CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 2

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 2

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 2 6912 3456 Centro de Ciberseguridad Industrial

Step 2. You cannot protect what you do not understand

After building governance capacity, many organizations make the common mistake of starting to implement security controls without really understanding what they are protecting.

The question is no longer What controls should we implement? but rather the necessary one: Do we really know our industrial operation?

NIS2 does not require protecting all assets equally. It requires managing risk in a proportionate manner. To achieve this, it is essential to understand how the operation works, what processes are essential, what systems support them, how they communicate with each other, and what impact their interruption would have.

In an industrial plant, the real critical asset is not a PLC or a server; the critical asset is the capacity to maintain operations.

An inventory is not an architecture

Many organizations have inventories with thousands of registered devices. However, when an incident occurs, it is difficult to answer seemingly simple questions:

  • Which industrial process would stop working?

  • What other systems depend on that device?

  • What communications does it use?

  • Which vendor can intervene on it?

  • Which industrial zones could be affected?

An inventory describes isolated elements, whereas an architecture allows an understanding of how the whole system works, and only when we understand the architecture is it possible to properly manage risk.

SG2CI begins by understanding before protecting

Within SG2CI, this second step corresponds to the Risk and Context Management domain, whose objective is to understand the industrial environment before deciding which measures should be implemented.

To do this, it is necessary to identify essential processes, the industrial functions supporting the operation, dependencies between systems, critical communications, and relationships with third parties critical to essential processes.

Only then is it possible to prioritize investments, justify decisions, and apply measures proportionate to the real risk.

RECIN to understand industrial architecture

To facilitate this work, SG2CI incorporates RECIN, CCI’s platform for modeling industrial architectures.

RECIN allows representing the organization and/or essential industrial processes from a logical and functional perspective, identifying zones with system-type components, conduits with communication components that connect services, and showing their relationships.

Its objective is not only to represent infrastructure, but to provide a vision that allows answering questions such as:

  • Which processes are really critical?

  • What dependencies exist between the different zones?

  • What impact would system unavailability have?

  • What controls does each zone require according to its criticality level?

In this way, architecture ceases to be a simple logical drawing and becomes a real risk management tool.

How to know if this second step is accomplished?

At the end of this phase, the organization should clearly know which processes are essential, which components support each of them, what their main dependencies are, and which elements represent a greater impact on operational continuity through their loss of integrity, availability, or confidentiality.

It is not yet about deploying security controls, but about understanding the organization and its essential processes sufficiently so that all subsequent decisions make sense.

A final reflection

Doctors do not operate on a patient without first knowing their anatomy and health. In industrial cybersecurity, the exact same thing happens: we must try to protect a plant by previously understanding its architecture so that investments are effective, priorities are right, and a false sense of security is avoided.

The second lesson proposed by SG2CI is that before protecting assets, one must understand how the industrial operation works.

In the next post, we will address the third step of the roadmap, which will consist of how to progressively implement protection, detection, and response capabilities using the priorities identified in SG2CI and leveraging RECIN’s capabilities to transform architecture into effective controls.

José Valiente
Director  CCI