Offshore Norge 104: Network Engineering for OT Cybersecurity

Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Offshore Norge 104

Revision 7 of Offshore Norge 104 – Recommended guidelines on cyber security baseline requirements for Operational Technology (OT) systems was published in June 2026. I reviewed it, focusing on where the guidance sits on the spectrum of network engineering for OT security, especially regarding hardware-enforced unidirectionality.

Overall, the guidance is better than most I have read in the last 15 years. It recognizes physical separation, unidirectional gateways, dedicated OT infrastructure and the cyber risks introduced by unnecessary network communications. It even relaxes a conventional DMZ requirement when hardware-enforced unidirectional gateways eliminate the attack path that the DMZ was intended to manage.

The secure remote access section is somewhat less forward-looking.

“Shall” Really Does Mean Shall

The document is industry guidance, not a government regulation, but is reads like a standard. It states explicitly that any organization wishing to claim compliance with the guidance/standard must adhere to all “shall” requirements. The word “should” describes a preferred but optional approach.
 
The network sections contain plenty of shall’s:
 
· “OT networks shall be segmented from IT.”
· “OT shall be segmented from supplier and other third-party networks.”
· “Management traffic shall be segmented from other OT traffic.”

Physical Segmentation Matters

ON 104 permits both logical and physical segmentation. VLANs are explicitly recognized as a logical mechanism, while physically separate IT and OT switches provide physical segmentation. Physical segmentation is preferred in several important places, but not universally. For example, at the very important IT/OT interface, “Switches used for OT networks should be dedicated to OT traffic only…” Virtualization gets stronger treatment: “On-premises OT systems shall not live in the same virtualisation infrastructure as IT systems.

VLANs, virtual switches and hypervisors are useful technologies, but they are software. ON 104 recognizes the value of physical segmentation.

Unidirectional Gateways

The guidance requires an OT DMZ with better than average documentation: put a DMZ between enterprise IT and OT networks, terminate communications there, and use at least a firewall to control what passes between networks. There is one interesting exception: “All network traffic between enterprise IT and OT networks shall be terminated in the OT DMZ… This is not applicable if the communication flows from OT to IT traverse hardware-enforced unidirectional gateways.” In other words, the document recognizes that the strength of protection provided by hardware-enforced unidirectionality is already stronger than some of the software-only provisions.

Strictly Necessary / Tolerable Risk

A lot of cybersecurity guidance says only “necessary” communications should cross important boundaries, such as the IT/OT interface. In my experience, however, “necessary” is not defined, and is widely interpreted by readers as any communications that save a little time, or a little money, or buy the organization a little flexibility. More or less any IT/OT communication can be deemed “necessary.”

What ON 104 says for any communications between network segments is that “only network traffic that is strictly necessary and that represents tolerable risk is allowed.” “Strictly” necessary will give some owners and operators pause. “Tolerable risk” is a reminder to look at attack scenarios, acceptable vs. unacceptable consequences and corporate risk tolerance when evaluating connections between networks, especially between OT and IT networks, and even more so between OT networks and the Internet.

Island Mode: Logical or Physical, but No Communications

Requirement CSBR 20 talks about “island mode” — the ability “to prevent any network communication between OT networks and non-OT networks.” This is the topic of my September 2026 webinar. “The OT environment shall have a simple and easily executable mechanism for physically or logically disconnecting OT systems from external networks.” Island mode is something that is activated in a cyber emergency, for example when ransomware is suspected of tampering with the IT network.

Describing the islanding requirement is commendable, but it would have been stronger to have at least a “should” in place to recommend physical separation over logical. As written, the islanding requirement is arguably too strong. In most industrial sites, the biggest cybersecurity priority is preventing cyber-sabotage information from entering safety-critical, critical-infrastructure and high-cost OT networks. Stating this as the requirement would make it clear that unidirectional gateways oriented from OT to IT comply with the islanding requirement.

This is an issue with the American TSA rail and pipeline security directives as well. While not explicitly documented, I’m told by pipeline customers that TSA auditors accept unidirectional connections as legitimate islanding (TSA calls it “isolation”), even though the directive/regulation neither requires nor recommends hardware-enforced unidirectionality.

This is important, because unidirectional gateway technology is arguably the least costly form of islanding in terms of lifecycle cost. The gateways enable businesses to continue to reap the material benefits of OT data flowing to IT business automation and third-party providers, even while islanded, without the risk of OT cyber-sabotage propagating back into the OT network.

More Conventional Remote Access

The secure remote access section is another place where ON 104 could go further. The guidance requires the usual: MFA, encryption, least privilege, time-limited sessions, explicit approval, logging, monitoring and gateway inspection. But while the requirements do not say so explicitly, they clearly assume software “secure” remote access (SRA), exclusively.

There is no discussion of hardware-enforced unidirectional remote screen view, which is arguably the strongest form of attended remote access. Nor is there discussion of unattended hardware-enforced unidirectional remote access architectures. In contrast, both of these technologies are highlighted in the now two-year-old 2024 CISA and partners guidance, Modern Approaches to Network Access Security.

More surprisingly, ON 104 says interactive remote access solutions shall support “secure file transfer with malware scanning.” Malware scanning is useful, but it is not deterministic protection, and file transfers, especially of complex or executable files, are a huge attack vector. The guidance/standard should not say that all remote access shall support this dangerous feature.

Better Than Most

In terms of network engineering, Offshore Norge 104 gets a lot right. ON 104 already recognizes the value of hardware-enforced unidirectionality at the IT/OT boundary. Applying the same network-engineering principle to remote access would make the document even stronger.

Want to talk through what hardware-enforced network security could look like in your OT environment? Book a demo here >>

About the author
Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Andrew Ginter is the most widely-read author in the industrial security space, with over 23,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox