A Story About OT Security Derived from the Intense Heat
It all started with an iced coffee I bought at a convenience store.
It is hot again this year. Every day, the news covers the intense heat across the country. In the area where I live, the temperature exceeded 40 degrees Celsius today. When I went out to the convenience store 200 meters away to buy an iced coffee, it felt like a sauna outside. By the time I walked back, the ice had melted in an instant, and the coffee was completely lukewarm by the time I got home. Moreover, since I had turned off the air conditioner before leaving, the room remained sweltering. I had lost both the cold coffee and the cool room.

I keenly felt that it would be a living hell without air conditioning. At the same time, it occurred to me: if the air conditioning at work were to stop, would we be able to work properly in the office?
How is air conditioning managed in companies these days?
When you commute and arrive at the office, the air conditioning is usually on, right?
However, depending on the size of the company, you don't often see "air conditioners" like the ones used at home. Buildings like office buildings are not managed floor by floor, but are sometimes centrally managed by the building's management side.
Physical equipment like this centrally managed air conditioning is called OT (Operational Technology).
This time, I will organize what is different about "OT equipment" like this air conditioning management system and the "IoT equipment" that continues to increase around us, why they are targeted, and how we should take countermeasures.
1. What is the difference between IT, OT, and IoT?
First, let's clarify the terminology.
Roughly speaking, IT handles "information," while OT controls "physical equipment and processes." IoT is a technology that connects everyday devices and equipment, such as home appliances and cameras, to a network.

Originally, it was a prerequisite that OT equipment be operated in an environment isolated from external networks. However, due to the needs for remote monitoring and energy-saving management, external connections have become common, and as a result, the risks of malware and unauthorized access have become a reality.
2. Why are they targeted? - Representative examples
When you think of malware intrusion routes, you probably think of intrusion from a PC.
However, in reality, it is not always the case that your company's PCs or servers are directly targeted. There have been cases in Japan where intruders entered through weak points (vulnerabilities) outside the company, such as business partners or contractors, and used that as a stepping stone to stop the main production line.
Toyota Motor Corporation suspends all factory operations (March 2022)
Toyota stopped all domestic factories on the 1st. The cause was that a supplier's system was hit by a cyberattack and went down. Kojima Press Industry (Toyota City, Aichi Prefecture), which handles automotive interior and exterior parts, announced on the 1st that it had detected a server failure on the night of February 26th and confirmed the presence of a virus infection and a ransom message.
According to a spokesperson for Kojima Press, the message was written in English. Early on the 27th, they cut off the network between the business partner and the outside world to prevent further attacks. It is said that it will take another 1 to 2 weeks for the system failure to be fully restored.
Toyota stopped 28 lines at 14 factories, and the one-day suspension will affect the production of approximately 13,000 Toyota vehicles. The 14 factories include the Motomachi Plant (Toyota City) and the Toyota Motor East Japan Iwate Plant (Kanegasaki Town, Iwate Prefecture), as well as the Hamura Plant of group company Hino Motors (Hamura City, Tokyo) and the Kyoto Plant of Daihatsu Motor (Oyamazaki Town, Kyoto Prefecture). In addition, Hino also suspended operations at its Koga Plant (Koga City, Ibaraki Prefecture) on the 1st.
3. Guidelines you should know
When discussing OT security, there are two representative guidelines that you should know for practical purposes.
① NIST SP 800-82 / IoT-related guidance
While NIST guidance covers a wide range of fields, IEC 62443 is differentiated by delving into the specific circumstances of manufacturing sites. Furthermore, in the most recent NIST draft, a direction is shown to integrate from security measures for individual IoT devices to risk management for the entire organization, including corporate networks, clouds, manufacturing sites, maintenance providers, and supply chains, and a shift in thinking from "protecting equipment" to "protecting the entire ecosystem where equipment is connected" is progressing.
② Ministry of Economy, Trade and Industry Factory System Guidelines
In Japan, the Ministry of Economy, Trade and Industry (METI) has formulated the "Cyber/Physical Security Measures Guidelines for Factory Systems" with the aim of strengthening the cyber attack response capabilities of the manufacturing industry.
Cyber/Physical Security Measures Guidelines for Factory Systems
4. Practical measures that can be implemented
Furthermore, the METI guidelines are structured to show the process itself: "First, organize your company's operations, critical assets, and zones, map measures to assumed threats, and continuously review them using PDCA."
The following five points correspond to individual measure items that are actually considered and executed within that process.
① Visualization and inventory of assets
It is not uncommon for OT and IoT devices to be missing from IT asset ledgers. It starts with identifying "what kind of air conditioning control systems, surveillance cameras, and smart locks are in the company, and who manages them."
② Separation of IT/OT networks
This is the most basic and important measure. Clearly separate OT networks such as air conditioning, power, and elevators from business IT networks using VLANs or firewalls. It is important to design with the premise that "just being on the same network can become an entry point into business systems."
③ Tightening of remote maintenance access
Vendor maintenance accounts and remote access accounts should not be kept in a state where they can be connected at any time, but should be switched to access that requires approval each time and has time limits.This is the "back door" most likely to be targeted.
④ Review of initial settings and authentication
Changing default passwords for IoT devices is the absolute basic, but the more devices there are, the harder it is to enforce. Creating a security checklist at the time of introduction and confirming them during regular inventory checks is effective.
⑤ Incident response plan
OT failures often require external contractors for recovery, so preparing a recovery flow different from IT failures is also essential.
Summary
OT security is not an "extension of IT security," but a field that requires a different axis of thinking that is directly linked to physical safety and availability. Future security personnel are required to grasp both the NIST concept of "protecting the entire ecosystem."
Perhaps this time of year, when we keenly feel the gratitude for air conditioning due to the extreme heat, is a good opportunity to think about "who is protecting that air conditioning and how."
If the air conditioning in your office stopped, could you work?
Author Profile
Yusaku Sakiyama. Background: Information Systems Department -> Factory Line Operations -> Information Systems Department -> SIer.
Interests: EDR, log analysis, AWS design and construction,
Apple products in general, generative AI utilization, etc.
#ControlSystem #NIST #METI #SecurityGuidelines #FactorySecurity #OTSecurity #IoTSecurity #CyberSecurity #Ransomware #SupplyChainAttack #MarubeniIDIGIO #IDIGIO #IT #Security
