Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

Cybersecurity Pros Face Significant Challenges with OT Security: Ponemon Report

62% of organizations in industries relying on operational technology experienced two or more business-impacting cyberattacks in the past 24 months, according to a report from Ponemon Institute and Tenable.

If you follow cybersecurity news as avidly as we do, you already know that industrial control systems underlying critical infrastructure are vulnerable, and they are under attack. But, how bad is it? Tenable commissioned Ponemon Institute to answer this question and provide insight into past events, preparedness and future priorities. The data from 701 respondents in industries that have OT infrastructure is presented in the report, "Cybersecurity in Operational Technology: 7 Insights You Need to Know". A few highlights are discussed below.

OT is not well-defended and vulnerabilities abound

Visibility into the attack surface is insufficient. Only 20% of respondents agreed or strongly agreed that they had sufficient visibility into their organization’s attack surface. This is very concerning because all security controls/processes depend on the visibility provided by comprehensive asset inventories. You are unlikely to manage and secure assets if you don’t even know about them.

Inadequate staffing and manual processes limit vulnerability management. The shortage of cybersecurity professionals has been well documented. In 2017, Forbes quoted the IS Audit and Control Association (ISACA) as predicting a global shortage of 2 million cybersecurity professionals by 2019. We are now in 2019, and I haven’t seen any data disprove ISACA’s prediction. The well-publicized cybersecurity skills shortage is exacerbated by reliance on manual processes to assess and remediate vulnerabilities.

Top impediments to effective vulnerability management

Using a five-point scale of strongly agree to strongly disagree, the following percentage of respondents agreed or strongly agreed with the below statements.

Statement

Agree/Strongly Agree

The security function of our organization has adequate staffing to scan vulnerabilities in a timely manner.

39%

Our organization is at a disadvantage in responding to vulnerabilities because we use a manual process.

53%

Security spends more time navigating manual processes than responding to vulnerabilities, which leads to an insurmountable response backlog.

55%

Source: title="Cybersecurity in Operational Technology: 7 Insights You Need To Know Ponemon Institute">Cybersecurity in Operational Technology: 7 Insights You Need To Know, Ponemon Institute and Tenable, April 2019.

Vulnerabilities Continue to Proliferate. The ability to assess and remediate vulnerabilities in a timely manner is extremely important. In the first 45 days of 2019, the Industrial Control System-Computer Emergency Response Team (ICS-CERT) issued 45 alerts describing vulnerabilities in industrial control systems1. These vulnerabilities apply to products from leading control system manufacturers, including ABB, AVEVA, Mitsubishi, Omron, Rockwell, Schneider Electric, Siemens and Yokogawa. That quantity is small compared to the 405 IT vulnerabilities discovered during the same period. However, staff responsible for OT security cannot put blinders on and focus only on OT vulnerabilities because IT/OT convergence means that both ICS and IT vulnerabilities can be exploited to attack critical infrastructure. 450 combined OT and IT vulnerabilities in 45 days is challenging for many organizations to assess and remediate. This velocity may or may not continue throughout the year, but even if it decreases by half, the number is challenging to manage without an automated process.

OT is under attack

According to the Operational Technology Cybersecurity Insights report, manual vulnerability management processes result in inadequate protection against cyber-attacks. The report reveals most organizations in industries that have OT infrastructure have experienced multiple cyber-attacks causing data breaches and significant disruption/downtime to business operations, plant and operational equipment. Over the past 24 months:

  • 90% have experienced at least one damaging cyberattack, and 62% have experienced two or more. These data refer to all damaging attacks, not just attacks against OT infrastructure. IT attacks are included because some can result in attackers pivoting from IT into OT.
  • 50% experienced an attack against OT infrastructure that resulted in downtime to plant and/or operational equipment.
  • 23% experienced a nation-state attack. Nearly one quarter were able to attribute an attack to a nation state. This is a serious concern due to the high level of expertise and funding nation-states can provide. Nation-states attackers are not script kiddies.

How can you move forward?

The survey reveals that 70% of respondents view “Increasing communication with C-level and board of directors about the cyber threats facing our organization” as one of their governance priorities for 2019. If this applies to you, you can reference the survey data in discussions with executive leadership as you discuss your organization’s security posture relative to OT attacks.

About this study

The report is based on a survey of 710 IT and IT security decision-makers in the following industries: energy and utilities; health and pharmaceutical; industrial and manufacturing; and transportation industries. Respondents were from the United States, United Kingdom, Germany, Australia, Mexico and Japan, and all respondents have involvement in the evaluation and/or management of investments in cybersecurity solutions within their organizations. The consolidated global findings are presented in this report.

1Tenable Research discovered a Remote Code Execution vulnerability in InduSoft Web Studio, an automation tool for human-machine interface and SCADA systems.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training