The rapidly approaching cyber age — this is the futuristic, sci-fi world of fully autonomous cars, robotic personal assistants, and smart, connected coffeemakers — requires a shift from cybersecurity to cyber immunity, said Kaspersky CEO Eugene Kaspersky during an MWC Barcelona keynote.

“Security is the mask on your face. That’s security. And immunity is the vaccination,” the self-described “anti-virus guy” said, likening COVID-19 to cyber.

Kaspersky’s MWC keynote follows some of the largest cyberattacks in recent history and comes as the telecommunications sector grapples with the growing threat landscape associated with 5G network deployments.

In a separate keynote, Stéphane Richard, chair of GSMA and CEO at Orange, called cybersecurity “one of our greatest challenges for this century.” He cited a survey conducted last year during the middle of the pandemic that asked about the biggest societal risks. About 50% of respondents cited infectious diseases, livelihood crisis, and climate change, “but cybersecurity and digital inequality followed closely with almost 40%,” he said.

“There are new cyber security fears with 5G as the ecosystem is becoming larger and more fragmented and other parts of our activities are becoming digital and vulnerable,” Richard said. “This is a constant race, requiring the very best collective technology, because no one can be protected any longer behind the closed, digital door.”

This is especially true as cybercriminals develop new and increasingly destructive ways to break down that digital door.

Kaspersky: ‘Just a Question of Time’

In fact, the lucrative cybercrime industry represents a huge roadblock to reaching the cyber age, Kaspersky said.

“Every day, we receive more than 300,000 new, unique, malicious files,” Kaspersky said, noting that during the three days he’s in Barcelona for the event, “we will receive about 1 million new, unique, malicious files, applications, scripts, etc. Actually, it’s a huge global problem, but technically speaking, we can handle that,” he added, in one of several pitches during the 10-minute talk directing the audience to his company’s IoT and embedded security product page.

His security company currently monitors about 1,000 malicious code projects, Kaspersky added. “I say ‘projects’ because it’s a group of hackers that, day by day, create new types of attacks,” he explained. And these “hundreds” of cybercriminal gangs have the technical chops to develop highly sophisticated attacks the likes of the SolarWinds breach and the ransomware attack against Colonial Pipeline.

“The problem is that many of these highly professional cyber criminals are slowing shifting from attacks on networks to industrial systems,” he added, noting that in the case of Colonial Pipeline, the ransomware gang shut down the company’s IT system, not operational technology (OT) control system that could shut down the physical fuel pipelines.

“But I’m afraid that it’s just a question of time when professional cyber criminals, these professional gangs, will switch to attacks on industrial systems, on Internet of Things, and critical infrastructure,” he said. “I’m afraid it’s coming.”

Zero-Trust Security for Industrial Networks

This requires a different approach to cybersecurity, Kaspersky said. Organizations can estimate the damage that a potential network attack would cost, do a risk-benefit analysis, and invest in the appropriate security tools, maybe cyber insurance to protect themselves, he explained.

“But if we speak about critical infrastructure, the damage is unpredictable,” he added. “So not just cost of your facilities, not just cost of your factory. It’s also the damage to businesses which depend on [the critical infrastructure], maybe on the nation level or regional level. So it damages the regional economy, or maybe the national economy. Unfortunately, cybersecurity doesn’t compensate this risk … it’s time to switch from cybersecurity to cyber immunity.”

Cyber immunity involves embedding security into the operating system level and segmenting networks and systems to secure industrial layers of an organization. It also requires implementing a zero-trust framework to restrict access on a least-privilege basis, and continual, automated threat hunting and response.

“So, even if one part of the system is compromised, it will not affect the rest of the system,” Kaspersky said. “I believe that is the solution to protect critical infrastructure.”

Cisco has a similar view. And in a blog about extending zero-trust security to industrial networks, Ruben Lobo a product manager in the IoT Industrial Networking group at Cisco, outlines zero trust requirements for IoT and OT networks. These include endpoint visibility and compliance, network segmentation, and threat detection and response.

“It establishes an initial level of trust for all connecting entities based on their business role, enforces it through the network infrastructure, and continuously verifies this level of trust and compliance in every access request,” Lobo wrote. “It identifies not just users, but endpoints, and applications to grant them the absolute minimum access they need.”