In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

★ Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute Liu Yao, Zhang Yabin, Zhang Xin, Wang Linkun, Xiong Wenze

★ National Petroleum and Natural Gas Pipeline Group Co., Ltd. Oil and Gas Regulation Center Sun Tieliang

Abstract:This article analyzes the differences between industrial control system cybersecurity and IT security, as well as their relationship with functional safety. It outlines the current technical and management issues in industrial control system cybersecurity, the new security challenges brought by the application of new technologies, and provides relevant suggestions based on the current state and trends of industrial control network security protection technologies.

Keywords:Industrial Control System; Cybersecurity; Functional Safety

1 Introduction

With the advancement of intelligence and networking in industrial control systems, the integration of information and physical systems is accelerating, leading to more cybersecurity challenges for industrial control systems. However, there are significant differences between industrial control network security and traditional IT security, mainly reflected in aspects such as real-time performance, availability, technical lifespan, patching, and antivirus capabilities. This article analyzes the main issues faced by industrial control system cybersecurity and the security requirements under the new situation, aiming to provide references and suggestions for the protection of industrial control system cybersecurity.

2 Definition and Scope of Industrial Control Systems2.1 Definition of Industrial Control Systems

Industrial control systems are integrated systems of hardware and software components that control industrial entities, capable of performing various functional tasks such as data acquisition, automatic control, and terminal execution. These include but are not limited to sensors, instruments, data acquisition and monitoring systems, distributed control systems, programmable logic controllers, dedicated controllers, human-machine interfaces, and remote terminal units.

2.2 Scope of Industrial Control Systems from the Perspective of IEC 62264-1

IEC 62264-1 provides a general model of enterprise control systems from the perspective of manufacturing enterprises, as shown in Figure 1, divided into four layers. Industrial control systems encompass Layer 0, Layer 1, Layer 2, and part of Layer 3: Layer 0 is the control object of the industrial control system; Layers 1 and 2 mainly complete industrial field control and process monitoring, which are the core functions of industrial control systems, and can be divided into continuous control, discrete control, and batch control; Layer 3 includes parts closely related to industrial field control, such as workflow/formula control and production process optimization. Most functions of Layer 3 and all functions of Layer 4 do not belong to the industrial control system category but are still part of business-related systems.

In actual industrial control system architectures in fields such as power and oil and gas, there are certain differences from this model, and some layers may not be applicable or may need to be flattened. Besides the enterprise perspective, the equipment perspective has a broader scope of industrial control systems, which are ubiquitous; various electromechanical equipment used in the industrial field will have control systems, such as those composed of PLCs or dedicated controllers.

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

Figure 1 Functional Hierarchical Model Defined in IEC 62264-1

3 Concepts of Industrial Control System Security

In English, safety and security represent different dimensions of safety. Generally, security refers to malicious incidents caused by external influences on the system, while safety refers to accidental incidents caused by internal errors (such as equipment failures or malfunctions) that lead to external impacts. Therefore, “cybersecurity” is Cyber Security, and “functional safety” is Functional Safety, representing different dimensions of system safety.

3.1 Industrial Control Network Security

According to IEC 62443-1-1, the definition of industrial control system network security is:

(1) Measures taken to protect the system;

(2) The state of the system resulting from establishing and maintaining protective measures;

(3) The ability to protect system resources from unauthorized access, as well as unauthorized or accidental modification, destruction, or loss;

(4) A computer-based system that can provide sufficient capability to ensure that unauthorized personnel and systems cannot modify software and its data or access system functions, while ensuring that authorized personnel and systems are not denied access;

(5) Preventing illegal or excessive penetration into industrial automation and control systems, or interference with the normal and expected operation of industrial automation and control systems.

Compared to IT system network security incidents, intruders in industrial control systems, after gaining system permissions, may not only steal sensitive information from enterprise users but also cause damage to industrial production processes, aiming to disrupt normal factory operations, even damaging equipment or causing major production accidents, leading to casualties and economic losses.

3.2 Functional Safety

Functional safety refers to avoiding unacceptable risks caused by system functional failures, focusing on how to bring the system into a safe and controllable state after a functional failure occurs. In the industrial field, industrial production systems achieve inherent safety goals through functional safety design and inherent safety design: achieving fault safety (even if equipment in the system fails, the system can timely detect and bring about or maintain a safe state) and error safety (even if personnel make operational errors, the system can timely bring about or maintain a safe state). Functional safety based on electrical/electronic/programmable electronic technology has been widely applied in fields such as petroleum, chemical, automotive, power, and rail transportation, playing an important role in ensuring production safety, with the basic standard being IEC 61508 (GB/T 20438).

3.3 Relationship Between Industrial Control Network Security and Functional Safety

With the deep integration of IT and operational technology (OT), cybersecurity threats gradually break through their own boundaries, posing threats to functional safety-related systems and their protective objects. The resolution of conflicts and collaborative protection between industrial control network security and functional safety technologies has become a hot issue and frontier technology in the field of industrial control system safety.

The International Electrotechnical Commission (IEC) established the TC65/WG20 working group, tasked with building a bridge between functional safety and cybersecurity in the field of industrial process measurement control and automation. This group proposed a coordinated framework for functional safety and cybersecurity based on the IEC 61508 and IEC 62443 series of standards, combined with the application requirements of industrial control systems, completing the IEC 63069 standard in May 2019. This standard not only provides unified definitions and explanations for potentially ambiguous concepts related to safety and security but also proposes an interaction framework for functional safety and cybersecurity. The interaction framework provides solutions for conflicts that may arise during the integration of the two, considering cybersecurity as providing a secure execution environment for system functions and functional safety. Based on the current analysis of the differences between functional safety and cybersecurity, this article starts from basic concepts to illustrate the fundamental connections between the two, as shown in Figure 2.

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

Figure 2 Relationship Between Functional Safety and Cybersecurity

From the perspective of functional safety, industrial control systems can be divided into safety-related systems and basic process control systems. A failure in the basic process control system will impose a requirement on the safety-related system; both types of systems may encounter cybersecurity issues. From the perspective of functional safety, if a safety-related system fails and is not timely controlled (for example, if redundancy is not designed), it will lead to functional failure. If an action requirement occurs at this time (the system is in a required mode) or the system is in a continuous mode, it will lead to hazardous events; in terms of cybersecurity: any vulnerability in a subsystem that is exploited will lead to a cybersecurity incident. The impact of incidents can be categorized into three types: no safety impact; becoming a new fault source for the basic process control subsystem; or becoming a new fault source for the safety-related system. Functional safety and cybersecurity have both connections and conflicts:

(1) Safety-oriented conflicts: At times, the requirements of safety and security may be completely opposite. For example, regarding fire doors, from the perspective of functional safety, the operation to open the fire door or fire door control system should be simple and obvious, ensuring easy opening in the event of a fire (imposing a requirement on the fire door); while from the perspective of security, the fire door should have access permissions set to prevent external intrusion.

(2) Redundancy conflicts: Redundancy can improve reliability and availability in safety, while from the perspective of security, more redundancy means more vulnerabilities or interfaces, potentially leading to more vulnerabilities.

(3) Design conflicts: Some designs that strengthen one aspect of security may create flaws in another aspect. A classic example is a car designed to automatically open the doors when subjected to significant pressure on the roof (i.e., during a rollover) to ensure the escape of occupants, but this feature provides convenience for car thieves; the former is a safety issue, while the latter is a security issue.

(4) Operational conflicts: Changes in functional safety require control, while cybersecurity needs timely updates.

Therefore, the cybersecurity of industrial control systems must consider the protection of production control systems and safety-related systems, achieving synergy with functional safety and resolving conflicts.

4 Characteristics of Industrial Control System Cybersecurity4.1 Cybersecurity Threats in Industrial Control Systems

The cybersecurity threats to industrial control systems mainly stem from vulnerabilities in operating systems, software, hardware, and protocols, which attackers often exploit to infiltrate systems. Devices commonly use outdated systems, with unpatched vulnerabilities and default passwords. Threats also include internal accidental events, third-party backdoors, and internal malicious attacks. With the advancement of industrial intelligence, digitization, and networking, systems are transitioning from closed to open, increasing attack paths and surfaces. Hackers may launch APT attacks against critical facilities, such as the Ukrainian power grid and Saudi petrochemical plant incidents. Common attack types and impact analysis at various levels within industrial enterprises are shown in Table 1.

Table 1 Types of Attacks and Impacts at Various Levels Within Industrial Enterprises

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

Unlike IT network security, the bottom line for industrial control security is to ensure production and prevent accidents. For industrial control systems, latent attacks and unknown viruses are two types of attacks that are currently difficult to suppress through existing network security measures, requiring reliance on other protective measures such as functional safety to control risks.

From cases such as the Stuxnet virus attack in Iran, it is evident that attacks on industrial control systems consist of two parts: one is network attacks, probing and infiltrating information networks to gain data modification permissions; the other is utilizing system design and business processes to tamper with instructions or data, causing abnormal operations or preventing safety responses. The first part is similar to conventional network attacks, while the second part reflects the uniqueness of industrial production, where attackers design strategies that combine business logic and protective mechanisms to bring the system to a specific state and hide their attack behavior. These events exhibit characteristics of information-physical coupling and attack concealment. Traditional industrial production systems are difficult to attack due to their closed and dedicated communication; however, as they evolve towards networking and intelligence, systems become open and interconnected, deeply coupling the information domain with the physical domain. Attacks on such systems must consider business processes and physical constraints, and their destructive power depends on these conditions. Industrial production systems have safety mechanisms against natural faults, but attackers often remain hidden for long periods, gaining knowledge of the system to evade monitoring, ultimately targeting specific business processes and safety mechanisms to formulate strategies, using network attack techniques to coordinate attacks on multiple targets, bypassing physical protections, disrupting industrial production processes and equipment, affecting normal factory operations, and even causing major production accidents. This latent and coordinated nature is the main difference between industrial attacks and traditional internet attacks.

4.2 Differences Between Industrial Control Network Security and IT Network Security

Compared to traditional information systems, the primary goal of industrial control systems is to complete measurement, control, monitoring, and other business functions related to industry, which has specific requirements in terms of security needs. Compared to IT network security, industrial network security must adapt to special physical environments, real-time performance, reliability, continuity, and the characteristics of industrial protocols, making protection more complex, costly, and challenging. ISA TR84.00.09 provides a comparison of industrial security and IT security, as shown in Table 2.

Table 2 Comparison of Industrial Security and IT Security

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends5 Analysis of Cybersecurity Requirements and Challenges in Industrial Control Systems5.1 Existing Problems in Industrial Control System Cybersecurity

Considering the characteristics of industrial control system cybersecurity, the following issues currently exist:

(1) A large number of operational industrial control systems are outdated, with limited cybersecurity considerations. Due to their long lifecycle and high reliability, many operational systems still use technologies from over a decade ago, with little consideration for cybersecurity risks and protective measures during deployment. Additionally, upgrading existing systems for cybersecurity requires a comprehensive assessment of the impact on current systems.

(2) The lifecycle and reliability of cybersecurity protection products may not be compatible with industrial control systems. If deployed without synchronizing the lifecycle with industrial control systems or unable to adapt to the industrial application environment, they cannot provide long-term protection for industrial control systems and may become new points of failure or risk in the system. For example, some industrial control systems require reliability of 99.99%, while security protection products generally struggle to meet this requirement.

(3) The complexity of industrial scenarios and diversity of equipment pose challenges to the universality of protective technologies. Industrial equipment systems are customized, with many combinations, significant differences, and low universality of communication protocols. The same device may also have configuration differences, and there are technical barriers between manufacturers, making it difficult to generalize attack and defense technologies. Many issues with equipment systems require specific manufacturers to address, and remote maintenance and upgrades by manufacturers may also lead to the leakage of confidential information.

(4) Industrial control systems have many access devices and dispersed suppliers, making it difficult to discover and control vulnerabilities and backdoors. The lifecycle of access devices is constantly changing, requiring defenses against new attacks and mitigation of new vulnerability risks. The dispersion of suppliers complicates supply chain management and traceability. Many foreign specialized software and hardware devices used in China operate as “black boxes,” making it difficult to identify security risks.

(5) Traditional IT security technologies do not meet the real-time requirements of industrial sites. IT systems have low requirements for response real-time performance, and brief reboots or interruptions are acceptable; however, industrial control systems have extremely high real-time requirements, and high latency may lead to production accidents.

(6) Industrial control systems have high availability requirements, making update and upgrade management difficult. Their design focuses on completing the actions required for the production process, so cybersecurity for industrial control systems must prioritize the stability and availability of the enterprise production process. Traditional IT security products require timely updates to their feature libraries; otherwise, they cannot provide effective protection. Most industrial enterprises do not allow industrial control systems to connect directly to the internet to minimize external disturbances, and upgrades require advance planning, professional operation, and comprehensive testing, leading to delays in updating feature libraries and weakened protective capabilities.

(7) Industrial devices have limited computing resources and weak antivirus capabilities. Outdated industrial hardware devices lack additional resources to support virus scanning and library updates, and installing antivirus software may affect production. Currently, there is a lack of antivirus tools or software specifically for industrial control systems.

(8) IT network security risk assessment methods are not entirely applicable to industrial control networks. The high-risk nature of industrial production systems means that attacks may lead to severe consequences, requiring cybersecurity risk assessments to be integrated with production safety risk assessments.

5.2 New Challenges Brought by New Technologies in Industrial Control Systems

The application of new technologies also brings new security challenges to industrial control systems:

(1) The fusion of information and physical systems brings new issues: traditional industrial production systems are isolated from the outside world, with monitoring and control operations mostly executed locally. After the fusion of information and physical systems, the originally closed industrial control systems have increased access devices and interconnected systems, with frequent and complex data exchanges between enterprises and various levels within factories, providing more types of channels and broader attack surfaces for external attacks, further increasing inherent vulnerabilities, and presenting a trend towards flattening, shortening the attack chain to the bottom-level production processes. Attackers can exploit vulnerabilities to tamper with the functional logic or data of control systems (including functional safety-related systems), causing the system to be controlled or uncontrolled, thereby damaging the physical domain production systems and triggering severe production safety accidents. Furthermore, how to deploy cybersecurity protection for functional safety-related systems (such as safety instrumented systems) set up for high-risk consequences and how cybersecurity protection does not affect the execution of safety functions remain unresolved issues.

(2) New intelligent technologies also bring new security challenges, such as the application of large-scale artificial intelligence (AI): AI learning frameworks and components have security vulnerabilities that can lead to industrial control system security issues; AI technology can enhance network attack capabilities, posing threats and challenges to existing network security protection systems; AI algorithms can obtain and record details of training data and runtime collected data through reverse attacks; AI technology can strengthen data mining and analysis capabilities, increasing the risk of leakage of sensitive industrial information.

6 Current Status and Trends of Cybersecurity Protection in Industrial Control Systems6.1 Cybersecurity Technologies for Industrial Control Systems

Currently, the cybersecurity protection technologies for industrial control systems mainly draw from and optimize existing technologies in the information technology field. During the 13th and 14th Five-Year Plans, relevant projects were initiated to preliminarily establish a protective technology system and develop corresponding devices and systems. Currently, commonly used cybersecurity protection technologies and development trends include: network segmentation and isolation, using industrial firewalls for isolation and filtering; upgrading security protocols, promoting the application of next-generation protocols; intrusion detection and response, deploying specialized devices, analyzing traffic, and utilizing artificial intelligence; industrial control honeypots for threat capture; strengthening identity authentication, adopting zero-trust architecture; vulnerability management and patching, updating and patching high-risk vulnerabilities, using virtual patches to mitigate risks; providing OT security training for relevant personnel; formulating emergency response plans, including contingency plans, drills, and data backups; and constructing attack graphs and other technologies. These technologies are categorized into passive and active based on protection strategies, with passive protection being measures taken after an attack and active protection being the elimination of potential threats before an attack. Currently, the focus of protection tends to be on boundary protection, but traditional defense technologies struggle to withstand new types of attacks. The cybersecurity protection of industrial control systems is transitioning from boundary and passive protection to deep and active protection. Furthermore, protection must consider both the industrial production system itself and functional safety; simply adding cybersecurity protection measures to functional safety systems may disrupt existing protective functions. Therefore, it is essential to consider the compatibility of various security technologies and establish a new protective technology system and solutions based on multiple factors.

6.2 Cybersecurity Management for Industrial Control Systems

Currently, the cybersecurity management of industrial control networks in production enterprises is mainly undertaken by the information technology department. However, due to the limited knowledge structure of personnel in the information technology department, there are certain obstacles to promoting cybersecurity management in industrial control networks, and the lack of professional talent restricts enterprises from enhancing their protective capabilities. Additionally, emergency plans for industrial control network security incidents are generally incomplete or even absent. Even if some units have plans, they are often difficult to effectively integrate with emergency plans for safety production accidents. When systems are attacked and production is interrupted, enterprises find it challenging to quickly resume production and minimize losses. The cybersecurity of industrial control systems is closely related to safety production, requiring the integration of traditional network security management strategies and processes into the production safety management system. Finally, the fragmentation of domestic cybersecurity standards for industrial control systems means that enterprises may lack applicable standards or cannot systematically obtain relevant standards, which is not conducive to building an effective management system. In summary, there are many issues in the management system, talent cultivation, system construction, and standard improvement of industrial control system cybersecurity that need urgent resolution.

6.3 Development Trends in Cybersecurity Protection for Industrial Control Systems

(1) Deep protection and active protection: Currently, the focus of protection for industrial control systems still leans towards boundary protection, such as the power system implementing a security protection strategy of “security zoning, network exclusivity, lateral isolation, and vertical authentication.” However, traditional defense technologies that block based on known attack characteristics can no longer effectively resist new types of network attacks, such as advanced persistent threats (APTs), where attackers often use covert and complex means to launch targeted attacks through persistent infiltration, exhibiting strong concealment, latency, and long-term entanglement. Therefore, under the new circumstances, the cybersecurity protection of industrial control systems is transitioning from simple boundary protection and passive protection to deep protection and active protection.

(2) Integrated protection: Cybersecurity protection technologies for industrial control systems must consider both the industrial production system itself and functional safety. Traditionally, relatively complete functional safety systems have been established for industrial production systems to ensure safety in the event of faults, failures, errors, or even natural disasters. However, under the new circumstances, network attacks as a new source of danger are often not considered in traditional functional safety systems. Simply adding cybersecurity measures may disrupt safety functions (such as hindering the execution of protective functions, reducing the timeliness of protective function actions, and increasing the load on protective systems), significantly increasing the safety risks faced by industrial production systems. Therefore, when addressing industrial systems, it is essential to fully consider the compatibility of various security technologies and not isolate the consideration of network security protection for the system. It is also necessary to consider whether the cybersecurity protection facilities deployed in OT systems will impact the inherent attributes of the production system, such as availability, reliability, real-time performance, determinism, durability, continuity, and robustness, to avoid issues where achieving cybersecurity ultimately leads to functional safety problems, thereby affecting the normal operation of industrial production systems and even impacting assets, personnel, and the environment.

In summary, the cybersecurity protection of industrial control systems needs to establish a new protective technology system and solutions based on the characteristics of network attacks, application scenario requirements, production business characteristics, and multi-security compatibility requirements.

7 Conclusion

In the future, as industrial digitalization and intelligence continue to advance, the cybersecurity issues of industrial control systems will become more complex. Therefore, it is necessary to continuously pay attention to the characteristics and needs of industrial control systems, promote the combination of technological innovation and management optimization, and build a multi-layered, all-encompassing protective system to ensure the safe and stable operation of industrial production.

References omitted.

Author Profiles

Liu Yao (1987-), female, from Taizhou, Jiangsu, senior engineer, bachelor’s degree, currently employed at the Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute, with main research directions in functional safety, industrial control information security, and integrated safety.

Zhang Yabin (1986-), male, from Baoding, Hebei, senior engineer, PhD, currently employed at the Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute, with main research directions in key technologies and standards for intelligent manufacturing and industrial control security.

Zhang Xin (1990-), male, from Liaocheng, Shandong, senior engineer, PhD, currently employed at the Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute, with main research directions in risk assessment and other key technology research and standard formulation.

Wang Linkun (1974-), male, from Heilongjiang, professor-level senior engineer, PhD, currently employed at the Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute, with main research directions in fieldbus and electromechanical control.

Xiong Wenze (1986-), male, from Quxian, Sichuan, senior engineer, master’s degree, currently employed at the Mechanical Industry Instrumentation Comprehensive Technology Economic Research Institute, with main research directions in safety and reliability analysis and evaluation of complex systems.

Sun Tieliang (1967-), male, from Dezhou, Shandong, senior engineer, bachelor’s degree, currently employed at the National Petroleum and Natural Gas Pipeline Group Co., Ltd. Oil and Gas Regulation Center, with main research directions in automation control, communication, and industrial control system cybersecurity.

· end ·

Source | “Automation Expo” August 2025 issue

Editor | He Min

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

For cooperation or consultation, please contact the Industrial Safety Industry Alliance platform secretary WeChat: ICSISIA20140417

Recommended Readings

Heavyweight | “Automation Expo” 2025 First Issue and “Special Issue on Industrial Control System Information Security (Volume 11)” Released

Must-Read for the 2025 Two Sessions | These Industrial Information Security Proposals Will Rewrite Industry Rules

Ministry of Industry and Information Technology | Risk Warning on Preventing Network Attacks Targeting DeepSeek Local Deployment

Insights | Industrial Long-Distance Oil and Gas Pipeline Control Security Protection: Strategies, Practices, and Prospects

DeepSeek Analysis | Current Status and Future Prospects of Zero Trust Security Architecture in the Industrial Field

White Paper | Northeast University: 2024 Industrial Control Network Security Situation White Paper (Download Attached)

Recommended Reading | The Five Network Security Technologies That Are About to Become Obsolete

Insights | Research on Encryption Technology for Industrial Programmable Control Systems

Recommended Reading | DeepSeek Insights and Reflections from the Perspective of Security Personnel

Ministry of Industry and Information Technology | In 2024, China’s Information Security Sector Revenue Will Reach 229 Billion Yuan

Attention | Results of Security Testing for Key Network Devices (19th Batch)

Power Safety | 2024 New Power System Safety Construction Guidelines Report (Download Attached)

Ministry of Industry and Information Technology and Thirteen Departments | 2024 List of Typical Project Cases for Network Security Technology Applications

Attention | Joint Issuance of the Implementation Plan for Improving Data Flow Security Governance by the National Development and Reform Commission, National Data Bureau, and Six Other Departments

In-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical TrendsIn-Depth Analysis of Industrial Control System Cybersecurity Requirements and Technical Trends

Leave a Comment