π Case Study
Gold Mine Cybersecurity Hardening at Newmont Tanami
Legacy OTA update mechanism lacked code signing, enabling spoofed firmware injection
ποΈ Project Overview
Securing AHS control network against ransomware targeting haul truck ECU firmware updates
π― Challenge
Legacy OTA update mechanism lacked code signing, enabling spoofed firmware injection
π§ Design Approach
Zero-trust architecture with hardware-enforced secure boot, TPM 2.0 attestation, and air-gapped update staging servers
π Design Diagram
AI-generated project design illustration
π Key Calculations
Attestation Interval
TTP / (latency + verification time)
Result: every 93 sec
Detects ECU tampering within sub-minute window
Firmware Signature Validation Time
RSA-3072 decryption + hash check
Result: 142 ms
Fits within 200ms safety-critical update window
π Results
Zero successful cyber intrusion in 22 months; firmware update success rate increased from 73% to 99.98%; achieved ISO/IEC 27001:2022 certification for AHS networkπ‘ Lessons Learned
- β’Secure boot must validate every firmware layer β bootloader, kernel, application
- β’Air-gapped staging requires manual cryptographic checksum verification before release
β Key Takeaways
- 1Secure boot must validate every firmware layer β bootloader, kernel, application
- 2Air-gapped staging requires manual cryptographic checksum verification before release