
Dragos
SOC, Detection & Response
OT/ICS & Critical Infrastructure Security
Implementing a Defensible Architecture
Joint Dragos + Palo Alto Networks whitepaper (Sept 2023) on building a defensible ICS/OT architecture for the electric power industry. It defines a defensible architecture as one that reduces agreed-upon risk through system design while simplifying human defenders' work, with three pillars: accurate asset visibility and inventory, environment segmentation, and log collection from systems of value. Findings from Dragos services engagements underline the urgency: 86% of electric-industry customers had limited-to-no ICS/OT visibility, 50% of engagements involved poor security perimeters, 54% found shared credentials in OT (the top lateral-movement path), and 17 of 21 tracked threat groups target the electric sector, with APTs and ransomware the two dominant vectors. The paper details how to define the "protection surface," decide where bi-directional vs read-only communication is required, and create segmentation rules based on origin/destination, time of day, and business need. It also lays out a Collection Management Framework covering Windows HMIs, Data Historians, Network Monitoring Appliances, and RTUs across control centers and transmission substations — including data types (Windows Event Logs, alarms, syslog, controller logic) and retention periods (60 days for Windows Event Logs, 120 for alarms, 7 for syslog). The joint solution pairs the Dragos Platform (ICS/OT asset visibility, intelligence-driven threat detection, vulnerability prioritization, address-group export to firewalls) with Palo Alto Networks NGFW (prevention-focused, automated policy enforcement) and supports compliance with NERC-CIP, ISA/IEC 62443, CFATS, and ANSI/AWWA G430.
Sept 2023Read →