Cyber intrusions into Australian Critical Infrastructure systems are happening with increased frequency. For many Operational Technology (OT) networks it’s not a matter if an intrusion will take place, but when. The Australian Signals Directorate’s (ASD) ‘Cyber Threat Report 2022-2023’ report highlighted the growing vulnerability of Australia’s critical infrastructure to cyber threats. During the 2022 – 2023 reporting period the ASD responded to 143 incidents reported by critical infrastructure entities, an increase from the 95 incidents reported during the 2021–2022 reporting period. 

The attack surface for operational technology (OT) networks is increasing due to the continued convergence between IT and OT networks. This convergence is driven by the desire of entities to reduce expenses, simplify operations and support Industrial Internet of Things (IIOT). Of course, this network convergence bridges the “air gap” that once separated these two environments, providing a pathway for malicious actors to gain access to industrial control systems. 

The ASD Information Security Manual (ISM), along with the Essential Eight strategies provide a framework for securing IT/OT systems against cyber threats. Here we take a brief look at three specific measures that, when implemented, will reduce the attack surface of these networks. 

1. Patching applications and operating systems.

Malicious cyber actors often exploit security weaknesses found in ICT, known as common vulnerabilities and exposures (CVEs), to break into systems, steal data, or even take complete control over a system. There are documented instances of malicious actors exploiting unpatched systems with a seven-year-old CVE. CVEs do not have a shelf life so you would be wrong to think that malicious actors are not continuously scanning for hosts with unpatched vulnerabilities.

The ASD recommends that “all entities patch, update or otherwise mitigate vulnerabilities in online services and internet-facing devices within 48 hours when vulnerabilities are assessed as critical by vendors or when working exploits exist. Otherwise, vulnerabilities should be patched, updated or otherwise mitigated within 2 weeks. Entities with limited cyber security expertise who are unable to patch rapidly should consider using a reputable cloud service provider or managed service provider that can help ensure timely patching.”

2. Network segmentation and segregation.

These are highly effective strategies to limit the impact of a network intrusion by malicious actors limiting their potential for lateral movement after an initial breach. This is achieved by segmenting and segregating each host and network at the lowest manageable level. Host-based and network-wide measures should complement each other and be centrally monitored, as firewalls alone are insufficient. In addition, employ the principles of least privilege, restricting communication to only necessary connections by creating zones to separate hosts and networks based on their sensitivity or criticality. Finally consider implementing a whitelist approach for network traffic, allowing access for only known good network traffic rather than blocking known bad network traffic.

3. Application control or whitelisting.

Application control or whitelisting can identify and block attempts to execute malware introduced by adversaries. The static nature of certain systems, like database servers and human-machine interface (HMI) computers, makes them particularly well-suited for implementing application whitelisting.

In conclusion, the convergence of IT and OT networks is increasing the attack surface used by malicious actors to exploit the networks of critical infrastructure operators. The adoption of best practices as outlined in the ASD ISM or other similar frameworks is essential to mitigate these risks.

Get in Touch

If you would like to discuss any of the topics in this article with one of our security consultants at AltTab please contact us on 1300252822 or via email at [email protected].

Back to insights