the necessary tooling installed.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"none\">Bring your own tools \/ bring your own\u202fdata is not\u202fallowed.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>The following pictures show how remote access activities are represented in the Purdue model.<\/p>\n<p><span role=\"presentation\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=744&amp;height=677&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png\" sizes=\"(max-width: 744px) 100vw, 744px\" srcset=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=372&amp;height=339&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 372w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=744&amp;height=677&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 744w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=1116&amp;height=1016&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 1116w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=1488&amp;height=1354&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 1488w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=1860&amp;height=1693&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 1860w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-44-39-6592-AM.png?width=2232&amp;height=2031&amp;name=undefined-Dec-03-2024-08-44-39-6592-AM.png 2232w\" alt=\"A diagram of a computer network\n\nDescription automatically generated\" width=\"744\" height=\"677\" \/><\/span><\/p>\n<hr \/>\n<h2><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\">How to consider NIS2, IEC 62443 when dealing with Access Controls?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span role=\"presentation\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=800&amp;height=406&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png\" sizes=\"(max-width: 800px) 100vw, 800px\" srcset=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=400&amp;height=203&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 400w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=800&amp;height=406&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 800w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=1200&amp;height=609&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 1200w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=1600&amp;height=812&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 1600w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=2000&amp;height=1015&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 2000w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-09-06-43-3064-AM.png?width=2400&amp;height=1218&amp;name=undefined-Dec-03-2024-09-06-43-3064-AM.png 2400w\" alt=\"A table with text on it\n\nDescription automatically generated\" width=\"800\" height=\"406\" \/><\/span><\/p>\n<hr \/>\n<h2><strong><span data-contrast=\"auto\">How can SSH help with the Access Management of IT-OT Converged systems?<\/span><\/strong><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p>&nbsp;<\/p>\n<p><span data-contrast=\"none\">As IT and OT are converging, it&#8217;s time\u202fto\u202fbridge\u202fthe security\/safety\u202fgap between IT and\u202fOT to protect\u202fcritical infrastructures,\u202fenergy grids,\u202fproduction sites,\u202fpower plants, cyber-physical systems (CPS),\u202for machines.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\"><span role=\"presentation\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=794&amp;height=433&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png\" sizes=\"(max-width: 794px) 100vw, 794px\" srcset=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=397&amp;height=217&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 397w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=794&amp;height=433&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 794w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=1191&amp;height=650&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 1191w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=1588&amp;height=866&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 1588w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=1985&amp;height=1083&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 1985w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-45-43-8643-AM.png?width=2382&amp;height=1299&amp;name=undefined-Dec-03-2024-08-45-43-8643-AM.png 2382w\" alt=\"IT_OT_covergence\" width=\"794\" height=\"433\" \/><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span data-contrast=\"none\">We offer, via our\u00a0<a href=\"https:\/\/www.ssh.com\/solutions\/privx-ot-secure-access-management\" target=\"_blank\" rel=\"noopener\">PrivX OT<\/a>\u00a0tool, a definitive and cost-effective solution portfolio to enable plant-wide security and enable digital services adoption, from remote assistance to data collection\u00a0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.ssh.com\/solutions\/privx-ot-secure-access-management\" target=\"_blank\" rel=\"noopener\"><strong><span data-contrast=\"auto\">PrivX OT by SSH Communications Security<\/span><\/strong><\/a><span data-contrast=\"auto\">\u00a0is a secure access management solution for industrial automation and manufacturing businesses that require access management at scale helping to:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Integrate with IT\/OT systems and provide secure access to modern as well as legacy ICS targets in hybrid environments to allow for local and remote troubleshooting and data collection.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Support, as a software-based solution, least-privilege and just-enough-access models that are not available with traditionally used VPNs and firewalls.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Grant just-in-time Zero Trust access to industrial targets, mitigating the risk of shared or leave-behind credentials.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li data-leveltext=\"\u2022\" data-font=\"Arial\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Arial&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">From industrial control systems to programmable logic controllers,\u202fSCADA, and plenty of other OT types, PrivX offers comprehensive cybersecurity for your IT OT landscape.\u202f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\"><span role=\"presentation\"><span lang=\"EN-GB\" xml:lang=\"EN-GB\" data-contrast=\"auto\">PrivX OT major benefits include:<\/span>\u00a0<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\"><span role=\"presentation\"><br \/>\n<\/span><\/span><\/h3>\n<ol>\n<li><strong>Easy-to-use, secure remote access and maintenance:<\/strong>\u00a0PrivX OT is fast to deploy with no software agents on the client or the server and no complex configurations. It allows you to enhance productivity thanks to single-sing-on (SSO) and always verified access.<\/li>\n<li><strong>Acces your IT\/OT as one:<\/strong>\u00a0Support your various IT as well as OT protocols (SSH,RDP,HTTPS, VNC, TCP\/IP) allows you to combine your IT\/OT data. You can easily analyze your process and product data and increase operational efficiency without the fear of data compromise.<\/li>\n<li><strong>Stay in control with centralised access management:<\/strong>\u00a0PrivX OT allows you to manage all your targets under a single pane of glass with full visibility into roles, sessions, sites and targets.<\/li>\n<li><strong>Comply with regulations:<\/strong>\u00a0PrivX OT Edition help you stay compliant with strict regulations applicable to remote access, automation, control system applications, and network and information systems: ISA\/IEC 62443, ISO 27001, NIS\/NIS 2.0, and NIST.<\/li>\n<\/ol>\n<p><span role=\"presentation\"><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">PrivX OT high level solution overview is shown in the following picture.<\/span>\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\"><span role=\"presentation\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=777&amp;height=438&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png\" sizes=\"(max-width: 777px) 100vw, 777px\" srcset=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=389&amp;height=219&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 389w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=777&amp;height=438&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 777w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=1166&amp;height=657&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 1166w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=1554&amp;height=876&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 1554w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=1943&amp;height=1095&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 1943w, https:\/\/www.ssh.com\/hs-fs\/hubfs\/undefined-Dec-03-2024-08-47-03-9299-AM.png?width=2331&amp;height=1314&amp;name=undefined-Dec-03-2024-08-47-03-9299-AM.png 2331w\" alt=\"A diagram of a computer system\n\nDescription automatically generated\" width=\"777\" height=\"438\" \/><br \/>\n<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong>About DT Asia<\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>How we help<\/strong><\/p>\n<p>If you need to know more about <span id=\"hs_cos_wrapper_name\" class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"text\">Plant-wide, global, or local IT\/OT access control at industrial scale<\/span>, you\u2019re in the right place, we\u2019re here to help! DTA is SSH\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Click here and here and here to know more:\u00a0<a href=\"https:\/\/dtasiagroup.com\/ssh\/\">https:\/\/dtasiagroup.com\/ssh\/<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT-OT convergence is the integration of Information Technology (IT) and Operational Technology (OT) systems, enabling seamless data exchange between business and industrial operations. Traditionally, IT systems manage business-critical data, including databases, networks, and applications. In contrast, OT systems oversee physical processes in industries like manufacturing, energy, and utilities, controlling devices such as SCADA systems, PLCs, [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":14578,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14577"}],"version-history":[{"count":2,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14577\/revisions"}],"predecessor-version":[{"id":14581,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14577\/revisions\/14581"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/14578"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}