Fortinet Global Report Finds 75% of OT Organisations Experienced at Least One Intrusion in the Last Year
“Fortinet’s 2023 State of Operational Technology and Cybersecurity Report shows that while OT organisations have improved their overall cybersecurity posture,
they also have continued opportunity for improvement. Networking and IT teams are under extraordinary pressure to adapt and become more OT-aware, and organisations are shifting to find and employ solutions that implement security across their entire IT/OT environment to reduce their overall security risk.”
Fortinet announced the findings from its global 2023 State of Operational Technology and Cybersecurity Report. The results represent the current state of operational technology (OT) security and point to the opportunity for continued improvement for organisations to secure an ever-expanding IT/OT threat landscape. In addition to the latest trends and insights impacting OT organisations, the report also provides a roadmap to help IT and security teams better secure their environments.
Key findings from the global survey include:
- OT continues to be targeted by cybercriminals at a high rate: While the number of organisations that did not incur a cybersecurity intrusion improved dramatically YoY (from 6% in 2022 to 25% in 2023), there is still significant room for improvement. In fact, three-fourths of OT organisations reported at least one intrusion in the last year. Intrusions from malware (56%) and phishing (49%) were once again the most common type of incidents reported, and nearly one-third of respondents reported being victims of a ransomware attack in the last year (32%, unchanged from 2022).
- Cybersecurity practitioners overestimated their OT security maturity: In 2023, the number of respondents who consider their organisation’s OT security posture as “highly mature” fell to 13% from 21% the year before, suggesting growing awareness among OT professionals and more effective tools for self-assessing their organisations’ cybersecurity capabilities. Nearly one-third (32%) of respondents indicated that both IT and OT systems were impacted by a cyberattack, up from only 21% last year.
- The connected device explosion underscores complexity challenges for OT organisations: Nearly 80% of respondents reported having greater than 100 IP-enabled OT devices in their OT environment, highlighting just how significant a challenge it is for security teams to secure an ever-expanding threat landscape. Survey findings revealed that cybersecurity solutions continue to aid in the success of most (76%) OT professionals, particularly by improving efficiency (67%) and flexibility (68%). However, report data also indicates that solution sprawl makes it more difficult to consistently incorporate, employ, and enforce policies across an increasingly converged IT/OT landscape. And the problem compounds with aging systems, with the majority (74%) of organisations reporting that the average age of ICS systems across their organisation are between 6 and 10 years old.
- Alignment of OT security under the CISO bodes well for the industry: While nearly every organisation faces an up-hill battle when it comes to finding qualified security practitioners due to the growing cybersecurity skills shortage, report findings suggest OT organisations are continuing to prioritise cybersecurity. A key indicator is that nearly every (95%) organisation plans on placing the responsibility for OT cybersecurity under a chief information security officer (CISO) in the next 12 months rather than an operations executive or team. The findings also reveal that OT cybersecurity professionals now come from IT security leadership rather than product management, and influence on cybersecurity decisions is shifting away from operations and to other leaders, especially CISO/CSO roles.
Fortinet’s global 2023 State of Operational Technology and Cybersecurity Report indicates ways organisations can strengthen their overall security posture. Organisations can address OT security challenges by adopting the following best practices:
- Develop a vendor and OT cybersecurity platform strategy. Consolidation reduces complexity and accelerates outcomes. The first step is to begin building a platform over time by partnering with vendors that engineer their products with integration and automation in mind to enable organisations to consistently incorporate and enforce policies across an increasingly converged IT/OT landscape. Seek to engage with vendors with a wide portfolio of solutions that can provide the basic solutions of asset inventory and segmentation and more advanced solutions, such as an OT security operations centre (SOC) or the ability to support a joint IT/OT SOC.
- Deploy network access control (NAC) technology. Solving challenges associated with securing ICS, SCADA, IoT, BYOD, and other endpoints requires advanced network access control to be part of a comprehensive security architecture. An effective NAC solution also helps to maintain complete control of an organisation’s network by managing new devices that want to connect or communicate with other parts of the organisation’s infrastructure.
- Employ a zero-trust approach. Implement the basic steps of asset inventory and segmentation, and provide continuous verification of all users, applications, and devices seeking access to critical assets.
- Incorporate cybersecurity awareness education and training. Cybersecurity training remains critical as the cybersecurity battle requires the collective empowerment of all employees to have the knowledge and awareness to work together to protect themselves and their organisation’s data. Organisations should consider including nontechnical training targeted toward everyone who uses a computer or mobile device, from teleworkers to their families.
A platform approach, with open APIs and a robust fabric-ready technology alliance ecosystem, designed to deliver OT-aware features to secure OT environments enables CISOs and security teams to reduce complexity, increase efficacy in the prevention and detection of ransomware, and speed incident triage, investigation, and response.
Collaboration across IT, OT, and production teams to assess cyber and production risks, specifically ransomware incidents, with the CISO can help ensure awareness, prioritisation, budget, and personnel allocations.
- The Fortinet 2023 State of Operational Technology and Cybersecurity Report is based on data from an in-depth worldwide survey of 570 OT professionals, conducted by a third-party research company.
- Survey respondents were from different locations around the world, including: Australia, New Zealand, Brazil, Canada, Egypt, France, Germany, India, Japan, Mexico, South Africa, United Kingdom, and United States, among others.
- Respondents represent a range of industries that are heavy users of OT, including: manufacturing, transportation/logistics, healthcare/pharma, oil, gas, and refining, energy/utilities, chemical/petrochemical, and water/wastewater.
- Most of those surveyed, no matter their title, are deeply involved in cybersecurity purchase decisions. And these individuals increasingly have the final say in OT purchase decisions. This year’s survey found that 91% of respondents are regularly involved in their organisation’s cybersecurity purchase decisions.
- Read the blog for key takeaways from Fortinet’s 2023 OT Security Report.
- Learn more about how the Fortinet Security Fabric brings end-to-end security to organisations of all sizes to prevent ransomware across all points of entry.
- Learn about Fortinet’s free cybersecurity training, which includes broad cyber awareness and product training. As part of the Fortinet Training Advancement Agenda (TAA), the Fortinet Training Institute also provides training and certification through the Network Security Expert (NSE) Certification, Academic Partner, and Education Outreach
- Learn more about FortiGuard Labs threat intelligence and research and Outbreak Alerts, which provide timely steps to mitigate breaking cybersecurity attacks.
- Learn more about Fortinet’s FortiGuard Security Services portfolio.
- Read about how Fortinet customers are securing their organisations.
- Follow Fortinet on Twitter, LinkedIn, Facebook, and Instagram. Subscribe to Fortinet on our blog or YouTube.