Risk & Resilience Practice: Boards of Directors as the Final Cybersecurity Defense for Industrials
The increasing adoption of new technologies and digitization has expanded the "attack surface" for cyber threats, posing significant challenges for organizations. Cyber defenses must evolve to combat sophisticated attacks originating from various directions. While some organizations might focus solely on managing daily cyber threats, the strategic security plan — outlining approaches and directions — is crucial, especially for the board of directors.
Boards play a pivotal role in defining objectives, setting major goals, and maintaining organizational direction over time. As cyber threats intensify due to increased digitization, cloud adoption, advanced connectivity, and AI, including generative AI (gen AI), boards across industries can guide strategies to enhance cyber resilience.
Understanding the organization's landscape is key. For instance, the industrial operational technology (OT) sector, embracing digitization, faces an escalating "attack surface." Once considered air-gapped from the internet, OT capabilities now make it vulnerable to cyberattacks, with threat actors actively seeking entry points.
Cyberattacks on OT space in 2021, publicly reported, showed a 140% increase over the previous year, with about 35% having physical consequences and estimated damages totaling $140 million per incident. Geopolitical risks in 2022 led to an 87% rise in ransomware incidents, with Europe and North America experiencing the highest increases.
Organizations should consider multiple cybersecurity landscapes, including:
-
Digital OT: Physical systems controlled and monitored through IT networks. Remote monitoring from centralized/local control centers sends commands to remote systems. However, digital access introduces new cyberattack pathways, especially with legacy equipment that is hard to secure.
-
Cloud and Edge Computing: Essential for video monitoring and cost-effective computing. Yet, these systems pose security challenges due to integration with IT systems and potential impacts on plant control systems.
-
Internet of Things (IoT) and Industrial IoT: Enables remote monitoring of critical parameters like pressure, pump viscosity, and temperature. Widespread deployment and low cost leave devices vulnerable to basic attacks.
-
AI: Provides cognitive insights and automates decision-making processes. However, these capabilities can also be exploited by attackers to take control or negatively affect targeted organizations.
Attack Surface Expansion:
An evolving digital environment creates a larger attack surface as threat actors become more innovative and sophisticated. Vulnerabilities are increasingly found in public clouds, where security misconfigurations are common. Lack of strong central oversight and governance in cloud usage exposes companies to significant risk.
Additionally, cybercrime groups are now technologically on par with nation states, thanks to the popularity of ransomware. This has enabled the creation of hacker organizations rivaling nation states in terms of talent and financial resources, with increased demand for specialized skills driving a thriving cyberattacker economy.
Freelance Hackers and Gen AI:
Attackers are pooling skills to become more specialized and sell their services for personal profit. The use of generative AI (gen AI) in developing novel attack techniques is another emerging trend, allowing threat actors to explore vulnerabilities, improve existing tools, and create new ones for various purposes.
Defenders' Response:
Despite the overwhelming nature of threats, the advancements in defensive strategies are encouraging. Over the past few years, organizations have strengthened their cyber defenses. The number of significant cyberattacks has remained relatively stable despite the growing volume of daily threats, indicating a maturing response.
In conclusion, the role of the board of directors in shaping strategic security plans and fostering a culture of continuous learning and adaptation is crucial in safeguarding organizations against the evolving landscape of cyber threats. By understanding their unique landscapes and responding proactively, organizations can mitigate risks and maintain cyber resilience.