📋 Case Study

Coal Mine ROC Cybersecurity Hardening in Appalachia

Legacy PLCs exposed to corporate IT network with no segmentation; failed NIST SP 800-82 audit

🏗️ Project Overview

Consol Energy’s Robinson Run ROC protecting 3 longwall operations

🎯 Challenge

Legacy PLCs exposed to corporate IT network with no segmentation; failed NIST SP 800-82 audit

🔧 Design Approach

Zero-trust architecture with OT/IT DMZ, ICS-specific IDS (Dragos), air-gapped backup ROC, and role-based access control (RBAC) aligned to ISA/IEC 62443-3-3

📐 Design Diagram

Coal Mine ROC Cybersecurity HardeningAppalachia • Zero-Trust OT/IT ArchitectureLegacy PLCs(Pre-Hardening)−92%Exposed PortsOT/IT DMZ(ISA/IEC 62443-3-3)Dragos ICS IDSMTTD: 4.2 hrs → 8.7 minAir-Gapped ROCBackup & RecoveryRBAC EngineNIST SP 800-82 Audit: FAILED → PASSED

AI-generated project design illustration

📐 Key Calculations

Attack Surface Reduction

Exposed Ports Pre − Exposed Ports Post
Result: 92% reduction
Eliminated direct internet-facing OT assets

Mean Time to Detect (MTTD)

Avg Detection Time (pre/post)
Result: 4.2 hrs → 8.7 min
Enabled proactive threat hunting

📊 Results

Passed all subsequent MSHA cybersecurity inspections; zero unauthorized access events in 24 months; achieved ISA/IEC 62443-3-3 Level 2 certification

💡 Lessons Learned

  • Cybersecurity cannot be retrofitted—must be embedded in ROC architecture design phase
  • OT security teams require joint reporting lines to both IT and mining operations

Key Takeaways

  • 1Cybersecurity cannot be retrofitted—must be embedded in ROC architecture design phase
  • 2OT security teams require joint reporting lines to both IT and mining operations