Whether it's because industrial control systems remain quite vulnerable to attacks, or because these systems manage valuable physical resources and uptime is essential—or a bit of both—attackers are increasingly targeting operational technology (OT) and industrial control systems (ICS).
Consider a recent warning by the FBI, CISA, the NSA, the EPA, and Israel's National Cyber Directorate that highlighted the threat actor behind the attack that occurred last year against the Municipal Water Authority of Aliquippa, Pennsylvania. Those attackers targeted a programmable logic controller from the manufacturer, Unitronics Vision. According to the reporting agencies, the attackers attempted to strike several US-based water facilities within multiple states that relied on devices from that manufacturer.
The attacks are growing. In this Washington Post story, China's cyber army is invading critical U.S. services, and threat actors have targeted power and water utilities, telecommunication, and transportation systems. While these attacks won't subside soon, those companies that run critical control systems are taking steps to secure their systems better.
Yet, even as attacks rise, organizations that own and operate ICS environments are decreasing the amount they spend on their security budgets and a fifth of such organizations don’t even have a security budget. This is despite the fact that the vast majority see threats against ICS devices as serious threats.
Consider the findings from a recent SANS ICS/OT survey, which revealed that 43.9% of respondents believe that the current threats against ICS are “high” and 24.8% believe the current threats are severe/critical. Shockingly, when asked to characterize their ICS/OT cybersecurity funding: 21% said they don’t have a budget.