What recent PLC attacks reveal about the state of OT cybersecurity

Awareness is significantly higher than it was 10 years ago and most operators understand that cybersecurity is important. The challenge, however, remains execution.

What you’ll learn:

  • Attackers can discover and infiltrate internet-connected industrial control systems.
  • The question isn’t whether adversarial actors have this capability. It is about why they keep discovering them.
  • Remote access was enabled to troubleshoot processes and respond quickly to issues. This, however, can lead to a state of unintended exposure.

The recent series of attacks on the internet-connected programmable logic controllers within U.S. critical infrastructure garnered extensive media coverage.

The headlines revolved around the reported connection to threat actors aligned with Iran and the national security implications.

These concerns are certainly valid, but they are in danger of overshadowing the most important point. For OT practitioners, the emerging details of these events are nothing new.

See also: Smart Industry's annual State of Initiative Survey is open!

If these incidents reveal anything about the current state of OT cybersecurity, it’s that the industry is operating in a transitional period.

Awareness is significantly higher than it was 10 years ago. Most operators understand that cybersecurity is important. The challenge is execution.

Many organizations have policies, guidance documents and technology investments, but they still struggle to maintain visibility of assets, govern remote access, validate recovery processes and establish OT-specific expertise.

The gap is no longer awareness. The gap is operational implementation.

According to reports, the attackers were able to discover and infiltrate internet-connected industrial control systems. These types of concerns have surfaced many times in the form of cybersecurity advisories issued over the last decade.

Despite years of guidance provided by government, standard and industry organizations, critical infrastructure operators continue to discover internet-accessible controllers, remote access pathways with inadequate controls and poor visibility into assets.

See also: U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

The question isn’t whether adversarial actors have the capability to discover these systems. The question is why they keep discovering them. And answering this question requires moving away from the adversarial actor and considering the operational realities that exist within many utilities, municipalities and industries.

The common questions

In the aftermath of every cyber event, many questions arise, such as who conducted the attack, what malware was used and was a nation-state behind the attack. These are all valid concerns for government and law enforcement.

Despite years of guidance provided by government, standard and industry organizations, critical infrastructure operators continue to discover internet-accessible controllers.

However, for the affected organization, they are not likely to have any impact on the outcome of the situation. For the operator, the consequences of a cyber event depend much more on practical questions such as:

  • What assets are accessible via the internet?
  • Who has access to these assets?
  • Can any changes in the controller logic be identified?
  • Is it possible to operate safely even in case of digital systems failure?
  • Does the recovery and backup process exist and is it verified?

Those organizations that can positively answer these questions are usually able to recover relatively quickly. Other organizations often discover their vulnerabilities after the fact. And the reasons for it are rarely related to the technology. They are usually related to preparedness.

Why are PLCs still connected to the internet?

One of the most common reactions to incidents such as the recent attacks on the water systems is the disbelief in their occurrence. Some might ask, “How could there still be a PLC directly connected to the internet?”

For those who spent some time in water treatment facilities, manufacturing plants, energy operations or municipal infrastructures, the response is quite different. Most of the exposed systems were not intentionally installed to represent a cybersecurity risk.

See also: Who’s winning the cybersecurity arms race? A region-by-region scorecard

They were just the result of decades of decisions that had to do with operational requirements to ensure reliability, availability, and supportability.

Remote access was enabled primarily to troubleshoot processes and respond quickly to issues, reduce travel costs and provide support to third parties.

Each decision was reasonable at the moment it was made. But, as time goes on, they can lead to a state of unintended exposure that is no longer completely understood by the entity operating the system.

In many small-scale utilities, the same people that operate the water treatment facility may also perform networking, SCADA administration, compliance reporting and cybersecurity-related duties. It’s not usually about the neglect. It’s about the lack of resources and OT cybersecurity specialists.

The expertise gap as the vulnerability

The cyber industry always tends to frame its conversations around acquisition of technology. The organization is supposed to buy:

  • Endpoint protection solution
  • Network monitoring
  • Firewall
  • Security information and event management platform
  • Threat detection solution

These technologies are valuable. However, many critical infrastructure organizations face a far greater issue that they simply lack OT cybersecurity expertise among their personnel.

One of the most common reactions to incidents such as the recent attacks on the water systems is the disbelief in their occurrence. Some might ask, ‘How could there still be a PLC directly connected to the internet?’

The difference between IT security and OT security is huge. A great IT/enterprise security specialist might be aware of how to manage authentication, cloud and enterprise networks. But he or she may not understand anything about:

  • Protection of the control logic
  • Operational safety
  • Industrial communications
  • Engineering workflows
  • Maintenance
  • Availability

It can be very hard to implement a cybersecurity recommendation without this knowledge. This expertise gap is especially problematic for small municipalities and utilities.

Third-party access: The forgotten attack surface

When considering PLCs and other industrial systems that are accessible via the internet, the emphasis tends to be placed on the assets in question. However, many OT incidents occur because of authorized remote access points which were initially created for legitimate reasons.

See also: AI ‘governance gap’ persists across industries as security incidents continue to rise

System integrators, OEMs, contractors and service providers often need access to commission, troubleshoot, update and perform other maintenance tasks. This access can be quite useful yet can pose some risks if not appropriately governed.

Some common issues include remote support solutions which were put in place a few years ago and haven't been regularly reviewed since. Some of these reviews might be verification of shared service accounts which are accessed by several outside personnel and could also lead to over-privileged access which exceeds current organizational requirements.

Many OT incidents occur because of authorized remote access points which were initially created for legitimate reasons.

Additionally, legacy VPN connections that are left running after completion of related projects could be part of vendor access channels which were used to circumvent existing security measures.

The easiest question organizations can start with is: "Which third parties have access to our OT environment at the moment, and when did we review it last time?"

See also: Attack chain glue: How one form of AI is hypercharging cyberattacks on manufacturing

Quite often, it turns out that the answer isn't as simple as it seems to be.

Effective governance of the environment implies regular reviews of all third-party access points, documented ownership of each one and appropriate access approval processes, as well as the ability to monitor and audit external activities in the OT environment.

In no way is the goal to prohibit vendor access—it just must be appropriate, necessary and visible.

About the Author

Andrew Barco

Andrew Barco

Andrew Barco is global program senior director for industrial ethernet for Weidmüller Global.

Sign up for our eNewsletters
Get the latest news and updates