Everyone agrees that network security is essential for IT systems
But let's not forget that securing OT (operational technology) networks is just as critical in industry as it is in utilities. A successful exploit on an industrial network could halt production, incur enormous costs and even put lives at risk. For OT systems, a secure network is essential, but it is no longer sufficient. There is still the issue of data security.
Before the advent of Industry 4.0 (and today even more so with Industry 5.0), the Internet of Things and the Digital Transition, it seemed quite simple to protect OT networks and data: for some it was enough to disconnect them, if necessary via an air gap . But this is no longer an option for any company that wants to remain competitive.
The modern enterprise needs secure access to OT data to increase efficiency and reduce production costs. The good news is that, with the right approach, secure access to OT data doesn't have to be complicated or expensive. Whatever your level of network security, there are simple and convenient ways to access OT data securely.
Data security is different from network security
As mentioned, there are secure and convenient ways to access OT data. This convenience is possible because data security is different from network security. While data security can be implemented alongside network security and be fully compatible with it, the goals of each are not exactly the same. The difference is a bit like home security.

Managing a system without network security is like leaving a door open, allowing anyone to enter your home. Unwanted visitors can take your belongings or hold your loved ones hostage for ransom. You may also be exposed to viruses from any infected person who enters!
Similarities between network security and a house with an open door
To protect the network, a company could adopt network access with Zero Trust concepts, with significant costs (and complexity). Such a solution often uses VPNs to limit network access to a known number of authorized people. Using a VPN is like only allowing invited guests with a key into your home. These guests can still bring unwanted viruses with them that could infect the family or hide unwanted people. A VPN that extends from the IT network to the OT simply extends the security perimeter to encompass the OT as well. If someone in IT were to receive a phishing email or insert a thumb drive with a virus on board, the malicious code could easily spread to OT as well.

Analogy of a house with shared key and VPN for network security
For data access, a better, cheaper and more secure solution is to simply close the network to everyone and set up secure data connections. It's like opening an invisible mail slot in your door and exchanging messages with an authorized courier. No one will be able to enter your home to bring a virus or hold your family members hostage. When you go to close the mail slot, that door will be locked again. Only the postman will know that it is there and only he is authorized and will be able to deliver or collect messages.

Analogy of a house with invisible mail slot and OT/IT network security
For industrial systems, the invisible mail slot is an outbound firewall port at the plant. The mail carrier is typically a tunneling application or an OPC or MQTT broker running on-premise or in a DMZ. If you use a DMZ, the IT side can implement the same mail slot interface and keep all incoming IT firewall ports closed as well. Using a DMZ between IT and OT is recommended by the EU NIS Directive 2 and NIST SP 800-82 as the best way to separate OT and IT networks. Every network must be secure, and any data connections between them must also be protected. Network security and data security should thus go hand in hand.
OT to IT Network Security Framework: Viable Options
Whatever level or type of network security we implement, we will need the right software and services to gain secure access to all data. If we simply need to isolate our OT system from IT or the Cloud, we can use OPC, MQTT or Sparkplug to establish outgoing connections while keeping all incoming firewall ports closed. Some tunneling/mirroring software, such as Skkynet's Cogent DataHub (distributed and supported by ServiTecno), they can do this and much more. Unlike OPC and MQTT, and in addition to these types of connections, a well-designed tunnel/mirroring solution can transfer data seamlessly across a DMZ in both directions, maintaining connection status and data quality information. data at each stage.

To create an even more secure connection and ensure a one-way data flow, you can also use a data diode. This is a hardware device that allows and enforces only one-way communication and prevents any type of message from the destination from returning to the source. Some tunnel/mirror solutions are fully compatible with data diodes and can also be used to aggregate data originating on the sender side or to distribute data to various clients on the receiving side. At ServiTecno we are equipped and available to provide you with every detail in this regard.
Can we work together?
Remember that network security and data security are both important. They can be implemented separately, but should work together as a single unit. Regardless of the level or type of network security we have, Skkynet (with the support and assistance of ServiTecno) provides the technology and know-how needed to fully integrate them with data security.
Taken from: Network security is not enough for OT data
