A recent joint cybersecurity advisory by the impressive duo of the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) has warned organisations of the threat from “unsophisticated cyber actors” targeting operational technology targets.
While this alert was aimed at critical infrastructure providers, and the US energy sector in particular, the message stays the same across any operational technology anywhere in the world: don’t forget the basics of security hygiene. Once you’re hacked, it matters not how clever the attackers were.
Sure, a more advanced attacker might bring persistent nation-state espionage to the compromised system party, or any other hypothetical risk you care to dream up, but every hacker that gets into your networks presents a very tangible threat to your business. The CISA and FBI advisory took the form of a warning about attackers using “basic and elementary intrusion techniques” to get into your systems.
I think that the use of “unsophisticated” to describe them was a less than helpful, not least as the most advanced hackers will look for the easiest initial access points to pull off an attack. That’s not being unsophisticated, that’s playing smart.
The overall messaging, however, is on point: unless you have the basics of good security hygiene in place, you are opening the doors to your networks to a much wider hacking talent pool.
“These alerts are very serious and come from observed actions by these malicious actors who are compromising critical systems,” said Thomas Richards, Infrastructure Security Practice Director at Black Duck.
“The motivation of the malicious actors is irrelevant, if an organisation’s exposed sensitive systems are exposed to the internet with no security hardening, they are at risk of a compromise.”
What can you do mitigate against hackers?
Nathaniel Jones, Vice President of Threat Research at Darktrace, warned that “as OT becomes more integrated with IT systems, it presents more opportunities for attackers. OT security is strongest when supported by robust IT security, requiring coordination between IT and OT teams to defend the entire network.”
This requires good security hygiene that is proactive in securing the digital estate and addressing vulnerabilities before they can be exploited. By doing this, Jones concluded, “organisations will be much better equipped to defend their networks against increasingly opportunistic threat actors.”
None of which means that the threat from advanced actors can be ignored, as Derek Manky, Chief Security Strategist & Global Vice President of Threat Intelligence with Fortinet’s FortiGuard Labs, reminds us.
“OT cyber threats have evolved dramatically as attackers increasingly target industrial environments with more sophisticated techniques,” Manky said, adding that “state-sponsored actors and financially motivated cybercriminals are focusing on disrupting industrial operations, often leveraging ransomware and advanced persistent threats.”
According to Manky, organisations should adopt the following operational technology mitigations:
- AI-driven threat detection that continuously learns and adapts to new attack patterns
- Automated security orchestration (SOAR) to streamline incident response and reduce manual workload
- Continuous Threat Exposure Management (CTEM) to identify and mitigate risks before they become exploitable
- Industry-wide intelligence sharing initiatives, such as MITRE ATT&CK for ICS, to improve collective defence strategies
- Zero Trust security frameworks tailored for OT environments, ensuring strict access controls and network segmentation
Related articles by Davey