ICSE 2024
Fri 12 - Sun 21 April 2024 Lisbon, Portugal

Vahiny Gnanasekaran1, Maria Bartnes1, Tor Olav Grøtan2, Poul Einar Heegaard1. 1: Norwegian University of Science and Technology, Norway; 2: SINTEF Digital.

Abstract:

The number of significant cyberattacks targeted by national state actors is growing in critical infrastructure. Industrial companies rely on detecting and responding appropriately to such attacks by practicing and developing procedures for cyber-incident response. This paper presents the findings from seven semi-structured interviews to identify distinct practices, challenges, and roles regarding cyber-incident response in the petroleum industry. The literature has only previously addressed specific IT, security, or Operational Technology (OT) teams, but has not considered the holistic view of cyber-incident response in industrial control systems between internal roles, and external actors, such as Security Operations Centers, Computer Security Incident Response Teams, emergency response teams, and on-site personnel. To address this, distinct qualitative research methods consisting of document analysis, and workshops as preparation for interviews, and analysis were conducted. A stakeholder diagram displays the most relevant incident response roles, along with a list of current challenges extracted from the interviews. Future research should consider extending the sample, and include other, organizational and procedural factors.

Mon 15 Apr

Displayed time zone: Lisbon change

14:00 - 15:30
Training, knowledge and Industrial challengesEnCyCriS/SVM at Amadeo de Souza-Cardoso
Chair(s): John Eidar Simensen IFE
14:00
20m
Full-paper
Building a Cybersecurity Knowledge Graph with CyberGraph
EnCyCriS/SVM
A: Paolo Falcarin Ca' Foscari University of Venice, A: Fabio Dainese Ca' Foscari University of Venice
14:20
20m
Full-paper
Training Developers to Code Securely: Theory and Practice
EnCyCriS/SVM
A: Ita Ryan University College Cork, A: Utz Roedig University College Cork, A: Klaas-Jan Stol Lero; University College Cork; SINTEF Digital
14:40
20m
Full-paper
On DevSecOps and Risk Management in Critical Infrastructures: Practitioners´Insights on Needs and Goals
EnCyCriS/SVM
A: Xhesika Ramaj Østfold University College (HiØ) / Norwegian University of Science and Technology (NTNU), A: Mary Sánchez-Gordón Østfold University College, A: Vasileios Gkioulos NTNU, A: Ricardo Colomo-Palacios Universidad Politécnica de Madrid
15:00
20m
Full-paper
Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry
EnCyCriS/SVM
A: Vahiny Gnanasekaran Norwegian University of Science and Technology NTNU, A: Maria Bartnes Norwegian University of Science and Technology NTNU, A: Tor Olav Grøtan SINTEF Digital, Poul Einar Heegaard Norwegian University of Science and Technology NTNU