Tenable study

Difficulties with OT security

Tenable, a cyber exposure company, has published the report: "Cybersecurity in Operational Technology: 7 Insights You Need To Know". The study shows the extent of cyberattacks faced by critical infrastructure operators.

Eitan Goldstein, Senior Director of Strategic Initiatives at Tenable © Tenable

The study, conducted independently by the Ponemon Institute, is based on a survey of 701 participants from companies and organizations in the critical infrastructure sector. The focus was on ICS and operational technology in energy and utility providers, healthcare and pharmaceuticals, industry and manufacturing, and transportation. All respondents are involved in investments in IT and/or OT cybersecurity solutions in their organizations, either in management or assessment.

According to the study, companies that use Industrial Control Systems (ICS) and Operational Technology (OT) are affected by cyberattacks. Key findings: 90 percent of respondents stated that their environments had been exposed to a cyberattack at least once in the past two years, with 62 percent even recording two or more attacks.

Further study results:

Lack of insight into the attack surface: 80 percent of participants do not know exactly which systems are part of their IT environments. This lack of transparency is the biggest obstacle to preventing business-damaging cyber attacks.

Lack of staff and manual processes slow down vulnerability management: Respondents cite a lack of staff (61 percent) and reliance on manual processes (55 percent) as the biggest hurdles to assessing and addressing vulnerabilities through targeted vulnerability management.

Advertisement

Management commitment is crucial: 70 percent of participants see better communication with decision-makers and the Board of Directors as a key objective in 2019.

IT and OT have long since become one in the digital era. However, this connection of previously isolated OT systems opens up various opportunities for attacks. The survey of OT and ICS experts conducted as part of the Ponemon study confirms that critical infrastructures are indeed constantly at risk.

"Those responsible for managing critical systems in production or transportation are almost unanimous in stating that they regularly have to defend against cyber attacks," says Eitan Goldstein, Senior Director of Strategic Initiatives at Tenable. "Organizations therefore need visibility into their converged IT/OT environments. They need to know not only what vulnerabilities exist, but also how to prioritize and remediate them. The security challenges of converged IT/OT systems can only be addressed by the respective critical infrastructure and cyber security teams working together." as

  • Xing Icon
  • LinkedIn Icon
Advertisement
Advertisement

You might also be interested in

Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Subscribe to our newsletter
Advertisement
Back to home