Several of the UK 's critical infrastructures are at risk of cyber-attack because they failed to take into account vulnerabilities created by the completion of the integration of industrial control and corporate IT systems , according to KPMG .
The global consultancy sought the opinion of 300+ experts in IT , engineering , and the utilities, energy, transportation, manufacturing, and construction industries
The vast majority (80%) said they have already or are planning to merge IT systems. Although 83% are aware that they are more likely to be targeted as a whole, 60% say this parameter did not contribute to their decision.
About half said their company does not invest much in cybersecurity, even though theoretically attacks on critical infrastructure are not uncommon.
In a Trend Micro report on attacks in 25 Organization of American States countries earlier this year, more than half (53%) of security executives surveyed said CNI attacks had increased compared to the previous year.
Over three-quarters (76%) also said the attacks had become more sophisticated.
It should be noted that information theft attacks (60%) were the most common threat against industrial control systems (54%), although the latter were particularly vulnerable – often because remediation is difficult due to the mission criticality of their operations and the fact that many of them run outdated operating systems.
Roy MacNamara of KPMG's cybersecurity group recommends that before considering the possibility of consolidation, managers should conduct a full assessment of the risks lurking, select the controls that are "most appropriate for their environment and decide whether they can ignore them or not."
As a minimum, CNI companies should consider their network demarcation and separation between corporate and process control environments, remote access security, system hardening, mobile media controls, third-party security, and even logging and monitoring.
Finally, physical and procedural security should not be neglected. They are essential for protecting remote systems and ensuring secure operation.
