Your mine wants the data out. Hackers want a way back in. Why one-way thinking could become mining’s next cyber-security advantage

Mining's growing appetite for operational data is making cyber resilience an architecture problem.

As mining operations push more production data into remote operations centres, cloud platforms and analytics systems, the industry faces a deceptively simple problem: how do you get useful data out of an operational network without creating another pathway back in? Chris Rule, General Manager Defence, Security and Resilience at GME, says the answer starts with knowing exactly how your mine is connected, who has access and which connections genuinely need to work both ways.

Modern mines thrive on connectivity.

Fleet telemetry feeds remote operations centres. Condition-monitoring systems tell maintenance teams when equipment is beginning to fail. Historians capture years of plant performance. OEMs diagnose machinery from hundreds or thousands of kilometres away. Cloud platforms crunch production data and dashboards put operational information in front of people who may never set foot on site.

All of that connectivity creates value. It also creates doors.

And according to Chris, mining companies need to become much more deliberate about deciding which of those doors actually need to swing both ways.

“The level of connectivity is growing. It’s proliferating, and controlling that connectivity is getting increasingly challenging for operators and owners of these systems,” Chris told The Rock Wrangler.

GME is the Asia Pacific distributor for US-based Owl Cyber Defense, a specialist in data diodes and cross-domain solutions used across government and critical infrastructure environments.

The issue sits at the increasingly blurred boundary between information technology and operational technology.

For miners, the risk is no longer confined to corporate email servers, laptops or databases. When enterprise IT is connected to the systems running a processing plant, haulage fleet or other critical infrastructure, a compromised corporate network can potentially provide a route towards the operational environment. The reverse can also be true.

An unmanaged or poorly secured connection installed to support a piece of operational equipment can potentially become another route into the wider corporate network. That changes the cyber-security conversation considerably.

For mine managers and operations leaders, this is not simply an IT issue. It is becoming an operational resilience issue.

Chris Rule, General Manager Defence, Security and Resilience at GME, says the answer starts with knowing exactly how your mine is connected, who has access and which connections genuinely need to work both ways.

Everybody wants the data

The commercial logic behind greater connectivity is hard to argue with. Mining companies want real-time visibility across increasingly complex and geographically dispersed operations.

Operational data that once remained largely within a plant or mine-site control system is now valuable across the business. Remote operations centres want it. Maintenance teams want it. Corporate analysts want it. Equipment suppliers want it. Increasingly, cloud-based applications and artificial intelligence systems want it too.

But there is an important distinction between needing data to leave an operational environment and needing somebody outside that environment to communicate back into it.

Chris believes operators should scrutinise that difference far more closely. “You need to think seriously about minimising what we’d call two-way data flows,” he said.

A conventional firewall can be configured to control traffic and reduce the risk. But Chris argues there is a fundamental difference between using software to tell a connection which direction it is allowed to operate and designing the connection so data physically cannot travel backwards.

That is where data diodes enter the picture.

A data diode creates a hardware-enforced one-way data path between a protected source network and a destination network. Image supplied by GME.

The one-way street

Despite the futuristic name, the basic principle behind a data diode is remarkably simple. It creates a one-way communications path.

Inside the system, data travels across a physical link from a transmitting side to a receiving side. The architecture allows information to move in one direction while eliminating the return communications pathway.

For a mine, that could mean historian, production or equipment-health information leaving the operational technology network for analysis elsewhere without simultaneously creating an inbound route from the corporate network.

Chris describes it as hardware-enforced separation. The distinction matters because software can be misconfigured, changed or potentially compromised. A physical one-way architecture is intended to remove that class of return-path risk altogether.

“If you can constrain your information flow requirements to a one-way solution, the data diode is the premier way of ensuring you get the right data flowing in the direction you want,” Chris said.

That does not mean every connection on a mine should suddenly have a data diode installed. Some systems genuinely require two-way communications. Remote control, particular diagnostic functions and other applications may need information travelling both ways.

More sophisticated cross-domain technologies can support controlled two-way exchanges, using filtering and inspection to determine what is permitted across the boundary.

The important question for the mine is therefore not, ‘Do we need a data diode?’ It is much more basic: does this connection actually need to work both ways? If the answer is no, why create a pathway back in?

In this schematic, SCADA, databases and OT assets can send approved information to external networks without creating a return communications path. Image supplied by GME.

A data diode creates a hardware-enforced one-way data path between a protected source network and a destination network. Image supplied by GME.

The problem hiding in plain sight

One of the more uncomfortable cyber risks on a mature mine may have accumulated gradually rather than arrived through one major technology project.

Consider the number of outside organisations that may have interacted with a large operation over its life. A drive supplier may have been given remote diagnostic access. Then the crusher OEM. Then a control systems integrator. Then an autonomous haulage specialist. Then a condition-monitoring provider. Then another contractor during an upgrade.

Each access arrangement may have been entirely sensible. The problem is what happens over five, 10 or 20 years.

“These types of third-party links proliferate in an uncontrolled manner,” Chris said. “Everyone in isolation is a completely legitimate connection to make.”

Collectively, however, the result can be a network with more doors than anybody realises. Contracts finish. People leave suppliers. Equipment is replaced. Temporary access arrangements quietly remain. Projects change hands. Credentials that once belonged to an important service provider may still exist years later.

That leads to perhaps the simplest and most important question in the entire discussion: who can access your mine’s operational network today? Not who should be able to access it. Not who management thinks can access it. Who actually can.

Know your network

Chris believes one of the first questions senior mining leaders should ask their cyber-security, IT and OT teams is whether they genuinely understand the network they are responsible for.

“Do we know our networks? Do we know how we are connected, both internally and to the wider world?” he said. “When was the last time we did an audit on that clear picture of it? Can we map our network connectivity?”

He cites an old cyber-security warning that should resonate particularly strongly with operators of long-lived industrial assets: “If you think your network is air-gapped, it’s not.”

The longer a network has existed, the greater the opportunity for legitimate but forgotten connections to accumulate. That makes network mapping and access auditing much more than a compliance exercise.

It becomes the equivalent of knowing which pipes, roads, conveyors or power feeds enter an operating facility. If you do not know the connection exists, you cannot properly manage the risk attached to it.

Chris reduces the issue to three questions mining leaders can readily take to their technical teams: Do we know our network? Have we separated our operational technology from our enterprise network? And do we know who is on it?

None requires a degree in cyber security. All deserve clear answers.

Segmentation can allow selected OT data to reach historian servers, cloud platforms, security operations centres and corporate networks while blocking access from higher-threat networks. Image supplied by GME.

Can the mine still run when the connection disappears?

There is another dimension to increasingly connected mining operations that has less to do with stopping hackers and more to do with what happens when technology simply becomes unavailable.

Chris believes critical operational systems should be designed around the assumption that, one day, external connectivity may disappear. “Philosophically you need to be able to operate in a disconnected mode, and you need to rehearse that and test it,” he said.

That principle has direct operational consequences. If a corporate network suffers a major ransomware attack and has to be shut down, can the mine still operate? Can local operators control critical equipment? Can safety systems continue to function independently? Can essential performance information still be collected? Can operational history still be recorded? Can production continue without cloud services? What happens if the remote OEM disappears at exactly the moment the site needs support?

Mining has spent years extracting enormous efficiency from remote operations, remote diagnostics and centralised expertise. The challenge is ensuring those efficiencies have not quietly become dependencies capable of stopping production.

Good segmentation can help. If an enterprise network is compromised but operational systems have been deliberately separated from it, the mine may be able to continue operating while the corporate incident is contained.

That is when cyber architecture becomes business continuity.

A lesson from Defence

Chris’s perspective is shaped partly by GME’s work across Defence and critical infrastructure.

Defence has long operated multiple networks with different levels of sensitivity and deliberately separates those environments. Highly sensitive systems may be isolated from internet-facing enterprise networks while controlled gateways move specified information between them.

Weapon systems present an even more relevant analogy for mining. Like operational technology, they must remain functional when external connectivity is unavailable.

Defence therefore places considerable emphasis on network separation, carefully defined information flows and the ability to operate disconnected.

Mining obviously does not need to replicate Defence architecture wholesale. Nor should it. But the underlying philosophy is relevant.

Not every network should be treated equally. Not every device needs access to everything else. And not every useful connection needs to be a two-way street.

A data diode is designed to physically enforce one-way data flow, allowing selected information out of a protected network while preventing a return path. Image supplied by GME.

The questions worth asking

Cyber security can quickly disappear into acronyms, standards and specialist terminology. For a mine manager or engineering leader, the practical questions are much simpler.

Ask your team to show you the network. Ask where the operational network touches the corporate network. Ask what information crosses that boundary and why. Ask which connections need to work both ways. Ask which third parties have remote access. Ask when those access rights were last reviewed. Ask whether the operation can continue safely if the corporate network is disconnected tomorrow.

And if an answer begins with, ‘We think...’, keep asking.

Mining’s growing appetite for operational data is unlikely to diminish. Nor should it. The productivity gains from connected equipment, remote operations, condition monitoring and advanced analytics are too valuable.

The challenge is making connectivity deliberate rather than accidental.

That means understanding where the network begins and ends, deciding exactly what information needs to move across those boundaries, and refusing to create a two-way communications path simply because that is the way it has always been done.

Because the most dangerous connection on a mine may not be the sophisticated cyber attack anybody is watching for. It may be the perfectly legitimate one everybody forgot was there.

Article Enquiry Form