πŸ“‹ Case Study

Canadian Gold Mine Cyber-Hardened SCADA Power Control

Legacy Modbus TCP SCADA exposed to ransomware via contractor VPN; no segmentation or authentication

πŸ—οΈ Project Overview

Kirkland Lake Deep Vein Expansion – Ontario

🎯 Challenge

Legacy Modbus TCP SCADA exposed to ransomware via contractor VPN; no segmentation or authentication

πŸ”§ Design Approach

IEC 62443-3-3 compliant architecture: DMZ firewall, OPC UA over TLS, role-based access control, air-gapped engineering workstation, continuous anomaly detection using ML on packet metadata

πŸ“ Key Calculations

Attack Surface Reduction %

(Old_ports βˆ’ New_ports)/Old_ports Γ— 100
Result: 87%
Quantifies exposure reduction

Mean Time to Detect (MTTD)

Ξ£(detection_times)/n
Result: 4.2 min
Meets Tier 3 IEC 62443 SL-C requirement

πŸ“Š Results

Zero successful intrusions in 24 months; 92% faster incident response; audit-ready compliance documentation

πŸ’‘ Lessons Learned

  • β€’OT security must be co-designed with electrical engineersβ€”not bolted on
  • β€’ML-based detection outperformed signature-based tools for zero-day anomalies

βœ… Key Takeaways

  • 1OT security must be co-designed with electrical engineersβ€”not bolted on
  • 2ML-based detection outperformed signature-based tools for zero-day anomalies