Trellix reports that manufacturing continues to face the highest volume of operational technology attacks, representing 42% of OT-related detections across its critical-infrastructure customers, with transportation and shipping, utilities, energy companies, and aerospace firms making up the remaining top targeted sectors, according to Cybersecurity Dive.Based on activity between April and September, the report notes that OT incidents have shifted from unintended spillover from IT breaches to deliberate operations carried out by criminal groups and state-sponsored actors. Trellix says intrusions frequently exploit weaknesses in the connection between IT and OT networks, with attackers using Cobalt Strike, PowerShell, stolen credentials, and scans for industrial control system protocols to move within environments. Instead of directly attacking low-level industrial controllers, threat actors increasingly compromise devices that bridge the two network layers, which often contain more common vulnerabilities but still enable interference with industrial equipment.Some attacks have attempted to corrupt or shut down safety-related systems. Trellix also warns about vulnerabilities in legacy protocols such as Modbus, proprietary Supervisory Control and Data Acquisition device-makers' protocols, DNP3, as well as increased targeting of programmable logic controllers, citing past Triton malware activity. The report urges segmentation, zero-trust controls, threat-intelligence sharing, and strong vendor requirements.
OT Security, Critical Infrastructure Security
Report: Operational tech remains primary target for hackers
Credit: Getty Images
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
