CEO Robert Lee warns less than 5% of global infrastructure invests in OT visibility, leaving critical systems vulnerable to advanced threats. (Getty Images)


February 01, 2024

The head of a cybersecurity company specializing in protecting industrial internet-connected systems, Robert Lee, has raised concerns about the insufficient investment by American providers of critical infrastructure services in protecting their operational technology (OT) systems. Lee, the CEO of Dragos Inc., highlighted during a recent webinar that while some companies have taken steps to enhance their cybersecurity, less than five percent of the world's infrastructure has invested in OT visibility.

Lee explained that the lack of investment in OT cybersecurity is rooted in the historical focus on enterprise IT networks by boards and CEOs. He noted that the unique nature of OT cybersecurity, with different communication protocols in factory and industrial networks, requires distinct solutions compared to traditional IT security.

One alarming revelation came from an electricity provider, indicating a significant disparity in spending on IT security ($100 million annually) versus OT security ($5 million annually). Lee emphasized the need to "turn on the lights in the house" to understand the vulnerabilities in the OT systems, which often go unnoticed.

A major concern raised by Lee is the potential proliferation of advanced attack frameworks like Pipedream. Discovered in 2022 and attributed to a foreign government, Pipedream is a highly scalable and reusable threat capable of manipulating programmable logic controllers (PLCs) and causing substantial damage to OT systems. Unlike traditional vulnerabilities, once deployed, Pipedream cannot be easily stopped or patched.

Lee warned of the increasing risk that such sophisticated capabilities could fall into the hands of threat actors with fewer resources than nation-states, posing a significant threat to critical infrastructure. He cited the example of Volt Typhoon, a China-based group discovered by Microsoft earlier in the year, targeting critical infrastructure organizations in Guam and the U.S. mainland.

Highlighting the evolving threat landscape, Lee emphasized the shift in OT networks from being customized to automated and commoditized. This makes them susceptible to attacks that can impact entire industrial sectors or geographic regions, underscoring the importance of preparedness and root cause analysis.

While there has been progress in raising awareness, particularly through government initiatives and collaboration with the private sector, Lee stressed the need for increased investment in identifying and responding to OT threats. He called for a collective effort involving asset owners, operators, and experts from the private sector and government to strengthen national and local security.

In a separate development, cybersecurity firm Kaspersky issued threat predictions for the industrial control and OT sectors in 2024. These predictions include the continued prominence of ransomware, targeted attacks on vehicles in the logistics and transport sector, the growth of politically motivated hacktivism, the widespread use of offensive cybersecurity for gathering threat intelligence, and the increased intertwining of cybercrime and traditional crime in logistics and transport due to rapid automation and digitization.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Trump Weighs Tariffs to Fight Digital Taxes on US Tech Firms

Former President Donald Trump is considering imposing tariffs on countries that tax American tech giants like Alphabet (Google) and Meta....

Elon Musk’s $44B Gamble on X May Finally Pay Off

When Elon Musk purchased Twitter in October 2022 for $44 billion, many saw it as a costly mistake. He immediately....

NASA Leadership Shake-Up Raises Doubts on Moon Mission Plans

NASA is facing a leadership shake-up as four senior officials linked to its Artemis moon program step down, raising concerns....

Elon Musk Unveils Grok 3, Claims It Outperforms ChatGPT & More

Elon Musk’s AI startup, xAI, has officially launched Grok 3, its latest artificial intelligence model, which he claims surpasses leading....

Google Canada Rejects Claims of Market Power Abuse

Google Canada has dismissed allegations of monopolistic practices in response to the Competition Bureau’s lawsuit over its advertising operations. The....

Google Expands AI Hub in Poland for Energy, Cybersecurity

Google is strengthening its presence in Poland by expanding its artificial intelligence (AI) initiatives in key sectors like energy and....

OpenAI Rejects Musk’s $97.4B Bid to Take Over the Company

OpenAI’s board has firmly declined a $97.4 billion buyout offer led by Elon Musk, reinforcing its stance that the company....

TikTok Returns to U.S. App Stores After Temporary Ban

Google and Apple have reinstated TikTok on their U.S. app stores following a brief removal, marking another twist in the....

NASA’s Stuck Astronauts Set to Return to Earth Sooner

Two NASA astronauts stranded aboard the International Space Station (ISS) for over eight months may finally return home sooner than....

Beats Powerbeats Pro 2 Launches with Heart-Rate Monitor

Apple’s Beats brand has unveiled the Powerbeats Pro 2, a long-awaited update to its popular fitness-focused earbuds. This new version....

Space Telescope Captures Stunning Ring of Light Around Galaxy

A newly spotted glowing ring in deep space has captivated astronomers worldwide. The Euclid space telescope, launched by the European....

Musk’s $97.4B Bid for OpenAI Sparks Fresh AI Battle

Elon Musk and his group have made a staggering $97.4 billion offer to take over OpenAI, reigniting tensions with CEO....