Key Report Findings Include:
Gap in Perception around ICS Risks at Different Levels within the Organization
61% of survey participants indicate a gap exists in the perception of cybersecurity risk to their ICS facilities between OT/ICS cybersecurity front-line teams and other parts of the organization. Of these, 35% indicate the gap is between senior management and the OT/ICS cybersecurity front-line teams.
Ransomware is the Biggest Threat to OT
The industrial community is seeing ransomware with increasingly sophisticated variants that have the capability to cause more disruption to system assets and process flows. When asked about the threat categories of most concern, 50% of respondents place ransomware at the top.
ICS Security Resources are Challenged, Even more so than IT
Security teams are commonly resource-challenged in IT, but even more so in ICS, where additional security and engineering knowledge is required to perform effective ICS active cyber defense. 47% of ICS organizations do not have internal dedicated 24/7 ICS security response resources to manage OT/ICS incidents, and just a slightly lower percentage (46%) of ICS organizations do have this function, leaving 7% unsure of their current state.
ICS System and Network Visibility Warrants Improvement, Investments are Planned
65% indicate their visibility is limited for control systems, while only 22% have the visibility needed to defend against modern threats, and 7% have no visibility into their control systems.
The SANS research demonstrates a clear call to action: “Critical infrastructure is targeted by cyber adversaries who have demonstrated their knowledge and desire to cause real-world consequences from cyber-attacks. ICS/OT facilities are advised to establish, maintain and mature an ICS Active Cyber Defense."
-Dean Parsons, Lead Researcher, SANS Institute
Why ABS Group?
We're the Experts
Our team is highly skilled in understanding how to manage cyber risk – and address it as an operational safety issue – across diverse industries and market sectors. From assessing and planning, to developing network protections, to managing your detection and incident response, ABS Group will work with you to understand and reduce your cyber risk.