Kaspersky study
Manufacturing industry targeted by cyber criminals
A Kaspersky report shows that conventional industrial computers are increasingly being targeted by cyber criminals. In 2018, almost half (47.2%) of ICS computers were affected by a cyberattack and 61 vulnerabilities were found.
The Kaspersky Report for the second half of 2018 shows the biggest sources of threats to industrial computers: the internet (26 percent), removable media (8 percent) and emails (5 percent).
"Most industrial computers are not infected by a targeted attack, but by widespread malware - malware that accidentally enters industrial systems via the Internet, removable media such as USB sticks or emails," explains Kirill Kruglov, security researcher at Kaspersky Lab ICS CERT. "The fact that the attacks are successful due to a lack of cyber security hygiene among employees shows that the majority of attacks can be prevented by training and raising awareness among the workforce."
Vulnerabilities in industrial systems
The ICS-CERT experts from Kaspersky Lab also examined industrial and IIoT/IoT systems for vulnerabilities. In 2018, 61 vulnerabilities were found, 29 of which were fixed by the manufacturers. These were found in third-party software (17), vehicle software (15), PLC development environments (14), IIoT (10) and HMI (human-machine interface; 5).
Recommendation for industrial cyber security
- Operating systems and application software on systems that are part of the company's industrial network must be updated regularly - just like in the classic corporate network;
- Apply security updates to PLC, RTU and network devices used on ICS networks;
- Restrict network traffic to ports and protocols used on edge routers and within the organization's OT networks;
- Check access control for ICS components in the organization's industrial network and at its borders;
- Use a dedicated protection solution on ICS servers, workstations and HMIs such as Kaspersky Industrial CyberSecurity. This solution includes network traffic monitoring, analysis and detection to protect OT and industrial infrastructure from random malware infections and dedicated industrial threats.
- Keep security solutions and all technologies up to date and ensure that all vendor-recommended protection technologies are enabled.
- Train employees, partners and suppliers who have access to the network accordingly. as









