Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Critical infrastructure operators add more insecure industrial equipment online

(Royal Academy of Engineering / Pixabay)

By Eric Geller

Internet-exposed ICS devices pose major risks to operational technology organizations in sectors ranging from energy and water to telecommunications, healthcare and manufacturing. Many cybersecurity experts have approached the exposure problem through the lens of legacy technology, warning about the dangers of forgotten or outdated industrial equipment. But Bitsight’s report illustrates how new equipment carries many of the same risks.

Internet-exposed OT devices are exhibiting a growing number of OT-specific vulnerabilities, according to Bitsight, including logic flaws, web authentication bypass flaws and vulnerabilities that could allow remote code execution. “These aren’t niche bugs,” researchers wrote. Bitsight has seen vulnerabilities with the highest possible severity score and “trivial exploit paths,” as well as flaws that could imperil “fuel infrastructure, building automation, water treatment systems, and critical manufacturing.”

Making matters worse, no single OT networking protocol is responsible for the rise in exposed devices. Instead, Bitsight saw “a slight upward trend” in exposure across most of the 13 most common protocols it studied.

Read more at Cybersecurity Dive

Click to listen highlighted text!