Utilities, Energy Sector Attacked Mainly Via IT, Not ICS

Stealing administrative credentials to carry out months-long spy campaigns is a top threat.

While industrial control systems (ICS) are the most talked-about when it comes to cyberattacks against energy and utilities firms, most attacks actually take aim at the enterprise IT networks used by these organizations, rather than critical infrastructure itself.

The Vectra 2018 Spotlight Report on Energy and Utilities shows that cyberattackers mainly look to spy and steal information from the energy and utility sectors, to be used in carefully orchestrated attack campaigns that tend to unfold over many months.

Source: ThreatPost