In its latest annual review, operational technology (OT) cybersecurity vendor Dragos raised alarms over the escalating threat of ransomware attacks and the pervasive issues of some vulnerability advisories lacking patches, mitigations or accurate data in the OT environments.
Dragos tracked 905 reported ransomware incidents impacting industrial organizations last year, a nearly 50% surge from 2022. CEO and founder Robert M. Lee emphasized during a press briefing that the ransomware problem is not under control nor a “falling off.”
Ransomware remains the number one attack in OT, the 2023 OT Cybersecurity Year in Review report wrote. “Industrial organizations have much to lose because operational disruptions can carry significant financial and reputational costs. Further, there can be numerous cascading impacts on downstream businesses and outputs.”
The report found manufacturing continues to be the primary target of ransomware among sectors. Robert M. Lee, of Dragos, pointed to digital connectivity and economic incentives as the potential driving force.
In addition, among hundreds of ransomware variants, Dragos tracked 50 ransomware variants that claimed to have impacted industrial organizations in 2023, a 28% increase year over year.
LockBit ransomware was the most-used ransomware variant, accounting for 25% of the total incidents against OT organizations, followed by ALPHV (9%) and BlackBasta (9%).
“Vendors really can prioritize the defense they put in place and how they're tracking the tactics or the methods of the adversaries [on LockBit ransomware]. With a smaller focus, they can end up mitigating a lot of the risk of a larger portion of that,” Lee said.
The dangers of 'flat networks'Dragos pointed out that the ransomware group’s ability to impact OT environments depends largely on the types of security controls network defenders have in place. While many assets are shielded behind at least a single layer of defenses such as firewalls or proxies, the effectiveness of these security controls varies greatly.
In 2023, Dragos identified that 28% of the organizations it engaged with had issues related to segmentation issues or improperly configured firewalls. Lee emphasizes that this figure likely underrepresents the broader industry scenario with a selection bias, as these “customers are already coming to Dracos to do OT security work [and] are already more sophisticated on their journey.”
The vendor also reported that about 70% of OT-related incidents originated from within the IT environment.
Lee points out the dangers of “flat networks”—environments lacking any form of segmentation between IT and OT networks.
“The idea that you're gonna have an air gap or completely segment or completely separate an OT network is lunacy,” he said. But “You want some segmentation and defensive architecture.”
Dragos: OT vendor community should provide better vulnerability guidanceDragos argues OT vulnerabilities should be addressed and mitigated differently from IT ones based on the strict operational requirements of OT systems, such as system uptime and vendor qualification processes.
Many vulnerability management programs focus their remediation on ‘Critical’ vulnerabilities with a Common Vulnerability Scoring System (CVSS) score of 9.0 or higher. However, this approach has three problems including the following:
Firstly, researchers often have no input to the final copy of a public advisory and CVSS scores may be inaccurate; Second, CVSS does not account for typical OT network architecture; Lastly, advisories often lack practical steps besides ‘apply the patch.’
In 2023, Dragos analyzed 531 OT vulnerability advisories, 31% had incorrect data, while Dragos found 9% to be more severe than the CVSS score, 4% to be less severe, and 1% were the same.
The report also showed that 28% of these advisories had no patch when announced, 74% had no mitigation at all, 73% had no vendor mitigation, and 19% had no patch and no mitigation.
“Our asset owners and operators are getting very poor guidance from the larger vendor community,” Lee said. “That's something that we've got to step up as a community and handle it better.”
Risk-based vulnerability managementDragos noted in the report that OT organizations should take the risk-based vulnerability management approach and only some vulnerabilities need immediate action.
Lee explained that only 3% of the OT vulnerabilities require to be fixed as soon as possible, “because they're either actively being exploited by adversaries or they pose real genuine risks on operations, life safety, health, etc.”
Another 68% are network exploitable with no direct operational impact, which organizations can deal with when they have more resources and mitigate through network monitoring, segment and multifactor authentication (MFA; and 29% of the OT vulnerabilities pose a possible threat but rarely require action, which organizations only need to monitor for signs of exploitation.
Comments