How to assure enterprise defence operations against the cyber threat

A UK-based defence organisation has a diverse manufacturing and engineering estate, from precision electronics factories to heavy manufacturing. These are made up of legacy businesses, and by its nature, operational technology can contain equipment commonly 20 to 30 years old, which has never been cyber assured. Project One led a programme to drive the enterprise to cyber assure and secure operational technology assets across all factories and buildings. This was preceded by an innovative project to secure all high-volume plants, designed and led by Project One in the prior two years.

Challenge

The small product, high-volume division secured a long-term contract with a government defence agency to supply product over a 15-year period. This required the three manufacturing sites and two testing locations to have their operational technology assured to international cybersecurity standards. This had never been done before and was required in a challenging timescale.

 

As the cybersecurity project mobilised, the board realised that they were carrying previously unknown risks through the vulnerabilities inherent in the aging manufacturing and engineering equipment. The risks of compromise and business continuity had to be swiftly addressed.

 

Once the cybersecurity project was well established, the rest of the corporation grew to realise that the same challenges existed in every corner of the business. A Group led cybersecurity assurance programme was developed to lead all component lines of business to discover their operational technology baseline, assess their systems in order of criticality and to remediate the findings.

 

The professional assurance of the total operational technology estate gave credibility to public and private sector clients and was soon followed by standards and mandates to do just what the programme had been set up to deliver.

 

As the programme proceeded, areas of business continuity problems were brought to light, and areas where operational effectiveness could be improved. Knowing and managing the baseline allowed critical vulnerabilities to be managed and resolved, which was not easily achievable before.

 

The impact of not having followed this course of action would have been an ever more vulnerable situation at a time when operational technology cybersecurity attacks are on the rise. Customer confidence would have eroded, and the risk of an adverse event was high.

Approach

During the high-volume business cybersecurity project, we worked with the local IT team to develop a bespoke process to assess all operational technology across five sites. There was no prior playbook as such a project had not previously been attempted. A team was recruited to carry out assessments, with extensive cybersecurity expertise. A rich set of artefacts were created, to accelerate future phases.

 

The team assured all Official Sensitive production lines as required under the long-term supply agreement, and all Secret lines as required for commercial customers. An approach was created to swiftly apply remediations, separated into five workstreams: physical, technical, change management, policy and supply chain. An as-is and to-be risk assessment made sure that the risk to the business was understood, and the outturn risk position was signed off by three members of the line of business board.

 

As the OT security project was being delivered, regular comms and learnings were being shared across Group Manufacturing. This resulted in a wider programme being established to replicate the journey across the whole enterprise. By this time, the project was delivering solidly and predictably, a backfill was sourced and Project One moved across to the central role in Group Cyber, but also supporting Group Manufacturing and Group Engineering.

 

The Cyber Security Assurance Programme for Operational Technology was mobilised, and ten Sectors and Business Units were targeted to mobilise local projects to establish their baselines, build project teams, budgets and to commence assurance. Project One created several accelerators: optimised programmatics, templates and policies. Tactical tools and approaches were developed and support provided to the strategic enterprise-built future solutions.

 

Every manufacturing and engineering site was visited and a set of workshops delivered across the entire enterprise, to build the overall knowledge levels and replay any best practise to the benefit of all. All lines of business were supported to build momentum and to hasten their move to an increasingly secure state.

 

During the programme, the changing world conditions brought about the busiest times for the business, where continuous production was key and innovation and efficiency were important. This meant that some questioned the need to split focus onto cybersecurity so directors across the business were briefed and included as part of the senior level organisational change campaign to move consciousness to include cybersecurity as a first order business priority.

 

Project One liaised with CTIO and CISO to decide strategy and to agree objectives which were laid onto each Sector and Business Unit. Plans for change management were created, supporting the technology, procedural and people deliveries across the enterprise. On a quarterly basis, briefings were offered to the Cyber heads and Heads of Manufacturing and Engineering. This included facilitating at cyber events to the one hundred most senior staff in the company in Manufacturing, Engineering, Cyber and IT.

Outcome
  • Cybersecurity, and in particular operational technology, has transitioned from a background function in a support department, to being a central part of the enterprise focus. The most senior staff across the business now recognise the issues and drive the cybersecurity in their own businesses.

 

  • Huge swathes of manufacturing and engineering estates have been or will be assured across a 10-year programme of work, and the processes are built-in for this to continue in perpetuity as BAU.

 

  • Both national defence and private sector customers recognise the leading defence contractor as a top tier provider, serious about protecting their estate, with the ability to maintain continuous design and manufacturing, and able to withstand potential cyber attacks.

 

  • The programme processes have evolved into BAU such that they can continue to protect the enterprise through continuous reassessments, risk evaluations, vulnerability mitigations and ongoing upgrades and remediations.

 

  • The workforce now understands their role in a world where cyber threats are real and are developing. They are better able to protect themselves and the business through greater awareness and knowledge.

 

  • As regulators require ever more evidence of governance and controls, the client is well placed to move with this, with an established set of processes and outcomes as delivered by the cybersecurity programme.

 

Project One value add:

 

  • Ability to swiftly energise an innovative project and deliver immediate outcomes

 

  • Rolling sleeves up, working embedded in the customer’s organisation to build a project, upskill and empower the permanent workforce and create enduring value

 

  • Without ego, the focus was on the outcome, to secure the business and to support the nation.

Are you looking for critical business transformation?

Let’s talk real change
Related insights and customer stories
Sign up to our eNewsletter

Get the latest news, relevant insights and expertise from our change experts

Marketing updates confirmation(Required)
Privacy policies confirmation(Required)