ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Protecting the industrial and manufacturing sectors from cyber-risks

Doug McKee at Trellix Advanced Research Center outlines the vulnerabilities of industrial control systems and explores how their security can be strengthened

 

The industrial and manufacturing sectors are driving forces behind the global economy; they support and underpin the production of goods and services worldwide. Everything from food and clothing production to car and electronics manufacturing relies on stability and security.

 

With these sectors being so critical to daily life and operations, disruptions can trigger a significant shift in the way of life for many people.

 

It’s no surprise that threat actors have increased their activity and operations within the space. Whether they are subject to ransomware initiatives extorting money or operation disruptions through destructive means, industrial and manufacturing organisations are increasingly under fire.

 

This exposure becomes exacerbated when factoring in the amount of bespoke and customised devices that are vital to functionality within plant operations. Systems such as Supervisory Control and Data Acquisition (SCADA) and Information Control Systems (ICS) require specific focus and assessments when visualising the cyber-security landscape. They can pose unique vulnerabilities that could result in exposure.

 

Small gaps with significant impact

Exploitative attacks that target these vulnerabilities can have huge implications – such as the Khuzestan Steel Co. attack in June 2022. This initiative saw the Advanced Persistent Threat (APT) group Predatory Sparrow (also known as Gonjeshke Darande) compromising the hydrogen gas ICS within Khuzestan Steel Co. and two other manufacturers.

 

The attack triggered widespread fires causing significant structural integrity damage, crippling steel production within Iran and disrupting a number of other sectors within the country.

 

Another older instance of ICS compromise took place in 2014 when an unnamed German Steel Mill was compromised in a similar way. Despite the attacker or motive never being confirmed, the modus operandi was clear – they conducted an improper shutdown in gaining access to the ICS and control unit of a blast furnace. This rendered the blast furnace unstable, resulting in “massive damage” to the unit and the complex.

 

The issue arises when trying to protect these systems; ICSs typically are located within the facility to provide direct control over physical machinery. Compared to centralised desktop control software, that is very much front-and-centre, there can be challenges when updating ICS systems.

 

ICS units tend to be highly customised, third-party installations. Unlike desktop units, which typically use standard operating systems where security patches are free and can be carried out with a simple system reboot, ICS updates are more complex. Many require specialist teams, which results in additional time, costs, as well as system downtime to fix issues.

 

These challenges, coupled with the fact that attackers are becoming ever more sophisticated at exploiting simple – and sometimes unintentionally overlooked – gaps in security, are putting ICSs at increased risk of attack.

 

Ever-looming threat of ransomware

Traditional cyber-attack strategies have also been utilised by threat actors to compromise operations. Recent findings from Trellix identified the manufacturing sector as the fourth most targeted for ransomware attacks within Q4 2022. Within this statistic, industrial goods and services comprised almost a third (32%) of sensitive data leaks that arose from ransomware extortion.

 

Furthermore, when looking at the activity of high-profile threat groups specifically, industrial goods and services were found to be a prime target for LockBit 3.0. The findings revealed that the prolific ransomware group focused approximately a third (29%) of its activity on this sector alone in Q4 2022 – signalling that ransomware continues to be an ever-present threat to the manufacturing industry.

 

The Colonial Pipeline attack in 2021 is a prominent example of crippling ransomware activity within the sector. Attributed to the DarkSide group, threat actors utilised a single compromised password to bypass the single-factor authentication of a legacy virtual private network (VPN). In gaining access to computerised equipment managing the pipeline, they were able to disrupt all operations and grind them to a halt.

 

Cases like this serve as a sobering reminder to ensure cyber-security risk is fully assessed for all IT and OT facets. Trellix research shows the most prominent type of vulnerability exploitation centres around authentication – or a lack of it – accounting for a third (34%) of CVEs.

 

Whether through tricking devices into displaying passwords in cleartext or gaining unauthenticated access via poorly implemented authentication, threat actors can move laterally throughout systems to execute commands at multiple levels.

 

Authentication is the first line of defence, and ensuring password and credential etiquette must be at the forefront of security practice. This can be as simple as avoiding using clear text storage, hard coding of credentials, and maintaining proper permissions for critical systems. Controls like multi-factor authentication are by no means a one-stop fix to all malicious attacks, but it may have made a difference in cases like Colonial Pipeline.

 

These attacks demonstrate how one weak link can break the whole chain. Therefore, it’s important to ensure organisations adopt a culture of vigilance when protecting against potential exploitation routes. A proactive and preventative approach to cyber-health is essential to avoid security compromises.

 

Active monitoring for active protection

The industrial and manufacturing sectors are unique when compared across economies. Ensuring full visibility over all IT and OT systems is important, and working with security operations teams and vendors to identify potential vulnerabilities is just as important.

 

Referring to OT guidance published by the National Cyber Security Centre (NCSC), as well as the US National Vulnerability Database (NVD) and Cyber-security and Infrastructure Security Agency’s (CISA) ICS Advisory can be excellent sources of information to map out industrial vulnerabilities.

 

Integrating facility management and monitoring tools with predictive software can automate the cyber-security ecosystem. By patching existing vulnerabilities and actively monitoring for potential new ones, existing systems can be updated and reinforced on an ongoing basis. This enables manufacturers to stay ahead of the game in combatting persistent and emerging threats, updating control systems for continuous protection.

 

Proper network segregation and monitoring works hand-in-hand with security teams to provide industrial and manufacturing companies protection from system compromises. While it may be easier to focus on traditional attack vectors such as OS and server compromise mitigation, the impact of overlooking SCADA and ICS can be significant.

 

Only by peering under the surface to find control systems that may not have been factored into organisational cyber-risk, can an organisation be fully secured.

 


 

Doug McKee is Principal Engineer and Director of Vulnerability Research for Trellix Advanced Research Center

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543