π Case Study
Canadian Gold Mine Cyber-Hardened SCADA Power Control
Legacy Modbus TCP SCADA exposed to ransomware via contractor VPN; no segmentation or authentication
ποΈ Project Overview
Kirkland Lake Deep Vein Expansion β Ontario
π― Challenge
Legacy Modbus TCP SCADA exposed to ransomware via contractor VPN; no segmentation or authentication
π§ Design Approach
IEC 62443-3-3 compliant architecture: DMZ firewall, OPC UA over TLS, role-based access control, air-gapped engineering workstation, continuous anomaly detection using ML on packet metadata
π Key Calculations
Attack Surface Reduction %
(Old_ports β New_ports)/Old_ports Γ 100
Result: 87%
Quantifies exposure reduction
Mean Time to Detect (MTTD)
Ξ£(detection_times)/n
Result: 4.2 min
Meets Tier 3 IEC 62443 SL-C requirement
π Results
Zero successful intrusions in 24 months; 92% faster incident response; audit-ready compliance documentationπ‘ Lessons Learned
- β’OT security must be co-designed with electrical engineersβnot bolted on
- β’ML-based detection outperformed signature-based tools for zero-day anomalies
β Key Takeaways
- 1OT security must be co-designed with electrical engineersβnot bolted on
- 2ML-based detection outperformed signature-based tools for zero-day anomalies