Story image

Tenable solution secures converged IT/OT environments

28 Feb 2019

Tenable has announced a Cyber Exposure solution to provide a unified view of cyber risk spanning information technology (IT) networks and operational technology (OT), from enterprise applications to industrial control systems.

This allows security leaders to use a single platform to measure, manage and reduce cyber risk across both IT and OT environments with Tenable Industrial Security which is integrated with Tenable.sc (formerly SecurityCenter) for vulnerability management on-premises.

Digital transformation means that the days of fully air-gapped OT assets are largely gone.

Modern OT environments increasingly interconnect with IT, resulting in a complex, sensitive and expanded attack surface.

As effective risk management is built on a unified understanding of the entire IT/OT attack surface, organisations are shifting responsibility for OT security to the Chief Information Security Officer (CISO).

Yet traditional IT security solutions lack the ability to continuously discover and assess sensitive OT assets.

Conversely, most OT security solutions don’t translate to the world of IT.

This lack of holistic visibility creates security blind spots and increases the chances of mission- and safety-critical systems being compromised or taken offline.

An attack on a high-value OT asset, for example, may begin by compromising a traditional IT asset and then moving laterally.

When used with Industrial Security, Tenable.sc aims to solve this problem by delivering clarity into an organisation’s converged IT/OT environments. Tenable.sc leverages Nessus scanners to gather security-related information from IT-based assets on OT and IT networks.

Tenable.sc combines that information with passively collected asset and vulnerability data from Industrial Security, which provides asset discovery and vulnerability management purpose-built for OT environments.

Designed for critical systems that require a non-intrusive approach to vulnerability management, Industrial Security is an OT-native solution that helps identify and prioritise OT risks so organisations can keep safety-critical production assets secure and fully functional.

The integration of Tenable.sc and Industrial Security provides a complete picture of IT and OT assets together, identifying exposures and vulnerabilities across the entire enterprise and helping organisations prioritise and manage cybersecurity against business risk.

Additional enhancements to the Tenable.sc and Industrial Security integrated solution include:

  • Integration with Tenable Cyber Exposure Technology Ecosystem to improve remediation and response processes for both IT and OT environments. Tenable’s market-leading integration partners span Security and IT technologies, including industry-leading SIEM, IT Ticketing and Configuration Management Database (CMDB) solutions. Together, these solutions accelerate the time-to-detect and remediate issues through a greater breadth of visibility across the modern attack surface, depth of analytics, and integrated data and workflows, fostering better collaboration across Security and IT Operations teams.

  • Expanded OT asset coverage which includes wider and deeper coverage of several thousand new devices from leading industrial manufacturers, such as Yokogawa and Emerson. These new manufacturers join the top 10 leading industrial manufacturers — including Siemens, Schneider, Rockwell/Allen-Bradley, Honeywell, Mitsubishi and others — whose devices are already covered by Industrial Security.

Tenable co-founder and chief technology officer Renaud Deraison says, “The interconnectedness of digital infrastructure today means the security of IT directly impacts OT, and vice versa.

“Without a single, unified view into converged IT/OT environments, CISOs are basically being asked to defend their organisations blindfolded and with one arm tied behind their backs, he says.   

“It’s bad cyber strategy and it places the business at serious risk.”

Trend Micro introduces cloud and container workload security offering
Container security capabilities added to Trend Micro Deep Security have elevated protection across the DevOps lifecycle and runtime stack.
Veeam joins the ranks of $1bil-revenue software companies
It’s also marked a milestone of 350,000 customers and outlined how it will begin the next stage of its growth.
Veeam enables secondary storage solutions with technology partner program
Veeam has worked with its strategic technology alliance partners to provide flexible deployment options for customers that have continually led to tighter levels of integration.
Veeam Availability Orchestrator update aims to democratise DR
The ability to automatically test, document and reliably recover entire sites, as well as individual workloads from backups in a completely orchestrated way lowers the total cost of ownership (TCO) of DR.
Why flash should be considered the storage king
Not only is flash storage being used for recovery, it has found a role in R&D environments and in the cloud with big players including AWS, Azure and Google opting for block flash storage options.
NVIDIA's data center business slumps 10% in one year
The company recently released its Q1 financial results for fiscal 2020, which puts the company’s revenue at US$2.22 billion – a slight raise from $2.21 billion in the previous quarter.
Limelight Networks celebrates 100th point-of-presence launch
The company has increased its global network capacity by 40% in just five months, bringing its total egress capacity to 42Tbps.
Salesforce continues to stumble after critical outage
“To all of our Salesforce customers, please be aware that we are experiencing a major issue with our service and apologise for the impact it is having on you."