Cybersecurity risks in mining’s operational technology: Implications of OT vulnerabilities and EU NIS2 compliance

IF 4.3 2区 社会学 Q2 ENVIRONMENTAL STUDIES
Fabian Teichmann
{"title":"Cybersecurity risks in mining’s operational technology: Implications of OT vulnerabilities and EU NIS2 compliance","authors":"Fabian Teichmann","doi":"10.1016/j.exis.2025.101774","DOIUrl":null,"url":null,"abstract":"<div><div>The mining and metals sector faces a surge in cyber incidents, with reported attacks tripling from 10 in 2023 to 30 in 2024. These attacks increasingly target operational technology (OT) – the industrial control systems that underpin extraction and processing – resulting in costly production stoppages. This study investigates the economic and governance challenges posed by these cybersecurity risks. We compare the expected costs of OT-related operational disruptions against the investments required for compliance with the European Union’s new NIS2 Directive on network and information security. Using case studies of European mining companies (e.g., Aurubis and Norsk Hydro) that experienced cyberattacks and now fall under NIS2 obligations, we examine how strong governance (such as board-level cybersecurity oversight and training for directors) correlates with incident frequency and severity. We develop an event-based Monte Carlo simulation model to estimate annual loss distributions from cyberattacks under different preventive investment levels. The results yield cost-risk curves illustrating diminishing marginal benefits of high cybersecurity expenditures. Our findings highlight a clear trade-off: proactive resilience investments and NIS2 compliance incur significant upfront costs, but can substantially reduce the probability of catastrophic OT outages and regulatory penalties. The analysis underscores that effective governance – including board accountability and dedicated cybersecurity leadership – is vital for mitigating risks. This interdisciplinary work offers insights for industry practitioners, regulators, and academics on balancing the socio-economic costs of cybersecurity in mining with the imperative of operational resilience and regulatory compliance.</div></div>","PeriodicalId":47848,"journal":{"name":"Extractive Industries and Society-An International Journal","volume":"25 ","pages":"Article 101774"},"PeriodicalIF":4.3000,"publicationDate":"2025-09-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Extractive Industries and Society-An International Journal","FirstCategoryId":"90","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214790X25001637","RegionNum":2,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"ENVIRONMENTAL STUDIES","Score":null,"Total":0}
引用次数: 0

Abstract

The mining and metals sector faces a surge in cyber incidents, with reported attacks tripling from 10 in 2023 to 30 in 2024. These attacks increasingly target operational technology (OT) – the industrial control systems that underpin extraction and processing – resulting in costly production stoppages. This study investigates the economic and governance challenges posed by these cybersecurity risks. We compare the expected costs of OT-related operational disruptions against the investments required for compliance with the European Union’s new NIS2 Directive on network and information security. Using case studies of European mining companies (e.g., Aurubis and Norsk Hydro) that experienced cyberattacks and now fall under NIS2 obligations, we examine how strong governance (such as board-level cybersecurity oversight and training for directors) correlates with incident frequency and severity. We develop an event-based Monte Carlo simulation model to estimate annual loss distributions from cyberattacks under different preventive investment levels. The results yield cost-risk curves illustrating diminishing marginal benefits of high cybersecurity expenditures. Our findings highlight a clear trade-off: proactive resilience investments and NIS2 compliance incur significant upfront costs, but can substantially reduce the probability of catastrophic OT outages and regulatory penalties. The analysis underscores that effective governance – including board accountability and dedicated cybersecurity leadership – is vital for mitigating risks. This interdisciplinary work offers insights for industry practitioners, regulators, and academics on balancing the socio-economic costs of cybersecurity in mining with the imperative of operational resilience and regulatory compliance.
采矿操作技术中的网络安全风险:OT漏洞和欧盟NIS2合规性的影响
采矿和金属行业面临着网络事件激增的问题,据报道,网络攻击从2023年的10起增至2024年的30起,增长了两倍。这些攻击越来越多地针对操作技术(OT),即支撑提取和加工的工业控制系统,导致成本高昂的生产中断。本研究调查了这些网络安全风险带来的经济和治理挑战。我们比较了与iot相关的运营中断的预期成本与遵守欧盟关于网络和信息安全的新NIS2指令所需的投资。通过对欧洲矿业公司(如Aurubis和Norsk Hydro)的案例研究,我们研究了强有力的治理(如董事会层面的网络安全监督和对董事的培训)与事件频率和严重程度之间的关系。我们开发了一个基于事件的蒙特卡罗模拟模型来估计不同预防投资水平下网络攻击的年损失分布。结果得出的成本-风险曲线说明了高网络安全支出的边际效益递减。我们的研究结果突出了一个明确的权衡:主动的弹性投资和NIS2合规性会产生大量的前期成本,但可以大大降低灾难性OT中断和监管处罚的可能性。分析强调,有效的治理——包括董事会问责制和专门的网络安全领导——对于降低风险至关重要。这项跨学科的工作为行业从业者、监管机构和学者提供了平衡采矿网络安全的社会经济成本与运营弹性和监管合规性的必要性的见解。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
6.60
自引率
19.40%
发文量
135
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信