Every external network connection (ENC) creates a potential pathway into or out of your environment. Like the doors and windows in a building, each one is a deliberate opening in an otherwise solid perimeter, and each one is a potential weak spot in your attack surface. Putting a lock on a door does not eliminate the opening. A locked door is still a risk, just one that is being managed, hopefully in a manner consistent with the threat environment and the consequences of a breach.
The challenge in OT is that external network connections are often poorly controlled as they get introduced. During capital projects, there is often little formal process to document the connection design and assess its risk. After the project is handed over, operations may add new connections without proper documentation or risk assessment, usually to solve a legitimate problem on a tight timeline. A vendor package arrives with its own remote support link already built in. A cell modem goes in for a two-week troubleshooting campaign and is still there six years later. A fiber run crosses a public right-of-way and routes through a third-party enclosure. Connections like these often go undocumented, are never formally assessed, and are protected far less than the systems they can reach.
This webinar presents a method for identifying and documenting external connections, assessing their risk, and deciding whether they should be approved or modified. We will cover how to scope what counts as an external network connection, how to apply ISA/IEC 62443-3-2 standard to characterize it using zone and conduit modeling, and how to conduct a risk assessment using CyberBowtie or other techniques.
- The presentation will cover a framework for an ENC management program,
- a guided questionnaire/template,
- a quantitative risk assessment approach, and
- a phased rollout path that ties ENC assessment into capital project lifecycle and management of change.
The session is intended for OT and ICS cybersecurity practitioners, control system and network engineers, process safety engineers, and operations, compliance, and risk professionals who support them.
Wed, Oct 28, 1:00 PM – 2:00 PM EDT – Can’t attend live? A recording will be emailed to all registered end users.
