The Cybersecurity and Infrastructure Security Agency has released a fact sheet providing critical infrastructure asset owners and operators guidance on reducing cybersecurity risks amid increasing cyberattacks on industrial control systems of critical infrastructure entities.
While the threat comes from unsophisticated cyber actors, who use basic and elementary intrusion techniques, failing to address poor cyber hygiene and system vulnerabilities could lead to significant consequences such as defacement, configuration changes, operational disruptions and physical damage, CISA said Tuesday.
Defending Against OT Cyber Threats
Authored by CISA, the FBI, the Environmental Protection Agency and the Department of Energy, the fact sheet urged critical infrastructure owners and operators to implement recommended mitigations, including removing operational technology, or OT, connections to the public internet; changing default passwords to strong, unique ones; and securing remote access to OT networks.
The authoring organizations advised critical infrastructure organizations to work with their third-party managed service providers, system integrators and system manufacturers who could provide system-specific configuration guidance for securing OT.