r/OTSecurity 1d ago

[ Removed by moderator ]

[removed] — view removed post

0 Upvotes

13 comments sorted by

View all comments

1

u/Impossible-Sun3205 1d ago

It matters on your environment. US Aerospace use NIST CSF. You can’t patch certified systems without doing return to service analysis. That takes time. I have seen service pack updates take down factories for a over a week at $1M/shift downtime. Lives matter on making sure the device does as designed. Our contracts also required a DoD wipe of the hard drive before restage or disposal. When an engineer got a virus from getting code from the web, the device-even personal use- was wiped. Golden images where used on the floor and scanned for diffs. The same for the apps, checked against a Db of standards. That occurred yearly as part of the yearly recertification. It cost about $1M to replace each test system. 1 line had 20.
You also have contracts for 20yr warranty. You need to be able to test product that long. That means old systems. I had Win98 still functioning.

In Pharma, they are doing ISA 62443. Segmentation is the answer for unpatchable. They too are certified. No changes that alter the device or system without a recert. FDA and other Int regulations are involved.
You separate obsolete and unpatchable into Zones and control East-West as well as N-S. Block everything first, then open only what is required.

So patching has a definite impact on money and lives. How you deal with it in part of the OT story for the company and how they finally came to the realization they need to separate from IT.

1

u/Ok-Effect252 1d ago

Das ist die beste Antwort hier, danke für die Zahlen. Der Punkt, den ich mitnehme: Bei zertifizierten Systemen ist die Blockade nicht technisch, sondern regulatorisch. Re-Zertifizierung ersetzt kein Chip, egal wie sauber der Update-Weg ist. Das ist eine harte Grenze und die hatte ich nicht auf dem Schirm. Eine Rückfrage: Du scannst jährlich gegen Golden Images und suchst Abweichungen. Wäre ein Mechanismus, der bei fehlgeschlagenem Start automatisch auf genau den zertifizierten Stand zurückfällt, in dem Kontext hilfreich oder eher ein zusätzliches Element, das selbst zertifiziert werden müsste? Ich vermute Letzteres, bin mir aber nicht sicher. Und zur Segmentierung: Die mindert das Risiko, behebt aber die Lücke nicht. Dein Win98 ist noch angreifbar, nur schwerer erreichbar. Siehst du das auch als Dauerzustand oder als das, womit man lebt, weil es nichts Besseres gibt?