What happened? - A growing threat landscape for industrial plants
The networking of production and industrial plants has considerably increased the attack surface for cyberattacks. NTT Data, a provider of AI, digital business and technology services, warns of the urgent need to act in order to protect against disruptions and outages caused by cyberattacks. Operational technology (OT), previously strictly isolated, is now exposed to the cyber threats known from the IT world and is proving to be extremely vulnerable.
Cybercriminals exploit these vulnerabilities in a targeted manner to pursue three main goals: crippling important systems for ransom demands using ransomware, stealing intellectual property for product piracy, and targeted sabotage to damage companies.
The details - Seven critical attack paths identified
NTT Data's experts have identified seven main entry points for cyberattacks on OT systems:
1. Unpatched vulnerabilities in legacy systems
OT systems are designed for long service lives and have often been in operation for ten years or more. Updates and patches for these systems are rare or no longer available at all. In some cases companies deliberately forgo available updates so as not to interfere with production processes.
2. Inadequate security functions
Many legacy systems use outdated protocols and interfaces, weak authentication mechanisms and unencrypted data transmission. New IoT devices too often lack sufficient security mechanisms. The problem: endpoint security solutions usually cannot be installed on either type of system.
3. Poorly secured remote access
Many OT systems are maintained remotely - by internal teams or external service providers. These access paths often use default passwords or shared passwords for several people. Robust security mechanisms such as multi-factor authentication, role-based access controls and session recording are frequently missing.
4. Stolen credentials from the darknet
Stolen access credentials are traded in the hundreds of thousands on the darknet. For targeted attacks, cybercriminals use malware such as infostealers that capture passwords as they are typed, or rely on phishing and social engineering. Thanks to AI, the fakes can now be made extremely convincing.
5. Missing network segmentation
Without dividing the network into different areas with controlled data traffic, attackers can use lateral movement. Even an office PC in administration can serve as a springboard into OT and endanger the entire operational technology.
6. Insecure supply chains
OT environments consist of complex systems from various hardware vendors, software specialists and system integrators. Cybercriminals compromise these suppliers in order to gain a foothold at several companies at once. The SolarWinds example showed the far-reaching consequences of such supply chain attacks.
7. Overloading systems through DDoS
DDoS attacks serve not only to extort through system overload but often also as a diversionary manoeuvre or to disable security systems in order to intrude undetected.
Context - Why the threat is growing
Christian Koch, Senior Vice President Cybersecurity IT/OT at NTT Data DACH, emphasises: "OT security is not a nice-to-have but a must, because digitalisation is increasing the attack surface and the number of attacks on industrial companies is reaching new record levels year after year."
Policymakers have responded: the EU and the German federal government are obliging industrial companies to implement comprehensive security measures through the NIS Directive, the Cyber Resilience Act, the Machinery Regulation and the IT Security Act. Because of its many poorly protected infrastructures and enormous damage potential, industry is among the most frequently attacked sectors.
Practical tips - Fundamentals for effective protection
According to NTT Data, companies must first establish full visibility across their entire OT environment. Only then can they determine risks and develop a suitable security concept.
The recommended basics include:
- Network segmentation to contain lateral movement
- Patch management for available security updates
- Secure remote access with multi-factor authentication
- Role-based access controls
- Session recording for traceability
Supplier access via VPN, LTE routers or TeamViewer-style systems deserves particular attention. These are often overlooked sources of risk that must be systematically secured.
Outlook - Regulatory requirements are rising
Regulatory requirements will be tightened further. Companies must prepare for comprehensive compliance obligations that go beyond previous security standards. The combination of the NIS Directive, the Cyber Resilience Act and the IT Security Act calls for structured approaches to OT security.
At the same time, attack methods continue to evolve. AI-supported attacks are becoming more sophisticated and harder to detect. Companies should therefore implement not only reactive security measures but also establish proactive threat detection and response.
Networking will continue to increase, creating additional attack surfaces. Only companies that treat OT security as a strategic priority and invest continuously in security measures will remain competitive in the long term and be able to meet regulatory requirements.