Site navigation

Kaspersky Report: Never Rule Out the Human Factor

Elizabeth Greenberg

,

human factor
Kaspersky’s new report reveals the plethora of vulnerabilities in OT networks Advances Persistent Threat (APT) groups can take advantage of.

Kaspersky‘s new report into the success of APT groups’ cyber attacks reveals the growing trend in cybersecurity coverage: the human factor can lead to the greatest vulnerabilities.

In a phenomenon Kaspersky deemed ‘Schrodinger’s virus’, many security systems appear to be mere phantoms – there in theory, but not effective in practice.

This is down to several key factors, chiefly because the people in charge of security rarely access the security systems at all.

The vital systems put in place to mitigate cyber incidents lack essential maintenance, such as updates and licensing keys. Further, users simply disable the security solution, or that solution does not scan or protect the total system.

APT attacks are a growing threat because actors are invested in evading detection; if security systems are outdated and leave certain services – like cloud, files, and URLs – out of their scanning, malware can run rampant.

Kaspersky has also seen improper configurations of security solutions, where users do not enable certain features, like requiring administrator details to disable protections, allowing cybercriminals do it themselves with little roadblocks.

Of equal importance, protection is not always installed on all endpoints of an Operational Technology (OT) network. This can be for several reasons, such as vendors requiring only their software is installed on an Industrial Control System (ICS) network, which can cancel the warranty of other systems.

The main issue stems from engineers thinking their ICS are completely isolated from the other network branches, but even when this is true, attackers have ways of getting around this.

OT Network Issues

The report delved into issues surrounding OT network isolation, such as the improper isolation of these systems. They can be connected to Information Technology (IT) and ICS networks or computers connected to different networks at different times.

Essentially, endpoints of different IoT devices are not secured, and the internal systems – be they OT, IT, or ICS – are therefore left vulnerable due to their connection.

Further, intermixing the uses of these networks can leave them vulnerable – Kaspersky noted an incident where an engineer used the same device for social networking as well as editing a PLC project. This machine, once infected, allows attackers to access devices on the OT network.

As well, vital security measures are often not taken when granting access to OT networks for employees or vendors. Often, this access is provided by remote administration utilities – while designed to be allowed on a temporary basis, these access portals were permanently operational, leaving easy access for attackers.

Even disgruntled employees could take advantage of these remote access provided years ago if these are not taken down.

The design of the networking equipment can also leave it in jeopardy, as many engineers opt for simplistic, ‘flat networks’ which have no firewalls or demilitarised zones to protect data, allowing attackers to easily move along the network after one successful penetration.


Recommended


Outdated Systems

While outside of the general human error, many cyber incidents Kaspersky investigated were routed in outdated operating systems, firmware, and software.

These are often caused by an inability to install updates due to the need to upgrade equipment to access the latest software, and the careful testing these updates require.

Though not directly related to the concept of human error, it does bring into question how the selection process of software and hardware can hold security systems back.

Tech debt is a concept often used to refer to the backlog of old hardware and software that is incompatible with other systems, or becomes obsolete quickly due to new innovations. Selecting software plans that are incompatible with other vendors, including other security vendors, can leave certain networks vulnerable to attack. Opting for security systems that cannot be applied to all devices or systems in a network can also leave the overall operation in jeopardy.

Not fully understanding the limitations of inner-workings of a system can make mitigation techniques useless as well – a simple update of a system cannot fix a major design flaw.

Concerningly, Kaspersky says that third party technologies in ICS have vulnerabilities in their components that can remain under the radar of OT manufacturers, and vendors, who shirk responsibility onto buyers.

Understanding all the risk factors, from human error to inherent software issues, is vital in mitigating risks, according to Kaspersky.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data