Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ENISA’s 2015 report called on European governments, critical-infrastructure operators, vendors and researchers to strengthen industrial control system (ICS) security through coordinated policy, practical safeguards, information sharing, training and research. It assessed evidence from eight EU Member States; its maturity profiles are a historical snapshot, not a current ranking of European countries.

Why ICS security needs a different approach

ENISA defines industrial control systems as industrial automation systems that acquire data, visualize operations and control industrial processes. They support continuity and functional and technical safety in sectors including energy, oil and gas, water and chemicals. A cyber incident can therefore affect both the delivery of essential services and the safe operation of physical processes.

That changes the priorities used to secure and respond to incidents in these environments. In a 2013 guide announcement, ENISA wrote: “While for traditional ICT systems the main priority is integrity, for ICS systems availability is the  highest priority (of the “CIA” scale : Confidentiality, Integrity, Availability.)” The wording is reproduced as published, including its spacing artifact. Availability matters because disruption to an industrial process can carry operational and safety consequences.

ENISA’s 2013 announcement also described the trade-off created by connectivity. Executive Director Professor Udo Helmbrecht said: “Until a few decades ago, ICS functioned in discrete, separated environments, but nowadays they are often connected to the Internet. This enables streamlining and automation of industrial processes, but it also increases the risk of exposure to cyber-attacks.“ (ENISA, 4 December 2013.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment
  • Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
  • ABIS BOOK
  • Packt Publishing

What the 2015 assessment covered

ENISA combined desk research on publicly available European and Member State policies and activities with interviews or questionnaires involving authorities in eight selected countries: Estonia, France, Germany, Lithuania, the Netherlands, Poland, Spain and Sweden. One country provided its input by questionnaire without an interview. The agency used a maturity model to organize the national evidence and identify lessons and good practices. The assessment and its findings are described in ENISA’s 2015 report, Analysis of ICS-SCADA Cyber Security Maturity Levels in Critical Sectors.

The model’s three dimensions

  • Legislation: the laws and policy framework for securing ICS and critical infrastructure.
  • Support to critical-infrastructure service providers: the help and mechanisms available to operators.
  • Local conditions: national circumstances that affect how security measures can be developed and applied.

The four profiles were categories, not a modern league table

  • Leading: stronger legislation and support mechanisms.
  • Proactive Supporters: focused on supporting operators and driving improvements.
  • Reactive Supporters: relied more on lessons learned and reactive improvement.
  • Early Developers: still developing legislation and support.

These profiles describe the approaches represented in ENISA’s selected 2015 sample. They do not establish how those countries—or other EU states—perform today.

Why ENISA called for improvement

The report identified practical obstacles that can make security policy difficult to implement: organizations may not have a clear picture of infrastructure assets and dependencies; operators may be reluctant to share information; and specialist ICS-SCADA security skills may be in short supply. These challenges connect the report’s policy agenda to the work required inside organizations: understand which assets and services depend on each other, make trusted incident-sharing possible, and develop people who understand both industrial processes and their technologies.

To illustrate the historical threat landscape, ENISA reproduced annual incident counts attributed to the U.S. Department of Homeland Security’s ICS-CERT Monitor. The figures rose from 9 in 2009 to 41 in 2010, 204 in 2011, 198 in 2012, 256 in 2013 and 245 in 2014. ENISA said reported incidents had increased more than 27 times between 2009 and 2014; it also cited the Monitor for the finding that 59% of incidents in 2013 targeted energy and critical manufacturing and that around 55% involved advanced persistent threats (APTs). These are historical U.S.-reported figures included in a European policy study, not current EU incident rates. ENISA cautioned that incidents could remain undetected or unreported.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ENISA’s six recommendations

1. Integrate ICS security into national cybersecurity and infrastructure policy

ENISA urged Member States to connect ICS-SCADA security with national cybersecurity strategies and critical-information-infrastructure protection. The intent was to avoid treating industrial security as a disconnected compliance exercise and to put it within the broader policy and infrastructure-protection framework.

2. Create security practices tailored to ICS-SCADA

The report called for a minimum security baseline for critical sectors, drawing on existing standards and guidance. Authorities, operators, vendors and standardization bodies would need to work together so the practices reflect industrial environments rather than simply transplanting assumptions from conventional IT security.

3. Establish a common approach to information sharing

ENISA recommended a shared method for exchanging threats, incidents and good practices among operators and Member States. That includes agreeing on an incident-data scheme and building the trust needed for organizations to contribute information. A common approach can make information more useful across organizations while addressing reluctance to share.

4. Make awareness continuous

Awareness should reach operators as well as policy makers and should not depend on a major breach to trigger attention. ENISA also emphasized understanding ICS threats in their own operational context instead of assuming they are identical to IT-security threats.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Develop specialist expertise through education and training

Assessing industrial cyber risk requires knowledge of both industrial processes and the technologies that control them. ENISA urged authorities, operators and vendors to cooperate in developing that expertise through education and training.

6. Fund research and ICS test beds

The report called for research programs and test environments involving specialists and vendors. Test beds can support work on threats and security by design; the recommendation makes research and practical evaluation part of the sector’s security capability, not a substitute for operational safeguards.

ENISA said realizing these recommendations would require discussion among Member States, operators and academia, followed by joint effort.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to use the report’s framework today

The report remains useful as a way to structure discussion, but not as evidence of present-day national implementation. A current comparison should use newer evidence and can retain ENISA’s three assessment dimensions while asking concrete questions within each:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Law and policy: Are ICS security and critical-infrastructure protection connected in national policy, and what sectors and assets are covered?
  • Support for operators: What practical assistance, incentives, incident-handling support and information-sharing arrangements are available?
  • Local conditions and capability: Are dependencies understood, are staff trained in both process and technology, and are research and testing resources available?

ENISA’s current energy-sector work says the agency works with European energy stakeholders and supports NIS2 implementation and electricity-network cybersecurity work. That current activity does not update the 2015 country maturity profiles. Likewise, CERT-EU’s 2022 mitigation guidance recommends general controls such as MFA for remotely accessible services, but it is not part of ENISA’s ICS-specific recommendations from 2015.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.