At the 9th annual Cyber Security Weekend – META conference held recently in Kuala Lumpur, Malaysia, Kaspersky presented an industrial cybersecurity review for the countries in the region and outlined the key cybersecurity challenges for industrial enterprises in the year ahead.
According to Kaspersky Security Network (KSN) statistics, in the second half of 2023, 32.6% of ICS computers globally had been attacked with malware. In the Middle East, Turkiye, and Africa (META) region the figure is 36.5% for Turkiye, 36.8% for Africa (27.5% in South Africa, 34.55% in Kenya, 28.8% in Nigeria, 33.17% in Ghana), and 33.5% for the Middle East region. There is a slight decrease in this figure in the region compared to 2022 which can be the result of industrial organisations paying more attention to cybersecurity.
African countries are undergoing rapid digitalisation and integration into the world’s economy, while at the same time facing a significant cybersecurity under-investment problem. In the second half of 2023, 7.55% of Operational Technology computers in Africa were exposed to threats via USBs (that is 20 times more than the figure of Western Europe); 7.2% faced threat by worms (that is 28 times more than in Australia & New Zealand); and 9.1% of OT computers were exposed to spyware (that is 7.7 times more than the figure for North America).
Kaspersky Industrial Control Systems Cyber Emergency Response Team (ICS CERT) predictions for 2024 highlight the persistence of ransomware threats, rise of cosmopolitical hacktivism, an outlook on the state of “offensive cybersecurity”, and transformative shifts in logistics and transport threats.
Looking back at 2023, Kaspersky predicted the industrial cybersecurity landscape continuing to evolve, with several key trends emerging. The pursuit of efficiency in IIoT and SmartXXX systems fueled an expanded attack surface, while the surge in energy carrier prices led to heightened hardware costs, prompting a strategic shift towards cloud services. The growing government involvement in industrial processes also introduced fresh risks, including concerns about data leaks due to underqualified employees and insufficient practices for responsible disclosure.
This retrospective analysis lays the groundwork for understanding the cybersecurity landscape faced by industrial enterprises in 2024, such as:
“The industrial sector’s cybersecurity is continuously going through significant changes, with both new types of attacks and more sophisticated versions of old ones. Ransomware attacks are still a big problem, and hackers are getting better at targeting large, profitable companies with more advanced methods. Hacktivists who are motivated by social issues are also becoming more active, adding another layer of complexity to the threats. The transportation and logistics industry is especially vulnerable to these changes because its systems are becoming more and more digital. This combination of cyber and traditional crime is a serious threat to global supply chains. To protect themselves, organisations need to prioritise cybersecurity and keep improving their defenses,” commented Evgeny Goncharov, head of Kaspersky ICS CERT.
KlearNow releases AI-powered post-entry audit built for CBSA CAD / D17-1-10 compliance. Live platform demo at ICPA Toronto, June 7–9
View Article
Identiv, Inc., a global leader in RFID- and BLE-enabled Internet of Things (IoT) solutions, today announced ID-Pixels™ 3.0, a family of next-generation Bluetooth Low Energy (BLE) inlays and labels.
View ArticleIndustry updates and weekly newsletter direct to your inbox!