- Develop a vendor and OT cybersecurity platform strategy to reduce complexity and achieve integration and automation.
- Deploy network access control (NAC) technology to secure endpoints and maintain control of the network.
- Adopt a zero-trust approach by implementing asset inventory, segmentation, and continuous verification of users, applications, and devices.
- Incorporate cybersecurity awareness education and training for all employees, including non-technical staff.
- Promote collaboration among IT, OT, and production teams to assess cyber and production risks and allocate resources effectively.
75% of OT Organizations Report Cybersecurity Intrusions in the Past Year
Fortinet’s latest report on the global state of operational technology (OT) and cybersecurity reveals that 75% of OT organizations have experienced at least one intrusion in the last year. The report highlights the need for continued improvement in securing the expanding IT/OT threat landscape and predicts a shift in OT cybersecurity responsibility from directors and managers to chief information security officers (CISOs) within the next 12 months.
Key findings from the survey include: Persistent cyber threats: While the number of organizations without cybersecurity intrusions has increased from 6% in 2022 to 25% in 2023, there is still significant room for improvement. Three-fourths of OT organizations reported at least one intrusion in the last year, with malware (56%) and phishing (49%) being the most common types of incidents. Additionally, 32% of respondents fell victim to a ransomware attack, consistent with the previous year. Overestimation of OT security maturity: Only 13% of respondents consider their organization’s OT security posture as “highly mature,” a decrease from 21% in the previous year. This suggests growing awareness among OT professionals and better self-assessment tools for evaluating cybersecurity capabilities. The impact of cyberattacks on both IT and OT systems has increased, with 32% of respondents reporting such incidents compared to 21% in the previous year. Complexity challenges: The proliferation of connected devices poses significant challenges for OT organizations, with nearly 80% of respondents having more than 100 IP-enabled OT devices in their environment. While cybersecurity solutions have improved efficiency (67%) and flexibility (68%) for most OT professionals, solution sprawl complicates the consistent implementation and enforcement of policies across the converging IT/OT landscape. Aging systems further compound the issue, with 74% of organizations reporting an average age of 6 to 10 years for their ICS systems. Shifting responsibility to CISOs: As a positive development, 95% of organizations plan to transfer OT cybersecurity responsibility to their CISOs in the next 12 months, signaling a prioritization of cybersecurity. OT cybersecurity professionals now predominantly come from IT security leadership, and decision-making influence has shifted away from operations executives to other leaders, especially CISOs and CSOs.
To strengthen overall security posture, the report recommends several best practices: