πŸ“‹ Case Study

Gold Mine Cybersecurity Hardening at Newmont Tanami

Legacy OTA update mechanism lacked code signing, enabling spoofed firmware injection

πŸ—οΈ Project Overview

Securing AHS control network against ransomware targeting haul truck ECU firmware updates

🎯 Challenge

Legacy OTA update mechanism lacked code signing, enabling spoofed firmware injection

πŸ”§ Design Approach

Zero-trust architecture with hardware-enforced secure boot, TPM 2.0 attestation, and air-gapped update staging servers

πŸ“ Design Diagram

OTA
ClientSecure
Boot
Air-Gapped
Staging Server
Unsigned firmwareAttestation
(93 s)
Signed firmware
(RSA-3072, 142 ms)
Legacy OTA
Challenge
Spoofed firmware
injection risk
Hardware-enforced
secure boot
TPM 2.0
Attestation
Gold Mine Cybersecurity HardeningNewmont Tanami β€’ Zero-Trust Firmware Lifecycle

AI-generated project design illustration

πŸ“ Key Calculations

Attestation Interval

TTP / (latency + verification time)
Result: every 93 sec
Detects ECU tampering within sub-minute window

Firmware Signature Validation Time

RSA-3072 decryption + hash check
Result: 142 ms
Fits within 200ms safety-critical update window

πŸ“Š Results

Zero successful cyber intrusion in 22 months; firmware update success rate increased from 73% to 99.98%; achieved ISO/IEC 27001:2022 certification for AHS network

πŸ’‘ Lessons Learned

  • β€’Secure boot must validate every firmware layer β€” bootloader, kernel, application
  • β€’Air-gapped staging requires manual cryptographic checksum verification before release

βœ… Key Takeaways

  • 1Secure boot must validate every firmware layer β€” bootloader, kernel, application
  • 2Air-gapped staging requires manual cryptographic checksum verification before release