Connect with us

Hi, what are you looking for?

HEADLINES

Industrial computers subjected to malicious cyber activity almost every second in 2018

Globally, Southeast Asia is the second top region with the most proportion of ICS computers on which malicious objects were detected and blocked by Kaspersky Lab at 57.8%.

In 2018, Kaspersky Lab detected and prevented activity by malicious objects on almost half of Industrial Control System (ICS) computers protected by the company’s products and defined as part of an organization’s industrial infrastructure. The most affected countries were Vietnam, Algeria and Tunisia. These are some of the main findings of the Kaspersky Lab ICS CERT report on the industrial threat landscape in H2 2018.

Malicious cyber activities on ICS computers are considered extremely dangerous threats as they could potentially cause material losses and production downtime in the operation of industrial facilities.

In 2018, the share of ICS computers that experienced such activities grew to 47.2% from 44% in 2017, indicating that the threat is rising.

According to the new report, the top three (3) countries worldwide in terms of the percentage of ICS computers on which Kaspersky Lab prevented malicious activity were the following: Vietnam (70.09%), Algeria (69.91%), and Tunisia (64.57%). The least impacted nations were Ireland (11.7%), Switzerland (14.9%), and Denmark (15.2%).

“Despite the common myth, the main source of threat to industrial computers is not a targeted attack, but mass-distributed malware that gets into industrial systems by accident, over the internet, through removable media such as USB-sticks, or e-mails. However, the fact that the attacks are successful because of a casual attitude to cybersecurity hygiene among employees means that they can potentially be prevented by staff training and awareness – this is much easier than trying to stop determined threat actors,” said Kirill Kruglov, security researcher at Kaspersky Lab ICS CERT.

Advertisement. Scroll to continue reading.

ICS Threats in Southeast Asia and the Philippines

Globally, Southeast Asia is the second top region with the most proportion of ICS computers on which malicious objects were detected and blocked by Kaspersky Lab at 57.8%.

In the region, the Philippines ranked fourth with the most ICS infections that were countered by Kaspersky Lab at 41.6% in the second half of 2018. According to Kaspersky Lab, the top main sources of threats for computers in the industrial infrastructure of organizations in the region are the internet, removable devices and email attachments.

“Regardless of industry, businesses will always have to deal with human error. But it will be more pronounced and threatening for industrial companies responsible for manufacturing and critical operations. From a technology standpoint, it’s worth noting that traditional IT security solutions will no longer be enough to protect industrial networks from these threats. ICS decision makers should now aim for a ‘True Cybersecurity’ which covers four key stages of attacks – predict, prevent, detect, and respond,” said Yeo Siang Tiong, GM for Southeast Asia at Kaspersky Lab.

Kaspersky Lab ICS CERT recommends implementing the following technical measures:

  • Regularly update operating systems, application software on systems that are part of the enterprise’s industrial network.
  • Apply security fixes to PLC, RTU and network equipment used in ICS networks where applicable.
  • Restrict network traffic on ports and protocols used on edge routers and inside the organization’s OT networks.
  • Audit access control for ICS components in the enterprise’s industrial network and at its boundaries.
  • Deploy dedicated endpoint protection solutions on ICS servers, workstations and HMIs, such as Kaspersky Industrial CyberSecurity. This solution includes network traffic monitoring, analysis and detection to secure OT and industrial infrastructure from both random malware infections and dedicated industrial threats.
  • Make sure security solutions are up-to-date and all the technologies recommended by the security solution vendor to protect from targeted attacks are enabled.
  • Provide dedicated training and support for employees as well as partners and suppliers with access to your network.
  • Use ICS network traffic monitoring, analysis and detection solutions for better protection from attacks potentially threatening technological process and main enterprise assets.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

In rigorous evaluations conducted by prestigious cybersecurity testing organizations, Kaspersky Plus (starting in Q4 2024, Kaspersky Premium), Kaspersky Endpoint Security for Business (KESB), and...

HEADLINES

"Given the Philippines' high exposure to cyber threats, it's important for both individuals and businesses to stay vigilant," said Adrian Hia, Managing Director for...

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

Advertisement