Top 10 Cybersecurity Trends in Critical Infrastructure for 2024
Mars Cheng
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In this DEF CON 32 presentation, Mars Cheng delivered a comprehensive overview of the critical cybersecurity landscape within Operational Technology (OT) environments, identifying the top 10 trends for 2024. Drawing insights from extensive surveys conducted with Chief Security Officers (CSOs) across various industrial sectors in 2023 and 2024, Cheng's talk aimed to demystify the often chaotic and industry-specific challenges of OT security. The research, spearheaded by TS1 Networks and the Association of Hackers in Taiwan, sought to understand the real-world priorities, concerns, and defensive strategies employed by those on the front lines of protecting critical infrastructure.

Key moments
- 0:00 Introduction to critical infrastructure cybersecurity trends
- 1:15 Survey methodology and scope for 2023-2024
- 2:10 Trend 1: Policy evolution in OT/ICS security
- 2:50 Trend 2: Insufficient security awareness for OT operators
- 4:00 Trend 3: Human resource gap and IT/OT integration challenges
- 6:00 Trend 4: Reliance on third-party help for OT incidents
- 6:30 Trend 5: High concern over operational impact of attacks
- 8:55 Trend 6: Common unprotected Windows devices in OT
Top 10 Cybersecurity Trends in Critical Infrastructure for 2024
Speakers: Mars Cheng, Research Manager, TS1 Networks; Executive Director, Association of Hackers in Taiwan
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=MIbQf08H5so
Overview
In this DEF CON 32 presentation, Mars Cheng delivered a comprehensive overview of the critical cybersecurity landscape within Operational Technology (OT) environments, identifying the top 10 trends for 2024. Drawing insights from extensive surveys conducted with Chief Security Officers (CSOs) across various industrial sectors in 2023 and 2024, Cheng's talk aimed to demystify the often chaotic and industry-specific challenges of OT security. The research, spearheaded by TS1 Networks and the Association of Hackers in Taiwan, sought to understand the real-world priorities, concerns, and defensive strategies employed by those on the front lines of protecting critical infrastructure.
The core of Cheng's presentation highlighted a persistent disconnect: while the criticality of OT security is universally acknowledged, the practical application and understanding of its unique demands often fall short. The speaker emphasized that OT environments, encompassing sectors like general manufacturing, automotive, pharmaceutical, oil and gas, and semiconductors, cannot be secured effectively by simply extending traditional IT cybersecurity paradigms. This talk provides a crucial data-driven perspective on where the industry stands, what threats are most pressing, and where significant gaps in policy, personnel, and technology continue to exist.
This analysis is particularly timely as global geopolitical tensions and the increasing digital integration of industrial processes make critical infrastructure a prime target for sophisticated adversaries, including nation-state actors and ransomware groups. Cheng's findings offer a vital roadmap for organizations and policymakers to address the most urgent cybersecurity deficiencies before they lead to catastrophic operational failures, economic disruption, or even physical harm.
Background
▶ Watch: Introduction to critical infrastructure cybersecurity trends (0:00)
The convergence of Information Technology (IT) and Operational Technology (OT) has been a defining trend in industrial environments for years, promising efficiency gains and enhanced data insights. However, this convergence has simultaneously introduced a complex web of cybersecurity challenges that traditional IT security models are ill-equipped to handle. OT systems, which control physical processes in critical infrastructure, are characterized by unique operational priorities—primarily availability and safety—that often supersede confidentiality, a cornerstone of IT security. This fundamental difference dictates distinct approaches to patching, system architecture, and incident response.
Prior to this research, a significant gap existed in understanding the nuanced perspectives and actual pain points of OT CSOs across diverse industrial sectors. While anecdotal evidence and high-profile incidents (e.g., Colonial Pipeline, Norsk Hydro) underscored the vulnerability of critical infrastructure, a systematic, data-backed assessment of the prevailing cybersecurity trends from the perspective of security leaders was lacking. The problem wasn't merely a lack of awareness, but a lack of specificity: knowing what was critical, how attacks manifested, and what effective countermeasures looked like in the highly varied OT landscape.
Mars Cheng and his team embarked on a multi-year survey initiative, collecting data in 2023 and expanding its scope in 2024 to include a broader representation of management-level personnel responsible for OT cybersecurity budgets and strategic decisions. This research aimed to provide clarity on several fronts: the maturity of cybersecurity policies, the adequacy of human resources, the efficacy of deployed security solutions, and the perceived impact of security incidents within OT environments. The overarching goal was to move beyond generic statements about OT criticality and deliver actionable insights grounded in the experiences of those directly managing these complex and vital systems. The survey's findings highlight that while many companies are deploying security solutions, there's a significant disparity in their effectiveness due to a failure to account for the unique operational constraints and technical requirements of OT.
Key Findings
▶ Watch: Trend 1: Policy evolution in OT/ICS security (2:10)
Mars Cheng's presentation distilled the complex landscape of critical infrastructure cybersecurity into ten key trends observed in 2024, based on direct feedback from OT CSOs. These findings illuminate the most pressing challenges and areas requiring urgent attention:
- Growing Policy and Regulatory Landscape: There is a clear global acceleration in the development of policies and regulations specifically targeting OT and Industrial Control Systems (ICS) security. Examples include the EU Cyber Resilience Act and national cybersecurity laws emerging in countries like Taiwan, Korea, and Japan. This signifies increasing governmental recognition of OT's criticality, yet implementation and compliance remain a significant undertaking for organizations.
- Critical Gap in OT Operator Security Awareness: Despite the rising threat landscape, security awareness and training for OT operators are critically insufficient. The survey highlighted that in 2023, phishing emails and employee actions (both malicious and unintentional) were identified as primary root causes for OT security incidents. While the 2024 data shifted focus to ransomware and patching, the underlying vulnerability stemming from human factors persists, indicating a fundamental failure in educating the workforce directly interacting with these systems.
- Severe Shortage of OT Security Professionals: A profound human resource gap exists for specialized OT cybersecurity professionals. The industry heavily relies on IT security professionals who often lack the specific domain knowledge required for OT environments, such as understanding industrial protocols, PLC programming, or the intricacies of specific manufacturing processes (e.g., semiconductor fabrication). This leads to a lack of integration between IT and OT security teams and significant difficulty in hiring qualified talent capable of bridging this knowledge divide.
- Inadequate Internal Incident Response Capabilities: Many organizations' internal security teams, particularly those focused on IT, lack the specialized capabilities to effectively manage and respond to OT security incidents. The survey indicated that CSOs frequently need to seek third-party assistance to handle complex OT breaches, highlighting a severe deficiency in internal preparedness and expertise.
- High Perceived Impact of OT Security Incidents: The concern regarding the potential impact of OT security incidents is extremely high among CSOs. In 2024, between 94% and 97% of respondents across various industries (including Germany, USA, and total global responses) expressed significant worry about the compromise of operational functions and productivity loss. This fear is often rooted in past experiences where IT incidents quickly cascaded into OT disruptions.
- Ransomware and Patching as Primary 2024 Root Causes: For 2024, CSOs identified ransomware attacks as their top priority and a key root cause of OT security incidents. Closely following ransomware, patching issues were also cited as a major contributing factor. This indicates a shift in the perceived immediate threat landscape compared to 2023, emphasizing the need for robust ransomware defense and effective vulnerability management strategies in OT.
- Widespread Deployment of Security Solutions (but with caveats): A significant 93% of surveyed companies reported deploying some form of cybersecurity solution within their OT environments, including network solutions and endpoint solutions. However, the process of selecting and proving these products via Proof of Concept (POC) often takes an average of three to six months, suggesting a cautious but slow adoption cycle.
- Mismatch Between IT and OT Security Solutions: A critical issue is the common practice of deploying IT cyber security solutions in OT environments that are not specifically designed for industrial operations. These IT-centric solutions often have drawbacks such as heavy memory usage or a lack of consideration for operational priorities (e.g., uptime, real-time control). This fundamental incompatibility can lead to performance degradation, instability, or even system downtime in sensitive OT systems, rendering the security solution counterproductive.
- Prevalence of Unprotected Windows Devices in OT: Despite the deployment of some security solutions, a substantial 61% of organizations still reported having unprotected Windows devices within their OT environments. This significant gap in coverage, whether for endpoint or network solutions, creates widespread vulnerabilities, particularly given that many industrial applications run on Windows and are susceptible to common IT-borne threats.
- Insufficient Manpower for OT Security Management: Even with deployed solutions, organizations face a severe lack of manpower to manage them effectively. The survey revealed a highly unfavorable device-to-staff ratio, with as few as one staff member responsible for over 200 OT devices. This heavy workload makes comprehensive security management, including monitoring, incident response, and solution optimization, extremely challenging.
Technical Deep Dive
▶ Watch: Trend 3: Human resource gap and IT/OT integration challenges (4:00)
The findings presented by Mars Cheng underscore a profound technical chasm between IT and OT cybersecurity. At its core, the distinction lies in the foundational priorities: IT prioritizes confidentiality, integrity, and availability (CIA), often with confidentiality taking precedence. OT, conversely, operates on the principle of availability, integrity, and confidentiality (AIC), where continuous operation and physical safety are paramount. This difference dictates every technical decision in an OT environment.
Operational Constraints and Legacy Systems: Many OT systems, particularly Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems, are designed for decades of continuous operation. They often run on legacy operating systems, including older versions of Windows (e.g., Windows XP, Windows 7, or even older embedded versions) for which vendor support has long ceased. These systems are typically difficult to patch due to vendor warranties, complex interdependencies, and the prohibitive cost of downtime. A single patch can require extensive testing, sometimes involving halting production for days or weeks, making routine patching impractical. This explains the finding that 61% of organizations still have unprotected Windows devices in OT.
Protocol and Network Architecture: OT networks often utilize specialized proprietary protocols (e.g., Modbus, Profinet, DNP3, EtherNet/IP) that differ significantly from standard IT protocols like HTTP, SMTP, or DNS. These protocols often lack inherent security features such as encryption or authentication. Furthermore, OT network architectures are frequently flat, lacking the segmentation common in IT environments. This means that a breach in one part of the OT network can quickly spread laterally, impacting critical processes. The reliance on IT-centric security solutions often overlooks these protocol specificities, leading to ineffective monitoring or even interference with real-time industrial communications.
Endpoint Security Challenges: Traditional IT Endpoint Detection and Response (EDR) or Antivirus (AV) solutions are often resource-intensive, consuming significant CPU and memory. Deploying such solutions on delicate OT endpoints or Human-Machine Interfaces (HMIs) can introduce latency, cause system crashes, or disrupt real-time control, directly violating the availability priority. This is the essence of the IT vs. OT security solution mismatch. OT-specific endpoint solutions must be lightweight, have minimal impact on system performance, and often rely on techniques like application whitelisting rather than signature-based detection to ensure operational stability.
Threat Vectors and Attack Surface: The talk highlighted phishing emails and employee actions as significant root causes. This is a technical vulnerability in the human element. Successful phishing can lead to initial access to the IT network, which can then be leveraged to pivot into the OT network, especially in environments with poor IT/OT segmentation. Once inside, ransomware (identified as a top 2024 threat) can encrypt critical files, including PLC programs, HMI configurations, or historical process data, leading to severe operational disruption. The vulnerability of unpatched systems provides easy entry points for exploits, allowing attackers to gain a foothold and move laterally.
Skill Gap Implications: The human resource gap for OT security professionals is a critical technical deficiency. IT security professionals, while skilled in network security, endpoint hardening, and vulnerability management for enterprise systems, typically lack understanding of Programmable Logic Controllers (PLCs), Distributed Control Systems (DCS), process engineering, or the specific risks associated with physical process manipulation. This means they might misconfigure security controls, misinterpret alerts from OT systems, or even inadvertently cause operational issues when attempting to implement IT-style security measures. For instance, securing a semiconductor fabrication plant requires deep knowledge of its highly sensitive and complex processes, where even minor security agent overhead could lead to wafer damage and massive financial losses.
Policy and Regulatory Impact: Emerging regulations like the EU Cyber Resilience Act aim to technically uplift OT security by mandating security-by-design principles, secure development lifecycles, and stricter incident reporting for connected devices. While these policies set the direction, the technical implementation requires organizations to re-evaluate their entire OT security stack, from secure hardware and software components to robust network segmentation and advanced threat detection capabilities tailored for industrial environments.
In summary, the technical deep dive reveals that securing critical infrastructure demands a holistic approach that respects OT's unique operational DNA, moves beyond generic IT solutions, invests in specialized technical expertise, and systematically addresses the vulnerabilities introduced by legacy systems and the IT/OT convergence.
Demo / Proof of Concept
▶ Watch: Trend 4: Reliance on third-party help for OT incidents (6:00)
The talk focused on presenting the findings from extensive surveys and analysis of cybersecurity trends within critical infrastructure. Therefore, the presentation by Mars Cheng did not include a live demonstration or a technical proof of concept of any attack vectors or defensive technologies. The content was entirely analytical, relying on collected data and expert observations to illustrate the top 10 trends.
Defensive Implications
▶ Watch: Trend 6: Common unprotected Windows devices in OT (8:55)
The insights gleaned from Mars Cheng's presentation offer crucial guidance for organizations striving to enhance their cybersecurity posture in critical infrastructure environments. Addressing the identified trends requires a multi-faceted and strategic approach that acknowledges the unique characteristics of OT.
- Develop OT-Specific Cybersecurity Policies and Governance: Organizations must move beyond generic IT policies and establish OT-specific cybersecurity frameworks that prioritize availability and safety. This includes defining clear roles and responsibilities for IT and OT teams, establishing incident response procedures tailored for industrial environments, and aligning with emerging global regulations like the EU Cyber Resilience Act. Regular audits and compliance checks against these specialized policies are essential.
- Invest Heavily in OT Operator Security Awareness and Training: Given that human factors like phishing emails and employee actions remain significant root causes, comprehensive and continuous security awareness training for all OT personnel is paramount. This training should be contextualized to the OT environment, highlighting real-world industrial scenarios, the specific risks of connecting IT and OT networks, and best practices for identifying and reporting suspicious activities. Gamification and regular simulated phishing campaigns can reinforce these lessons.
- Bridge the OT Security Professional Skill Gap: Organizations must actively address the human resource shortage by investing in specialized training programs for both existing IT and OT staff. This could involve cross-training IT professionals in industrial control systems (ICS) fundamentals and OT personnel in cybersecurity principles. Recruiting efforts should target individuals with dual IT/OT competencies or provide pathways for existing employees to acquire these specialized skills. Fostering strong IT/OT convergence through shared understanding and collaborative teams, rather than just reliance, is critical.
- Strengthen Internal OT Incident Response Capabilities: Relying on third parties for every OT incident is unsustainable. Organizations should develop and regularly test OT-specific incident response plans that account for the unique challenges of industrial environments, such as the need to maintain operations during an incident, safely isolate compromised systems, and recover from highly specialized backups. This includes establishing dedicated OT security operations centers (SOCs) or integrating OT security monitoring into existing SOCs with specialized analysts and tools.
- Prioritize Ransomware Defense and Patch Management for OT: With ransomware identified as a top threat, organizations must implement robust defense strategies. This includes comprehensive network segmentation to isolate critical OT assets from IT networks and less critical OT segments, deploying OT-specific endpoint protection that can detect ransomware without disrupting operations, and establishing immutable backups of critical industrial data and configurations. For patching issues, a risk-based approach is needed: for systems that cannot be immediately patched, implement virtual patching, network-level micro-segmentation, and continuous monitoring to detect exploit attempts. Develop a well-defined vulnerability management program tailored for OT, understanding vendor-specific patch cycles and testing requirements.
- Adopt OT-Specific Security Solutions: The widespread use of IT-centric solutions in OT is a critical misstep. Defenders should prioritize and procure OT-specific security solutions that are designed with operational priorities in mind. These solutions are typically lightweight, understand industrial protocols (e.g., Modbus, Profinet), and offer features like passive network monitoring, asset inventory, vulnerability detection without active scanning, and application whitelisting for critical endpoints. Proof-of-concept (POC) evaluations should rigorously test operational impact alongside security efficacy.
- Address Unprotected Windows Devices in OT: The 61% statistic on unprotected Windows devices is alarming. Organizations must conduct a comprehensive inventory of all Windows-based assets in their OT environment. For legacy systems that cannot be patched or upgraded, implement compensating controls such as host-based firewalls, application whitelisting (e.g., AppLocker or commercial OT-specific solutions), strict least privilege access controls, and robust network segmentation to minimize their exposure. Consider virtualization or micro-segmentation solutions to encapsulate vulnerable systems.
- Optimize Manpower and Automation: The severe manpower shortage (1 staff for >200 devices) necessitates leveraging automation and smart tools. Implement OT asset management systems for automated inventory and configuration management. Deploy security information and event management (SIEM) systems with OT connectors to centralize logs and alerts, reducing manual monitoring burden. Explore Security Orchestration, Automation, and Response (SOAR) platforms tailored for OT to automate routine incident response tasks and reduce analyst fatigue.
By systematically addressing these defensive implications, critical infrastructure operators can build a more resilient and secure operational environment, mitigating the risks highlighted by Mars Cheng's comprehensive analysis.
Key Takeaways
- OT security is fundamentally distinct from IT security: Prioritizing availability and safety over confidentiality, OT environments demand specialized solutions, policies, and personnel that cannot be effectively managed with IT-centric approaches.
- Human factors remain a critical vulnerability: Insufficient security awareness among OT operators and a severe shortage of specialized OT cybersecurity professionals are major impediments to effective defense.
- Policy and regulation are evolving, but practical implementation lags: While global policies like the EU Cyber Resilience Act are emerging, organizations struggle with the practical challenges of compliance and integrating these mandates into daily operations.
- Generic IT security solutions are often inadequate and detrimental: Deploying resource-heavy IT security tools in sensitive OT environments can cause operational disruption, highlighting the need for lightweight, OT-specific solutions.
- Unprotected legacy systems (especially Windows) pose significant risks: A large percentage of OT organizations still operate vulnerable, unpatched Windows devices, creating easy targets for ransomware and other exploits.
- Strategic investment in talent, training, and tailored technology is crucial: To overcome these challenges, organizations must invest in developing OT-specific cybersecurity expertise, implement targeted awareness programs, and adopt solutions designed to respect OT's unique operational constraints.
About the Speaker(s)
Mars Cheng is a distinguished figure in the cybersecurity community, particularly recognized for his expertise in critical infrastructure and OT security. He serves as a Research Manager at TS1 Networks, an organization dedicated to cybersecurity research and solutions. Beyond his corporate role, Cheng is a prominent advocate for hacker community engagement as the Executive Director of the Association of Hackers in Taiwan. In this capacity, he plays a pivotal role in organizing numerous cybersecurity conferences and competitions, fostering talent and knowledge exchange within the region. His extensive experience includes speaking at various international cybersecurity conferences, including a recent presentation at Black Hat USA 2024 just prior to his appearance at DEF CON 32, underscoring his reputation as a thought leader and frequent contributor to the global security discourse.