
Bridging the IT and OT Gap: Inside the OWASP OT Top 10 Project
How a new open-source framework maps critical cybersecurity risks to global industrial standards.
In this episode, OMICRON OT cybersecurity expert Simon Rommer speaks with Andreas Happe, who is a security researcher and PhD student at the Vienna University of Technology, and Siegfried Hollerer, who is a security architect and analyst as well as a NIS auditor at the Austrian Ministry of the Interior and lecturer at the St. Pölten University of Applied Sciences in Austria.
Simon and his guests discuss their work and experience with the OWASP Operation Technology (OT) Top 10 Project, which is an open-source awareness initiative and practical framework created to identify and rank the most critical cybersecurity risks and vulnerabilities affecting OT environments.
They also describe how critical cybersecurity risks are mapped directly to major international frameworks, like IEC 62443 and NIST, providing infrastructure operators with immediate, actionable countermeasures and a shared vocabulary for improved industrial resilience.
Get more information about OT Cybersecurity for the Power Grid:
OT CYBERSECURITY FOR THE POWER GRID
"Each of the OT top 10 item is mapped to the matching standard requirements. Then you have based on the link from the risk to the mapping table a pretty comprehensive list of security measures which you can then place into your OT systems to protect against the corresponding risk."
Siegfried Hollerer
Security Architect & Analyst & NIS Auditor at the Ministry of the Interior (BMI) in Austria & Lecturer at Fh St. Pölten
"When we started to write the individual top 10 items we tried to take a very wholistic approach. Not only focusing on technology problems but also on organizational or awareness problems."
Andreas Happe
Security Research & PhD Student at the Tu Wien