January 3, 2024
November 12, 2024
 —  
Blog

Creating a Defensible Architecture: Analyzing the SANS 2024 ICS State of ICS/OT Cybersecurity Report and the Five Critical ICS Controls

Creating a Defensible Architecture: Analyzing the SANS 2024 ICS State of ICS/OT Cybersecurity Report and the Five Critical ICS Controls

October was so busy with events that I never got to share my thoughts after reading the SANS 2024 State of ICS/OC Cybersecurity Report. I will have a few blogs on the topic, but I wanted to start with one of the foundational components of their report. SANS has always been big on the Five Critical Controls as a basis for creating an OT cybersecurity strategy, and they begin the report with a survey on the priority of the five controls for ICS/OT networks. 

The results:

Key Takeaways from the SANS 2024 ICS Cybersecurity Report

This indicates that a proactive stance on OT/ICS cybersecurity is important: Don’t just monitor what is happening; instead, strive to protect your network. Over 63% of the survey respondents indicated that deploying a defensible architecture was the #1 or #2 priority for their budget over the next year. 

But what exactly does that translate to for OT/ICS projects? The 2024 results are enlightening, especially when compared to the 2023 results. The results show a definitive acknowledgment that the OT perimeter needs to be a key focus, as the monitoring deployed in 2023 is not preventing attacks. In 2023, there were no mentions of perimeter security in the projects, in 2024, it was the #1 priority of over 55% of respondents and in the top 3 for almost 95% of OT teams.

2024 Top Architecture Priority Results:

2023 Top Initiative Results:

Proactive OT/ICS Security: Moving Beyond Monitoring

I hope OT/ICS CIOs and CISOs recognize the importance of proactively protecting their networks. A defensible architecture is the path forward in an AI-powered cyber security attack environment, and BlastWave will be a critical part of this solution.

I will be doing a much deeper dive on the Five Critical ICS Controls over the next few months, not only as BlastWave but also with our partners that solve some of the other ICS controls issues (like monitoring) to create a comprehensive OT/ICS Cybersecurity Protection solution.

Interested in a demo of BlastWave and how to secure your OT network in less than 30 days? Check us out at https://www.blastwave.com/schedule-a-demo

OT Secure Remote Access
Network Cloaking
Network Segmentation

Experience the simplicity of BlastShield to secure your OT network and legacy infrastructure.

Schedule a Demo