OT/ICS & Critical Infrastructure Security
Industrial control systems, OT, energy, utilities, critical infrastructure
Reports in this theme

Inside Europe's Cyber Incidents 2026
Eye Security's report provides an analysis of cyber incidents in Benelux and Germany, highlighting the prevalence of business email compromise (BEC) and ransomware attacks, with a focus on financial motivations and the role of phishing. The report also discusses the impact on critical industries and the effectiveness of MDR solutions.

Threat Landscape Report 2025
The 2025 Threat Landscape Report highlights the increasing sophistication of cyber threats, the convergence of geopolitical and cyber activities, and the critical role of supply chain attacks. It emphasizes the need for proactive cybersecurity measures to counter emerging threats.

Navigating the security landscape of generative AI
This whitepaper explores the security challenges and mitigation strategies for generative AI systems, focusing on threat vectors like context window overflow, agent vulnerabilities, and indirect prompt injections. It emphasizes an agile approach to security, integration with frameworks like NIST AI RMF, and the importance of regulatory alignment.

FBI Internet Crime Complaint Center (IC3) Annual Report 2024
The FBI's IC3 Annual Report for 2024 highlights a significant increase in cybercrime, with a record high in financial losses. Key themes include the rise of cryptocurrency-related fraud, ransomware, and scams targeting older adults. The report also emphasizes the role of public awareness and collaboration with private sectors in combating cyber threats.

OT/ICS Cybersecurity Year in Review 2025
Dragos' 8th annual OT/ICS Cybersecurity Year in Review analyzes the 2024 threat landscape and shows OT is no longer a niche target: adversaries, hacktivists and ransomware crews are converging on industrial systems as geopolitical conflict continues. Dragos now tracks 23 threat groups (9 active in 2024) and identified two new ones — GRAPHITE (APT28-linked; hydro, energy, logistics, defense in Eastern Europe/Middle East, credential-phishing that bypasses 2FA, Ubiquiti EdgeRouter C2, growing use of legitimate internet services) and BAUXITE (oil & gas, electric, water/wastewater and chemical manufacturing across the US, Europe, Australia and Middle East). Russia-linked KAMACITE and ELECTRUM continue to collaborate on Ukraine-focused OT operations, with KAMACITE broadening spear-phishing (LummaStealer, TAT24-97 loader) to European ONG targets and ELECTRUM extending its wiper arsenal with AcidPour (an evolution of AcidRain, which had disrupted KA-SAT and German wind turbines). China-linked VOLTZITE remains the most critical group to track in critical infrastructure, exploiting internet-facing VPN/firewall bugs and using living-off-the-land techniques against SOHO routers and shared botnets (65% of sites assessed had insecure remote conditions). Ransomware attacks rose 87% year over year, hitting manufacturing hardest where downtime forces payment; CARR-style campaigns showed even basic HMI abuse over internet-exposed OT can cause tangible disruption. Vulnerability analysis: 22% of 2024 advisories had incorrect data, 22% were network-exploitable and perimeter-facing, 39% could cause both loss of view AND loss of control (down from 53%), and Dragos provided mitigations for 47% of advisories that shipped without any. The report reiterates the SANS ICS 5 Critical Controls and the "Now, Next, Never" framework as the best defense, and highlights supply chain / DLL-hijack risks, servo drives, and IoT in ICS as emerging research areas.
Create a free account to see every report in this theme.
