Blogs & Stories

Trustwave Blog

The Trustwave Blog empowers information security professionals to achieve new heights through expert insight that addresses hot topics, trends and challenges and defines best practices.

Trustwave Announces Operational Technology Security Maturity Diagnostics

Trustwave has just launched OT Security Maturity Diagnostic, which is an assessment and advisory service centered on ensuring the security of industrial automation and control systems.

OT Diagnostic by Trustwave is optimized to gain insight into an organization’s current state of OT security across people, processes, and technology. This service is increasingly necessary to defend against threat actors attempting to take advantage of the evolving convergence of IT/OT and the vulnerable data transfer between systems and networks.

Operational Technology environments tend to be unique, designed to conduct specific tasks, and in many cases, not designed with security in mind. In fact, many were created before cybersecurity was a primary concern. Trustwave realizes the constraints in many OT environments and that standard information technology security models and frameworks do not fully support these special requirements. 

Delivered through its Consulting and Professional Services business, Trustwave’s team of OT experts will baseline an OT cybersecurity posture and build a roadmap leading to a mature strategy.

The Benefit of OT Maturity Diagnostic by Trustwave

Trustwave can undertake and complete an assessment in a relatively short period of time allowing for quick feedback to the business regarding risks and recommendations. 

Trustwave’s experts take a collaborative workshop approach with clients, enabling findings and recommendations to be discussed in an open and informed way with internal teams to maximize learning opportunities and ensure that key parts of the business and operations are engaged. 

The team will:

  • Align your cyber programs’ target state to best practices and established standards.
  • Align security and business requirements to baseline the cybersecurity program.

Identify top risks to generate “quick wins” to help decision-makers mature the organization efficiently and effectively.  Deliver quick feedback to the business to support broader initiatives, business alignment, and visibility into risks.

Trustwave understands that all client projects are important and require appropriate planning and alignment. Therefore, Trustwave follows a clear, consistent, and distinct set of project activities to enable effective and efficient delivery. 

At the end of the engagement, all customers will receive an Assessment Report that is tailored to the organization’s needs with findings and recommendations organized by identify, protect, detect, respond, and recover.  The assessment report contains the following:

Executive Review: The Executive Review provides a high-level overview for the executive team. The review includes the synthesis of report findings and recommendations and allows quick identification of strengths and opportunities.

Gap analysis and assessment details: This section presents the detailed findings and observations regarding the gaps between your current and desired states of maturity. The details help define foundational capabilities and document operational cybersecurity challenges. Operational domain analysis across people, processes, and technology, which support the enterprise cybersecurity functional risk categories, provides a more prescriptive plan to empower the organization. The operational analysis includes the following domains:

  • Governance & Policy
  • Risk Management
  • Asset Management
  • Identity & Access Management
  • Awareness & Training
  • Processes & Playbooks
  • Monitoring & Detection
  • Continuity, Contingency, & Recovery Planning
  • Technology & Architecture
  • Metrics & Reporting

Roadmap: This section of the final report shows how an organization can move from its current state to where it needs to be in a defined timeframe. The roadmap will help identify and articulate the vision for advancing the maturity of your OT security program, create actionable steps for achievement, and provide a narrative to obtain stakeholder engagement and define requirements.

The Trustwave Advantage

Trustwave believes using a mature defense-in-depth approach to industrial automation and control systems is crucial. With malicious actors continuously advancing their technical capabilities and resources to attack OT/IT networks, relying on security through obscurity or air-gapped networks is no longer practical to protect your infrastructure.

Trustwave bases its OT Security Maturity Diagnostic service offering on NIST CSF and ISA/IEC 62443 (Cyber Security Controls for Automated and Control System Environments).

Finally, once the diagnostic results are known, Trustwave can provide consultancy services to help an organization bolster resilience to threats to its OT environment. Our specialized delivery team has broad experience across the functional domains and emerging cybersecurity areas. In addition, team members have extensive cybersecurity knowledge and experience solving complex security, data, and infrastructure challenges and can articulate issues at the technical and board levels.