New Claroty report focuses on challenges and priorities of federal OT cyber incidents
New data from industrial cybersecurity firm Claroty disclosed that 68 percent of federal OT (operational technology) administrators and managers reported experiencing an OT cyber-incident in the past year, while 90 percent of federal OT leaders say their agency has prioritized OT cybersecurity in the past two years. However, only approximately half felt confident they could detect or mitigate a threat today.
In a report titled ‘Guardians of Government: The State of Federal OT Security,’ MeriTalk, government IT’s top digital platform, and Claroty identify critical gaps and cite best practices for federal security professionals to enhance operational security. The report examines the state of federal OT security, identifies critical strategy gaps, and offers recommendations to strengthen resilience.
“We are seeing Federal civilian and DoD agencies that place a strategic emphasis on securing their diverse OT environments as among the most prepared to defend against threats to their operations,” Heather Young, regional vice president at Claroty, U.S. Federal, commented in a Tuesday media statement. “These agencies have prioritized collaboration between OT and IT security teams, they continually assess vulnerabilities, and they are standardizing risk models and upskilling teams to meet current and future threats. This is what is needed to increase resilience across the Federal government.”
The Claroty report identified that only 55 percent of federal OT leaders felt fully confident they could detect and mitigate a threat if it were to occur today and only 20 percent gave their agency an ‘A’ grade for cybersecurity preparedness. Gaps in network visibility, vulnerability/risk management, and secure remote access and monitoring were all identified as hindering OT security readiness. Additionally, 65 percent are concerned about the number of OT assets in their agency that have reached end-of-life but remain internet-facing.
One-third of respondents cited the complexity of OT environments (including geographic distribution) and the need to increase collaboration between OT and IT security teams as areas for improvement. To accelerate progress, OT leaders recommend standardizing risk models, enhancing visibility and access controls, and upskilling staff.
The report highlights that effective security measures rely on agencies that have integrated OT into their risk management framework, regularly assess vulnerabilities, and utilize updated methodologies for vulnerability awareness. To expedite advancements, OT leaders suggest standardizing risk models, improving visibility and access controls, and enhancing the skills of staff members.
Despite a mounting focus, federal OT leaders reveal a gap between their agency’s OT security prioritization and current preparedness levels. Two out of three (68 percent) say their agency experienced an OT-related cyber incident in the past year, only half feel confident they could detect and mitigate additional threats, and yet 69 percent still give themselves at least a ‘B’ grade when asked to rate the effectiveness of their current strategies, resources, and security measures.
When asked to examine their OT strategies, federal leaders report key security deficiencies in network OT behavioral or traffic visibility, vulnerability, and risk management, and secure remote access and monitoring. The number of legacy OT assets and segmentation issues are also of concern. Additionally, 65 percent are concerned about the number of OT assets in their agency that have reached end-of-life but remain internet-facing, and 39 percent identify that the majority of their OT environments are air-gapped (meaning they have no direct connection to the internet or other connected computers).
The report disclosed that OT leaders know identifying vulnerabilities is a vital step to preventing cyberattacks and disruptions to essential services. “One in four assess vulnerabilities continuously, while another 50% assess their systems at least quarterly. About half have now incorporated the more insightful Exploit Prediction Scoring System (EPSS) and Known Exploitable Vulnerabilities (KEV) while the majority still use the Common Vulnerability Scoring System (CVSS) either alone or alongside the others. More than half use the insights from their vulnerability processes and risk assessments to inform important investment decisions,” it added.
New data also showed that federal agencies are making steady investments across a range of OT security capabilities, with network protection and asset management leading the way. However, full implementation remains a work in progress, and one in four reports delaying the critical task of improving visibility. Also, when it comes to new OT security investments, 53 percent of OT leaders say their agency is very likely to consider cloud-based solutions.
As OT environments and traditional IT converge, two-thirds (62 percent) have combined OT and IT security teams. However, bridging the OT/IT gap remains an ongoing effort.
Going forward, federal OT leaders overwhelmingly recommend two areas of resource investments to accelerate progress: improvements in or adoption of best practices, most notably in the areas of improving visibility, access control, and network segmentation/isolation, and in up-leveling skills, training, and awareness. Leaders also recognize the critical role of embracing modern technology and the latest security innovations to optimize their OT security posture.
To address strategic gaps, agencies should establish comprehensive visibility into all OT assets and their communications. Implement continuous asset discovery and map these insights with asset, and asset communication patterns (devices, frequency, and protocols) to maintain real-time insight into anomalies, including misconfigurations, downtime, and cyber threats.
Furthermore, instead of trying to address every vulnerability, which is becoming increasingly frequent and numerous, security teams can prioritize their efforts – focusing on vulnerabilities most likely to be exploited and those actively being used in attacks, especially within their most critical and exposed assets.
An effective OT baseline can arm agencies with the right insight for detecting threats on an ongoing basis and mitigating them based on their OT environments. Implement security tools purposefully designed for OT to detect anomalies, exposed vulnerabilities, suspicious activity, and policy violations. Integrate these OT-specific capabilities into the agency’s centralized cybersecurity operations for unified visibility and response.
Strict role and policy-based access, multi-factor authentication, continuous monitoring of user activities and sessions (with the ability to immediately terminate sessions if needed), and full audit trails for session replays are essential. Given the diminishing effectiveness of perimeter defenses, the enforcement of rigorous access controls becomes even more critical, particularly for safeguarding internet-facing OT assets approaching end-of-life stages.
Effective network segmentation between IT and OT environments, as well as within OT networks based on risk profiles, is essential for limiting the damage of successful attacks, adversary reconnaissance, lateral movement, and persistence for later use. Agencies should develop and continually refine granular segmentation strategies aligned with their unique OT architectures and risk tolerances.
For those with an existing OT security strategy, agencies should test its efficacy against all stages of an OT attack. This can be done in cyber ranges and other testing mechanisms that go beyond tabletop exercises to include the assurance that compensating controls for unpatchable legacy systems are viable. Incorporate incident response plans for ongoing readiness and clarity of responsibilities.
Despite progress, achieving full alignment between IT and OT cybersecurity strategies and operations is an ongoing challenge for many agencies. Agency leaders should work with their CISOs to break down remaining silos between IT and OT functions through unified policies, shared tools and dashboards, joint incident response plans, and centralized reporting structures while maintaining sensitivity to the differences in mitigation and processes required between OT and IT.
Earlier this month, Claroty found that traditional vulnerability management approaches overlook 38 percent of the riskiest CPS assets. This gap poses a significant blind spot that could be exploited by threat actors. Claroty’s Team82 analyzed over 20 million OT, connected medical devices (IoMT), IT, and IoT assets, revealing that a substantial portion of the highest-risk OT and IoMT assets would be missed by conventional vulnerability management methods.