
Article
Five expert recommendations to build a resilient cybersecurity strategy
Operational technology environments are more connected than ever. Remote access, cloud-connected systems, integrated operations centres and increasing data exchange between IT and OT networks have brought significant operational benefits. They have also expanded the opportunities to attack organisations operating critical infrastructure and industrial facilities. Recent incidents across the energy, manufacturing, water and transportation sectors have shown that cyber events can lead to operational disruption, reputational damage and significant financial consequences.
In many cyber incidents, the first indication of an attack comes from unusual behaviour within the control system itself and not from a flashing light. Operators may observe unexpected process changes, abnormal system responses or unexplained actions that require investigation and escalation.
While some cyber threats produce obvious symptoms, more sophisticated attacks may attempt to manipulate industrial processes while avoiding detection, as demonstrated by attacks such as Stuxnet. This remains one of the most important cybersecurity events in industrial operations. By targeting industrial control systems and influencing the behaviour of physical equipment, it showed how cyberattacks can affect the kind of critical assets found across energy, process industries and mining operations. It also highlighted the importance of preparing operators to recognise unusual conditions and respond effectively when control systems cannot be fully trusted.
Cybersecurity can be broken down into three main pillars: people, processes, and technology. You may have the technology to prevent and detect a compromise, but if you do not have proper processes and procedures in place and your staff – your front-line defence – are not adequately trained to use this technology, you create vulnerabilities.
Modern facilities in the digital age are critically dependent on computer-based systems to operate and protect equipment and processes. Yet, how often do we stop and consider the following question: How do I safely shut down the facility if I cannot use the computer-based control system to do so?

This is where a digital twin may be helpful as a training tool to equip operators and engineers to recognise symptoms of a compromise of the control system and respond accordingly.
A digital twin may be used to simulate a security breach and develop decision-making and mitigative responses to the simulated cyberattack. Developers can incorporate several scenarios to test and refine operator recognition of system compromises and their response to secure the process safely.
However, while common live attacks and malware with overt symptoms such as remote access trojans, cryptolocker, and denial of service trojans can be developed in a digital twin, highly engineered covert attacks such as Stuxnet cannot.
A digital twin can provide a real-time, responsive environment to simulate various types of control system compromises. It can also train and test operators on the diagnostic process to identify the extent of the compromise, level of availability and integrity of the control and safety systems and take appropriate actions to respond to a loss of control.
A digital twin is a valuable tool in developing decision-making trees to determine the extent of the threat and the appropriate response. This approach mimics the aerospace industry’s use of simulators to simulate systemic failures enabling the development, evaluation and application of viable troubleshooting and decision-making procedures in real-time virtual environments. The objective is to train front-line operational personnel to recognise a control system compromise, declare an emergency, initiate the safe shutdown of decision-making criteria to determine the salient extent of compromise and control, implement actions to secure the facility and correspond with the level of compromise.
Beyond training operators, digital twins can act as secure testing environments for cybersecurity exercises. Organisations can use virtual environments to validate procedures, assess the operational impact of cyber incidents and refine response strategies before applying changes to live systems. This enables teams to build confidence in both their technical controls and operational decision-making processes.

While industrial organisations recognise the importance of incident preparedness, testing cyber response plans in live operational environments is rarely practical.
For many organisations, testing cyber response plans in a live environment is simply not practical. An offshore platform cannot be deliberately disconnected to assess operator response, and a mining operation cannot pause critical production systems to rehearse every possible cyber scenario.
This creates a challenge: how can organisations prepare personnel to respond to cyber-related disruptions without introducing unnecessary operational risk?
In oil and gas facilities, digital twins can provide a safe environment for operators and engineers to rehearse cybersecurity scenarios that would be difficult or impossible to replicate in a live plant.
These scenarios may include:
By simulating these situations, organisations can evaluate decision-making processes, validate response procedures and improve operator readiness before an actual incident occurs.
Mining operations often rely on highly integrated systems connecting mine sites, processing facilities and remote operating centres. As connectivity increases, so does the importance of preparing for cyber-related disruptions.
Digital twins can be used to simulate:
These exercises can help organisations identify gaps in procedures, improve response planning and strengthen operational resilience without affecting production activities.