Category: OT Cybersecurity

  • The NCA OTCC Compliance Gap: Why 77% of Saudi Infrastructure Operators Are Exposed

    The Compliance Gap Is Real and Documented

    The National Cybersecurity Authority’s assessments of OT cybersecurity posture across Saudi Arabia’s critical infrastructure sectors consistently find a significant gap between the OTCC requirements and the actual security posture of operational facilities. Industry analysis suggests that a substantial majority of OT environments in the Kingdom’s critical infrastructure — estimates range from 65-80% — do not fully meet the OTCC baseline requirements.

    This is not a surprising finding to anyone who has assessed OT environments in the Kingdom. Most of the facilities currently operating in Saudi Arabia’s energy, water, transport, and industrial sectors were designed and commissioned before OT cybersecurity was a defined engineering requirement. The control systems are functional and often well-maintained from a process engineering perspective. But the cybersecurity dimensions — network segmentation, access control, monitoring, incident response capability — were not part of the original design scope because they were not required when the systems were built.

    Why the Gap Exists

    The OT cybersecurity compliance gap in Saudi Arabia has three primary sources.

    Legacy systems designed without security. Most operational OT environments in the Kingdom were commissioned between the 1980s and the 2010s — before OT cybersecurity frameworks existed and before the threat landscape had developed to the point where OT attacks were considered a realistic operational risk. The engineers who designed those systems were not negligent; they designed to the standards and threat understanding of their time. But the systems they designed are now connected to broader networks in ways that were not anticipated, running software versions that are no longer supported, and exposed to threat actors whose capability has grown significantly since commissioning.

    The IT/OT organizational split. In most Saudi critical infrastructure operators, the IT function and the OT function are organizationally separate and often have limited interaction. IT security teams understand network security, identity management, and cyber incident response in the IT context. OT engineering teams understand process control, instrumentation, and operational continuity. The intersection — OT cybersecurity — requires both sets of expertise, and the organizational structure rarely creates effective collaboration between them.

    Project scope exclusion. Even new facilities being designed and commissioned now frequently do not include OT cybersecurity requirements in their design scope. The project team is an engineering team. The controls integrator is a specialist in process control, not cybersecurity. Unless OT cybersecurity requirements are explicitly included in the project scope — which requires the project owner to specify them and the project team to price them — they will not appear in the delivered system.

    The Regulatory Trend

    The NCA’s enforcement engagement across sectors has been progressively increasing. The OTCC is not a voluntary framework and the NCA’s posture has shifted from guidance and awareness to compliance assessment and enforcement. Organizations that are not addressing the compliance gap are accumulating regulatory exposure that is distinct from — and in addition to — the operational security risk they carry.

    The enforcement approach the NCA has developed draws on the model established by other mature regulatory frameworks for critical infrastructure: assessment of compliance posture against the framework requirements, identification of material gaps, issuance of remediation requirements with defined timelines, and escalating consequence for organizations that fail to demonstrate progress against those requirements.

    What Organizations Need to Do

    The practical path to OTCC compliance starts with an honest assessment of current posture. Not a self-assessment produced by the OT engineering team, which will reflect what the team knows how to assess, but an independent OT security assessment conducted by specialists with both OT knowledge and cybersecurity expertise. That assessment establishes the gap against the OTCC framework, prioritizes findings by risk level, and produces a remediation roadmap that the organization can execute against.

    For facilities currently in design or construction, the most cost-effective approach is to address OT security requirements in the design scope before the network architecture is locked and before control system procurement is completed. Changing a network architecture at 60% design is expensive. Changing it after commissioning is very expensive. Not changing it and receiving a compliance finding is potentially more expensive still.

    Concept Dash offers complimentary OT gap assessments for infrastructure operators in the Kingdom. If your facility is among the majority that have not yet fully addressed the OTCC compliance requirements, a conversation now is significantly less expensive than a compliance enforcement action later. Visit conceptdash.ca or send a direct message.

  • Where OT Security Meets BIM: The Convergence That Infrastructure Engineers Must Understand

    The Convergence Point

    Building Information Modelling has evolved well beyond its origins as a 3D drafting tool. Modern BIM models for major infrastructure projects contain not just the geometric information of the physical asset, but rich data about the systems embedded in that asset: mechanical equipment specifications, electrical system design, control panel locations, network infrastructure routing, instrumentation placement, and increasingly, the data architecture of the operational technology networks that will control the facility once it is commissioned.

    That evolution has created a convergence point that the infrastructure engineering community has not fully recognized: BIM models now contain detailed information about OT network topology — information that has significant security implications if the model is not itself properly secured and if the OT design information it contains is not reviewed through a cybersecurity lens during the design phase.

    What BIM Models Reveal About OT Systems

    A detailed BIM model for a water treatment plant, a power substation, or a district cooling facility contains the location of every PLC cabinet, every SCADA workstation, every HMI, every network switch in the control system, and the routing of the control system cabling between them. It contains the logical architecture of the control system — which equipment is controlled by which PLC, how the PLCs communicate with each other and with the supervisory SCADA system, and how the SCADA system connects to the corporate IT network for reporting and remote access.

    This information is essential for the engineering team designing and installing the control system. It is also a detailed map of the OT network topology that a threat actor with access to the BIM model could use to plan an attack on the facility’s operational technology systems. The same information that makes the BIM model useful for engineering is what makes it valuable to a malicious actor — if they can access it.

    The Design Stage Integration Opportunity

    The convergence of BIM and OT cybersecurity creates a significant opportunity that most infrastructure projects are not currently capturing: the integration of OT security review into the BIM design process at the point when the OT network architecture is being developed.

    When OT security specialists review the BIM model at the network architecture design stage — typically at 30-40% design completion — they can identify security weaknesses in the OT network design and recommend modifications before the architecture is committed to detailed design and procurement. A network segmentation gap that is visible in the BIM model at 35% design is resolved through a design revision. The same gap discovered during commissioning requires physical network modifications, software reconfiguration, and delays to the commissioning programme.

    The practical process is straightforward: include OT security review as a formal gate in the BIM design review process, alongside structural, mechanical, and electrical reviews. The OT security reviewer examines the control system design elements of the BIM model against the applicable security framework (IEC 62443, NCA OTCC) and produces a findings report with design-stage recommendations. The project team incorporates the recommendations into the design before the review milestone.

    Digital Twin Security

    The convergence extends into operations through digital twins. A digital twin that contains real-time OT operational data — sensor readings, equipment status, network traffic patterns — is an information asset that requires the same security consideration as the OT environment itself. If the digital twin is connected to the OT network and accessible through the corporate IT environment or externally, the security of that connection needs to be designed as carefully as the security of the OT network it mirrors.

    Concept Dash’s combined BIM and OT cybersecurity capability — integrating our digital twin practice with our OT security team — positions us to provide this integrated design review for infrastructure projects in Saudi Arabia. If you are developing a BIM model for a facility that will have significant OT infrastructure, the time to integrate the security review is now, not at commissioning. Contact us to discuss how this can be incorporated into your project’s design workflow.

  • Saudi Arabia’s OTCC Framework: What Regulators Require and What It Means for Infrastructure Projects

    The Regulatory Context

    Saudi Arabia has one of the most developed OT cybersecurity regulatory frameworks in the Middle East. The National Cybersecurity Authority’s Operational Technology Cybersecurity Controls — known as the OTCC — establish the baseline requirements that critical infrastructure operators in the Kingdom are expected to meet. This is not a voluntary standard or a best-practice guideline. It is a regulatory expectation, and the NCA’s enforcement engagement across sectors has been progressively increasing.

    The OTCC applies to organizations that own or operate critical national infrastructure in Saudi Arabia: energy, water, transport, communications, health, and financial services. If you are delivering or operating infrastructure in any of these sectors in the Kingdom, the OTCC defines your regulatory baseline for OT security.

    The Five OTCC Domains

    OT Cybersecurity Governance is the first domain and the foundational one. It covers the organizational policies, roles, and responsibilities that define how OT security is managed at the institutional level. This includes having a designated OT security function — not just relying on the IT security team — documented policies for OT asset management, change control, and risk management, and integration of OT security into the organization’s overall risk management framework. Governance means accountability: someone in the organization needs to own OT security, have the authority to make decisions about it, and have the resources to execute those decisions.

    OT Risk Management is the second domain. It requires formal OT security risk assessments conducted on a defined cadence, maintenance of an accurate and current OT asset inventory (which most organizations do not have), and implementation of a risk treatment plan that addresses identified vulnerabilities in a prioritized and documented way. The risk management discipline the OTCC requires is not a one-time compliance exercise. It is an ongoing management practice that needs to be embedded in the organization’s standard operating procedures.

    OT Security Controls covers the technical measures that protect OT environments. Network segmentation between IT and OT networks is the most fundamental control — and the one most frequently absent in older facilities. Access controls including multi-factor authentication for remote connections. Configuration management for controllers and systems, ensuring that changes to OT system configurations are tracked, approved, and reversible. Patch management processes designed for the OT environment, which often cannot be patched on the same schedule as IT systems without affecting process continuity.

    OT Security Operations covers the monitoring, detection, and incident response capabilities that enable organizations to identify threats and respond to them. This is the area where most OT environments are most exposed. Network monitoring that is standard in enterprise IT — intrusion detection, anomaly alerting, traffic analysis — is frequently absent in OT networks. The monitoring gap is significant: you cannot detect and respond to threats you cannot see.

    OT Supply Chain Security addresses the security of third-party vendors, integrators, and service providers who have access to OT systems. This is particularly relevant for infrastructure projects where the controls vendor, commissioning team, and ongoing support provider all typically have remote access paths into the OT environment. The OTCC requires that these access paths be managed — not just opened and forgotten.

    What This Means for Project Design

    For infrastructure projects in design or construction, OTCC requirements translate into specific design decisions that need to be made while the project is still being engineered. Network architecture must provide appropriate IT/OT segmentation. Control system design must accommodate the access control requirements the OTCC specifies. Commissioning procedures must include OT security validation alongside process safety validation.

    The critical point is timing. These are not features that can be economically retrofitted after commissioning. They are design decisions. A network segmentation architecture specified at 30% design completion costs a fraction of what the same segmentation costs after a system has been commissioned with a flat network architecture.

    At Concept Dash, our OT cybersecurity team — working through our partnership with our NACSA-licensed cybersecurity partner — helps project teams translate OTCC requirements into design specifications and commissioning requirements before the design window closes. Reach out for a complimentary gap assessment if your infrastructure project has not yet addressed OT security in the design scope.

  • What an OT Security Assessment Actually Involves: A Practical Guide for Infrastructure Projects

    Making OT Cybersecurity Practical

    Over the past weeks I have made the case that OT cybersecurity is an engineering design problem, not an IT department problem. This article makes that case practical: what does an OT security assessment actually involve, what does it produce, and what does it mean for the way a project is designed and delivered?

    What an OT Security Assessment Is

    An OT security assessment is a structured evaluation of the cybersecurity posture of an operational technology environment. It covers the systems that control physical processes — PLCs (Programmable Logic Controllers), SCADA systems (Supervisory Control and Data Acquisition), DCS (Distributed Control Systems), SIS (Safety Instrumented Systems), HMI workstations (Human Machine Interfaces), and the network infrastructure that connects them.

    For infrastructure projects, the most relevant international framework is IEC 62443 — the international standard for industrial automation and control systems security. In Saudi Arabia, the NCA’s Operational Technology Cybersecurity Controls (OTCC) establish the regulatory baseline. These two frameworks overlap significantly and together define what good OT security looks like in this region and market.

    Scope of a Comprehensive OT Assessment

    Asset inventory and identification is the starting point. This sounds simple; it rarely is. Most operational facilities do not have an accurate, current inventory of their OT assets — what controllers they have, what software versions they run, how they are connected, who has access to them. Building that inventory is a prerequisite for everything else. Without it, you cannot assess vulnerability, cannot prioritize mitigation, and cannot demonstrate compliance.

    Network architecture review examines how the OT network is structured and how it relates to the corporate IT network and external connectivity. The fundamental principle of OT network security is segmentation — the OT network should be separated from the IT network by a defined boundary (typically a demilitarized zone) that controls and monitors the flow of information between them. Many operational facilities, particularly those built before OT cybersecurity became a serious design consideration, have flat network architectures where IT and OT systems are on the same network segment. This is the condition that made the Triton attack possible: the attackers could reach the safety controllers from the corporate network because the segmentation boundary did not exist.

    Vulnerability assessment identifies specific known vulnerabilities in the OT assets identified in the inventory. OT systems run specialized software, including real-time operating systems, controller firmware, and HMI applications that often run on versions of Windows that are no longer supported by Microsoft — because the OT vendor’s engineering software has not been updated to run on current Windows versions and the vendor’s update schedule is not aligned with Microsoft’s. This creates a patching problem that is fundamentally different from IT security: in IT, the answer to an unpatched operating system is to update it; in OT, the update may break the process control application, and the update cycle is measured in years, not months.

    Access control review examines who has access to OT systems and how that access is managed. Remote access — used by controls vendors for monitoring and support — is one of the most significant and most undercontrolled access paths in OT environments. Many OT systems have remote access channels installed by vendors during commissioning that remain active, unmonitored, and without multi-factor authentication for the life of the system.

    Incident response assessment covers the organization’s capability to detect, respond to, and recover from OT security incidents. In most OT environments, this capability is underdeveloped or absent. There is no OT-specific incident response procedure. There is no OT network monitoring that would alert operations staff to anomalous activity. The water treatment attack in Oldsmar, Florida succeeded in reaching the SCADA system because there was no monitoring that would have detected the intrusion — it was caught by a human who happened to be watching.

    Assessment Output and Project Integration

    A properly scoped OT security assessment produces a risk-ranked findings report, a gap analysis against the applicable framework (IEC 62443 and/or NCA OTCC), and a remediation roadmap that prioritizes findings by risk level and provides specific technical and procedural recommendations for each.

    For projects in design or construction, the assessment findings translate directly into design specifications. Network segmentation requirements become network architecture drawings. Access control requirements become commissioning standards. Monitoring requirements become scope items for the control system integrator.

    This is where the design stage timing matters most. Incorporating OT security requirements into the design scope costs a fraction of retrofitting them after commissioning. A network segmentation architecture specified at 30% design becomes a standard part of the control system procurement. The same requirement identified after a system has been commissioned requires physical network modifications, software reconfiguration, and often a controls vendor engagement that costs 10-20 times what the original specification would have cost.

    Concept Dash’s OT cybersecurity team offers complimentary gap assessments for infrastructure operators in Saudi Arabia. If your facility or program has not addressed OT security in the design scope, reach out before the design is committed — not after.

  • The Blind Spot in Infrastructure Delivery: OT Cybersecurity and the Triton Attack

    The Attack That Targeted Physical Destruction

    In 2017, a cyberattack hit a petrochemical facility in Saudi Arabia. Not the corporate network. Not the email server. The Safety Instrumented System — the engineered last line of defence designed to prevent explosions, chemical releases, and loss of life when process conditions exceed safe operating limits.

    The malware was called Triton. Also known as TRISIS. It was purpose-built to compromise Schneider Electric’s Triconex safety controllers — systems installed in facilities precisely because they are supposed to be the failsafe when everything else goes wrong. The intent of the attack was not data theft. It was not ransomware. It was physical destruction of the facility and harm to the people working in it.

    The only reason it did not succeed was a coding error in the malware that triggered a plant shutdown before the payload fully deployed. The attackers were sophisticated enough to develop malware targeting a specific safety controller platform. They made a programming mistake that triggered an emergency shutdown — which alerted the facility’s security team to the intrusion.

    That was 2017. The capability that failed in 2017 has had eight years to improve.

    This Is Not an Isolated Event

    In 2021, an attacker gained access to the SCADA system of a water treatment plant in Oldsmar, Florida, and attempted to increase sodium hydroxide levels to 100 times the safe concentration. The attack was spotted by an operator watching his screen in real time. There was no automated alert. No intrusion detection system. No OT network monitoring. Just a human who happened to be looking at the HMI at the right moment.

    In 2015 and 2016, coordinated cyberattacks on Ukraine’s power grid caused blackouts affecting hundreds of thousands of people. The attackers did not target the utility’s IT network primarily. They targeted the operational technology systems that control circuit breakers and distribution substations — the systems that physically switch power on and off across the grid.

    These are not IT security problems that the IT department should have caught and prevented. They are attacks on the Operational Technology systems that control physical processes — and they are successful precisely because OT environments are almost never designed with cybersecurity as a requirement.

    The Design Gap That Creates the Vulnerability

    Most infrastructure facilities being designed, built, and commissioned today have the following in common: the engineering team designed the SCADA architecture. The controls integrator programmed the PLCs and DCS. The facility was commissioned and handed over. And at no point in that process did anyone assess whether the OT network is properly segmented from the corporate IT network, whether the HMI workstations are running patched operating systems, whether the remote access paths used by the controls vendor for ongoing support are secured against unauthorized access.

    This is not a technology gap. The technologies for OT network segmentation, OT-appropriate access control, and OT network monitoring exist and are proven. It is a design gap. OT cybersecurity requirements are not included in project scope because they are not understood as engineering design requirements — they are perceived, incorrectly, as an IT operational concern that someone else will handle after commissioning.

    Why the Middle East Is a High-Priority Target

    The combination of factors that makes the Middle East a high-value target environment for OT-focused threat actors is well documented in the threat intelligence community. Concentration of critical infrastructure — energy, water, petrochemical, transport — in a geopolitically significant region. Rapid digitalization and connectivity of operational systems that were previously air-gapped. A geopolitical environment that motivates state-sponsored threat actors with the capability and patience to conduct sophisticated OT attacks.

    Triton targeted a Saudi facility. The most capable OT malware ever publicly analysed was built specifically to attack infrastructure in this region. That is not a coincidence, and it is not a threat that has diminished since 2017.

    What Infrastructure Engineers Need to Do Now

    OT cybersecurity should be on every infrastructure project’s risk register, from early design through commissioning and into operations. Not as a future consideration. Now. Specifically, this means including OT security requirements in the project scope at the design stage, engaging OT security specialists to review the control system architecture before it is locked, and ensuring that commissioning procedures include OT security validation alongside process safety validation.

    The frameworks exist. IEC 62443 provides the international standard for industrial control system security. In Saudi Arabia, the NCA’s Operational Technology Cybersecurity Controls (OTCC) establish the regulatory baseline that critical infrastructure operators are expected to meet. Understanding and designing to these frameworks is a professional responsibility for anyone delivering infrastructure in this region.

    Concept Dash’s OT cybersecurity team — working through our partnership with a NACSA-licensed cybersecurity firm — provides OT gap assessments and security design services for infrastructure projects in Saudi Arabia and the GCC. The cost of an assessment at design stage is a fraction of the cost of a compliance finding, a breach, or a physical safety incident after commissioning.