The recent FrostyGoop breach underscores a fundamental truth in the cybersecurity landscape: Attackers will target where they perceive vulnerabilities. When obstacles are significant, they simply shift their focus to other targets, seeking out new victims.
In April, FrostyGoop, which leverages Modbus TCP for operational technology (OT) attacks, compromised an energy company in Lviv, Ukraine. This incident caused a two-day interruption in heating services for customers. It highlights the increasing risk faced by municipal networks as state-sponsored attackers target critical infrastructure amid rising geopolitical tensions.
While achieving flawless security is unattainable, organizations can aim to create defenses robust enough to deplete an attacker’s resources, thereby encouraging them to abandon their efforts or move elsewhere. Achieving this requires three critical components: dedicated leadership, a skilled project team, and a sufficient budget to implement necessary measures effectively.
Organizations of all sizes must prioritize their capital investments wisely. This decision-making process must strike a balance between under-investing and over-engineering solutions. Conducting thorough risk assessments and clearly defining security needs are crucial for allocating resources effectively. Numerous frameworks exist to guide this process for industrial-controlled systems (ICS). For example, the SANS Institute provides a free guide outlining five essential ICS/OT cybersecurity controls, enabling even non-specialist executives to oversee and enforce basic security standards. These controls can range from cost-effective internal implementations to more expensive external consulting projects employing best practices.
Strengthening Defensible Architecture
One of the primary focuses within SANS’s five critical controls is developing a defensible architecture. This means designing a system that minimizes agreed-upon risks through thoughtful design and implementation. As noted by SANS, the human element is crucial for transforming a defensible architecture into a defended one.
Key characteristics of a defensible architecture include gaining accurate visibility over crucial assets, segmenting networks when feasible, limiting bidirectional communication to necessary instances, collecting traffic and logs from vital systems, and establishing a robust cyber defense posture. These measures are vital for preventing attackers from accessing and maintaining control over critical systems.
Securing Remote Access
Securing remote access is another essential area. Traditionally, OT networks were isolated from the internet, but the rise of remote work and the need for operational efficiency have made remote access commonplace. This connectivity, while convenient, introduces significant security risks if not managed correctly.
Organizations must ensure remote access is secure by employing strong authentication methods like multifactor authentication (MFA). Access should be granted on a least-privilege basis, providing users only with the resources necessary for their roles. Implementing Virtual Private Networks (VPNs) and monitoring remote sessions for unusual activity can further enhance security. Additionally, establishing clear remote access policies ensures adherence to best practices and prompt response to potential security incidents.
The Ripple Effect of Breaches
It’s crucial to understand that a successful breach often has a cascading effect, potentially impacting:
- Other organizations using similar vulnerable technologies, such as unpatched routers.
- Entities with similar architectural weaknesses, allowing attackers to exploit alternative vulnerabilities.
- Vendors within the same industry, leading to broader supply chain attacks.
- Organizations under the same governmental jurisdiction, like municipal utilities or administrative offices.
The Human Element: Talent and Culture
Discussions between cybersecurity professionals and adversary simulation experts frequently highlight a shortage of talent or budget constraints. When talent is available, solutions tend to be more effective. In its absence, decision-makers often rely on persuasive sales pitches for new cybersecurity solutions.
To advance the industry, we must make cybersecurity roles as appealing as offensive roles. Social media often highlights red team achievements more dramatically than the more discreet successes of blue teams. Proper defenders often don’t know what they’ve prevented, while successful breaches are more visible and celebrated. By fostering a culture that values defenders, we can ensure our organizations stay vigilant and prepared against evolving threats.
Building a Resilient Cybersecurity Posture
As Bruce Schneier aptly puts it, “attacks never get weaker, they only ever get stronger.” Our security posture must be robust enough to withstand past attacks and more. This doesn’t require an unlimited budget, but rather strategic investment in effective security measures for a reasonable cost.
The FrostyGoop incident serves as a crucial reminder for municipal leaders and cybersecurity professionals. By focusing on strategic investments, strengthening defensible architecture, securing remote access, and valuing the human element in cybersecurity, organizations can build a resilient defense against emerging threats. It’s time to acknowledge the essential role of defenders and support them in safeguarding our critical infrastructure.



