How to Defend Industrial Systems From Cyberthreats

TL;DR
Industrial security should prioritize adversary behavior, native system functionality, and operational risk instead of relying mainly on enterprise security practices or vulnerability lists. Defenders should validate vulnerability information, use MITRE ATT&CK for ICS to identify coverage gaps, protect engineering documents and safety systems, and apply lessons from incident response cases to select practical controls.
Transcript
Hello, everyone, and thanks for joining me today as we get a little bit of a sneak peek into my keynote this year at the RSA Conference. Um, what we're going through is the industrial cyber threat landscape. Now, specifically, we're looking at two thousand and nineteen review. And the reason for this, and really the whole point of the talk, is it's... Read More
Key Insights
- Industrial infrastructure includes far more than utilities and oil and gas. It also encompasses manufacturing, mining, shipping, rail, renewable energy, and the building automation systems supporting data centers, making industrial cybersecurity relevant to a broad range of companies.
- Industrial security requires a strategy designed for industrial missions, systems, threats, and risks. Copying an enterprise security program into an operational environment can be ineffective because industrial organizations prioritize safe, reliable operations and face distinct technical and operational conditions.
- Native system functionality can enable damaging attacks without vulnerabilities or exploits. An adversary who gains the ability to operate a circuit breaker may de-energize a substation through an intended control function, so defenders must examine behaviors and authorized capabilities as well as software flaws.
- Industrial vulnerability information requires careful validation before remediation decisions are made. Dragos found that 26 percent of industrial vulnerabilities published in 2019 contained errors involving CVSS scores, processes, hardware, software, or whether the reported issue worked at all.
- Threat visibility changes the apparent scale of industrial cyber risk. Industrial environments once seemed relatively quiet partly because defenders were not looking deeply inside their networks, but increased monitoring revealed more teams consistently and specifically targeting industrial control system environments.
- Eleven tracked threat teams were consistently and specifically targeting industrial control system environments. Dragos added two teams to the nine highlighted in the previous year, demonstrating why defenders need current intelligence about adversary behavior rather than assumptions based on historically limited reporting.
- MITRE ATT&CK for ICS provides a shared lexicon and knowledge base for adversary tactics, techniques, and procedures. Defenders can use the framework to assess threat coverage, identify security gaps, and move beyond a narrow focus on indicators, vulnerabilities, exploits, and malware.
- Safety systems and engineering information are high-consequence targets. Incident response work showed concern about adversaries modifying systems that protect people and aggressively studying infrastructure documents and diagrams, including regulatory information published on company websites and demonstrably used for targeting.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why is enterprise security insufficient for industrial systems?
Enterprise security practices cannot simply be copied into industrial environments because the two settings have different missions, threats, systems, and risks. Industrial organizations have invested heavily in safe and reliable operations, but their security programs also need an industrial-specific focus. Effective protection must reflect operational functions and consequences rather than assuming controls designed for ordinary enterprise networks will work unchanged.
Q: What industries are included in the industrial cyber landscape?
The industrial cyber landscape includes utilities and oil and gas, but it extends much further. It covers manufacturing, mining, shipping, rail, renewable energy, and many forms of automation. It also includes building automation systems inside the data centers that power cloud services. This broad scope means industrial cybersecurity concerns apply, in some form, to nearly every company.
Q: Why should industrial defenders focus on adversary behavior?
Industrial attackers may cause operational effects by using functionality already built into control systems, without requiring malware, an exploit, or a software vulnerability. For example, someone able to operate a circuit breaker could de-energize a substation through its native controls. Defenders therefore need to understand adversary behaviors, tactics, and intended outcomes alongside technical weaknesses and indicators.
Q: How reliable were industrial vulnerability reports in 2019?
Dragos found errors in 26 percent of the industrial vulnerabilities published in 2019. Problems included incorrect CVSS scores, incorrect processes, incorrectly identified hardware or software, and reported vulnerabilities that did not work at all. Poor validation and quality assurance can lead organizations to patch systems that introduce no actual risk, wasting limited defensive resources.
Q: How many threat teams targeted industrial control systems?
Dragos tracked 11 different teams or threats that were consistently and specifically targeting industrial control system environments. The previous year’s review had highlighted nine active threats, and two new ones were added in the 2019 review. The increase also reflects improved visibility into industrial environments, since limited monitoring had previously obscured the amount of hostile activity.
Q: What is MITRE ATT&CK for ICS used for?
MITRE ATT&CK for ICS gives defenders a shared lexicon and knowledge base for discussing adversary tactics, techniques, and procedures. It helps organizations move beyond indicators, vulnerabilities, exploits, and other narrow technical details. Security teams can map tracked threats to known behaviors, evaluate whether defenses provide adequate coverage, identify gaps, and guide industrial security investments.
Q: What dangerous industrial attack techniques deserve attention?
Safety system compromise is among the most dangerous concerns because modifying a safety system could hurt or kill people. Adversaries are also aggressively seeking engineering documents and infrastructure diagrams that help them understand potential targets. Some of this information is published on company websites because of regulatory requirements and has been demonstrably used by adversaries for targeting.
Q: How can organizations improve industrial cybersecurity programs?
Organizations can improve their programs by using industrial-specific strategies, validating vulnerability claims before patching, monitoring adversary behavior, and applying MITRE ATT&CK for ICS to find defensive gaps. They should also incorporate lessons from assessments and incident response cases, protect safety systems and engineering information, and select practical controls based on their own requirements and operational risks.
Summary & Key Takeaways
-
Industrial environments extend beyond utilities and oil and gas to manufacturing, mining, shipping, rail, renewable energy, data-center building automation, and other automated operations. Their missions, systems, threats, and risks differ from enterprise environments, so copying an enterprise security strategy into industrial networks does not adequately address their security requirements.
-
Vulnerabilities remain relevant, but adversaries can cause serious operational consequences by using legitimate system functions without exploiting software flaws. Dragos found errors in 26 percent of industrial vulnerabilities published in 2019, including incorrect CVSS scores, affected products, and claims about vulnerabilities that did not work, making careful validation essential.
-
Dragos tracked 11 teams consistently and specifically targeting industrial control system environments after adding two during the reviewed year. The presentation connects these threats with MITRE ATT&CK for ICS, incident response lessons, dangerous techniques, safety system compromise, exposed engineering information, and prescriptive controls that organizations can use to improve industrial defenses.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator