A New Wave of Cyber Attacks: Five Actions to Take Now

By Sonu Shankar – Industry Week
 
Originating in China, Russia and Iran, these new threats are stealthier and more sophisticated.
 
The National Security Administration and the FBI have recently raised alarms over the growing threat of destructive Chinese cyberattacks on American critical infrastructure. 
While manufacturers have certainly had their fair share of cyber threats over the years, most notably a recent surge in ransomeware attacks, these attacks use different tactics, ones that manufacturers may be unfamiliar with. 

According to a recent U.S. hearing on the issues, the People’s Republic of China (PRC) is now actively “pre-positioning” its attackers inside critical systems to carry out physically destructive attacks, in the event of a future conflict.

Cyber threat actors in China, such as “Volt Typhoon,” are more technically advanced and well-resourced than other cybercriminal or ransomware groups in operation today. They are able to evade existing defenses and sneak inside manufacturers’ networks without being detected, hide inside them for many years, and launch sudden attacks to cripple operational technology (OT) systems. 

China isn’t the only country doing this. Other foreign adversaries – particularly Russia and Iran – are developing similar capabilities that can be used across critical infrastructure sectors.
It is important for all companies to develop greater “cyber resilience” within their operational technology systems, to both prevent and recover from these attacks. Here are five steps toward doing so.

1. Maintain Accurate IoT/OT Asset Inventory

Sophisticated threat actors like Volt Typhoon move laterally across a network through a stealth tactic called “living off the land” (LOTL).

READ FULL ARTICLE

You cannot copy content of this page