Klaus Mochalski and Daniel Weber (telent) discuss best practices for OT SOCs in the KRITIS environment. Learn why the trend is toward outsourcing, how the “KISS” principle protects against a paralyzing flood of alerts, and how AI-powered SOAR systems reduce response times from hours to minutes — without compromising process stability.
Sound Bites
Daniel Weber: “[…]In the OT sector, it was actually standard practice that if you had a syslog server, or if the firewall and control system logs, or control system vendor logs, were distributed in a decentralized manner, and you wanted greater visibility.”
Daniel Weber: “[...]It’s not enough just to set up the system and have the classic ‘green checkmark’ audit solution because it’s required by law [...]I also have to operate the whole thing effectively and, above all, maintain it over the long term to derive real value from it.”
Daniel Weber: “[...]Right now, based on the inquiries we’re getting, the trend is more toward outsourcing the whole thing to a service provider, because they can then provide the necessary resources, since you can no longer tell an auditor that a control room technician at a power plant with five power plant units [...] can manage them 24/7 around the clock.”
Daniel Weber: “Let’s just turn them all on for a moment. Then 900 alarms will go off per hour. And that won’t provide any visibility. So we always approach this according to the KISS principle. As in ‘Keep it simple, stupid’, that’s just how you have to put it [...]”
Daniel Weber: “[...]We don’t have any customers for whom we actively defend against attacks, that is, by enabling a firewall rule or isolating a host. That doesn’t happen in OT. We don’t have any customers who want that.”
Daniel Weber: “The system simply creates the incident, pulls all the logs, processes them, asks the AI for a recommendation on how to proceed [...] and then, of course, I’ve reduced the time it takes to handle a case from an hour to just a few minutes.”
Chapters
00:00 Introduction and Guest Introductions
01:17 History of OT SOCs and Early Projects
02:02 Regulatory Requirements and Market Trends
03:15 Technologies and Use Cases in OT Security
05:35 The Importance of Security for Availability and Production
06:52 The Market for SIEM Systems and OT Integration
09:04 Hybrid Models and Outsourcing of OT SOCs
14:02 Best Practices for Setting Up an OT SOC
18:33 Use of AI in the OT SOC Environment
22:30 Improving Efficiency Through AI and Automation
23:30 Recommendations for Getting Started with OT SOCs
Keywords
OT Security, SOC, Cybersecurity, Critical Infrastructure, AI, Attack Detection, SIEM, Managed Services, OT Industry, Security Strategy