As cyberattacks on operational technology (OT) environments surge, organizations must reassess their security strategies. With the expanded attack surface from growing cloud adoption and the proliferation of IoT devices, what should organizations look for in OT security vendors and best practices to fortify their defenses against these escalating threats?
The alarming rise in OT cyberattacks Cyberattacks targeting OT systems are on the rise, driven by financially motivated threat actors and geopolitical tensions.
According to Fortinet's “2024 State of Operational Technology and Cybersecurity Report,” nearly 73% of organizations experienced an intrusion impacting OT systems only or both IT and OT systems this year, up from 49% last year, while intrusions that only impacted OT systems went up from 17% to 24%.
The report also found respondents claiming that their organization has complete visibility of OT systems within their central security operations dropped from 10% last year to 5% in 2024.
Richard Springer, director of OT solutions marketing at Fortinet, explains the shift: “Due to recent and public events of manufacturing production stoppages or interruptions, the bad actors are assessing and adding these manufacturing losses with their ransom calculus.”
“Thus, manufacturing has become a higher value target,” Springer told SDxCentral. “Additionally, recent geopolitical events place even more focus for criminal and nation-state groups to disrupt material production and supply chains.”
OT security trends As cyberattacks on OT environments surge, organizations need threat, anomaly and vulnerability management solutions to identify exposed assets, detect malicious activity, and prioritize alerts, Forrester analysts noted in the firm's latest OT security solutions Wave report.
Fully air-gapped architectures have become rare amid the convergence of IT and OT and the shift from physical to digital controls. Therefore, organizations now “deal with OT-specific attacks that can come directly from the internet, propagate across remote third-party connections, or cascade from IT systems,” the Forrester report explained.
Key considerations for choosing OT security vendors To address these challenges, OT security vendors are adopting two main strategies: providing best-of-breed solutions for specific use cases in OT environments or offering comprehensive end-to-end OT security platforms.
Forrester recommends OT security solutions customers look for vendors that have:
- Expertise and capabilities across IT, IoT, and OT: Choose vendors that understand the unique challenges of industrial control devices and secure them without hindering performance or operations. As OT assets are increasingly integrated with IoT devices and IT systems, OT expertise alone isn’t enough, analysts noted. “Look for OT security vendors who thrive in digitally converged environments with native capabilities and seamless integration with other cybersecurity solution providers to manage the IT, IoT, and OT triple threat.”
- Integrated platform for multiple use cases: Given security talent and resource constraints, organizations should choose vendors offering integrated platforms that address various cybersecurity needs, including OT-tailored asset discovery, threat and vulnerability detection, and secure privileged access management. The platform also should integrate seamlessly with existing technology portfolios and evolve over time, while functioning effectively in diverse environments, including on-premises, rugged locations, and areas with low network connectivity.
- Preventative capabilities: While detection is crucial, don’t forget protection. Choose vendors that strengthen network, endpoint, and identity protection measures alongside detection and response features to prevent attacks on OT environments.
“A true OT platform contains additional security solutions that are already integrated across the platform, including third parties, to grow as the organization’s security posture matures, including taking on zero trust and OT network and security operations.”
Who are the leading vendors? In the Wave report, Forrester identified Palo Alto Networks and Cisco as leaders; Claroty, Tenable, Dragos, Nozomi Networks, Forescout, Fortinet, Armis, and Honeywell as strong performers; and Microsoft, OPSWAT, Hexagon, Industrial Defender, and TXOne Networks as contenders.
Best practices for defending OT systems In addition to the vendor selection, Fortinet said organizations should adopt the following OT security best practices:
- Create network zones or segments for strong network policy controls at all points of access to reducing intrusions.
- Establish visibility and compensating controls for OT assets.
- Integrate OT into security operations and incident response planning.
- Embrace OT-specific threat intelligence and security services.
- Consider a platform approach to your overall security architecture.
“You need to be able to segment your infrastructure, forget having a big, large infrastructure, break it down into zones that can talk to each other,” Pasquier said, adding that the main challenge for customers is achieving this segmentation because they often lack visibility into their assets and network interactions.
Comments