The Cyber Security Review | Monday, April 24, 2023
Cybersecurity mitigations and standards are implemented through penetration testing, a necessary part of critical infrastructure assessments.
FREMONT, CA: Penetration testing is essential to a critical infrastructure assessment because it enables all stakeholders to evaluate risks and adopt cybersecurity mitigations and standards. It is the portion of a vulnerability assessment that involves a more in-depth examination of a network via the perspective of informed knowledge. You are searching for various difficulties, including software vulnerabilities, network problems, phishing scams, and other human-based attacks. You evaluate and grade these potential exploits before executing them within the environment during penetration testing.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Data indicates that the market for penetration testing will be worth $1.51 billion in 2021 and reach $4.1 billion by 2030, representing a healthy 12.1 percent CAGR over the eight years beginning in 2022. The paper identifies numerous growth factors, including smartphone-driven data consumption, new data center building, Internet of Things-connected devices, and the advent of intelligent infrastructure.
Testing is essential for vital infrastructure since the stakes are so high. Examples such as the hacking of a municipal water system in Oldsmar, Florida, in February 2021 demonstrate the destructive capability of hackers. The attackers attempted to contaminate the city's drinking water by raising the levels of caustic soda. Thankfully, staff prevented the act from being carried out, but the incident highlights the dangers infrastructure providers confront.
A Matter Of When
Critical infrastructure providers' interest in penetration testing, risk, and vulnerability assessments is driven by both the expanding threat landscape and the expansion and volatility of cyber insurance. Penetration testing is not a new practice, but its importance has increased because of the rise in nation-state attacks and the success of attacks such as the Colonial Pipeline.
Vital infrastructure providers are now looking for someone they can trust to perform penetration testing. Exposing what they may have overlooked (perhaps for years) and addressing it before it's too late is a crucial component of mitigation measures.
CISOs believe the odds are no longer in their favor by the end of 2022. This revelation causes CISOs to no longer believe that the odds are in their favor; thus, they advocate for risk or vulnerability assessments and penetration testing to make their firm a less desirable target. After testing and implementing countermeasures, there is still vulnerability because determined actors can compromise any system. The mitigation reduces the likelihood and enhances overall resilience.
More individuals in the OT industry view penetration testing as essential. It is a measure of a company's cyber hygiene, falling under the umbrella of vulnerability management. Penetration testing causes anxiety, but it also drives change. When an expert organization conducts the testing, it will mimic attacks and train the security staff to respond to and survive a threat attack.
Continuous Targeted Evaluation
Avoiding testing heightens hazards. Risks escalate within vital infrastructure since management cannot request penetration testing once and consider it "done" forever. Continuous testing is necessary due to the always-shifting threat scenario.
Risks are inherent to penetration testing, and hiring a seasoned supplier who knows and handles these risks is essential. In the case of IT penetration testing, for instance, the vendor will transmit certain details of an organization's infrastructure over the internet over encrypted channels. This requires evaluating all possible network perimeter defenses so ICS traffic and protocols are carried across public lines. If this is executed incorrectly, it will increase the attack surface.
Some OT systems have never been subjected to a vast array of hazards. A provider of infrastructure, for instance, may have ten to fifteen-year-old facilities that were the "latest and best" at the time. The hardware that supports these designs is five to ten years older.
The implementation of protocols in these older OT network systems is less resilient than that of newer devices; therefore, the tester must proceed cautiously. They could transmit a basic ping to a device with an inadequately built TCP IP stack, but a few days later, the device would fail due to its meager 36 kilobits of memory.
More in News