How Could Criminals Ransom Industrial Control?

240 views
β€’
June 10, 2024
by
RSAC Cybersecurity
YouTube video player
How Could Criminals Ransom Industrial Control?

TL;DR

Cybercriminals primarily disrupt operational technology by attacking enterprise IT, with operational shutdowns occurring as a secondary effect. Direct OT extortion remains unattractive because established ransomware methods, particularly data theft and encryption, do not translate cleanly to physical processes, but a workable method for holding an industrial facility hostage could change attackers’ return on investment.

Transcript

Ah, there we go. Awesome. Uh, and obviously, yeah, thank you so much to RSA for the opportunity and privilege. Um, my name is, is Rick Derbyshire. I'm a senior security researcher at Orange Cyberdefense. And I'm, uh, Charl van der Walt. I'm a head for security research at Orange Cyberdefense. You can tell that, uh, Rick and I work for the same comp... Read More

Key Insights

  • Recent OT-related incidents are predominantly criminal attacks against enterprise IT, with operational disruption appearing as a secondary consequence rather than the result of attackers directly compromising industrial controls.
  • The thirty-five-year incident study examines publicly reported cases by actor, tools and techniques, and how far attackers progressed through the Purdue Model, revealing changes in both attack volume and criminal behavior.
  • Incident volume increased sharply between 2020 and the time of the presentation, while criminals became more prominent than in earlier periods that included substantial state and hacktivist activity.
  • Routine activity theory states that crime becomes likely when a motivated offender, a suitable victim, and the absence of a capable guardian converge in the same setting.
  • Industrial organizations are suitable targets because they possess valuable assets, are visible and available to attackers, and may be vulnerable, while manufacturing represents twenty-five percent of victims in the presenters’ other datasets.
  • Direct OT attacks offer an unfavorable return on investment because criminals would need to acquire specialized technical skills and capabilities while existing IT-focused extortion continues producing substantial returns.
  • Cyber extortion succeeds by taking something valuable from a victim, presenting a clear and present threat, demanding payment, and then returning the withheld asset or capability after payment.
  • OT ransomware requires a different extortion mechanism because data exfiltration and encryption do not translate cleanly to cyber-physical operations, making traditional IT ransomware methods poorly suited to directly holding industrial processes hostage.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why do ransomware attacks disrupt operational technology?

Ransomware attacks often disrupt operational technology indirectly by compromising the enterprise IT systems of industrial organizations. The resulting business interruption can force operations to stop even when attackers have not reached industrial controllers or lower levels of the Purdue Model. The presenters describe incidents involving factories and pipeline operations as examples of IT attacks producing secondary consequences for physical operations.

Q: Why do criminals usually attack industrial IT instead of OT?

Criminals usually target industrial IT because existing ransomware and cyber extortion methods already deliver a strong return on investment. Directly attacking operational technology would require additional skills, tools, and capabilities. Furthermore, common extortion actions such as stealing data and encrypting systems are not easily transferred to physical processes, so criminals lack an equally effective and established OT business model.

Q: What is routine activity theory in OT cybersecurity?

Routine activity theory is a criminology framework stating that crime is likely when three conditions converge: a motivated offender, a suitable victim, and the absence of a capable guardian. Applied to operational technology, industrial organizations may already be visible, valuable, and vulnerable targets with limited technical guardianship. The remaining question is whether criminals have enough financial motivation to attack OT directly.

Q: What makes an industrial organization a suitable cybercrime target?

An industrial organization can be a suitable target because it has valuable assets, is visible and available to attackers, and may contain vulnerable systems. The presenters also state that manufacturing businesses constitute twenty-five percent of victims in their other datasets and have maintained that share for the last five years, demonstrating that criminals already select these organizations for IT-focused attacks.

Q: How has the pattern of OT cyber incidents changed since 2020?

The presenters’ analysis shows that the volume of publicly reported incidents affecting operational technology increased sharply between 2020 and the time of the presentation. The dominant actor also changed, with criminals becoming especially prominent alongside continuing state and hacktivist activity. These criminals mainly used IT tools and techniques and generally reached higher, IT-oriented levels of the Purdue Model.

Q: What makes cyber extortion financially effective?

Cyber extortion is financially effective because an attacker can take something valuable from a victim, hold it hostage, present a clear and immediate threat, demand payment, and potentially return what was withheld. The presenters argue that this criminal business model, rather than ransomware software itself, drives profitability. Its success explains why criminals continue favoring proven IT attacks over specialized OT operations.

Q: Why does conventional ransomware not translate directly to OT?

Conventional ransomware depends heavily on data exfiltration and encryption, but those actions do not translate cleanly to operational technology and physical processes. OT environments therefore do not offer criminals the same straightforward method for taking an asset, withholding it, and returning it after payment. A viable direct OT extortion model must create a credible, controllable, and potentially reversible threat to operations.

Q: What is the Dead Man’s PLC concept intended to demonstrate?

Dead Man’s PLC is presented as a novel conceptual technique for holding an entire operational or industrial facility to ransom. Its purpose is to explore how the essential mechanics of cyber extortion might be translated into operational technology despite the limitations of data theft and encryption. The practical model is also intended to help defenders anticipate and counter a possible future OT threat.

Summary & Key Takeaways

  • The presenters examine publicly reported cyber incidents affecting operational technology across thirty-five years. Their analysis indicates that incident volume rose sharply from 2020 onward, while the dominant actor shifted toward criminals using familiar IT tools and techniques. These attackers generally reached only higher, IT-oriented levels of the Purdue Model.

  • Routine activity theory provides a framework for explaining criminal behavior through three converging conditions: a motivated offender, a suitable target, and an absence of capable guardians. Industrial organizations appear visible and vulnerable, while their technical protections may be immature. The missing condition for direct OT attacks is sufficient criminal motivation.

  • Criminal motivation depends heavily on return on investment. Conventional cyber extortion is already profitable, while directly attacking OT would require new skills and capabilities. Because physical operations do not accommodate data exfiltration and encryption like IT systems do, criminals need a different mechanism for creating a reversible and credible threat against industrial facilities.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š