PrivX™ OT Case Study - Industrial Crane Manufacturer
A Marine Vessel Operator Secures Remote Access, Diagnostics and IoT Data Collection
Customer
The customer is a global industrial crane manufacturer and services provider with operations in major ports for loading and unloading containers using automation.
Customer's security and operational concerns
Crane operations are mostly automated but they need regular optimization, maintenance and upgrades to be effective. These adjustments are done mostly remotely by engineers and technicians from all over the world.
The customer soon realized that this mission-critical access from the public cloud environment came with risks, including:
- Production disruptions: Remote-operated cranes are vulnerable to cybersecurity attacks, whether they are connected to the internet. A hacker accessing a crane could disrupt port operations, cause material accidents or jeopardize the safety of the harbor workforce.
- Industrial espionage: Ungoverned access to port operations could allow stealing optimization, diagnostics or other type of data from cranes.
- Regulatory violations: With the emergence of the Network and Information Security 2 (NIS2) Directive, poorly secured ports are subject to substantial fines.
Customer challenge - complex access management, incomplete control
The customer had segmented its networks and was running a private port network with basic level access control to the 5G port network itself. However, with this set up:- There was a general lack of oversight of remote access to ports (who did what, when and with what rights)
- The customer was not able to limit access even per maritime facility, meaning that a technician operating in Asia could access ports in Europe, and vice versa.
- Once a technician was inside the network, they had access to many cranes.
- Restricting privileges to the minimum for the task at hand was hard to configure or limited.
- Internal employee and third-party access tracking and identification was limited.
- The customer had multiple point solutions in use for access.
- Access credentials were insufficiently managed.
PrivX OT deployment in the customer environment
The customer decided to radically simplify their access management environment by replacing the point solution approach they had implemented earlier. Instead of using VPN tunnels per access, they centralized their management under one Digital Gatekeeper, PrivX OT.
- PrivX was integrated with multiple IAMs and ADs to always link an ID to a role for each session.
- Both employees and vendor technicians log in to a VPN service, opening access to a VPN gateways zone behind a firewall.
- After this phase, PrivX restrict access to a minimum needed to get the job done.
- PrivX offers multiple authentication methods, including:
- AD/LDAP user & password
- Local user & password
- OpenID Connect
- MFA (TOTP & Biometric)
- Passkeys / FIDO2
- TLS client certificate
- SSH public key
- External JSON web token
- PrivX Authorizer
- After authentication, PrivX automatically maps the identity to the right role for access.
- PrivX stores and rotates the credentials needed for access or enables passwordless access. Credentials are vaulted and rotated after use, or in the case of passwordless access, the user never even sees or handles any credentials.
- The user (maintenance engineer, vendor engineer, ship technician, etc.) only sees a list of available targets based on the role – and nothing else.
- The user selects the target from the list and gets access to it. The target can be a single application, gauge, or crane operation module, depending on the task at hand. The actions the user is allowed to perform can be restricted as necessary, allowing options ranging from read-only or to full access.
- Through AWS Direct Connect, the traffic is routed to a cloud-hosted PrivX instance best suited for the connection, based on the load and location.
- All sessions produce an audit trail. For the most important connections, session recording or live monitoring is available. It also possible to require external authorization by the site admin for critical sessions.
- After the session is over, offboarding is automatic. Every session is verified each time it is made, in a just-in-time (JIT) fashion to align with the Zero Trust security framework.
Ensuring access control and restrictions at the user level
.
PrivX OT is the centralized and streamlined access gateway for all the cranes at port. Any employee or third party gets access from any location to an individual crane in a uniform, controlled way.
PrivX PAM technology comes in different flavors