Regulation-Directed Cybersecurity Best Practices for Operational Technology Environments

dc.contributor.authorKAICHETTY, PRAHITHA
dc.contributor.authorVUPPALA, SREELEKHA
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerFjeld, Morten
dc.contributor.supervisorElahi, Haroon
dc.date.accessioned2026-08-12T13:36:09Z
dc.date.issued2026
dc.date.submitted
dc.description.abstractOperational Technology (OT) systems refer to hardware and software used to monitor and control physical processes, devices, and infrastructure in industrial environments. These systems are typically designed for long operational lifecycles and are expected to function reliably over extended periods. In recent years, industrial sectors have increasingly integrated OT systems with Information Technology (IT) networks to enable digital transformation, improve data-driven decision-making, and support remote monitoring and control, thereby enhancing operational efficiency and connectivity. However, this integration also introduces significant cybersecurity risks. The incorporation of legacy OT systems into modern and continuously evolving IT environments makes them more vulnerable to cyberattacks and easier to exploit. Cyber incidents targeting OT systems can result in severe consequences, including physical damage to equipment, production disruptions, financial losses, safety risks to personnel, and loss of operational control. Consequently, OT environments have emerged as critical targets for malicious actors. To address the growing cybersecurity threat landscape, the European Union has introduced the Network and Information Security Directive 2 (NIS2) Directive, which establishes standardized cybersecurity requirements for essential and important entities, including those in the manufacturing sector. Prior to the introduction of NIS2, the National Institute of Standards and Technology (NIST) cybersecurity framework has been widely adopted across industries as a best-practice guideline for managing cybersecurity risks. Most companies are required to meet the NIS2 requirements, however redesigning the security infrastructure from scratch is an expensive and complicated process. One possible approach to address this issue is to map NIS2 requirements to existing cybersecurity frameworks. In this thesis, NIST standards are mapped to the NIS2 Directive to identify compliance gaps and evaluate cybersecurity alignment within IT and OT environments. The associated risks in OT components are analyzed through the development of a Failure Modes and Effects Analysis (FMEA) table. Additionally, an OT and IT component checklist is created to ensure the adequacy mitigation and redundancy measures across systems. This approach helps identify existing gaps, thereby improving overall security and strengthening compliance. Furthermore, it enables organizations to proactively address vulnerabilities and adapt to evolving cybersecurity threats.
dc.identifier.coursecodeDATX05
dc.identifier.urihttps://hdl.handle.net/20.500.12380/312125
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectOperational Technology(OT), Security Standardization, Network and Information Systems Directive, Risk Analysis, Cybersecurity regulation
dc.titleRegulation-Directed Cybersecurity Best Practices for Operational Technology Environments
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 26-153 PK SV.pdf
Size:
2.16 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Size:
2.35 KB
Format:
Item-specific license agreed upon to submission
Description: