By Gregory Hale
Digital transformation in manufacturing is continuing is growth curve, which is increasing the attack surface facing OT security professionals. If that is not stress-inducing enough, it is also abundantly clear reports of vulnerabilities for industrial control systems (ICS) are on the rise.
Add those two factors together and it means security experts need to ensure they stay one step ahead.
Twice a week reports release from the Cybersecurity and Infrastructure Security Agency (CISA) on vulnerabilities in various products from major suppliers to smaller providers. To that end, there was a 41 percent increase in ICS vulnerabilities disclosed in the first half of this year compared to the previous six months, which is significant given that last year vulnerabilities jumped by 25 percent from 2019 and 33 percent from 2018, according to the third Biannual ICS Risk & Vulnerability Report released by cybersecurity provider, Claroty.
“What we have seen is the increased can be directly connected to the fact there is more researchers working in the industry,” said Chen Fradkin, a security researcher at security provider, Claroty. “That means you get an increased number of vulnerabilities and they are big. The vulnerabilities have been there all along, so it is important to understand that means they have been available to threat actors that have significant resources and been able to exploit them.”
More People Finding Vulnerabilities
“To me, that doesn’t mean there are more vulnerabilities, it means there are more people finding vulnerabilities,” said Joel Langill, founder and managing member of the Industrial Control System Cyber Security Institute LLC. “You are seeing more well-funded organizations do the vulnerabilities rather than the independents.
“The reason why I don’t get excited anymore is because a lot of times they are not tracking against whether it is a current product, these are just raw numbers,” Langill said. “I don’t think there are any more vulnerabilities that exist today than 15 years ago. Nobody could find them 15 years ago because they didn’t know how, they didn’t have the capabilities, now they have the capabilities and the capacity.”
On top of that, Langill said there are more vulnerabilities reported, but they “don’t have exploits attached to them.”
Fradkin said they have found more vulnerabilities affecting level one components like PLCs, controllers and RTUs.
“We think this rise of vulnerabilities that may lead to remote code execution is higher this past six months and they have been there all along,” she said. “This is the style of vulnerabilities that have been exploited in attacks like Triton, with attacks on PLCs.”
The Triton attack occurred when malicious actors used a custom attack framework to manipulate a Triconex safety system at a critical infrastructure facility and inadvertently caused a process shutdown.
Vulnerabilities in Existence
These vulnerabilities were not just added in, they have been in existence for quite some time. They are just now being discovered, as long as suppliers create a fix – and as long as users apply the fix. That leads into patch management, a tried-and-true industry hot point where users often can’t shut down a process just to patch. Often that means users can become more susceptible to attacks unless they come up with a mitigation strategy.
“It is hard to upgrade OT devices and so over the years there are vulnerabilities that are accumulating because you don’t upgrade as often,” Fradkin said. “There are still old devices out there, but there is also the fact there are more researchers with more resources able to find vulnerabilities.”
Does that mean more shutdowns to patch?
“Not necessarily,” Fradkin said. “We have come to the conclusion mitigation steps are something to keep your focus on. You can also create a prioritization of what is easier to patch and create a plan to patch it. But when patching is practically impossible, mitigation steps are possible. We find some mitigations steps are possible like segmenting your networks, or deploying a remote access solution. These are basics of security and now you can boost your security in your OT network by doing these steps.”
Yes, there are more vulnerabilities discovered, but not all are created equal.
“In every disclosure you can prioritize what is important to (the manufacturer),” Fradkin said. “The security people need to create a plan to work and deal with vulnerabilities. They need to prioritize them based on criticality, based on the impact it will have on the network. Then they can relate to each one. Some of them they can say we can patch, maybe this one we can just do mitigation steps.”
With more remote access for workers, it also plays into the hands of attackers.
Remotely Exploited
“The majority of vulnerabilities are exploited remotely,” Fradkin said. “Just around 61 percent of vulnerabilities are accessible on the network remotely. I think that ties into remote connections and the ability to work from home and it will keep rising when we migrate to a cloud-based architecture then you are going to have your entire management platform accessible through the Internet.”
While understanding and creating fixes for this increased number of vulnerabilities is important, it all comes into perspective as the industry is seeing an ever-increasing amount of attacks against all types of sectors.
“There is a realization the industry is a valuable target because of the criticality of it,” Fradkin said. “Because of the money the attackers can gain from it; we have seen it in the Colonial Pipeline attack and the JBS Foods attack.”
More vulnerabilities leans more to the possibilities of more attacks, which means manufacturers need to be able to have 20/20 vision on their network.
“Visibility is the first step to understand how your network works,” Fradkin said. “Which assets you have, what you need to protect and how. When a company doesn’t have a good picture of their reality, they have a hard time protecting it.”
A rise in vulnerabilities does not mean it is the end of the world, manufacturers just need a good plan and they need to start with the security basics and move up from there.
“One thing keeps repeating itself, people should go with a defense-in-depth strategy,” Fradkin said. “You can’t rely on one solution. You can’t rely on a single point of protection. You have to have deep thought in implementing various protection techniques and how you scatter them across your network. There are specific mitigations steps you need to have segmentation in your network and a remote access solution.”
Micro Segmentation
Researches are going to keep finding vulnerabilities, but what manufacturers need to keep their eye on what they really need to do.
“People need to stop worrying about vulnerabilities and start securing their architectures,” Langill said. “There should be very little unmitigated risk if people are following basic cybersecurity practices, which means establishing security zones and fortifying the entry points and conduits in the zones and deploying detection mechanisms on top of that so if you see irregular activity you generate an alert and have someone look at it. To this day, I still don’t see a lot of that being done.
“Micro segmentation will address 90 percent of these problems right out of the gate. With micro segmentation, you have nowhere to go. If you attack a device, you attack the device and your consequence and impact ends,” Langill said. “As long as people deploy networks that aren’t designed around standard security design, they are going to be vulnerable. Follow best security practices create security zones based on relative risk of exposure and consequence.”

