Understanding compensating controls for Operational Technology
Compensating controls in OT environments are alternative security measures when risks posed by vulnerabilities can't be patched immediately.
In OT environments, systems often cannot be taken offline for updates due to their critical role in infrastructure and production processes. Compensating controls secures the OT environment and reduces the risk until the vulnerability can be fully remediated using permanent solutions, such as patches or hardware replacements.
The following table describes certain scenarios where compensating controls helps in reducing risk:
| Use case scenario | Compensating controls |
|---|---|
| Unauthorized access to programmable logic controllers (PLCs). |
|
| Buffer Overflow in Human Machine Interfaces (HMI) Panels |
|
| Man-in-the-Middle Attacks on PROFINET |
|
| Denial of Service (DoS) on SCADA Systems |
|
| Malware Infection on Engineering Workstations |
|