Saturday, June 25 2022

A report on critical infrastructure in the UK reveals a disparity between perceived threats to critical infrastructure security and the reality of cyber risks.

Bridewell Consulting engaged market research firm Censuswide to survey 250 security leaders across critical infrastructure sectors, referred to in the UK as critical national infrastructure. The survey examined the aviation, chemicals, energy, transport and water sectors.

The study sheds light on the widespread use of older systems lacking security support, which allow attackers to access and manipulate operational technology systems. The majority of organizations surveyed said they rely on aging systems; 79% of the organizations reported systems that were over five years old, and 34% over ten years old.

The survey results point to environments that are often reliant on Internet-connected technologies in critical industrial operations, with 84% of the environments reported as accessible from corporate networks and 58% accessible from the Internet. The report emphasizes that defined layers of network segregation are critical in minimizing an attacker’s movement within a network.

The participating organizations demonstrated a willingness to take advantage of cloud advantages such as reductions in operational expenses, greater scalability, and potentially improved physical resilience; 98% of the organizations surveyed have either migrated elements of their operational technology environments to the cloud or are planning to do so. Misconfigured cloud systems are among the largest attack vectors, as a study of third-party cloud services recently demonstrated.

In addition to the risks posed by an aging yet increasingly connected infrastructure and the potential for human error, decision-makers have also identified these threats to be among the most dangerous to their critical infrastructure organization: cyber attacks (39%), malware (34%), and physical security risks (28%).

Only 20% of respondents selected attacks from nation-states as a major risk, and only 18% chose threats from third-party suppliers, which could indicate some complacency around supply chain risks despite recognition by the National Cyber Security Centre as an area of vulnerability.

The researchers urge decision-makers to qualify and quantify all supply chain risks and threats before undertaking adaptive risk management procedures, as the consequences of successful cyberattacks can include financial penalties, downtime, dismissal of employees, reputational damage, and loss of revenue.

Previous

Supreme Court Limits Scope of Federal Anti-Hacking Law

Next

Cybersecurity M&A and Funding Update: June 11

Check Also

Widget

Don’t Miss

Firmware Supply Chain Company Binarly Raises $3.6 Million

SecureDisruptions

Binarly Inc., a cybersecurity company building technology to address repeatable security failures in the firmware supply chain, today announced $3.6 million in seed funding from WestWave Capital and Acrobator Ventures. Prominent cybersecurity leaders Michael Sutton, Thomas ‘Halvar Flake’ Dullien, Jamie Butler, Ryan Permeh, Bryson Bort, Pedram Amini, Chris Ueland and David Mandel from Emerging Ventures […]

Allied Universal Acquires Three Companies

SecureDisruptions

Allied Universal®, the leading security and facility services company, is continuing its global expansion with the acquisition of three companies located in New York, the Netherlands and Denmark. The largest of the three companies, International Protective Service Agency, is headquartered in New York, NY, and provides comprehensive security and event services for clients located throughout New York and New Jersey. IPSA founder and owner Jerry […]

SEMPRE.ai ACQUIRES NEWSPACE NETWORKS

SecureDisruptions

SEMPRE.ai, the technology company created to secure America’s critical infrastructure, announced the acquisition of NewSpace Networks to further safeguard and expand the availability of terrestrial, maritime, airborne and space-based wireless communications. Integration of the two companies’ technologies has been underway for more than a year, with the first commercial products having been tested domestically with the U.S. Department of […]

Quickpass Cybersecurity Secures $7M in Series A Funding Round

SecureDisruptions

Quickpass Cybersecurity, a leading provider of Privileged Access Management and Helpdesk Security Automation for MSPs (Managed Service Providers), announced a new $3 million round of financing in partnership with Arthur Ventures. This completes their Series A round of financing, totaling $7 million. This round of funding will enable Quickpass to accelerate the company’s efforts to […]

GreyNoise Raises $15 Million in Series A Funding

SecureDisruptions

GreyNoise Intelligence, the cyber security company analyzing internet scanning traffic to separate threats from background noise, today announced that it has raised a $15 Million round of Series A funding led by Radian Capital. With participation from CRV, Inner Loop, Stone Mill Ventures and Paladin Capital, this brings the total of funding raised to date to […]

Immuta Raises $100 Million in Series E Funding

SecureDisruptions

Immuta, the leader in data access and data security, today announced that it has secured $100 million in Series E funding. With this investment, Immuta will meet growing data security and privacy demands by accelerating secure data access across all cloud platforms. Only Immuta can automate access to data by discovering, securing, and monitoring data […]