Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry
Vahiny Gnanasekaran1, Maria Bartnes1, Tor Olav Grøtan2, Poul Einar Heegaard1. 1: Norwegian University of Science and Technology, Norway; 2: SINTEF Digital.
Abstract:
The number of significant cyberattacks targeted by national state actors is growing in critical infrastructure. Industrial companies rely on detecting and responding appropriately to such attacks by practicing and developing procedures for cyber-incident response. This paper presents the findings from seven semi-structured interviews to identify distinct practices, challenges, and roles regarding cyber-incident response in the petroleum industry. The literature has only previously addressed specific IT, security, or Operational Technology (OT) teams, but has not considered the holistic view of cyber-incident response in industrial control systems between internal roles, and external actors, such as Security Operations Centers, Computer Security Incident Response Teams, emergency response teams, and on-site personnel. To address this, distinct qualitative research methods consisting of document analysis, and workshops as preparation for interviews, and analysis were conducted. A stakeholder diagram displays the most relevant incident response roles, along with a list of current challenges extracted from the interviews. Future research should consider extending the sample, and include other, organizational and procedural factors.
Mon 15 AprDisplayed time zone: Lisbon change
14:00 - 15:30 | Training, knowledge and Industrial challengesEnCyCriS/SVM at Amadeo de Souza-Cardoso Chair(s): John Eidar Simensen IFE | ||
14:00 20mFull-paper | Building a Cybersecurity Knowledge Graph with CyberGraph EnCyCriS/SVM A: Paolo Falcarin Ca' Foscari University of Venice, A: Fabio Dainese Ca' Foscari University of Venice | ||
14:20 20mFull-paper | Training Developers to Code Securely: Theory and Practice EnCyCriS/SVM A: Ita Ryan University College Cork, A: Utz Roedig University College Cork, A: Klaas-Jan Stol Lero; University College Cork; SINTEF Digital | ||
14:40 20mFull-paper | On DevSecOps and Risk Management in Critical Infrastructures: Practitioners´Insights on Needs and Goals EnCyCriS/SVM A: Xhesika Ramaj Østfold University College (HiØ) / Norwegian University of Science and Technology (NTNU), A: Mary Sánchez-Gordón Østfold University College, A: Vasileios Gkioulos NTNU, A: Ricardo Colomo-Palacios Universidad Politécnica de Madrid | ||
15:00 20mFull-paper | Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry EnCyCriS/SVM A: Vahiny Gnanasekaran Norwegian University of Science and Technology NTNU, A: Maria Bartnes Norwegian University of Science and Technology NTNU, A: Tor Olav Grøtan SINTEF Digital, Poul Einar Heegaard Norwegian University of Science and Technology NTNU |