Ransomware attacks increasingly target critical infrastructure: essential systems such as energy, water, transport and finance. According to the FBI, more than 40% of attacks in 2023 alone hit these sectors. At the same time, agencies such as CISA and the UK’s NCSC are warning infrastructure companies about growing threats from state-backed adversaries or other malicious actors.

The recent incident at American Water illustrates how vulnerable infrastructure companies can be. Although the incident was limited to billing systems, the suspected ransomware attack highlights the urgent need for organizations to implement ZTNA and begin segmenting on-premise, cloud and hybrid networks, as well as workloads, to prevent IT network breaches from reaching operational technology (OT) and interfering with essential services and critical operations.

Important findings

  • Ransomware attacks on critical infrastructure are increasing.
  • Zero-trust architectures and microsegmentation are critical for protection.
  • Companies should segment their networks to minimize the impact of attacks.

Security risks

Think of OT as devices that control the physical world (power grids, machines, pipelines). These include monitoring and data acquisition systems (SCADA), industrial control systems (ICS) and distributed control systems (DCS). Traditionally, these systems have been managed separately from IT, but that has changed with the growth of IoT and Industry 4.0. Today, these systems are more connected and integrated. Add to that the complexity of managing remote employees, contractors and third parties who need access to IT and OT to perform daily maintenance, which increases your security risks.

While tools like IAM, PAM and MFA manage access, they don’t answer one crucial question: What happens when an attacker bypasses those defenses? Microsegmentation closes this gap in a zero-trust strategy. It divides a network into smaller, isolated segments, limiting the ability of attackers to act laterally and ensuring that a breach in one area does not reach other critical assets. Microsegmentation is essential for critical infrastructure organizations and provides granular security controls that protect on-premise, cloud and hybrid environments.

10 Best Practices for Securing OT

When it comes to securing IT and OT systems, managers need to assess their risk and develop a strategy focused on zero-trust principles. Start with these 10 best tips:

  1. Assume a breach and minimise its impact: Operate as though a breach has already occurred. Segment network access, encrypt data at rest and in transit, and analyse your network to detect and respond to threats quickly.
  2. Understand your network resources: Companies should map their entire network, identify critical assets, workloads, and data flows. This helps determine which segments need the highest level of protection.
  3. Increase visibility in OT systems: Organizations need better visibility into their OT and industrial control systems to secure, maintain and quickly isolate potential security incidents.
  4. IoT Password Management: Organizations have strict password policies for users, but don’t always apply them to servers, applications, and IoT devices. IoT/machine credentials must be secure, authenticated and changed regularly.
  5. Use IAM solutions: Use identity and access management tools such as multifactor authentication (MFA), single sign-on (SSO), and privileged access management (PAM) to centralize and manage user identities, authentication, and authorization.
  6. Implement valuable segmentation projects that are straightforward to put into practice: Microsegmentation can seem overwhelming, but it does not have to be. Take a step-by-step approach and focus on critical areas that are easy to implement and offer significant value.
  7. Use granular segmentation policies: Apply microsegmentation at the workload or application level, not just for entire servers. This provides more precise control and limits an attacker’s ability to switch between segments.
  8. Monitor and update policies regularly: Continuously monitor network traffic between segments to detect anomalies and improve defense.
  9. Test for breach scenarios: Perform penetration tests to simulate potential attacks and identify gaps in your segmentation strategy.
  10. Back up systems regularly: Ransomware attacks block access to data and systems. A secure backup solution helps mitigate the impact and enables system recovery to minimize downtime.

Sources

  • Protecting Critical Infrastructure with Zero-Trust and Microsegmentation – Security Boulevard, Security Boulevard.