Huge increase in water and wastewater vulnerabilities

Sustainability

Global industrial cybersecurity watchdog, Claroty, has noted a worrying increase in the vulnerability of water and wastewater systems.

Over the past two years vulnerabilities have increased 54 percent from 2H 2019 and 63 percent from 2H 2018, higher than the other critical infrastructure sectors of critical manufacturing (up 15 percent from 2H 2019 and 66 percent from 2H 2018), energy (up eight percent from 2H 2019 and 74 percent from 2H 2018) and commercial facilities (up 14 percent from 2H 2019 and 140 percent from 2H 2018)

Throughout the second half (2H) of 2020, 71 percent of industrial control system (ICS) vulnerabilities disclosed were remotely exploitable through network attack vectors, according to Claroty’s second Biannual ICS Risk & Vulnerability Report, which also revealed a 25 percent increase in ICS vulnerabilities disclosed compared to 2019, as well as a 33 percent increase from 1H 2020.

The report comprises the Claroty Research Team’s discoveries alongside trusted open sources, including the National Vulnerability Database (NVD), the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), CERT@VDE, MITRE, and industrial automation vendors Schneider Electric and Siemens.

During 2H 2020, 449 vulnerabilities affecting ICS products from 59 vendors were disclosed. Of those, 70 percent were assigned high or critical Common Vulnerability Scoring System (CVSS) scores, and 76 percent do not require authentication for exploitation.

“The accelerated convergence of IT and OT networks due to digital transformation enhances the efficiency of ICS processes, but also increases the attack surface available to adversaries,” said Amir Preminger, vice president of research at Claroty. “Nation-state actors are clearly looking at many aspects of the network perimeter to exploit, and cybercriminals are also focusing specifically on ICS processes, which emphasises the need for security technologies such as network-based detection and secure remote access in industrial environments. It is heartening to see a growing interest in ICS within the security research community, as we must shine a brighter light on these vulnerabilities in order to keep threats at arm’s length.”

The critical manufacturing, energy, water and wastewater, and commercial facilities sectors – all designated as critical infrastructure sector – were by far the most impacted by vulnerabilities disclosed during 2H 2020 and shows increases from the previous two years across the board.

Assessment of ICS vulnerabilities sees growth in third-party researchers

The number of ICS vulnerabilities disclosed in 2020 increased by more than 30 percent compared to 2018 and nearly 25 percent compared to 2019. Two factors contribute to this spike in recent years: a heightened awareness of the risks posed by ICS vulnerabilities, and researchers and vendors increasingly focused on identifying and remediating security flaws as effectively and efficiently as possible. This growth indicates security research focused on ICS products is maturing.

Third-party researchers were responsible for 61 percent of discoveries, many of which were cybersecurity companies. This signals a change in focus to include ICS alongside IT security research, which is further evidence of the accelerated convergence between IT and OT. Among all third-party discoveries, 22 reported their first disclosures, a positive sign of growth in the ICS vulnerability research market.

The Claroty Research Team discovered and disclosed 41 vulnerabilities during 2H 2020, affecting 14 vendors. These represent the direction and core objectives of the team’s research focus. Overall, Claroty researchers have found and disclosed more than 70 ICS vulnerabilities to date.   

Publishing Information
Page Number:
12
Related Articles
Connecting Kiwi cleantech ventures with global opportunities
Fourteen ambitious Kiwi cleantech startups will soon chase global investment and partnership opportunities as part of the 2024 Cleantech Trek to the USA and Europe. Estimated to be worth more than...
NZ gets carbon credentials
CEP will be launching its new energy and carbon management credentials next month. The new credentials – Certified Professional in Energy and Certified Professional in Carbon - are being introduced...
Support for governments critical minerals list
Both Straterra and the Aggregate & Quarry Association have spoken in support of the recently announced draft critical minerals list. The release of the draft critical minerals list cements the...