Shall we change OT FW password every 90 days ?
Hi guys, I have four process plants with around 40 firewalls deployed across different process areas. Most of them are managed locally, which means we have to physically access the Engineering Workstation (EWS) or go down to the site to perform any administration. There is no remote management capability.
Our Group Security now requires us to change all firewall passwords every 90 days and enforce a password history of the last three passwords.
The challenge is that I’m the only OT Cybersecurity Engineer supporting all four plants, while our E&I engineers are already fully occupied with daily operations. Requiring on-site password changes every 90 days for around 40 firewalls will create a significant operational burden and consume resources that could be better spent on higher-risk cybersecurity activities.
What are your thoughts? Do you think there are valid reasons to request an exception or an alternative control? In an OT environment, would it be more practical to retain strong, unique passwords, implement strict access control and logging, and only require password changes when there is evidence of compromise or personnel changes, rather than enforcing a fixed 90-day rotation?