{"id":51623,"date":"2022-09-28T08:54:37","date_gmt":"2022-09-28T00:54:37","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=51623"},"modified":"2022-09-28T08:54:40","modified_gmt":"2022-09-28T00:54:40","slug":"93-of-global-ot-organizations-94-in-ph-experienced-intrusion-in-past-12-months","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/09\/28\/93-of-global-ot-organizations-94-in-ph-experienced-intrusion-in-past-12-months\/","title":{"rendered":"93% of global OT organizations, 94% in PH, experienced intrusion\u00a0in past 12\u00a0months\u00a0"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">News Summary&nbsp;<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Fortinet, a global leader in broad, integrated, and automated cybersecurity solutions, today released its\u00a0global 2022 State of Operational Technology and Cybersecurity\u00a0Report. While industrial control environments continue to be a target for cyber criminals\u00a0with global: 93% (Philippines: 94%) of\u00a0<a rel=\"noreferrer noopener\" href=\"https:\/\/www.fortinet.com\/solutions\/industries\/scada-industrial-control-systems\/what-is-ot-security?utm_source=pr&amp;utm_campaign=what-is-ot\" target=\"_blank\">Operational Technology (OT)\u00a0<\/a>organizations experiencing an intrusion in the past 12 months \u2013 the report uncovered widespread gaps in industrial security and indicated opportunities for improvements. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key\u00a0findings of the report include:\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>OT activities lack centralized visibility, increasing security risks.\u00a0<\/strong>The Fortinet report found that only 13% of respondents have achieved centralized visibility of all OT activities. Additionally, only 52% of organizations are able to track all OT activities from the security operations center (SOC). At the same time, 97% of global organizations consider OT a moderate or significant factor\u00a0in their overall security risk. The report findings indicate that the lack of centralized visibility contributes to organizations\u2019 OT security risks and weakened security posture.\u00a0<\/li><li><strong>OT security intrusions significantly impact organizations\u2019 productivity and their bottom line.\u00a0<\/strong>The Fortinet report found that 93% (Philippines: 94%) of OT organizations experienced at least one intrusion in the past 12 months. The top\u00a03 types of intrusion Philippine organizations experienced were malware, phishing email, and hacker. As a result of these intrusions, nearly 50% (Philippines: 66%) of organizations suffered an operation outage that affected productivity with 90% of intrusions requiring hours or longer to restore service. In the Philippines, 85% of OT organizations took hours and more to return to service while 4% took weeks. Additionally, one-third of global respondents saw revenue, data loss, compliance and brand-value impacted because of security\u00a0intrusions.\u00a0<\/li><li><strong>Ownership of OT security is not consistent across organizations.\u00a0<\/strong>According to the Fortinet report, OT security management falls within a range of primarily director or manager roles, ranging from the Director of Plant Operations to Manager of Manufacturing Operations. Only 15% of global survey respondents say that the CISO holds the responsibility for OT security at their\u00a0organization.\u00a0In the Philippines, CEOs are getting more involved in influencing cyber security because it is becoming a bigger issue in management teams.\u00a0<\/li><li><strong>Organizations do not have full visibility into OT activities<\/strong>.\u00a0OT security gaps persist, with many organizations not having full visibility. The proportion of activities is centrally visible within the organization\u2019s cybersecurity operations.\u00a0In\u00a0the Philippines,\u00a0<strong>88%\u00a0<\/strong>of OT organizations that do not have complete central visibility.\u00a0<\/li><li><strong>OT security is gradually improving, but security gaps still exist in many organizations.\u00a0<\/strong>When asked about the maturity of their organization\u2019s OT security posture, only 21% of global surveyed organizations have reached level 4, which includes leveraging orchestration and management. Notably, a larger proportion of Latin America and APAC respondents have reached level 4 compared to other regions. The report found that a vast majority of\u00a0organizations use between two and eight different vendors for their industrial devices and\u00a0have between 100 and 10,000 devices in operation, adding\u00a0complexity.\u00a0<\/li><\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">OT Security is a Corporate-Level Concern&nbsp;<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">As\u00a0OT systems\u00a0increasingly become targets for cyber criminals, C-level leaders recognize the importance of securing these environments to mitigate risks to their organizations. Industrial systems have become a significant risk factor since these environments were traditionally air-gapped from IT and corporate networks, but now these two infrastructures are becoming universally integrated. With industrial systems now being connected to the internet and more accessible from anywhere, organizations\u2019 attack surface is increasing significantly.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the IT threat landscape becoming more sophisticated, connected OT systems have also become vulnerable to these growing threats. This combination of factors is moving industrial security upward in many organizations\u2019 risk portfolio. OT security is a growing concern for executive leaders, increasing the need for organizations to move toward full protection of their industrial control system (ICS) and supervisory control and data acquisition (SCADA) systems.&nbsp;<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Best Practices to Overcome OT Security Challenges&nbsp;<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Fortinet\u2019s global\u00a02022 State of Operational Technology and Cybersecurity\u00a0Report\u00a0indicated ways organizations can address OT systems\u2019 vulnerabilities and strengthen their overall security posture. Organizations can address their OT security challenges by:\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Establish Zero Trust Access to prevent breaches<\/strong>. With more industrial systems being connected to the network,\u00a0Zero Trust Access\u00a0solutions ensure that any user, device or applications without proper credentials and\u00a0permissions are denied access to critical assets. To advance OT security efforts, Zero Trust Access solutions can further defend against both internal and external\u00a0threats.\u00a0<\/li><li><strong>Implementing solutions that provide centralized visibility of OT activities<\/strong>. Centralized, end-to-end visibility of all OT activities is key to\u00a0ensuring\u00a0<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">organizations strengthen their security posture. According to Fortinet\u2019s&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.fortinet.com\/resources-campaign\/research-papers\/2022-the-state-of-operational-technology-and-cybersecurity\">report<\/a>, top-tier organizations \u2013 which make up the 6% of respondents who reported no intrusions in the past year \u2013 were more than three times as likely to have achieved centralized visibility than their counterparts who suffered intrusions.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Consolidating security tools and vendors to integrate across environments<\/strong>. To remove complexity and help achieve centralized visibility of\u00a0all devices, organizations should look to integrate their OT and IT technology across a smaller number of vendors. By implementing\u00a0integrated security solutions, organizations can reduce their attack surface and improve their security\u00a0posture.\u00a0<\/li><li><strong>Deploying network access control (NAC) technology.\u00a0<\/strong>Organizations that avoided intrusions in the past year were more likely to have a\u00a0NAC\u00a0in place, ensuring that only authorized individuals can access specific systems critical for securing digital\u00a0assets.\u00a0<\/li><\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Securing OT Environments with the Fortinet Security Fabric&nbsp;<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">For more than a decade, Fortinet has\u00a0protected OT environments\u00a0in critical infrastructure sectors such as energy, defense, manufacturing, food, and transportation. By designing security into complex infrastructure via the Fortinet Security Fabric, organizations have an efficient, non-disruptive way to ensure that their OT environment is protected and compliant. With full integration and shared threat intelligence, industrial organizations gain fast, automated responses to attacks in any vector. Fortinet\u2019s Security Fabric covers the entire converged IT-OT network to close OT security gaps, deliver full visibility and provide simplified management.\u00a0<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">About the Fortinet OT and Cybersecurity Survey:&nbsp;<\/h1>\n\n\n\n<ul class=\"wp-block-list\"><li>This year\u2019s State of Operational Technology and Cybersecurity Report is based on a survey of more than 500 global\u00a0OT\u00a0professionals conducted in March\u00a02022.\u00a0<\/li><li>The survey targeted people holding leadership positions responsible for OT\u00a0and OT security, from managers to C-level executives. Respondents represent a range of industries that are heavy users of OT, including manufacturing, transportation and logistics, and\u00a0healthcare.\u00a0<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Only 15% of global survey respondents say that the CISO holds the responsibility for OT security at their\u00a0organization.\u00a0In the Philippines, CEOs are getting more involved in influencing cyber security because it is becoming a bigger issue in management teams.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":51624,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[169,286,54,2103,96,2727,1656],"class_list":["post-51623","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-fortinet","tag-it-security","tag-security","tag-security-breach","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=51623"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51623\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/51624"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=51623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=51623"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=51623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}