Share this article on:
Dragos Inc released its fifth annual Dragos ICS/OT Cybersecurity Year in Review (YIR) report, a comprehensive report on cyber threats facing industrial organisations.
The report named the emergence of three new threat groups targeting ICS/OT environments, including two that have gained access into the OT systems of industrial organisations. It also shows the number of discovered vulnerabilities in OT systems in 2021 more than doubled over the previous year to 1,703.
Ransomware became the number one attack vector among industrial organisations, with manufacturing as the most targeted sector representing 65 per cent, or 211, of the ransomware cases detected at industrial organisations.
The Dragos YIR report is an annual overview and analysis of ICS/OT-focused global threat activities, vulnerabilities, and industry insights and trends. The report aims to share data-informed observations and lessons learned from within the industrial community to give asset owners and operators actionable information and recommendations to help them more fully understand cyber risks to their ICS/OT environments and strengthen their cyber readiness.
While the industrial community has discussed the importance of OT cyber security for years, 2021 brought high-profile attacks that showed the real-world outcomes on local communities and global economies, according to Robert M. Lee, chief executive officer and co-founder of Dragos Inc.
"Data from our YIR shows that cyber risk to industrial sectors is accelerating at a time when digital transformation initiatives are driving hyper connectivity, which increases risk and exposure."
"The real-world observations and data-backed insights in our 2021 YIR report can serve as practical, timely guidance as the industrial community strives to understand where they are exposed, what threat groups are doing, and how to build security and resiliency into their OT systems," Lee said.
Details of the 2021 year in review:
Based on data gathered from annual customer service engagements conducted by Dragos' cyber security experts in the field across the range of industrial sectors, the top challenges industrial organisations need to address are:
The YIR report highlights incident response use cases from the field and examines previously undisclosed compromises of OT systems to add context to the major ICS/OT headlines of 2021 – from the effects of the SolarWinds breach on ICS/OT environments to an example of an attack targeting an OT system that moved laterally to the IT network of an electric operator.
Finally, the YIR also provides recommendations for five key OT cyber security controls, that if implemented effectively, can result in a strong defence against increasing ICS/OT cyber threats in 2022 and beyond.
[Related: Macquarie Telecom and Blacktree Technology to provide defence-related co-location services]