CEO Robert Lee warns less than 5% of global infrastructure invests in OT visibility, leaving critical systems vulnerable to advanced threats. (Getty Images)


February 01, 2024

The head of a cybersecurity company specializing in protecting industrial internet-connected systems, Robert Lee, has raised concerns about the insufficient investment by American providers of critical infrastructure services in protecting their operational technology (OT) systems. Lee, the CEO of Dragos Inc., highlighted during a recent webinar that while some companies have taken steps to enhance their cybersecurity, less than five percent of the world's infrastructure has invested in OT visibility.

Lee explained that the lack of investment in OT cybersecurity is rooted in the historical focus on enterprise IT networks by boards and CEOs. He noted that the unique nature of OT cybersecurity, with different communication protocols in factory and industrial networks, requires distinct solutions compared to traditional IT security.

One alarming revelation came from an electricity provider, indicating a significant disparity in spending on IT security ($100 million annually) versus OT security ($5 million annually). Lee emphasized the need to "turn on the lights in the house" to understand the vulnerabilities in the OT systems, which often go unnoticed.

A major concern raised by Lee is the potential proliferation of advanced attack frameworks like Pipedream. Discovered in 2022 and attributed to a foreign government, Pipedream is a highly scalable and reusable threat capable of manipulating programmable logic controllers (PLCs) and causing substantial damage to OT systems. Unlike traditional vulnerabilities, once deployed, Pipedream cannot be easily stopped or patched.

Lee warned of the increasing risk that such sophisticated capabilities could fall into the hands of threat actors with fewer resources than nation-states, posing a significant threat to critical infrastructure. He cited the example of Volt Typhoon, a China-based group discovered by Microsoft earlier in the year, targeting critical infrastructure organizations in Guam and the U.S. mainland.

Highlighting the evolving threat landscape, Lee emphasized the shift in OT networks from being customized to automated and commoditized. This makes them susceptible to attacks that can impact entire industrial sectors or geographic regions, underscoring the importance of preparedness and root cause analysis.

While there has been progress in raising awareness, particularly through government initiatives and collaboration with the private sector, Lee stressed the need for increased investment in identifying and responding to OT threats. He called for a collective effort involving asset owners, operators, and experts from the private sector and government to strengthen national and local security.

In a separate development, cybersecurity firm Kaspersky issued threat predictions for the industrial control and OT sectors in 2024. These predictions include the continued prominence of ransomware, targeted attacks on vehicles in the logistics and transport sector, the growth of politically motivated hacktivism, the widespread use of offensive cybersecurity for gathering threat intelligence, and the increased intertwining of cybercrime and traditional crime in logistics and transport due to rapid automation and digitization.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

US Senators Question AI Chat Apps Over Kids’ Safety

Two U.S. senators are asking tough questions about the safety of AI chatbot apps that let users build custom virtual....

Amazon’s last-minute bid for TikTok as U.S. ban nears

Amazon has made a last-minute offer to acquire TikTok as a U.S. ban on the popular video-sharing app is set....

TikTok’s Fate in the US: Time Running Out for a Deal

TikTok users in the United States are once again on edge as the clock ticks down on a potential ban.....

Bitcoin Investor Buys an Entire SpaceX Flight for the Ultimate Polar Adventure

A bold new chapter in space tourism unfolded as Chun Wang, a Bitcoin investor and entrepreneur, launched into orbit on....

Elon Musk’s xAI Acquires X in $33 Billion Stock Deal

Elon Musk’s artificial intelligence startup, xAI, has officially taken over his social media platform, X, in a deal valued at....

Trump Considers Lowering Tariffs to Seal TikTok Deal

Former U.S. President Donald Trump signalled on Wednesday that he might reduce tariffs on China to facilitate the sale of....

U.S. Robotics Firms Urge National Strategy to Compete China

American robotics companies are calling for a national U.S. robotics strategy to strengthen the industry and maintain a competitive edge....

Waymo Plans Self-Driving Taxi Service in Washington by 2026

Alphabet’s autonomous taxi service, Waymo, is expanding to Washington, D.C., with plans to launch in 2026. The announcement, made on....

Trump Aides Used Signal for Secret War Talks – What to Know

Top officials from the Trump administration reportedly used the encrypted messaging app Signal to discuss military plans, sparking concerns over....

PsiQuantum Secures $750M to Advance Quantum Computing

According to sources, Quantum computing startup PsiQuantum is securing at least $750 million in funding, pushing its valuation to $6....

Are We Ready to Mine Metals from Space? The Future of Asteroid Mining

Asteroid Mining: A Sci-Fi Dream or an Inevitable Future? For decades, space enthusiasts and scientists have imagined a future where....

Nvidia CEO Surprised By Public Quantum Computing Companies

Nvidia CEO Jensen Huang admitted he was unaware that publicly traded quantum computing firms existed when he previously commented on....