Rising threats to industrial systems and IoT
According to ENISA, cyberattacks on operational technology (OT) and industrial control systems (ICS), including SCADA, increased by 30% in 2024. The convergence of IT and OT creates new attack vectors, requiring comprehensive security strategies for critical infrastructure facilities.
Key vulnerabilities stem from legacy equipment, insufficient network segmentation, weak access management, and flaws in communication protocols. There is a growing risk of targeted attacks aimed at the physical destruction of systems in energy, transport, and water supply sectors.
Regulatory requirements and security standards
The implementation of the European NIS2 directive tightens cybersecurity requirements for critical infrastructure operators, mandating security management systems aligned with ISO/IEC 27001. Ukraine is also strengthening requirements for establishing comprehensive information security systems (KSZI) for state and strategic facilities.
Technological solutions for infrastructure protection
Members of the Intecracy Group consortium offer joint solutions to protect IoT and SCADA systems:
- Softline and IQusion provide design and implementation of KSZI for the public sector and strategic enterprises.
- SL Global Service delivers cloud cybersecurity solutions, including identity and access management (IAM), security information and event management (SIEM), and data loss prevention (DLP).
- AZIOT provides security at the IoT platform level, integrating devices and industrial protocols (MQTT, Modbus, BACnet).
Strategic approaches to security
Effective protection of industrial systems requires a multi-layered approach: implementing the Zero Trust concept, network microsegmentation, leveraging artificial intelligence for anomaly detection, and establishing security operations centers (SOC) for continuous incident monitoring.
Impact on the industry
For critical infrastructure operators and the tech sector, these rising threats and stricter regulations mean that cybersecurity is now a critical business continuity factor. Failure to secure OT/ICS systems can lead to physical destruction of assets, prolonged operational downtime, and severe legal and financial penalties under NIS2 and KSZI frameworks.
Recommendations
To protect industrial systems and ensure regulatory compliance, organizations should take the following practical steps:
- Implement Zero Trust: Adopt network microsegmentation to isolate legacy OT equipment and prevent lateral movement of threats.
- Deploy robust monitoring: Establish Security Operations Centers (SOC) and use AI-driven anomaly detection to identify threats in real time.
- Achieve compliance: Design and implement comprehensive information security systems (KSZI) and align security management with ISO/IEC 27001.
- Secure IoT and access: Integrate secure communication protocols (MQTT, Modbus) and deploy IAM, SIEM, and DLP solutions.
Prepared by a Software Ukraine member. Original publication.