OT systems are a prime target due to their criticality and the potential impact if these systems are disrupted. As the number and capability of threat actor targeting OT increases, so too does the need for robust cyber security controls.
However, the complexity, scale, and long-standing nature of OT systems often means organisations can lack a holistic view of their environment, which undermines their ability to implement effective cyber security measures. Traditionally, OT networks were isolated (or ‘air-gapped’) from the internet and external systems. However, modern operational demands have led to increased connectivity as networks now integrate with enterprise systems, third-party vendors and cloud services. This makes designing appropriate security controls increasingly critical, to reduce the risks to previously isolated systems.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Utility Cybersecurity: Situational Awareness Cuts Risk
March 14, 2022
The electric utility industry is one of the most critical infrastructure industries that highly affect people’s lives and economic activities. The power grids connect the systems of power generation, substation, transmission, and distribution over a wide area. They are going modernized and under threat from nation-state attacks. In the US, Biden’s administration took action to protect ...
- National Security Agency Cybersecurity Technical Report: Network Infrastructure Security Guidance
March 4, 2022
Guidance for securing networks continues to evolve as new vulnerabilities are exploited by adversaries, new security features are implemented, and new methods of securing devices are identified. Improper configuration, incorrect handling of configurations, and weak encryption keys can expose vulnerabilities in the entire network. All networks are at risk of compromise, especially if devices are not properly ...
- Cisco Releases Security Updates for Multiple Products
March 3, 2022
Cisco has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. For updates addressing lower severity vulnerabilities, see the Cisco Security Advisories page. CISA encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates: Cisco Expressway ...
- NATO Cyber Security Centre experiments with secure network capable of withstanding attack by quantum computers
March 2, 2022
Scientists have predicted that quantum computers will one day be able to break some commonly used encryption methods. That’s why NATO and Allies are already testing post-quantum solutions. The NATO Cyber Security Centre (NCSC) has successfully tested secure communication flows in a post-quantum world using a Virtual Private Network (VPN) provided by the United Kingdom-based company Post-Quantum. ...
- Building cyber secure Railway Infrastructure
February 28, 2022
The European Union Agency for Cybersecurity (ENISA) delivers a joint report with the European Rail Information Sharing and Analysis Center (ISAC) to support the sectorial implementation of the NIS Directive. The report released today is designed to give guidance on building cybersecurity zones and conduits for a railway system. The approach taken is based on the recently ...
- British Airways has been hit by ‘technical issues’ that have paralysed IT system
February 26, 2022
British Airways has cancelled all short-haul flights from Heathrow until midday leaving passengers stranded while further disruption is expected throughout Saturday due to ongoing technical issues. The airline said the problem, which may also cause delays for its customers using Gatwick and London City Airport, is related to a hardware issue and is not because of ...
