Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational Cyber Security Centre (NCSC-HR)
The measures that carry most of the work in this sector
06Network security
Segmentation is the highest-return control because it does not touch the devices - it separates production from the office network.
05Cyber hygiene
Patches cannot be applied outside a planned outage, so the risk needs compensating controls and a written decision.
07Access control
Permanent vendor remote access on a shared account is the most common real risk.
12Business continuity
Recovery also means safely restarting the process, which is an operational procedure, not an IT one.
What we most often find
- Production and office networks with no real segmentation
- Vendor remote access without per-request approval and without records
- Systems past vendor support, with no risk assessment or board decision
- An OT device list in the documentation older than reality
Check for yourself
Tri alata koja rade u pregledniku, bez registracije:
Entity categorisation check
Incident reporting deadline calculator
Readiness check against the 13 measures
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.