1、SurveyThe State of ICS/OT Cybersecurity in 2022 and BeyondWritten by Dean ParsonsOctober 20222022 SANS Institute2The State of ICS/OT Cybersecurity in 2022 and BeyondExecutive SummaryThe industrial control system(ICS)/operational technology(OT)security community is seeing attacks that go beyond tradi
2、tional attacks on enterprise networks.Given the impacts to ICS/OT,fighting these attacks requires a different set of security skills,technologies,processes,and methods to manage the different risks and risk surfaces,setting ICS apart from traditional IT enterprise networks.Adversaries in critical in
3、frastructure networks have illustrated knowledge of control system components,industrial protocols,and engineering operations.From the previously observed impactful attacks,such as CRASHOVERRIDE1 in the electric sector,human machine interface hijacking through remote access2 in water management,and
4、ICS-specific ransomware3 in the manufacturing and energy sectors,to the more recent Incontroller/PIPEDREAM4 advanced scalable attack framework targeting multiple ICS sectors,ICS/OT attacks are more disruptive with the possibility of physically destructive capabilities.Threat intelligence supports th
5、e fact that industrial security defenders across all sectors must address new challenges and face serious threats.The 2022 SANS ICS/OT Cybersecurity survey results reveal several changes and significant focus on ICS operational improvements;however,progress in key areas needs more emphasis to defend
6、 our critical infrastructure into the future.Industrywide insights from this survey include:Significant change in who is being called to perform ICS incident response A shift in the responsibility for implementing security controls in ICS/OT Continued value and investment in ICS-specific training an