news.mlab.sh
Back to the feed
threat-intel

You Need Cyber Deception for OT

High
Summary

Operational Technology (OT) systems present a significant challenge for cybersecurity due to the lack of traditional security telemetry and the difficulty in tracing attacker activity after they move from IT networks into OT environments. Cyber deception offers a solution by creating realistic decoys and traps that expose attacker behavior across the entire attack path, regardless of where it originates. This allows defenders to gain insights and respond more effectively to IT-to-OT attacks, as demonstrated by the 2015 Ukrainian power grid attack.

Operational Technology (OT) systems, such as those controlling industrial processes and critical infrastructure, are increasingly vulnerable to cyberattacks. A key obstacle for defenders is the inherent difficulty in securing these systems, primarily because they don’t generate the same type of security telemetry as traditional IT networks. After an attacker successfully moves from an enterprise IT network into an OT environment, investigators often find a ‘black box’ – an environment with little to no useful security logs or forensic data. This makes it incredibly challenging to understand how an attack unfolded and to effectively respond to it.

Traditional IT security investigations rely on a set of familiar questions: Who logged in? What process was executed? Was a known command-and-control address contacted? However, these questions are often impossible to answer with confidence in OT environments. A Programmable Logic Controller (PLC) won’t reveal if an attacker queried it, and a Remote Terminal Unit (RTU) won’t produce meaningful authentication logs. Even if logs exist, they may be retained locally, overwritten quickly, or in formats incompatible with standard security analytics tools.

Cyber deception addresses these problems by creating a layered defense strategy that mimics real IT and OT assets. These decoys – fake credentials, simulated devices, and misleading information – are strategically placed to entice attackers and expose their activity. The goal is to create a believable attack path, allowing defenders to observe an attacker’s movements and gather intelligence across both IT and OT domains.

The 2015 Ukrainian power grid attack serves as a stark example. The attackers gained initial access through enterprise IT systems, meticulously gathering reconnaissance and harvesting credentials before moving into the OT network. The lack of security telemetry in the OT environment made it nearly impossible to determine the full scope of the attack and to identify the attacker’s methods. Had deceptive elements – such as fake credentials, decoy devices, and misleading network diagrams – been deployed in both IT and OT, defenders would have been able to detect the attack earlier and gain valuable intelligence about the attacker’s tactics and objectives.

Cyber deception doesn’t require transforming every OT asset into a modern IT endpoint. Instead, it focuses on creating believable decoys that expose an attacker’s behavior without disrupting operational processes. By observing an attacker interacting with these decoys, defenders can gain a comprehensive understanding of the attack path and respond with greater precision and confidence.

Read the full article at Dark Reading