ICS Vulnerability Disclosures Grew 110% Over Last Four Years (Sabong News)
Author
MB Technews
Date
MARCH 06 2022
Industrial control system (ICS) vulnerability disclosures grew a staggering 110% over the last four years, with a 25% increase in the second half (2H) of 2021 compared to the previous six months, according to new research released today by
, the security company for cyber-physical systems across industrial, healthcare, and enterprise environments. The fourth Biannual ICS Risk & Vulnerability Report also found that ICS vulnerabilities are expanding beyond operational technology (OT) to the Extended Internet of Things (XIoT), with 34% affecting IoT, IoMT, and IT assets in 2H 2021.
The report presents a comprehensive analysis of ICS vulnerability data from
, Claroty’s award-winning research team, along with trusted open sources, including the National Vulnerability Database (NVD), the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT),
, MITRE, and industrial automation vendors Schneider Electric and Siemens.
“As more cyber-physical systems become connected, accessibility to these networks from the internet and the cloud requires defenders to have timely, useful vulnerability information to inform risk decisions,” said Amir Preminger, vice president of research at Claroty. “The increase in digital transformation, combined with converged ICS and IT infrastructure, enables researchers to expand their work beyond operational technology (OT), to the Extended IoT (XIoT). High-profile cyber incidents in 2H 2021 such as the Tardigrade malware, the Log4j vulnerability and the ransomware attack on NEW Cooperative show the fragility of these networks, stressing the need for security research community collaboration to discover and disclose new vulnerabilities.”
To access the complete set of findings, in-depth analysis, and additional steps to defend against improper access and risks, download the Biannual ICS Risk & Vulnerability Report: 2H 2021.
Team82’s newly launched Slack channel is available as well for additional discussion and insight into the report.
.