OT Security, Critical Infrastructure Security

Report: Operational tech remains primary target for hackers

Credit: Getty Images

Trellix reports that manufacturing continues to face the highest volume of operational technology attacks, representing 42% of OT-related detections across its critical-infrastructure customers, with transportation and shipping, utilities, energy companies, and aerospace firms making up the remaining top targeted sectors, according to Cybersecurity Dive.

Based on activity between April and September, the report notes that OT incidents have shifted from unintended spillover from IT breaches to deliberate operations carried out by criminal groups and state-sponsored actors. Trellix says intrusions frequently exploit weaknesses in the connection between IT and OT networks, with attackers using Cobalt Strike, PowerShell, stolen credentials, and scans for industrial control system protocols to move within environments. Instead of directly attacking low-level industrial controllers, threat actors increasingly compromise devices that bridge the two network layers, which often contain more common vulnerabilities but still enable interference with industrial equipment.

Some attacks have attempted to corrupt or shut down safety-related systems. Trellix also warns about vulnerabilities in legacy protocols such as Modbus, proprietary Supervisory Control and Data Acquisition device-makers' protocols, DNP3, as well as increased targeting of programmable logic controllers, citing past Triton malware activity. The report urges segmentation, zero-trust controls, threat-intelligence sharing, and strong vendor requirements.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds