{"id":2322,"date":"2024-01-08T15:00:00","date_gmt":"2024-01-08T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/protecting-critical-infrastructure-means-getting-back-to-basics"},"modified":"2024-01-08T15:00:00","modified_gmt":"2024-01-08T15:00:00","slug":"protecting-critical-infrastructure-means-getting-back-to-basics","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/08\/protecting-critical-infrastructure-means-getting-back-to-basics\/","title":{"rendered":"Protecting Critical Infrastructure Means Getting Back to Basics"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt88b17fe45b631322\/64f15f8ab87334170acd5072\/Cyberecurity_Andrii_Yalanskyi_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Critical infrastructure organizations are undergoing dramatic changes in their technology and cybersecurity landscapes that make them both more efficient and more vulnerable.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Power, oil and gas, utility, and other sectors that rely on operational technology (OT) are integrating more Internet of Things (IoT) and smart devices, while OT systems are being converged with IT operations that are steadily moving onto cloud platforms. The convergence of OT and IT streamlines operations, which enables organizations to make use of mobile computing, perform predictive analysis in the cloud, and expand their networks to include third parties and supply chain partners. But it also makes them more vulnerable to both external and internal cyberattacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, nation-state actors and cybercriminals increasingly are targeting the industrial and manufacturing sectors, especially if they involve critical infrastructure. Ransomware attacks, which <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-highlights-dual-ransomware-attack-in-rising-cybertrends\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">are again on the rise<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;after a lull in 2022, frequently target infrastructure, because the critical nature of their operations make it more likely that victims will pay ransom to unfreeze their systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another reason attackers target industrial and manufacturing systems is that a lot of OT consists of older devices and sensors that are inherently unsecure because they weren&#8217;t designed to be used in Internet-accessible environments. Original equipment manufacturers (OEMs) are applying security controls to new devices, but it likely will take years before they are fully integrated into existing systems.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">The Real Threats May Not Be What You Think<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Industrial and manufacturing organizations may once have been able to rely on the segregation of OT from IT, but they can no longer build an OT security strategy around segmented environments. Mixing OT and IT streamlines operations, but it also creates cybersecurity gaps that threat actors can take advantage of, leveraging the connectivity to move from one topology to another. Most attacks involving OT start with attacks on IT systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Securing the converged environments can become a complex challenge, compounded by the fact that it is difficult to find both security engineers and OT experts. As a result, most companies struggle with the delineation between OT and IT\/security.<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">&nbsp;<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Building a security strategy that encompasses the entire enterprise requires practicing the basics of security, understanding where weaknesses exist and the paths an attacker can take, conducting simulations, and practicing responses. And it helps to start by understanding a couple essential facts.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Russia and China Aren&#8217;t Your Biggest Concern&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nation-states get the headlines, and with good reason. Russia, China, Iran, and North Korea are&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2022\/11\/04\/microsoft-digital-defense-report-2022-ukraine\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">targeting critical infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which tends to be heavy with OT, and have been responsible for some of the most high-profile attacks in recent years, such as those on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/colonial-pipeline-critical-infrastructure-operators-blind-cyber-risks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Colonial Pipeline<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. But most OT organizations should be more worried about opportunistic criminals looking to make money from ransomware or other profitable attacks.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">It&#8217;s Not the Devices; It&#8217;s the Access&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many OT devices are rife with vulnerabilities and need to be upgraded, but they are not the real problem when it comes to industrial systems being vulnerable. The real problem is the access to IT systems. Threat actors don&#8217;t exploit OT devices directly. They take advantage of vulnerabilities in IT systems \u2014 most often misconfigurations and poor architecture \u2014 to gain access and then move through the network.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Practice, Practice, Practice<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Protecting a converged OT\/IT environment is less about modernizing old OT devices as it is about performing basic hygiene and ensuring that good IT and OT practices are in place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To begin with, remember the old security dictum that you can&#8217;t manage what you don&#8217;t know you have. Rigorous asset management \u2014 bridging both IT and OT \u2014 is essential. That visibility allows you to identify the vulnerabilities most likely to be targeted by attackers and understand how an attack can be carried out.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s also important to simulate attacks against the organization&#8217;s assets, which will improve your ability to predict how and when those attacks could happen. Chief information security officers (CISOs) need to implement tight security programs that regularly simulate attacks, focusing on attacks against IT that cascade to OT and the shock points along the way. And then, do it again \u2014 practice, practice, practice. There is no silver bullet from a vendor that will solve your problems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A vendor can help an organization with response readiness, determining where the choke points are between IT and OT. A third party can, for example, show you how to identify at an early stage any attack that bridges the perimeter and how best to mitigate it. It can also help with establishing simulations and training staff. After all, because hiring and retaining skilled IT pros is one of the biggest challenges in cybersecurity, improving the skills of the people you already have is especially important.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For critical infrastructure organizations, however, it still comes down to the basics. They need to first recognize that the technology and cybersecurity landscapes have changed. And then they must perform rigorous asset management and repeated simulations to enable their security teams to fend off even the most sophisticated threats. There may not be a silver bullet, but following a solid plan like that can help keep defenders ahead of modern and complex attacks made against their increasingly mixed IT and OT environments.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/protecting-critical-infrastructure-means-getting-back-to-basics\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical infrastructure organizations are undergoing dramatic changes in their technology<\/p>\n","protected":false},"author":12,"featured_media":2323,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2322","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=1200%2C715&ssl=1",1200,715,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=300%2C179&ssl=1",300,179,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=640%2C382&ssl=1",640,382,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=640%2C381&ssl=1",640,381,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=1200%2C715&ssl=1",1200,715,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=1200%2C715&ssl=1",1200,715,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=1024%2C610&ssl=1",1024,610,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/protecting-critical-infrastructure-means-getting-back-to-basics.jpg?fit=1200%2C715&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2322"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2322\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2323"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}