Skip to main content

Cyber Resilience Act (CRA) and OT Cybersecurity: Insights from the Siemens Webinar

 

On May 21st, Siemens hosted a webinar for its Solution Partners focusing on OT (Operational Technology) Cybersecurity. This is the first newsletter that Faentia Group is dedicating to its Clients to highlight the key takeaways from the event.

The webinar addressed the provisions of the Cyber Resilience Act (CRA), the new European regulation focusing on products with digital elements. This topic was framed within a broader context characterized by a rise in cyberattacks—even within the OT domain—and the progressive introduction of regulations targeting both critical infrastructures and products placed on the European market.

The core elements introduced by the CRA include cybersecurity obligations throughout the entire product lifecycle, such as: risk assessment, security function design, vulnerability management, technical documentation, user information, declaration of conformity, and the support period.

During the webinar, it was emphasized that industrial machinery, complex systems, and modular solutions can be considered "products with digital elements" when they include logical or physical connections, either direct or indirect, to other products or networks. In such cases, the entire product or system must be evaluated, rather than just its individual components.

A pivotal point concerned the pyramid of responsibilities:

  • The product supplier (hardware and/or software) is responsible for their own component;
  • The machinery manufacturer or system integrator is responsible for the machine or the overall system;
  • The asset owner must assess vulnerability exposure within their own plant;
  • Importers and entities placing products on the European market must ensure that the products comply with applicable requirements.

The OT Cybersecurity approach explained by Siemens during the webinar is based on a defense concept structured around three pillarsplant security, network security, and system integrity.

It is crucial to understand that 100% absolute protection does not exist; however, adopting specific measures significantly reduces attack surfaces and vectors.

The recommended standard pathway begins with an initial situation analysis (Assessment): identifying which assets are present, which are critical, what vulnerabilities they might have, and which elements must be protected as a priority. Only after this phase does it make sense to implement specific measures such as network segmentation, access control, or other countermeasures.

Cybersecurity is a continuous process involving: assessment, implementation of measures, monitoring, malware or anomaly detection, business continuity, and disaster recovery. As threats evolve, protective measures must also be updated over time.

During the webinar, Siemens also highlighted the technologies it is implementing to prevent and monitor attacks on OT networks.

We would like to draw your attention to the software line called SINEC Security Software Suite, which consists of several products:

  • SINEC Security Inspector for active asset detection;
  • SINEC Security Guard for asset and vulnerability mapping;
  • SINEC Security Monitor for continuous monitoring and detection of anomalies, unexpected devices, or network events.

To learn more about SINEC, please visit the following webpage: https://www.siemens.com/en-us/products/sinec/

Another component not mentioned in the webinar, but which we highly recommend to our Clients, is the Scalance S Industrial Security Appliance for protecting industrial networks and automation systems.

To better understand these components, we suggest reviewing the content available at the following web address: https://www.siemens.com/it-it/products/scalance/s-industrial-security-appliance/