The study, which involved companies from sectors such as energy, water, transportation, heavy industry, etc., reveals that 75% of the surveyed companies state that the vulnerability level of their OT infrastructures remains high.
This is partly due, according to those responsible for this research, to the fact that in many cases these types of infrastructures and industrial sector companies prioritize keeping their devices and machines operational over carrying out a «security» task that is almost never simple and where any «stoppage» can involve significant economic and production losses.
In this regard, as Mario García, director of Check Point for Spain and Portugal, has explained, many of these companies often work with proprietary systems that are extremely closed, have a great dependence on an external provider, and apply the classic «if it works, don't touch it» approach when faced with a possible service interruption that could be fatal.
This of course does not mean that these infrastructures are not exposed. Quite the opposite. As explained by the CCI, the implementation of IoT systems, not properly separating production systems from IT systems, or continuing to rely on obsolete computer infrastructure (Windows XP and even Windows NT) exposes these industries to all kinds of vulnerabilities. It is not surprising, in this sense, that relatively easy-to-prevent and avoid attacks such as ransomware or spear phishing find these industries to be easy systems to exploit.
The positive news, however, is that in recent years there has been an increased awareness of the importance of investing in security in this type of company. Thus, the report indicates that most of the companies that participated in this survey are beginning to consider, at least in their new projects, basic Industrial Cybersecurity requirements, with a special emphasis on compartmentalizing networks and a «layered» approach that implies that even if one part of the operation is compromised, the rest of the company can continue functioning with relative normality.
Additionally, they also show a greater willingness to identify possible future threats and agree (41%) that the main cyber threat they may face in the future will come from one that compromises the security of their IoT devices, with multi-vector attacks (21%) in second place and ransomware (20%) in third.




