Perhaps more than in any other industry, cybersecurity in chemical production is also about protecting employees and the environment. The supported chemical company already has a well-established and effective IT security team. However, the OT of the process plants had not been monitored for cyber incidents until now. Given the high level of digitization and networking of the production lines, however, this had become necessary in order to strengthen protection against data theft as well as protection for people, plants and the environment in chemical production.
First, a risk analysis was carried out to examine three production lines of the chemical company at one site. For this, a Rhebo Industrial Security Assessment was carried out to identify existing security gaps and vulnerabilities.
Rhebo Industrial Security Assessment
Rhebo Industrial Protector
Rhebo Managed Protection
To run the Rhebo Industrial Security Assessment, a Rhebo sensor was integrated into each OT network. Over a period of two weeks, the sensors passively and non-intrusively recorded the OT communication and stored it as packet captures (pcap). Afterwards, Rhebo experts analyzed the communication logs, using methods such as deep packet inspection, automated anomaly detection and forensic analysis.
As a result, the chemical company was able to gain visibility into its OT for the first time. It was revealed – not surprisingly – that the chemical production plant had a relatively homogeneous infrastructure. Although several hundred devices were identified in each monitored OT network, they were from only a few manufacturers.
However, the security posture and network quality scored in the middle range. Observations that led to this assessment included:
On the stability and availability assessment side, the team identified
The sensors integrated as part of the Rhebo Industrial Security Assessment remained in the OT networks and were put into operation with a Rhebo Controller as a network intrusion detection system (Rhebo Industrial Protector). Rhebo regularly supported the chemical company in evaluating anomaly alerts and assessing the risk situation until the company had built up sufficient in-house expertise to operate the intrusion detection system independently.
through asset discovery and visualization of connections and systems properties.
through continuous security monitoring with anomaly detection.
through Rhebo support for establishing the detection baseline and assessing incidents.