Since information and communication systems (ICS) are typically connected to internet platforms, additional security measures are necessary. This new guide provides key considerations for ICS-based computer emergency response teams (ICS-CERCs).
ICS are essential for various industrial processes, including energy distribution, water treatment, and transportation, as well as for chemical, governmental, defense, and food processes. ICS are lucrative targets for intruders such as criminal groups, foreign intelligence services, phishers, spammers, and terrorists. Cyber ​​incidents affecting ICS can have devastating effects on a country's economy and the lives of its citizens. They can cause prolonged power outages, paralyze transportation networks, and trigger environmental catastrophes. Therefore, the ability to respond to ICS incidents and mitigate their impact is fundamental to protecting critical information infrastructure and optimizing cybersecurity at the national, European, and global levels. Therefore, ENISA deemed it appropriate to create this guide on best practices for prevention and preparedness for organizations with CERC-ICS, highlighting the following conclusions:
• While the main priority for ICT systems is integrity, the priority for ICS is availability (on the “CID” scale: Confidentiality, Integrity, Availability). This is because ICS are essential to ensure the smooth operation of critical infrastructures.
• Key ICS stakeholders lack sufficient cybersecurity knowledge. Similarly, existing Computer Emergency Response Teams (CERTs) do not always fully understand all the sector-specific technical aspects of ICS.
• Given the potential for significant damage to ICS, the recruitment process for ICS-CERCs requires rigorous personnel selection, and many other factors must be carefully considered, such as an individual's ability to perform under pressure and their willingness to respond outside of working hours.
• The importance of cooperation at both the national and international levels must be recognized.
The unique challenges faced by ICS cybersecurity services can be simplified through best practices by CERTs, the application of established global and European best practices, and improved sharing of best practices.
Professor Udo Helmbrecht, Executive Director of ENISA, stated: “While ICS operated in separate and specific environments until a few decades ago, today they are typically connected to the internet. This enables the streamlining and automation of industrial processes, but also increases the risk of exposure to cyberattacks.”

More information