Dragos, a leading cybersecurity player focused on operational technology (OT) environments, today announced a $74 million extension of its Series D funding round.
The funding extension builds on the $200 million Dragos raised in 2021.The funding injection is set to help the company maintain its growth trajectory and expand into global markets. OT commonly refers to industrial types of networks, such as power and utilities as well as those used in manufacturing environments. In recent years, both attackers and regulators have paid increasing attention to OT security, which has led to growth and opportunity for Dragos.
"This funding is important for us to maintain our position and continue growing the business in a targeted way," Phil Tonkin, chief of staff at Dragos, told SDxCentral. "We want to take this all the way through to IPO in the future."
The operational technology threat landscapeThe OT threat landscape has changed in recent years in a number of ways. Tonkin pointed out the shift from the development of capabilities targeting specific sectors to creating universal tool sets that can be used against any industry.
"The big shift is moving towards tool sets, which are pretty much universal and exploit the homogeneous nature of OT systems," Tonkin said.
Tonkin explained that many OT networks are homogenous because the underlying protocols and even code used in devices across different industries are often very similar or even the same. Adversaries have recognized this and developed universal tool sets like the Pipedream framework that can be tailored to target many types of critical infrastructure due to these shared vulnerabilities arising from homogenous infrastructure.
Another significant shift is the rise in ransomware attacks. Criminals have started to recognize the value of OT systems in their ever-expanding implementation of ransomware attacks on IT systems.
"The operational systems are being hit just as a simple consequence of missing segmentation within customers' environments," Tonkin said.
Tonkin noted that more sophisticated ransomware groups have deliberately gone after OT systems while already inside an environment, because they know targeting these systems adds leverage for businesses to pay ransoms. Essentially, criminal groups now understand that disrupting industrial operations through ransomware can significantly increase coercion on victims.
Flat networks and patching remain key risksAmong the common risks that Tonkin says are prevalent in OT networks is a lack of patching for known risks and flat networks with no segmentation.
The reason why flat, nonsegmented networks tend to occur is due in part to help enable easier interconnectivity between systems and third parties, often between the IT and OT networks. The lack of patching is often due to the complexity of OT deployments and production requirements.
As it turns out, though, Tonkin argued that not all vulnerabilities do need to be patched, at least right away. One of the things that Dragos does is help to identify what actually is being targeted and is potentially at risk by using threat intelligence and asset visibility.
Why zero trust isn't coming to OT networks anytime soonAcross multiple industries, zero trust is commonly considered to be a best-practice approach to helping reduce risk.
While a zero-trust approach would help reduce risk in OT, Tonkin said that in his view, a full zero-trust approach is just not feasible for many OT environments. Tonkin explained that true zero trust is very difficult to achieve in most OT networks due to the inherent requirements and constraints of these systems. OT devices need to implicitly trust each other for secure and low-latency communications. Adding security measures like point-to-point authentication could introduce performance issues. While zero-trust concepts may work at the edge for remote access; Tonkin noted that this is not practical within operational systems, given that devices cannot be easily modified with new features.
Tonkin also said no one wants to take on the risk of being the first to implement immature zero-trust technologies in critical infrastructure. Traditional network monitoring and controls are still better options for most OT environments.
"Until there is a time when these [zero-trust] capabilities can be implemented without further risk in those environments, it's still better to implement traditional controls and network security with monitoring as a way of getting a better resolution of what's happening within the environment."
Comments