Uppsats
Regulation-Directed Cybersecurity Best Practices for Operational Technology Environments
H
Chalmers tekniska högskola / Institutionen för data och informationsteknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
Operational Technology (OT) systems refer to hardware and software used to monitorand control physical processes, devices, and infrastructure in industrial environments.These systems are typically designed for long operational lifecycles and are expectedto function reliably over extended periods. In recent years, industrial sectors haveincreasingly integrated OT systems with Information Technology (IT) networks toenable digital transformation, improve data-driven decision-making, and supportremote monitoring and control, thereby enhancing operational efficiency and connectivity. However, this integration also introduces significant cybersecurity risks.The incorporation of legacy OT systems into modern and continuously evolving ITenvironments makes them more vulnerable to cyberattacks and easier to exploit.Cyber incidents targeting OT systems can result in severe consequences, includingphysical damage to equipment, production disruptions, financial losses, safety risksto personnel, and loss of operational control. Consequently, OT environments haveemerged as critical targets for malicious actors.To address the growing cybersecurity threat landscape, the European Union hasintroduced the Network and Information Security Directive 2 (NIS2) Directive, whichestablishes standardized cybersecurity requirements for essential and importantentities, including those in the manufacturing sector. Prior to the introduction ofNIS2, the National Institute of Standards and Technology (NIST) cybersecurityframework has been widely adopted across industries as a best-practice guidelinefor managing cybersecurity risks. Most companies are required to meet the NIS2requirements, however redesigning the security infrastructure from scratch is anexpensive and complicated process. One possible approach to address this issue is tomap NIS2 requirements to existing cybersecurity frameworks. In this thesis, NISTstandards are mapped to the NIS2 Directive to identify compliance gaps and evaluatecybersecurity alignment within IT and OT environments. The associated risks in OTcomponents are analyzed through the development of a Failure Modes and EffectsAnalysis (FMEA) table. Additionally, an OT and IT component checklist is createdto ensure the adequacy mitigation and redundancy measures across systems.This approach helps identify existing gaps, thereby improving overall security andstrengthening compliance. Furthermore, it enables organizations to proactivelyaddress vulnerabilities and adapt to evolving cybersecurity threats.
Information
- Författare
- KAICHETTY, PRAHITHA, VUPPALA, SREELEKHA
- Lärosäte / institution
- Chalmers tekniska högskola / Institutionen för data och informationsteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- H
- Språk
- Engelska