{"id":18610,"date":"2025-07-17T09:59:18","date_gmt":"2025-07-17T13:59:18","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=18610"},"modified":"2025-07-28T17:03:55","modified_gmt":"2025-07-28T21:03:55","slug":"critical-infrastructure-protection-securing-essential-systems-against-cyber-threats","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/critical-infrastructure-protection-securing-essential-systems-against-cyber-threats\/","title":{"rendered":"Critical Infrastructure Protection: Securing Essential Systems Against Cyber Threats"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-from-cyber-attacks-on-emergency-call-centers-to-electric-and-telecom-network-infiltrations-here-s-what-to-know-about-the-threats-plaguing-critical-infrastructure-sectors-and-how-to-fight-back\">From cyber attacks on emergency call centers to electric and telecom network infiltrations, here\u2019s what to know about the threats plaguing critical infrastructure sectors and how to fight back<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cWe\u2019re sorry, the number you are calling is not available.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Service outages can bring emergency services like 911 to a standstill. While old tech is to blame in some cases, data from Carbyne and NENA\u2019s (911 Association) <a href=\"https:\/\/carbyne.com\/the-pulse-of-9-1-1\/\">2025 survey report<\/a> indicates that telephony denial of service (TDoS) attacks and cyber attacks were to blame for one in 10 outages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly worrisome when you consider that NENA estimates that these centers handle the <a href=\"https:\/\/www.nena.org\/page\/911statistics\">240 million 911 calls made each year<\/a> (i.e., 457 calls per minute). But emergency services isn\u2019t the only <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\">critical infrastructure sector<\/a> that needs protection and is at risk due to modern cyber threats:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hackers recently opened the water closure system\u2019s valves to full capacity at the Lake Risevatnetdam facility in Norway. (<strong>Source:<\/strong> <a href=\"https:\/\/energiteknikk.net\/2025\/06\/hackere-apnet-ventil-pa-fullt-ved-dam-anlegg\/Risevatnet\">Energiteknikk<\/a>) \u00a0<\/li>\n\n\n\n<li>In Q1 2025, education as a sector experienced an average of 4,484 weekly attacks per organization. Government and telecom sector organizations came in second and third, totaling 2,678and 2,664 weekly attacks per organization, respectively. (<strong>Source:<\/strong> <a href=\"https:\/\/blog.checkpoint.com\/research\/q1-2025-global-cyber-attack-report-from-check-point-software-an-almost-50-surge-in-cyber-threats-worldwide-with-a-rise-of-126-in-ransomware-attacks\/\">Check Point Research<\/a>)<\/li>\n\n\n\n<li>305 U.S. healthcare-related data breaches involving protected health information (PHI) of 500+ individuals were reported in 1H 2025. (<strong>Source:<\/strong> <a href=\"https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf\">U.S. Department of Health and Human Services<\/a>).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So, what can organizations do to mitigate these risks and improve critical infrastructure security?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-an-overview-of-the-growing-need-for-critical-infrastructure-protection\">An Overview of the Growing Need for Critical Infrastructure Protection<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"508\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map-1024x508.jpg\" alt=\"A screenshot from NetScout's DDoS Cybr Attack Map online tool\" class=\"wp-image-18612\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map-1024x508.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map-300x149.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map-768x381.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map-1536x761.jpg 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/netscout-ddos-cyber-attack-map.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of <\/em><a href=\"https:\/\/horizon.netscout.com\/\"><em>NetScout\u2019s Cyber Threat Horizon Real Time DDoS Attack Map<\/em><\/a><em>, which shows DDoS and other types of cyber attacks occurring in real time. The illustrated attacks were occurring at the moment I snapped a screenshot.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Warfare is no longer just a world of gunfire, missiles, and foxholes. Many wars are now waged in cyberspace, targeting countries\u2019 critical infrastructure, including hospitals, power grids, and water facilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, attacks in the digital realm extend far beyond the reach of your company network. They have real-world repercussions that can result in people being hurt or killed. We\u2019ve seen this in Russian hackers\u2019 repeated attacks on Ukraine\u2019s electric grids, causing multiple localized blackouts since 2015.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what about an attack on the U.S. critical infrastructure facilities and entities?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We saw that with the <a href=\"https:\/\/www.fbi.gov\/news\/press-releases\/fbi-deputy-director-paul-abbates-remarks-at-press-conference-regarding-the-ransomware-attack-on-colonial-pipeline\">Colonial Pipeline ransomware attack<\/a> by the DarkSide ransomware group, which targeted 90+ critical infrastructure organizations.<\/li>\n\n\n\n<li>The U.S. faces an <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/joint-statement-cisa-fbi-dc3-and-nsa-potential-targeted-cyber-activity-against-us-critical\">increasing risk of critical infrastructure cyber attacks<\/a> by Iran-affiliated or state-sponsored threat actors. They\u2019ve already been <a href=\"https:\/\/www.nozominetworks.com\/blog\/threat-actor-activity-related-to-the-iran-conflict\">targeting transportation and manufacturing sector organizations<\/a>, as well as <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-335a\">water and wastewater facilities<\/a>.<\/li>\n\n\n\n<li>Officials are concerned that China state-sponsored hacker groups Salt Typhoon and Volt Typhoon are <a href=\"https:\/\/www.yahoo.com\/news\/china-admits-behind-closed-doors-180000472.html\">embedded throughout North American power grids and telecom networks<\/a> and pose risks to U.S. and Canada\u2019s critical infrastructures.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If these systems are compromised or become inoperable, it can spell disaster for the thousands or potentially millions of people living in the targeted communities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-most-targeted-critical-infrastructure-sectors-cis\">Most Targeted Critical Infrastructure Sectors (CIS)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Curious as to which sectors rank as cybercriminals\u2019 top targets? In 2024 alone, the <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2024_IC3Report.pdf\">FBI\u2019s Internet Crime Complaint Center (IC3)<\/a> received 4,878 complaints from organizations across 14 of the 16 <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\">critical infrastructure sectors<\/a> (CIS) that were impacted by cyber threats. That\u2019s more than 18 reported complaints <em>per day<\/em>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of those, the IC3 ranked the following critical infrastructure sectors by the number of reported ransomware attacks and data breaches:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Critical infrastructure<\/strong> ranked #1 for ransomware attacks and #5 for data breaches.<\/li>\n\n\n\n<li><strong>Healthcare\/public health<\/strong> ranked #2 for ransomware attacks and #1 for data breaches.<\/li>\n\n\n\n<li><strong>Government facilities<\/strong> ranked #3 for ransomware and #3 for data breaches.<\/li>\n\n\n\n<li><strong>Financial Services<\/strong> ranked #4 for both ransomware attacks and data breaches.<\/li>\n\n\n\n<li><strong>Information Technology<\/strong> ranked #5 for ransomware (138) and #2 for data breaches.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"598\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3-1024x598.jpg\" alt=\"A chart based on data from the FBI IC3's Internet Crime Report 2024 that demonstrates why critical infrastructure protection is an increasingly important area of concern\" class=\"wp-image-18613\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3-1024x598.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3-300x175.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3-768x448.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3-1536x897.jpg 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-protection-reported-attacks-fbi-ic3.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Data source: The FBI IC3\u2019s 2024 Internet Crime Report. The numbers in green represent the total number of reported critical infrastructure sector-related attacks.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Again, these numbers represent strictly the reported issues. How many more went unnoticed or unreported? That\u2019s a good question, and one we\u2019ll likely never know the answer to.<\/p>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Related: <\/strong><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/10\/cisa-releases-thirteen-industrial-control-systems-advisories\">CISA Releases 13 Industrial Control Systems Advisories<\/a> (July 10, 2025)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cyber-threats-pose-skyrocketing-financial-concerns-for-cis-organizations\">Cyber Threats Pose Skyrocketing Financial Concerns for CIS Organizations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Claroty\u2019s independent global survey of 1,100 critical infrastructure professionals (<a href=\"https:\/\/claroty.com\/resources\/reports\/the-global-state-of-cps-security-2024-business-impact-of-disruptions\">The Global State of CPS Security 2024: Business Impact or Disruptions<\/a>) provides data showing that in the previous 12 months:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>45% of critical infrastructure cybersec pros reported financial impacts of at least $500,000 due to cyber attacks on cyber-physical systems (CPS).<\/li>\n\n\n\n<li>27% indicated losses stemming from these CPS-targeting attacks surpassed $1 million.<\/li>\n\n\n\n<li>12% of respondents said these attacks cost their organizations at least $5 million.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The financial costs of cyber attacks were largely the <em>indirect<\/em> costs. We\u2019re talking about legal fees (31%), loss of customer and partner relationships (30%), regulatory fines (28%), and brand reputation recovery (27%).<\/p>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Related:<\/strong><a href=\"https:\/\/www.thesslstore.com\/blog\/2-cyber-incidents-that-cost-one-companys-clients-6m\/\"> 2 Cyber Incidents That Cost One Company\u2019s Clients $6M+<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-there-are-also-the-non-financial-costs-to-consider\">There Are Also the Non-Financial Costs to Consider\u2026<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">And while money concerns are significant, there are other considerations related to poor critical infrastructure security that can keep you up at night:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Consumers lose confidence in public and private sector organizations that can\u2019t (or won\u2019t) do what\u2019s necessary to protect their data.<\/li>\n\n\n\n<li>Power grid-related disruptions leave entire communities without communications, clean water, and other basic services and necessities.<\/li>\n\n\n\n<li>Compromised or disrupted traffic control systems for trains, automobiles, and airlines can have devastating consequences.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.the-independent.com\/news\/health\/patient-death-cyber-attack-nhs-kings-college-b2776800.html\">Cyber attacks can be a matter of life and death<\/a>, particularly when it comes to hospitals and other healthcare-related services. Ambulances are diverted to other hospitals, patients may not get their medications, and surgeries get canceled. <a href=\"https:\/\/www.aha.org\/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and\">Change Healthcare\u2019s February 2024 ransomware attack<\/a> is a perfect example of that, as the attack impacted virtually every U.S. hospital in some way.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-crime-statistics\/\">By the Numbers: 50 Cyber Crime Statistics for 2025<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-look-at-the-causes-of-critical-infrastructure-cyber-attacks\">A Look at the Causes of Critical Infrastructure Cyber Attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hacks and other cyber attacks targeting critical infrastructure stem from many risk factors. And while some may involve complex and intricate plans, it\u2019s often the unsophisticated methods that are most effective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following list of factors isn\u2019t comprehensive, but it underscores the growing need to improve critical infrastructure protection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-poor-security-measures-and-practices\">Poor Security Measures and Practices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Password security is one crucial area in which many organizations fail. Employees using weak, easy-to-guess passwords (or using hard-coded or default credentials) leave organizations across all sectors vulnerable to account compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/password-security-what-your-organization-needs-to-know\/\">Poor passwords<\/a> can be brute forced, which seems to have been the case in the Norwegian dam cyber incident we mentioned earlier. <a href=\"https:\/\/claroty.com\/blog\/cyberattack-on-norwegian-dam-highlights-password-exposure-risks#:~:text=The%20initial%20point%20of%20entry%20of%20the%20attack%20was%20a%20web%2Daccessible%20control%20panel\">Claroty reports<\/a> that the cybercriminal(s) gained access to the organization\u2019s OT environment by <a href=\"https:\/\/www.thesslstore.com\/blog\/dont-let-these-password-cracking-attacks-catch-you-off-guard\/\">exploiting a weak password<\/a> on a \u201cweb-accessible control panel\u201d used to manage the dam\u2019s minimum water flow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Their activities went unnoticed for four hours, during which time (thankfully) no one was hurt. But things could have been a whole lot worse for people living in that region.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/dont-let-these-password-cracking-attacks-catch-you-off-guard\/\">Don\u2019t Let These Password Cracking Attacks Catch You Off Guard<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-vulnerable-aging-infrastructure\">Vulnerable, Aging Infrastructure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Industrial systems have lifespans that span decades. According to the U.S. Department of Energy (DOE), <a href=\"https:\/\/www.energy.gov\/gdo\/articles\/what-does-it-take-modernize-us-electric-grid\">many of the power grids operating throughout the U.S.<\/a> were built when a beehive was a popular (yet questionable) lady\u2019s hairstyle and Freddie Mercury first sang \u201cBohemian Rhapsody.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As such, internet security (understandably) wasn\u2019t a consideration when these systems were designed and put into operation. Unfortunately, bad guys also know this and actively seek ways to exploit these legitimate concerns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Research from the Czech Technical University (CTU) in Prague recently published research covering 376 peer-reviewed Chinese studies relating to attack models on U.S. power grids. <a href=\"https:\/\/www.linkedin.com\/pulse\/china-studying-how-hack-crash-our-power-grids-erika-langerov%C3%A1-2jkpc\">According to researcher Erika Langerov\u00e1<\/a>, Head of Cybersecurity Research at <a href=\"https:\/\/www.uceeb.cz\/en\/home\/\">CTU UCEEB<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe warning signs are clear. Chinese scholars have built a vast body of detailed, simulation-based research on how to destabilize Western power grids, meanwhile Chinese cyber operators have already proven capable of gaining access to the very same real systems. Whether or not they plan to act, the mere existence of such capability demands serious defensive preparation.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-poor-cybersecurity-hygiene-and-awareness-related-issues\">Poor Cybersecurity Hygiene and Awareness-Related Issues<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Did you know that 7 in 10 of the U.S.\u2019s <a href=\"https:\/\/www.epa.gov\/enforcement\/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities\">drinking water systems don\u2019t meet baseline security requirements<\/a>? This <a href=\"https:\/\/www.thesslstore.com\/blog\/epa-7-in-10-us-community-water-systems-at-risk-cyber-attacks\/\">lack of even basic security for these essential community water systems<\/a> is particularly concerning when you consider that there are many ways bad guys can infiltrate or otherwise attack critical infrastructure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>snooping in insecure communication channels<\/li>\n\n\n\n<li>exploiting vulnerabilities in industrial control systems and other OT and IoT technologies<\/li>\n\n\n\n<li>employing <a href=\"https:\/\/www.thesslstore.com\/blog\/social-engineering-attacks-a-look-at-social-engineering-examples-in-action\/\">social engineering techniques<\/a> to trick or manipulate privileged users into providing access<\/li>\n\n\n\n<li>abusing ineffective physical and digital <a href=\"https:\/\/www.thesslstore.com\/blog\/the-role-of-access-control-in-information-security\/\">access controls<\/a> (e.g., exploiting weak, default, or hard-coded credentials, exploiting poorly configured remote services, etc.)<\/li>\n<\/ul>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/social-engineering-statistics\/\">Social Engineering Statistics 2025: When Cyber Crime &amp; Human Nature Intersect<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malicious-insiders\">Malicious Insiders<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes, the biggest threats come from within. <a href=\"https:\/\/info.everfox.com\/360\">Research from Everfox<\/a> shows that one in three security leaders within the financial and banking sector recognize insider threats as a top security concern.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, in 2024, a <a href=\"https:\/\/www.foxbusiness.com\/technology\/former-google-engineer-indicted-stealing-ai-secrets-aid-chinese-firms\">former Google engineer was indicted<\/a> for aiding Chinese firms by stealing AI trade secrets from his employer. And the Coinbase insider-assisted crypto data breach involved <a href=\"https:\/\/www.coinbase.com\/blog\/protecting-our-customers-standing-up-to-extortionists\">bribed customer-support agents<\/a> handing over customers\u2019 personal and financial data, including government documents.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-remote-access-and-supply-chain-issues\">Remote Access and Supply Chain Issues<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Data from Claroty\u2019s CPS survey of business disruptions indicates some serious concerns.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Eight in 10 respondents said at least one cyber attack in the previous 12 months originated from a third-party supplier\u2019s access to their CPS environment.<\/li>\n\n\n\n<li>Of those, 45% indicated this was the case in <em>5 or more attacks<\/em> within the same period.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, nearly two-thirds of respondents cop to having \u201conly partial or no understanding of third-party connectivity to the CPS environment.\u201d So, if these numbers are based on an incomplete picture, it makes you wonder how many cyber incidents and data breaches may have gone unnoticed and unreported.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-critical-infrastructure-protection-how-to-secure-your-systems-against-cyber-attacks\">Critical Infrastructure Protection: How to Secure Your Systems Against Cyber Attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Critical infrastructure security and cybersecurity ultimately boil down to resilience and having a comprehensive CIP strategy. It\u2019s not only about identifying threats but knowing how to respond while also keeping the lights on (and I mean that quite literally for a certain obvious sector) when crap hits the fan. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can\u2019t protect yourself against 100% of threats. However, critical infrastructure protection can be layered to ensure your organization\u2019s communications, devices, networks, and other systems are as secure as possible against external and internal threats. We\u2019ll share some of these highlights and point you to some useful industry resources.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-perform-regular-cyber-risk-assessments-and-update-response-plans\">1. Perform Regular Cyber Risk Assessments and Update Response Plans<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SAFECOM and the National Council on Statewide Interoperability Coordinators (NCSWIC) reiterate the <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2025-03\/25_0319_s-n_two-things_911-cyber-resources-guide_508C.pdf\">importance of cyber risk assessments<\/a> and having current cyber incident response and vulnerability response plans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk assessment helps organizations identify, document, and measure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>which threats and vulnerabilities bad guys can exploit,<\/li>\n\n\n\n<li>the likelihood of these risks being exploited,<\/li>\n\n\n\n<li>the estimated impact of these issues, and<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This series of processes helps CIS organizations figure out which risk responses to prioritize and develop and implement plans to address them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-have-clear-visibility-of-your-network-s-and-digital-assets\">2. Have Clear Visibility of Your Network(s) and Digital Assets<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s no secret that critical infrastructure organizations are increasingly implementing \u201csmart\u201d technologies across their networks. This means that the apps, IoT devices, or systems that critical infrastructure organizations rely on are connected to the internet. Bad guys can potentially access them, and insecure IoT devices expand organizations\u2019 attack surfaces.<\/p>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-secure-iot-devices-within-your-enterprise\/\">A 5-Minute Guide on How to Secure IoT Devices Within Your Enterprise<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As such, all of these things should be closely tracked and monitored within your ecosystem. This way, you know what you have, where everything is, and which entities have access to XYZ.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-track-critical-processes-and-permissions\">Track Critical Processes and Permissions<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Track and log everything. Log what systems are connected to the internet, which entities have access to them, and which systems and individuals make changes (and specifically what changes are made).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remember the <a href=\"https:\/\/www.wired.com\/story\/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever\/\">SolarWinds SUNBURST supply chain attack<\/a> a few years back? In that situation, cybercriminals targeted the third-party service provider to inject malicious code into the company\u2019s Orion platform updates that went out to ~18,000 customers. The list of potential victims included U.S. government agencies, federal contractors, cybersecurity firms, and software companies (although it\u2019s estimated that \u201conly\u201d 100 were compromised by the attack).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What made things particularly challenging with regard to identifying and tracking the attackers is that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The attackers used an employee\u2019s VPN account. (How they got access hasn\u2019t been disclosed.)<\/li>\n\n\n\n<li>SolarWinds didn\u2019t track everything internally when it came to their build servers (and the attackers deleted some logs as well).<\/li>\n\n\n\n<li><a href=\"https:\/\/www.wired.com\/story\/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever\/\">WIRED reports<\/a> that many of the affected federal agencies \u201cdidn\u2019t maintain adequate network logs\u201d and didn\u2019t even put their servers behind firewalls.<\/li>\n\n\n\n<li>Many of those impacted by the Sunburst backdoor had misconfigured servers that weren\u2019t restricted to communicating with SolarWinds only.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-adopt-strong-authentication-mechanisms-and-access-controls\">3. Adopt Strong Authentication Mechanisms and Access Controls<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A crucial way to protect your network and all of the devices connected to it is to know <em>who<\/em> or <em>what<\/em> connects to it. This requires authenticating the external users, devices, or services that connect to your network, as well as those entities that are already inside it and whether they\u2019re connecting to the internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But traditional passwords typically aren\u2019t enough. It\u2019s best to use multiple layers of security:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Implement multi-factor authentication (MFA) methods across all devices, networks, and systems.<\/li>\n\n\n\n<li>Deploy <a href=\"https:\/\/www.thesslstore.com\/blog\/client-authentication-certificate-101-how-to-simplify-access-using-pki-authentication\/\">certificate-based authentication<\/a> to authenticate and secure your users, servers, IoT devices, applications, and their sensitive data in transit.<\/li>\n\n\n\n<li>When passwords are being used, ensure that they\u2019re salted and hashed. Passwords should never be stored in plaintext or encrypted formats \u2014 only their <a href=\"https:\/\/www.thesslstore.com\/blog\/password-salting-a-savory-way-to-secure-your-secrets\/\">salted password hash values<\/a> should be stored.<\/li>\n\n\n\n<li>Put specific, documented processes in place for when user accounts must be deactivated (e.g., an employee leaves the company or a contractor\u2019s work is concluded).<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-securely-manage-these-digital-identities\">Securely Manage These Digital Identities<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Much like their non-ICS counterparts, critical infrastructure organizations must have the tools and processes in place to identify and securely manage all human- and non-human identities on their networks. In terms of certificate-based identities, think of IoT device certificates and user authentication certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regularly scan and monitor your domain and network for any expired, revoked, rogue, or unauthorized certificates.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-central-palette-1-color has-central-palette-19-background-color has-text-color has-background has-link-color wp-elements-df71ca0f6981c387e221e229e1883794\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1.png\" alt=\"\" class=\"wp-image-17524 size-full\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1-300x151.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/02\/trust-lifecycle-manager-dashboard-tools-1024x516-1-768x387.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-central-palette-7-color has-text-color has-link-color wp-elements-eec278cd911a009bda9c639e68f22e55\" id=\"h-digicert-trust-lifecycle-manager-simplifies-pki-digital-certificate-management\">DigiCert Trust Lifecycle Manager Simplifies PKI &amp; Digital Certificate Management<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DigiCert Trust Lifecycle Manager is an all-in-one PKI &amp; certificate lifecycle management (CLM) solution. Explore how this tool can help you keep a close eye on your PKI and avoid certificate outages.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-7-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/www.thesslstore.com\/solutions\/digicert-trust-lifecycle-manager.aspx\" style=\"color:#ffffff\">Learn More<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-update-your-devices-and-systems\">4. Update Your Devices and Systems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In 2017, <a href=\"https:\/\/learn.microsoft.com\/en-us\/security-updates\/securitybulletins\/2017\/ms17-010\">EternalBlue<\/a> was a harsh reminder of the importance of keeping systems patched and up to date. It\u2019s estimated that 200,000 devices globally fell prey to the critical exploit, which enabled attackers to use a vulnerability in legacy Windows operating systems to carry out remote code execution. These public and private sector organizations\u2019 computers became very expensive paperweights.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft emphasized the <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2017\/05\/14\/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack\/#sm.00001f8dkuuuzdpfwvt2bhyvcw0pp\">responsibility tech companies and their customers share<\/a> when it comes to protecting their systems:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe fact that so many computers remained vulnerable two months after the release of a patch illustrates this aspect. As cybercriminals become more sophisticated, there is simply no way for customers to protect themselves against threats unless they update their systems. Otherwise they\u2019re literally fighting the problems of the present with tools from the past.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-5-implement-physical-measures-to-combat-cyber-threats-and-other-dangers\">5. Implement Physical Measures to Combat Cyber Threats and Other Dangers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While embracing digital technologies is great in terms of operational improvements, it\u2019s not always great for mitigating cyber threats. Simply relying on digital security tools isn\u2019t enough when it comes to protecting critical infrastructure. Having physical security measures is a must, serving as a failsafe should your organization\u2019s other critical infrastructure protection methods fail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The idea of using analog mechanisms to build physical resilience and mitigate the physical impacts of cyber attacks aligns with the Idaho National Laboratory\u2019s \u201c<a href=\"https:\/\/inl.gov\/national-security\/cie\/\">cyber-informed engineering<\/a>\u201d (CIE) strategic initiative. CIE is <a href=\"https:\/\/www.osti.gov\/biblio\/1995796\">akin to a marriage between cybersecurity and engineering<\/a> by using engineering tools and approaches in ways that improve cybersecurity outcomes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few quick examples of some physical security measures for critical infrastructure protection include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Disabling device ports on devices to prevent USB-based attacks.<\/strong> (Think of <a href=\"https:\/\/spectrum.ieee.org\/the-real-story-of-stuxnet\">Stuxnet<\/a>, a cyber attack involving a worm installed on a USB device was used to target Iran\u2019s nuclear industrial control systems.)<\/li>\n\n\n\n<li><strong>Installing monitoring and sensor technologies \u2014 one example is using <\/strong><a href=\"https:\/\/www.theverge.com\/cyber-security\/693588\/cybersecurity-cyberattack-critical-infrastructure-war-expert-iran\"><strong>pressure detection and shutoff mechanisms<\/strong><\/a><strong> in water facilities.<\/strong> This device serves as a failsafe that\u2019s akin to how a circuit breaker mitigates the risks associated with voltage spikes.<\/li>\n\n\n\n<li><strong>Ensuring there are manual physical controls in place that are operational.<\/strong> When things are going wrong, you need to know that there\u2019s a way to revert to manual controls when digital ones are compromised or unresponsive.<\/li>\n\n\n\n<li><strong>Securing access to facilities and sensitive infrastructure.<\/strong> Only the individuals who need access should have access, period.<\/li>\n\n\n\n<li><strong>Employing ballistic barricades and fencing.<\/strong> This approach adds another layer of protection to critical infrastructure by protecting sensitive equipment against tampering and <a href=\"https:\/\/myfox8.com\/news\/storylines\/power-grid-attack\/2-years-since-moore-county\/\">gunfire attacks<\/a>.\u00a0<\/li>\n\n\n\n<li><strong>Monitoring and surveillance are non-negotiable.<\/strong> Think PKI key cards, biometrics,\u00a0cameras, and security personnel \u2014 these are just a few examples of the security technologies you can employ to help physically secure your systems.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-ensure-your-organization-meets-regulatory-requirements\">Ensure Your Organization Meets Regulatory Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many industry and geographic regulations include cybersecurity-related requirements that applicable organizations must adhere to. This will become even more critical with increasing <a href=\"https:\/\/www.thesslstore.com\/blog\/harvest-now-decrypt-later-hndl\/\">harvest now, decrypt later attacks<\/a>, and the ever-growing need for organizations across all sectors to embrace <a href=\"https:\/\/www.thesslstore.com\/blog\/nist-pqc-standards-are-out-where-do-we-go-from-here\/\">post-quantum cryptography<\/a>. &nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many regulations vary by industry and geographic location. For example, U.S. electricity service providers must adhere to the <a href=\"https:\/\/www.ferc.gov\/\">Federal Energy Regulatory Commission<\/a> (FERC) and the North American Electric Reliability Corporation (NERC), with <a href=\"https:\/\/www.nerc.com\/pa\/Stand\/Pages\/Default.aspx\">NERC creating and enforcing standards<\/a> that aim to keep the country\u2019s electrical grids operational and secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Financial Services sector also has experienced some pretty big changes so far in 2025:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The European Union\u2019s<\/strong> <a href=\"https:\/\/www.eiopa.europa.eu\/digital-operational-resilience-act-dora_en\"><strong>Digital Operational Resilience Act (DORA)<\/strong><\/a>officially took effect. This regulation aims to strengthen the sector\u2019s information and communication technology (ICT) security and resilience to help financial entities withstand significant operational disruptions<\/li>\n\n\n\n<li>Organizations globally felt the impact when the <strong>Payment Card Industry\u2019s Data Security Standards (<\/strong><a href=\"https:\/\/blog.pcisecuritystandards.org\/just-published-pci-dss-v4-0-1\"><strong>PCI DSS versions 4.0 and 4.0.1<\/strong><\/a><strong>)<\/strong> took effect. This updated regulation features 12 key security requirements that aim to address emerging threats and enhanced technologies.<\/li>\n\n\n\n<li><strong>The new <\/strong><a href=\"https:\/\/www.thesslstore.com\/blog\/x9-pki-for-financial-services\/\"><strong>ASC X9 PKI<\/strong><\/a> made its debut. Unlike traditional public key infrastructure, this one is independent of traditional browser influences. In June, <a href=\"https:\/\/www.digicert.com\/news\/asc-x9-and-digicert-perform-key-ceremony\">DigiCert performed its formal key signing ceremony<\/a>, officially marking the launch of the X9 PKI.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-additional-critical-infrastructure-protection-resources\">Additional Critical Infrastructure Protection Resources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/attack.mitre.org\/matrices\/ics\/\">MITRE ATT&amp;CK Framework Matrix for Industrial Control Systems<\/a><\/li>\n\n\n\n<li>NIST\u2019s <a href=\"Cyber%20Security%20Framework%202.0\">Cyber Security Framework 2.0<\/a><\/li>\n\n\n\n<li>A joint fact sheet from CISA, DC3, FBI, and NSA: <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/iranian-cyber-actors-may-target-vulnerable-us-networks-and-entities-interest\">Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest<\/a>.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.osti.gov\/biblio\/1995796\">The Cyber-Informed Engineering Implementation Guide<\/a> from the U.S. Department of Energy Office of Scientific and Technical Information (OSTI).<\/li>\n\n\n\n<li><a href=\"https:\/\/www.dhs.gov\/publication\/safety-and-security-guidelines-critical-infrastructure-owners-and-operators\">Safety and Security Guidelines for Critical Infrastructure Owners and Operators<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.energy.gov\/ceser\/cybersecurity-capability-maturity-model-c2m2\">Cybersecurity Capability Maturity Model (C2M2)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>From cyber attacks on emergency call centers to electric and telecom network infiltrations, here\u2019s what to know about the threats plaguing critical infrastructure sectors and how to fight back \u201cWe\u2019re&#8230;<\/p>\n","protected":false},"author":17,"featured_media":18611,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16,10200],"tags":[13279],"class_list":["post-18610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","category-monthly-digest","tag-critical-infrastructure","post-with-tags"],"views":5816,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/07\/critical-infrastructure-feature2.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/18610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=18610"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/18610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/18611"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=18610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=18610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=18610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}