Taking our head out of the sand – Challenges of Operational Technology Security at an Airport
Download resourcesAbout this session
Andrew Faber, who leads IT security risk management at the Greater Toronto Airports Authority, describes the scale of operational technology at Toronto Pearson: over 12,500 cameras and PLC panels generating most network traffic, cloud-managed runway lighting, stormwater and glycol de-icing systems, a cogeneration plant and 30 kilometres of baggage conveyors. After a tour of recent OT incidents, from water plants to Colonial Pipeline, he cites Mandiant's finding that OT breaches are crimes of opportunity built on insecure remote access and unpatched internet-facing systems. His six 'whys' explain the difficulty: decades-long asset lifecycles versus monthly patch cycles, OT that now rides on IT stacks and Bluetooth, engineers and security staff without a shared language for risk, CISOs who report to CIOs and own no pumps, happy-path testing that fears vulnerability scans, and the loss of isolation to cloud and remote access, plus supply-chain risk in imported transformers. GTAA's response combines shared ownership, OT staff in the risk process, a Dragos crawl-walk-run framework, dedicated OT policies and architecture, and a multi-year vendor partnership rather than a tool purchase.
IT Security staff have grown up in a world of patch management, mirrored test environments, DMZs and defense in depth. We have code and penetration testing to find security concerns with deployments. We have mature frameworks with NIST, PCI and ISO to guide our way to establish risk appetites and identify improvements needed. The world of Operational Technology is difficult for an IT Security practitioner to understand and work within given its different objectives, culture and background. Toronto Pearson airport is currently in a operational technology shift which is challenging our business, our IT security department and our management. I will highlight this progression of this technology and culture shift and provide our learnings and pitfalls. My goal is to provide you with our experience as we mature the technology security in our operational environment at the airport.
Key takeaways
- Write lifecycle security support into OT contracts: know how long the vendor will patch, and design for upgrades, test windows and rollback from day one.
- Put OT engineers in the cyber risk process; they own the impact and safety side of risk that IT cannot assess alone.
- Kill insecure remote access first (TeamViewer, PC Anywhere, RDP on the internet); Mandiant sees most OT breaches start there or on unpatched internet-facing systems.
- Do not accept 'the OT network provides the security' from vendors; require the application itself to withstand a penetration test before exposing it.
- Buy OT monitoring tools only alongside people and process change, or the audit finding gets a dashboard and no risk reduction.
Speakers

Andrew Faber is the Director, IT Security Risk Management at the Greater Toronto Airports Authority (GTAA), operator of Toronto Pearson International, Canada’s largest airport. Andrew is responsible for the GTAA’s information security services… Read moreRead less
Andrew Faber is the Director, IT Security Risk Management at the Greater Toronto Airports Authority (GTAA), operator of Toronto Pearson International, Canada’s largest airport. Andrew is responsible for the GTAA’s information security services organization and oversees the team that not only develops the organization’s information security strategy and roadmap, but also manages delivery of that strategy through IT Security governance and awareness training. A key element of Andrew’s role consists of ensuring that an appropriate cyber security incident response plan is both in place and well aligned with the airport’s overall incident response plan. Throughout his career, Andrew has successfully developed and delivered information security roadmaps for a number of organizations across multiple industries, including financial services, health care, retail and telecommunications. Andrew holds both a CISSP certification from ISC2 and an ABCP certification from the Disaster Recovery Institute in Canada. Prior to joining the GTAA, Andrew was the Director of Information Security for Aimia (Aeroplan) responsible for the company’s Canadian business units. Andrew has also specialized in the Payment Card Industry Compliance program as a certified auditor.
