Outdated and unsupported legacy operational technologies (OT) are exposing substantial vulnerabilities for manufacturers facing escalating threats from nation-state attacks, according to new research from BlackBerry Limited.
“Global manufacturers are headed for stormy waters as nation states up the ante on surveillance and the risk of a cyber incident is high – and rising – yet the industry is hampered by a threat surface that is largely antiquated and difficult to defend. Over the last year, three cybersecurity trends significantly impacted OT and IoT infrastructure: ransomware attacks, phishing attacks, and third-party software vulnerabilities,” says Shishir Singh, chief technology officer, cybersecurity at BlackBerry.
“Cybersecurity has become a significant barrier to progress, and managers shackled by aging hardware and outdated operating systems are challenged to unify security across old and new to forge ahead with modernization. With aged and isolated equipment, the truth is that it is difficult to put protection into these environments. But not impossible, and with a lightweight footprint and OS agnostic solution, protection can be extended to every eligible endpoint to mitigate this exposure across manufacturing infrastructure,” Singh adds.
- While many (41%) anticipate an elevated risk of cyberattack in 2023, three-quarters of respondents (75%) fear nation-state attacks on the sector and 65% are concerned about foreign governments spying on their facilities. At the same time, 68% say OT infrastructure is difficult to defend and 86% admit to running core functions on outdated and unsupported legacy operating systems.
Manufacturing IT decision-makers are predominantly concerned with malicious malware attacks (56%), followed by phishing attacks (49%) and unauthorized access by non-malicious insiders (45%).
- Research also showed that 65% of manufacturing IT decision-makers believe the cost of a cyber breach to be $250,000 or less. Almost half (47%) of respondents estimate that business downtime would account for just one-tenth of that cost, while 63% point to cyber incidents resulting in a loss of customers or impacting supplier relationships (59%). With unplanned downtime costs soaring due to global inflation and production lines running at a higher capacity, this contrasts with a recent report estimating the true average cost of a data breach in the industrial sector to be more than 16 times higher at $4.24 million.