Blog
/
/
March 24, 2020

Securing Operational Technology in Remote Working Conditions

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
24
Mar 2020
Remote work poses new challenges for cybersecurity professionals. Use these tips to secure your operational technology (OT) in remote working conditions.

Remote work poses new challenges

As organizations rapidly transition to remote working, security professionals tasked with defending critical infrastructure and OT systems are faced with a broad set of challenges. New business measures, many of which were enacted overnight, have introduced risks to OT environments that can be safety-critical. This blog post summarizes the emerging vulnerabilities and offers advice for OT security professionals to stay secure under these evolving and dynamic business conditions.

Remote access

Under new business pressures, operators and engineers are being granted levels of remote access that were previously considered unacceptable risks. Remote access to OT networks has always been a significant threat vector, whether the intended users are company staff or third-party contractors and vendors. Compromised remote access can serve as a launching point for many other malicious or dangerously misguided activities – something referred to many times in the recently released MITRE ATT&CK for ICS matrix under the ‘Initial Access’ and ‘Lateral Movement’ sections. This is especially true in the current period of sweeping and sudden changes in working practices, where staff may not have been trained in advance and static cyber defenses have to be rapidly adjusted. The potential for new oversights and mistakes is at an all-time high.

Many OT security architectures heavily rely on a ‘defense-in-depth’ approach, which involves building multiple layers of defense outside the core OT functions. This has always been vulnerable to a dedicated attacker or an effective worm malware. However, recent measures have seen a rapid escalation in the most dangerous form of remote access, which likely emerges within most of those defensive layers – and without the long planning process that would usually be followed in preparation.

These changes open the door to new vulnerabilities at a time when industrial environments are already experiencing significant operator resource problems. Remote access is not efficient, which means these organizations will already be struggling. Asking these organizations to also take on new security responsibilities, that take time to put in place and facilitate, hugely exacerbates the problem.

Convergence with IT

This transition to remote access exposes some of the longer-term security challenges faced by teams overseeing industrial environments. This includes the historical trend of IT hardware, operating systems, and services invading OT networks for financial efficiency without being suitable for the availability-first environment – hence the difficulty of maintaining up-to-date patching.

The increasing interconnectivity of OT and IT means that defending against an attack on the operational side, whether intentional or as collateral damage, has become of paramount importance. Vulnerable OT equipment is often used as a gateway for a more pernicious attack on the network, and in equal measure, attacks that start in the corporate IT system can result in disruption to physical operations – causing catastrophic losses to production.

Supply chain risk

Physically establishing a test environment may be impossible given the current circumstances, and yet the production environment has to keep running. This may again result in a lower level of testing than was previously acceptable, as well as opening up another vector of attack through the supply chain – as pre-infected hardware and malware can appear directly within the production environment.

In these conditions, carrying out risk and security reviews for all vendors and the products they are purchasing has never been more important. Additional reviews and monitoring of any outsourced or open-sourced components will be critical to mitigate against supply chain risk – but these precautions may be neglected due to current business environments and policies.

An overnight change

The sudden shift in working practices will also expose the limitations of staff training – for example, in what they are supposed to be doing and not doing over remote access. Taken away from the secure environment normally supported by a location in a physical HQ, security professionals and OT engineers will now be working within their own home networks, which invariably will not be as secure as the working environment. The required level of education cannot be rolled out over this short timeframe. As well-meaning employees seek to urgently resolve business obstacles, protocol will inevitably be breached.

Further, sudden changes in static security like firewall rules are destabilizing, and more likely to have errors and unwanted permissions. Alterations to OT systems, in particular safety-critical processes, take enormous forward planning, and it is extremely rare for them to have to take place because of sudden and fundamental change.

Mitigating the risks

The transition to remote working means OT security teams will have to be able to better investigate security incidents without being onsite. This means a marked improvement in visibility and forensic capabilities is required.

The limitations of traditional security tools reliant on rules and signatures of previously identified threats will be thrown into the spotlight under the current circumstances. Organizations will instead need to move to more flexible security platforms that can adapt to sudden business changes. Hundreds of organizations have turned to cyber AI as an ally in enhancing their defense strategy to combat these OT challenges. AI is particularly suited to supporting security teams in this new set of dynamic conditions due to three key features:

  • The detection capability is consistent across both OT and IT technologies. These are always intermingled in real OT networks, but significant remote access increases the presence of more traditionally IT services and risks.
  • Its unsupervised machine learning core does not require extensive manual configuration or maintenance. This is particularly crucial at a time when working practices have changed to generally less efficient methods, meaning human resources are now at a premium.
  • The Cyber AI Analyst advances both of the prior themes even further by automatically applying expert IT and OT analysis skills, saving human analysts large amounts of time on triage and investigation.

The Industrial Immune System can be installed within just one hour, allowing organizations to adapt to these sudden changes within the timeframe required. Darktrace is committed to helping its customers with their urgent cyber security needs at this time of rapid and sudden change.

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
David Masson
VP, Field CISO

David Masson is VP, Field CISO at Darktrace, and has over two decades of experience working in fast moving security and intelligence environments in the UK, Canada and worldwide. With skills developed in the civilian, military and diplomatic worlds, he has been influential in the efficient and effective resolution of various unique national security issues. David is an operational solutions expert and has a solid reputation across the UK and Canada for delivery tailored to customer needs. At Darktrace, David advises strategic customers across North America and is also a regular contributor to major international and national media outlets in Canada where he is based. He holds a master’s degree from Edinburgh University.

Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

OT

/

April 4, 2025

Darktrace Named as Market Leader in the 2025 Omdia Market Radar for OT Cybersecurity Platforms

Default blog imageDefault blog image

We are pleased to announce that Darktrace / OT has been named a Market Leader in Omdia’s  2025 Market Radar for OT Cybersecurity Platforms. We believe this highlights our unique capabilities in the OT security market and follows similar recognition from Gartner who recently named Darktrace / OT as the sole Visionary in in the Magic Quadrant for Cyber Physical Systems (CPS) Protection Platforms market.

Historically, IT and OT systems have been managed separately, creating challenges due to the differences of priorities between the two domains. While both value availability, IT emphasizes confidentiality and integrity whereas OT focuses on safety and reliability. Organizations are increasingly converging these systems to reap the benefits of automation, efficiency, and productivity (1).

Omdia’s research highlights that decision makers are increasingly prioritizing comprehensive security coverage, centralized management, and advanced cybersecurity capabilities when selecting OT security solutions (1).

Rising productivity demands have driven the convergence of OT, IT, and cloud-connected systems, expanding attack surfaces and exposing vulnerabilities. Darktrace / OT provides a comprehensive OT security solution, purpose-built for critical infrastructure, offering visibility across OT, IoT, and IT assets, bespoke risk management, and industry-leading threat detection and response powered by Self-Learning AITM.

Figure 1: Omdia vendor overview for OT cybersecurity platforms
Figure 1: Omdia vendor overview for OT cybersecurity platforms

An AI-first approach to OT security  

Many OT security vendors have integrated AI into their offerings, often leveraging machine learning for anomaly detection and threat response. However, only a few have a deep-rooted history in AI, with longstanding expertise shaping their approach beyond surface-level adoption.

The Omdia Market Radar recognizes that Darktrace has extensive background in the AI space:

“Darktrace has invested extensively in AI research to fuel its capabilities since 2013 with 200-plus patent applications, providing anomaly detection with a significant level of customization, helping with SOC productivity and efficiency, streamlining to show what matters for OT.” (1)

Unlike other security approaches that rely on existing threat data, Darktrace / OT achieves this through Self-Learning AI that understands normal business operations, detecting and containing known and unknown threats autonomously, thereby reducing Sec Ops workload and ensuring minimal downtime

This approach extends to incident investigations where an industry-first Cyber AI AnalystTM automatically investigates all relevant threats across IT and OT, prioritizes critical incidents, and then summarizes findings in an easily understandable view—bringing production engineers and security analysts together to communicate and quickly take appropriate action.

Balancing autonomous response with human oversight

In OT environments where uptime is essential, autonomous response technology can be approached with apprehension. However, Darktrace offers customizable response actions that can be set to “human confirmation mode.”

Omdia recognizes that our approach provides customizable options for autonomous response:

“Darktrace’s autonomous response functionality enforces normal, expected behavior. This can be automated but does not need to be from the beginning, and it can be fine-tuned. Alternative step-by-step mitigations are clearly laid out step-by-step and updated based on organizational risk posture and current level of progress.” (1)

This approach allows security and production to keep humans-in-the-loop with pre-defined actions for potential attacks, enforcing normal to contain a threat, and allowing production to continue without disruption.  

Bespoke vulnerability and risk management

In the realm of OT security, asset management takes precedent as one of the key focus points for organizations. With a large quantity of assets to manage, practitioners are overwhelmed with information with no real way to prioritize or apply them to their unique environment.

Darktrace / OT is recognized by Omdia as having:

“Advanced risk management capabilities that showcase metrics on impact, exploit difficulty, and estimated cost of an attack […] Given the nascency of this capability (April 2024), it is remarkably granular in depth and insight.” (1)

Enabling this is Darktrace’s unique approach to AI extends to risk management capabilities for OT. Darktrace / OT understands customers’ unique risks by building a comprehensive and contextualized picture that goes beyond isolated CVE scoring. It combines attack path modeling with MITRE ATT&CK  techniques to provide hardening recommendations regardless of patching availability and gives you a clearer view of the potential impact of an attack from APT groups.

Modular, scalable security for industrial environments

Organizations need flexibility when it comes to OT security, some want a fully integrated IT-OT security stack, while others prefer a segregated approach due to compliance or operational concerns. The Darktrace ActiveAI Security Platform offers integrated security across multiple domains, allowing flexibility and unification across IT and OT security. The platform combines telemetry from all areas of your digital estate to detect and respond to threats, including OT, network, cloud, email, and user identities.

Omdia recognizes Darktrace’s expansive coverage across multiple domains as a key reason why organizations should consider Darktrace / OT:

“Darktrace’s modular and platform, approach offer’s integrated security across multiple domains. It offers the option of Darktrace / OT as a separate platform product for those that want to segregate IT and OT cybersecurity or are not yet in a position to secure both domains in tandem. The deployment of Darktrace’s platform is flexible—with nine different deployment options, including physical on-premises, virtual, cloud, and hybrid.” (1)

With flexible deployment options, Darktrace offers security teams the ability to choose a model that works best for their organization, ensuring that security doesn’t have to be a “one-size-fits-all” approach.

Conclusion: Why Darktrace / OT stands out in Omdia’s evaluation

Omdia’s 2025 Market Radar for OT Cybersecurity Platforms provides a technical-first, vendor-agnostic evaluation, offering critical insights for organizations looking to strengthen their OT security posture. Darktrace’s recognition as a Market Leader reinforces its unique AI-driven approach, flexible deployment options, and advanced risk management capabilities as key differentiators in an evolving threat landscape.

By leveraging Self-Learning AI, autonomous response, and real-world risk analysis, Darktrace / OT enables organizations to detect, investigate, and mitigate threats before they escalate, without compromising operational uptime.

Read the full report here!

References

  1. www.darktrace.com/resources/darktrace-named-a-market-leader-in-the-2025-omdia-market-radar-for-ot-cybersecurity-platforms
Continue reading
About the author
Pallavi Singh
Product Marketing Manager, OT Security & Compliance

Blog

/

Cloud

/

April 2, 2025

Fusing Vulnerability and Threat Data: Enhancing the Depth of Attack Analysis

Default blog imageDefault blog image

Cado Security, recently acquired by Darktrace, is excited to announce a significant enhancement to its data collection capabilities, with the addition of a vulnerability discovery feature for Linux-based cloud resources. According to Darktrace’s Annual Threat Report 2024, the most significant campaigns observed in 2024 involved the ongoing exploitation of significant vulnerabilities in internet-facing systems. Cado’s new vulnerability discovery capability further deepens its ability to provide extensive context to security teams, enabling them to make informed decisions about threats, faster than ever.

Deep context to accelerate understanding and remediation

Context is critical when understanding the circumstances surrounding a threat. It can also take many forms – alert data, telemetry, file content, business context (for example asset criticality, core function of the resource), and risk context, such as open vulnerabilities.

When performing an investigation, it is common practice to understand the risk profile of the resource impacted, specifically determining open vulnerabilities and how they may relate to the threat. For example, if an analyst is triaging an alert related to an internet-facing Webserver running Apache, it would greatly benefit the analyst to understand open vulnerabilities in the Apache version that is running, if any of them are exploitable, whether a fix is available, etc. This dataset also serves as an invaluable source when developing a remediation plan, identifying specific vulnerabilities to be prioritised for patching.

Data acquisition in Cado

Cado is the only platform with the ability to perform full forensic captures as well as utilize instant triage collection methods, which is why fusing host-based artifact data with vulnerability data is such an exciting and compelling development.

The vulnerability discovery feature can be run as part of an acquisition – full or triage – as well as independently using a fast ‘Scan only’ mode.

Figure 1: A fast vulnerability scan being performed on the acquired evidence

Once the acquisition has completed, the user will have access to a ‘Vulnerabilities’ table within their investigation, where they are able to view and filter open vulnerabilities (by Severity, CVE ID, Resource, and other properties), as well as pivot to the full Event Timeline. In the Event Timeline, the user will be able to identify whether there is any malicious, suspicious or other interesting activity surrounding the vulnerable package, given the unified timeline presents a complete chronological dataset of all evidence and context collected.

Figure 2: Vulnerabilities discovered on the acquired evidence
Figure 3: Pivot from the Vulnerabilities table to the Event Timeline provides an in-depth view of file and process data associated with the vulnerable package selected. In this example, Apache2.

Future work

In the coming months, we’ll be releasing initial versions of highly anticipated integrations between Cado and Darktrace, including the ability to ingest Darktrace / CLOUD alerts which will automatically trigger a forensic capture (as well as a vulnerability discovery) of the impacted assets.

To learn more about how Cado and Darktrace will combine forces, request a demo today.

Continue reading
About the author
Paul Bottomley
Director of Product Management, Cado
Your data. Our AI.
Elevate your network security with Darktrace AI