Why is it virtually impossible to upgrade Operational Technology (OT)?
Sort by:
Look at companies like Schneider Electric—the Pacific Gas and Electric Company (PG&E) is a huge customer of theirs but they don't want to use the updated firmware or the updated versions of it because everything's validated on a specific version. And we have the same problem in lab environments: Once we do the validation process, which is a total pain, you don't want to go through all that again. We do our best to avoid it and we end up on these laboratory information management systems that are five revs out of date. And we keep using them—that's the reality in biotech. Until we get the people to do it.
How do you force them to upgrade? Because they're creating a huge attack surface. Is the company even supporting those machines anymore? And how are they supporting them on an unsupported OS? When those machines come up for renewal on their contract, that's a strong negotiation point right there.
Exactly. The complication is that we own the machine because we bought the robot and the machine that came with it, but we can’t update those machines without affecting the way the robot functions. So you're kind of stuck until the vendor says, "Okay, now we'll allow this update, but it requires this on the computer and it requires this on the robot," and they have to match because that's the way they validate it. It's brutal.
The problem is that these machines are supported by outside people for the most part, who we have to bring in. That's where it gets dicey because you need to give them access in a remote session. It’s not a good feeling when you know you have to give onsite people control over your system. So we created a second wireless network for when we have to bring the machine out of our locked network for servicing, etc. We only put the machines on that network so the technicians can have access. We always had a session going on and they can't really click anything, but we click on their behalf so there's no direct connection to the machine.