Skip to main content

Measures to protect industrial control systems (ICSs)

Securing industrial control systems (ICSs) protects data, infrastructure, processes and people. The NCSC has summarised the key measures.

Control systems consist of one or more devices that control, regulate or monitor the behaviour of other devices or systems. In industrial production, the term industrial control system (ICS) is commonly used.

For some time now, ICSs have also been increasingly used outside of manufacturing, for example in home automation or traffic control. In principle, any system that regulates or monitors a physical process can be called an ICS. Most of the basic rules for protecting such systems also apply outside industrial production.

Security is an ongoing process, not a one-off project. The following measures provide an overview of the most important steps to take. A good place to start is with measures that have a major impact with relatively little effort, such as changing all default passwords.

Key measures at a glance:

  • Asset database for all devices
    Maintain a comprehensive inventory of all ICS devices and associated systems. You can only protect your network effectively if you know what is connected to it. An automatic alert should be triggered whenever an unknown device connects to the network.
  • Software inventory and patch management
    Keep a record of all software in use and implement systematic patch and lifecycle management. Enable allowlisting on critical devices so that only known and approved programs can be run.
  • Secure configurations
    Change all default passwords and consistently follow the manufacturers' hardening guidance, in other words their instructions for secure configuration. Administration interfaces must never be directly accessible from the internet. Software signing should be enabled wherever possible.
  • Robust network architecture
    ICS networks and office networks must be strictly separated or isolated from one another using clearly defined network zones. Remote access should only be permitted via VPN with two-factor authentication. Network traffic should be encrypted throughout.
  • Multi-layer malware protection
    Make sure that all connected Windows systems are protected by up-to-date antivirus software. It is important that protection works on several levels, so that malware that makes it past one layer is detected at the next. Direct internet connections from the systems should be prevented.
  • Authentication and authorisation
    Assign access rights consistently according to the principle of least privilege, including for external maintenance companies. Two-factor authentication should be mandatory for exposed interfaces. There should be no standard accounts with preset passwords.
  • Central log analysis
    Collect and analyse logs from all system classes centrally. Define a baseline for normal operational events. Anything that deviates from this baseline must be investigated. As successful attacks are often only discovered months later, retaining logs for a sufficient amount of time is crucial.
  • Physical protection
    Physical protection must extend beyond the ICSs themselves to include peripheral systems, administration systems, and remote installations. Every physical interface is a potential access point and must be secured accordingly.
  • Backup and recovery
    Clear backup processes should be defined and tested for recovery at least every six months. Include configuration files in backups. Regularly check the integrity of backups using cryptographic hash values.
  • Security incident management
    Prepare for incidents before they happen by establishing clear processes, defining responsibilities, and carrying out regular exercises. After every incident, carry out a root cause analysis and use the results to identify specific improvements.
  • Security culture
    Security is not just an IT issue. It must be integrated into all business processes and anchored at senior management level. Having an independent role with the necessary resources and powers ensures that risks are communicated upwards without being filtered or distorted.

SANS, a security institute in the United States, has published 20 key controls that can be used to protect IT infrastructures in general. Some of these controls can also be applied to ICSs. Further recommendations have been issued by the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) and the National Institute of Standards and Technology (NIST). The NCSC's recommendations are based on these documents.

Further information

ICT minimum standard