📋 Case Study
Coal Mine ROC Cybersecurity Hardening in Appalachia
Legacy PLCs exposed to corporate IT network with no segmentation; failed NIST SP 800-82 audit
🏗️ Project Overview
Consol Energy’s Robinson Run ROC protecting 3 longwall operations
🎯 Challenge
Legacy PLCs exposed to corporate IT network with no segmentation; failed NIST SP 800-82 audit
🔧 Design Approach
Zero-trust architecture with OT/IT DMZ, ICS-specific IDS (Dragos), air-gapped backup ROC, and role-based access control (RBAC) aligned to ISA/IEC 62443-3-3
📐 Design Diagram
AI-generated project design illustration
📐 Key Calculations
Attack Surface Reduction
Exposed Ports Pre − Exposed Ports Post
Result: 92% reduction
Eliminated direct internet-facing OT assets
Mean Time to Detect (MTTD)
Avg Detection Time (pre/post)
Result: 4.2 hrs → 8.7 min
Enabled proactive threat hunting
📊 Results
Passed all subsequent MSHA cybersecurity inspections; zero unauthorized access events in 24 months; achieved ISA/IEC 62443-3-3 Level 2 certification💡 Lessons Learned
- •Cybersecurity cannot be retrofitted—must be embedded in ROC architecture design phase
- •OT security teams require joint reporting lines to both IT and mining operations
✅ Key Takeaways
- 1Cybersecurity cannot be retrofitted—must be embedded in ROC architecture design phase
- 2OT security teams require joint reporting lines to both IT and mining operations