With the increasing digitalization of industrial operations, the integration of Operational Technology (OT) and Industrial Control Systems (ICS) has become common practice. However, this convergence has also expanded the attack surface for cyber threats, making cybersecurity a critical priority for industrial facilities.

Emerging Risks in OT/ICS Environments

OT/ICS environments face a variety of cyber threats that can compromise the safety and continuity of industrial operations. Among the main risks recently identified are:

Ransomware Attacks

The significant increase in ransomware attacks on industrial organizations is alarming. According to Dragos' "Year in Review" report, published in February 2025, there was an 87% increase in ransomware attacks against industrial organizations compared to the previous year. These attacks often result in significant operational disruptions and substantial financial losses.

ICS-Specific Malware

The evolution of malware targeting ICS systems is a growing concern. The "FrostyGoop" malware, discovered by Dragos in July 2024, is a notable example. This malware exploits the Modbus TCP protocol, widely used in industrial environments, to disrupt critical operations. The attack on the Lviv district heating system in Ukraine in January 2024, attributed to FrostyGoop, left more than 600 residential buildings without heating for two days in sub-zero temperatures.

Vulnerabilities in ICS Products

The presence of critical vulnerabilities in ICS products from various vendors increases the risk of exploitation by malicious actors. In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued advisories about critical and high-risk vulnerabilities in industrial control products from manufacturers such as Schneider Electric, Rockwell Automation, B&R Industrial, and BD. These vulnerabilities include OS command injection, unsafe data deserialization, and the use of outdated cryptographic algorithms.

Protection Strategies for OT/ICS Environments

To mitigate the risks associated with OT/ICS environments, it is essential to implement robust protection strategies tailored to the specificities of these systems. Some recommended approaches include:

Network Segmentation

Implementing network segmentation between IT and OT environments is fundamental to limit the spread of threats. Creating security zones and using industrial firewalls help control traffic and prevent unauthorized access.

Vulnerability Management

Establishing a continuous vulnerability management program is crucial. This involves identifying, assessing, and remediating vulnerabilities in OT/ICS systems and devices. Regular application of patches and security updates, when possible, is a recommended practice.

Continuous Monitoring

Implementing continuous monitoring solutions allows for the early detection of suspicious or anomalous activities. Intrusion detection tools specific to OT environments can identify malicious behaviors and trigger rapid responses to mitigate potential impacts.

Training and Awareness

Training employees and operators on cybersecurity practices is essential. Regular training programs help create a security culture, reducing the risk of human errors that could compromise system security.

Real Case: Attack on Littleton Electric Light & Water Department

A concrete example of the risks faced by industrial facilities is the attack on the Littleton Electric Light & Water Department (LELWD), a public power utility in the U.S. In November 2023, it was discovered that the advanced persistent threat (APT) group known as VOLTZITE had maintained persistent access to LELWD's network since February 2023, totaling over 300 days of compromise. During this period, the attackers collected data on OT systems, although no sensitive customer data exfiltration was identified. This incident highlights the need for continuous vigilance and proactive defense strategies in OT/ICS environments.

Conclusion

Cybersecurity in OT/ICS environments is a complex challenge that requires a multifaceted approach. Implementing appropriate protection measures, combined with continuous awareness and training, is essential to ensure the resilience of industrial operations against emerging cyber threats. Companies like Dbaseline are prepared to assist organizations in evaluating and strengthening their cybersecurity strategies, ensuring the protection of critical infrastructures and business continuity.