Regulation-Directed Cybersecurity Best Practices for Operational Technology Environments
| dc.contributor.author | KAICHETTY, PRAHITHA | |
| dc.contributor.author | VUPPALA, SREELEKHA | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Fjeld, Morten | |
| dc.contributor.supervisor | Elahi, Haroon | |
| dc.date.accessioned | 2026-08-12T13:36:09Z | |
| dc.date.issued | 2026 | |
| dc.date.submitted | ||
| dc.description.abstract | Operational Technology (OT) systems refer to hardware and software used to monitor and control physical processes, devices, and infrastructure in industrial environments. These systems are typically designed for long operational lifecycles and are expected to function reliably over extended periods. In recent years, industrial sectors have increasingly integrated OT systems with Information Technology (IT) networks to enable digital transformation, improve data-driven decision-making, and support remote monitoring and control, thereby enhancing operational efficiency and connectivity. However, this integration also introduces significant cybersecurity risks. The incorporation of legacy OT systems into modern and continuously evolving IT environments makes them more vulnerable to cyberattacks and easier to exploit. Cyber incidents targeting OT systems can result in severe consequences, including physical damage to equipment, production disruptions, financial losses, safety risks to personnel, and loss of operational control. Consequently, OT environments have emerged as critical targets for malicious actors. To address the growing cybersecurity threat landscape, the European Union has introduced the Network and Information Security Directive 2 (NIS2) Directive, which establishes standardized cybersecurity requirements for essential and important entities, including those in the manufacturing sector. Prior to the introduction of NIS2, the National Institute of Standards and Technology (NIST) cybersecurity framework has been widely adopted across industries as a best-practice guideline for managing cybersecurity risks. Most companies are required to meet the NIS2 requirements, however redesigning the security infrastructure from scratch is an expensive and complicated process. One possible approach to address this issue is to map NIS2 requirements to existing cybersecurity frameworks. In this thesis, NIST standards are mapped to the NIS2 Directive to identify compliance gaps and evaluate cybersecurity alignment within IT and OT environments. The associated risks in OT components are analyzed through the development of a Failure Modes and Effects Analysis (FMEA) table. Additionally, an OT and IT component checklist is created to ensure the adequacy mitigation and redundancy measures across systems. This approach helps identify existing gaps, thereby improving overall security and strengthening compliance. Furthermore, it enables organizations to proactively address vulnerabilities and adapt to evolving cybersecurity threats. | |
| dc.identifier.coursecode | DATX05 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/312125 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.subject | Operational Technology(OT), Security Standardization, Network and Information Systems Directive, Risk Analysis, Cybersecurity regulation | |
| dc.title | Regulation-Directed Cybersecurity Best Practices for Operational Technology Environments | |
| dc.type.degree | Examensarbete för masterexamen | sv |
| dc.type.degree | Master's Thesis | en |
| dc.type.uppsok | H | |
| local.programme | Computer systems and networks (MPCSN), MSc |
