Stefanos Evripidou
Exploring the Security Culture of Operational Technology (OT) Organisations: The Role of External Consultancy in Overcoming Organisational Barriers
Evripidou, Stefanos; Ani, Uchenna D; Hailes, Stephen; McK. Watson, Jeremy D
Abstract
Operational Technology (OT) refers to systems that control and monitor industrial processes. Organisations that use OT can be found in many sectors, including water and energy, and often operate a nation's critical infrastructure. These organisations have been under a digitalisation process, which along with increasing regulatory pressures have necessitated changes in their cybersecurity practices. The lack of internal resources has often compelled these organisations to turn to external consultancy to enhance their security. Given the differences between OT and Information Technology (IT) security practices and that OT cybersecurity is still in its infancy, developing a security culture in OT environments remains a challenge, with little research investigating this topic. We have conducted 33 interviews with professionals with a security related role working in various OT sec-tors in the UK, on the subject of security culture development. Our analysis indicates three key organisational barriers to the development of a security culture: governance structures, lack of communication between functions, and the lack of OT cybersecurity expertise. Subsequently, the role of consultants and security solution vendors in overcoming these barriers through consultancy is demonstrated. We therefore argue that these stakeholders play a crucial part in the development of security culture in OT and conclude with recommendations for these organisations.
Citation
Evripidou, S., Ani, U. D., Hailes, S., & McK. Watson, J. D. (2023, August). Exploring the Security Culture of Operational Technology (OT) Organisations: The Role of External Consultancy in Overcoming Organisational Barriers. Presented at Nineteenth Symposium on Usable Privacy and Security (SOUPS 2023), Anaheim, California, USA
Presentation Conference Type | Speech |
---|---|
Conference Name | Nineteenth Symposium on Usable Privacy and Security (SOUPS 2023) |
Conference Location | Anaheim, California, USA |
Start Date | Aug 6, 2023 |
End Date | Aug 8, 2023 |
Deposit Date | Jan 31, 2024 |
Publisher URL | https://www.usenix.org/conference/soups2023/presentation/evripidou |
Related Public URLs | https://www.usenix.org/conference/soups2023/technical-sessions |
You might also like
Digital twins in cyber effects modelling of IoT/CPS points of low resilience
(2023)
Journal Article
Super-forecasting the 'technological singularity' risks from artificial intelligence
(2022)
Journal Article
Downloadable Citations
About Keele Repository
Administrator e-mail: research.openaccess@keele.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search