Cyber threats
The SANS Institute survey, ‘Threat-Informed Operational Technology Defense: Securing Data vs. Enabling Physics’ reveals that cyber criminals have a robust understanding of operational technology (OT) and industrial control system (ICS) engineering, already launching attacks that have impacted operations and endangered safety.
“This research concludes that industrial control systems can no longer be ignored,” said Ian Bramson, global head of industrial cybersecurity at ABS Group. “Organisations that take a ‘copy and paste’ approach to applying IT security tools, processes and best practices into an OT/ICS environment can expect problematic consequences.”
Key findings of the survey indicate that there is a gap in perception around ICS risks at different levels within organisations, with senior management not understanding the threat as perceived by cybersecurity front-line teams.
Also a hindrance to effective cybersecurity are resources challenges, with nearly half of ICS organisations lacking a round-the-clock dedicated team to respond to cyber threats. The survey also found that system and network visibility was limited with less than a quarter of respondents saying they had the visibility needed to defend against modern threats.
“ICS/OT facilities are advised to establish, maintain and mature an ICS Active Cyber Defense,” said Dean Parsons, lead researcher and certified instructor, SANS Institute. “Specifically, facilities must ensure ICS/OT defenders have knowledge of their control systems, the evolving threat landscape and, with ICS network visibility, monitor for abnormal events in control system network traffic,” he added.