## Securing ICS – going beyond IT

It is often stated that industrial control system (ICS) environments are difficult to protect from cyber attack. The use of legacy equipment, extended system life cycles, real-time requirements etc. are often quoted as reasons why ICS is so difficult to protect. These are valid arguments and should not be dismissed; however, the danger with this message is that ICS owner/operators may become daunted by prospect of implementing a cyber security programme. There is little acknowledgment of how the characteristics of ICS can be leveraged to provide a significant security benefit. Applying IT best practise is not always suitable for ICS environments, causing operational issues and security controls that fail to reach their potential. ICS environments allow the implementation of strict deny-by-default, allow-by-exception policies. Such strict configurations may be unmanageable in many IT environments due to the fluid nature within IT, where users may want to use a variety of different programmes and services. ICS environments are much more static meaning that strict configurations are manageable, resulting in a more robust control system where compliance with change management procedures and health and safety executive (HSE) work permit systems are enforced and auditable. By blindly applying IT policy, the benefits of this environment could be missed.

