Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry

Vahiny Gnanasekaran, Maria Bartnes, Tor Olav Grotan, Poul Einar Heegaard

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The number of significant cyberattacks targeted by national state actors is growing in critical infrastructure. Companies rely on detecting and responding appropriately to such attacks by practicing and developing procedures for the cyber-incident response. This paper presents the findings from seven semi-structured interviews to identify distinct practices, challenges, and roles regarding cyber-incident response in the petroleum industry. The literature has previously addressed specific IT, security, or Operational Technology (OT) teams only, but has not considered the holistic view of cyber-incident response in industrial control systems between internal roles, and external actors, such as Security Operations Centers, Computer Security Incident Response Teams, emergency response teams, and on-site personnel. To address this, a novel framework for empirical inquiry consisting of document analysis, and workshops as preparation for interviews, were conducted. The stakeholder diagram displays the most relevant incident response roles and a list of current challenges extracted from the interviews. Future research should consider extending the sample, and include other, organizational and procedural factors.

Original languageEnglish
Title of host publicationProceedings - 2024 IEEE/ACM 4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability, EnCyCriS/SVM 2024
PublisherAssociation for Computing Machinery, Inc
Pages53-60
Number of pages8
ISBN (Electronic)9798400705656
DOIs
StatePublished - 15 Apr 2024
Externally publishedYes
Event4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability, EnCyCriS/SVM 2024, held in conjunction with the 46th IEEE/ACM International Conference on Software Engineering, ICSE 2024 - Lisbon, Portugal
Duration: 15 Apr 2024 → …

Publication series

NameProceedings - 2024 IEEE/ACM 4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability, EnCyCriS/SVM 2024

Conference

Conference4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability, EnCyCriS/SVM 2024, held in conjunction with the 46th IEEE/ACM International Conference on Software Engineering, ICSE 2024
Country/TerritoryPortugal
CityLisbon
Period15/04/24 → …

Keywords

  • critical infrastructure
  • cyber-incident
  • cybersecurity
  • incident response
  • operational technology

Fingerprint

Dive into the research topics of 'Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry'. Together they form a unique fingerprint.

Cite this