The Draos Report: 65% Have Unsecure Remote Access
Draos released the OT/ICS cybersecurity year-in-review report. 65% of the environments Draos assessed had unsecure remote access. 45% had active SSH connections to the internet. Less than 5% of OT organizations worldwide monitor their networks. Manufacturing is the top targeted sector because plants lack security. Mike Holcomb said a client with 100 plants had no firewall between IT and OT. Ransomware infections kept taking plants down.
State Actors and Activists: Low Impact Meets High
Holcomb distinguished activists from state actors. Activists like the Iranian Cyber Avengers break into internet-exposed PLCs and deface screens. Their impact is low. One incident in Ireland left 160 people without water for 2 days. State actors like Sandworm launch fewer attacks but the impact is high. Sandworm caused a blackout in Ukraine in 2015 for hundreds of thousands of people in sub-zero temperatures. The talk noted growing alignment between activist groups and state adversaries such as the Cyber Army of Russia Reborn.
Frosty Goop: Malware Recreated in 30 Seconds
Frosty Goop is a simple piece of malware that targeted Enko controllers. Holcomb demonstrated that anyone can recreate it in ChatGPT in 30 seconds. The malware used Modbus, an unauthenticated protocol, to read and write registers. In Ukraine, it shut off heating to 600 apartment buildings for 2 days during winter. Shodan searches still show Enko devices exposed on the internet with Telnet and Modbus ports open. Holcomb named his version Snow Crash.
Sandworm’s Campaign and a Suspicious Explosion
In 2017 Sandworm had full control of a petrochemical facility in the Middle East and a dozen ways to cause an explosion. Last year, Draos tracked the same group hammering a US petrochemical facility for 6 weeks. An explosion occurred shortly after. The CEO said the safety instrumented system tripped and caused it. That was the same system targeted in the Triton attack. Holcomb noted the facility was part of the 95% that do not monitor their networks, leaving no evidence of a cyber cause.
Fundamentals That Stop Every Attacker
Holcomb argued that mastering five fundamentals defends against activists, ransomware operators, and state adversaries. Backup and recovery ensure quick restoration after an incident. Asset management means knowing what is on the network. Secure network architecture starts with a firewall between IT and OT. Incident response prepares teams for compromise. Continuous vulnerability management closes gaps. He emphasized that most attacks come through IT, so the firewall is the single biggest risk reducer. These basics work even on 30-year-old equipment.
Q&A
How do hardware security and vendor efforts affect OT security? Vendors like Siemens lead with bug bounties and vulnerability management, but old protocols like Modbus remain unauthenticated and will take years to replace; fundamentals still reduce the vast majority of risk. ▶ 24:53
Notable Quotes
65% of those environments had unsecure remote access. Mike Holcomb · ▶ 4:58
45% of those environments had active SSH connections to the internet. Mike Holcomb · ▶ 5:46
less than 5% of OT organizations today are actually monitoring their networks Mike Holcomb · ▶ 6:14
a very simple piece of malware that you can recreate in Chat GPT in 30 seconds or less Mike Holcomb · ▶ 17:36
Sandworm had full control of a prochemical facility in the Middle East. Mike Holcomb · ▶ 21:02
Key Takeaways
- 65% of OT environments have unsecure remote access; 45% have SSH exposed to the internet.
- Less than 5% of OT organizations monitor their networks, leaving blind spots.
- Mastering five fundamentals—backup, asset management, firewall, incident response, vulnerability management—defends against all threat actors.
About the Speaker(s)
Mike Holcomb is the Fellow of Cybersecurity and the ICS/OT Cybersecurity Global Lead for Fluor, one of the world’s largest engineering, procurement, and construction companies. His current role provides him with the opportunity to work in securing some of the world’s largest ICS/OT environments, from power plants and commuter rail to manufacturing facilities and refineries. As part of his community efforts, Michael founded the BSidesICS/OT and BSides Greenville conferences along with the UpstateSC ISSA Chapter. He has his Masters degree in ICS/OT cybersecurity from the SANS Technology Institute. Additionally, he maintains cyber security and ICS/OT certifications such as the GRID, CISSP, GICSP, ISA 62443, and more. He posts regularly on LinkedIn and YouTube to help others learn more about securing ICS/OT and critical infrastructure.