CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 3

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 3

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 3 6912 3456 Centro de Ciberseguridad Industrial

Step 3. Building response capability

In the previous step, we identified essential processes, the components supporting them, their dependencies, and the necessary communications to maintain operations. Now that we understand what we need to protect, a new question arises:

What capabilities does the organization really need to reduce risk and act when protective measures are not enough?

Many organizations address this issue by deploying controls independently, such as a firewall, a monitoring tool, multi-factor authentication, endpoint protection, or an incident response procedure.

All these measures may be necessary, but their effectiveness depends on being part of a coordinated capability.

Because it has been proven when suffering a high-impact cyber incident that protecting without detecting creates a false sense of security, detecting without responding produces alerts with no consequences, and responding without prior knowledge of the architecture can lead to decisions that worsen the impact on operations.

Three capabilities that must work as one

Protection aims to reduce the likelihood of an incident affecting industrial processes. It includes measures such as segmentation, access control, system hardening, vulnerability management, or communications protection.

However, no set of controls completely eliminates risk. For this reason, the organization must also have capabilities to detect anomalous behavior, unauthorized access, unexpected changes, or communications that do not correspond to the usual operation of the process.

When detection confirms that something is occurring, response begins at that very moment, and general procedures are no longer enough. It will be necessary to know which systems can be isolated, which functions must be maintained, which responsible parties must intervene, and which decisions could affect physical safety or operational continuity.

Protection, detection, and response must be designed jointly around the essential industrial process.

SG2CI turns measures into operational capabilities

Within SG2CI, this third step is developed mainly through domains D5 (Culture, training, and communication), D6(Protection and control of industrial systems), and D7 (Monitoring, detection, and response).

  • Domain D5 aims to make people an active part of protecting the industrial operation. Cybersecurity ceases to be the exclusive responsibility of a specialized area and becomes a shared capability among operators, maintenance, engineering, OT managers, IT managers, management, and vendors. Role-tailored training, internal communication, and periodic drills allow the organization to respond in a coordinated manner when a risk situation arises.

  • Domain D6 establishes the capabilities required to protect industrial processes against unauthorized access, configuration errors, uncontrolled changes, or cyberattacks. It includes the protection of industrial zones, control of communications between conduits, identity and access management, system hardening, engineering station protection, vulnerability management, and the application of measures proportionate to the criticality level identified during the risk analysis.

  • Domain D7 develops capabilities to continuously observe the behavior of the industrial operation, identify deviations from expected functioning, and coordinate an effective response. It is not limited to implementing monitoring tools, but establishes how to generate visibility over the operation, manage alerts, investigate an incident, and coordinate actions among operations, maintenance, OT, IT, cybersecurity, and external vendors.

The combination of these three domains allows the organization to evolve from a collection of independent technical controls into an integrated operational capability, where people know their role, protective measures respond to real risk, and the organization is prepared to detect and respond in a coordinated manner when preventive barriers are no longer enough.

 

RECIN to transform architecture into effective controls

The architecture modeled in RECIN during the previous step now makes it possible to decide where security measures should be applied.

The identified zones can be associated with specific protection requirements. Conduits allow analyzing which communications are necessary, which ones should be restricted, and what security mechanisms should be used. Services and dependencies help assess the impact that blocking, isolating, or stopping a particular component would have.

RECIN allows moving from a generic statement like “we must segment the network” to much more precise decisions, such as which zones must be separated, which flows must be monitored, which accesses require greater guarantees, or what controls each component needs based on its function and criticality.

In this way, controls are no longer implemented uniformly and begin to respond to the real risk of each process.

ESCIM to prepare the organization to act

Although RECIN allows designing protection and understanding where activity should be observed, the organization needs to verify if it is prepared to respond. To do this, SG2CI also relies on ESCIM, CCI’s platform for designing and executing industrial cyber incident scenarios.

ESCIM makes it possible to represent how an incident could evolve, what techniques an attacker might use, what evidence could be detected, and what decisions the different responsible parties should make during each phase. The goal is not to predict the exact next incident, but to train coordination capacity before it occurs.

 

Through these scenarios, the organization can verify whether the controls designed in RECIN generate sufficient visibility, whether alerts reach the right people, and whether response decisions take into account operational continuity and the safety of the industrial process.

How to know if this third step is accomplished?

At the end of this phase, the organization should know which controls protect each essential process, what activity needs to be observed, which events should generate an alert, and how to act when an anomalous situation is detected.

It should also be able to demonstrate that response decisions have been rehearsed and that coordination exists between technical and operational areas.

It is not about having all the tools on the market, but about having a coherent capability, proportionate to the risk, and prepared to function under pressure.

 

A final reflection

An industrial plant is not protected simply because it has many controls, just as a city is not safe solely because it has walls. It also needs surveillance, the ability to interpret what is happening, and people prepared to make decisions when a threat appears.

The third lesson proposed by SG2CI is that protection reduces risk, detection prevents the incident from remaining hidden, and response limits its impact on operations.

RECIN allows transforming industrial architecture into controls and observation points. ESCIM allows verifying whether the organization will know how to act when those controls are not enough.

In the next post, we will address the fourth step, which will consist of how to govern the risk introduced by vendors, maintainers, integrators, manufacturers, and external services participating in essential industrial processes.

José Valiente
 CCI Director