Success Story
For one of the most important utilities in Northern Italy we have designed and started a service OT SOC dedicated to the protection of SCADA infrastructure and field systems. The project started with theanalysis punctual of the messages exchanged through the main industrial protocols, reconstructing flows, dependencies and expected behaviors. This allowed us to assess the cyber risks associated with potential sabotage, both external and internal. We defined an integrated model consisting of specialized technologies, monitoring systems, operational procedures, and qualified personnel. The tuning, which lasted a year, has allowed us to accurately distinguish the truly relevant events from the normal functioning of the systems. Today, customers have access to immediate, qualified, and contextualized alerts, with an extremely low number of false positives and a much faster, more informed, and effective response capability.
The challenges
A vast field made it complex to map OT assets, connections, dependencies and operational anomalies
Many heterogeneous technologies required specialized skills to correlate OT cyber events, flows and risks
The conversion from Modbus RTU to Modbus TCP made it difficult to read, understand and trace OT messages.
Distinguishing systemic plant behaviors from cyber threat-like events was a key challenge.
Telemetry was distributed across multiple instruments, hindering a single, rapid, and reliable view of the data.
The solution