Skip to main content

SANS 2024 State of ICS/OT Cybersecurity

This white paper, SANS Certified Instructor Jason Christopher explores the growing trends in cyber threats, vulnerabilities, and risks across industrial environments, including actionable recommendations for how organizations can improve their security posture.

SANS-Survey-2024-ICS-OT-Cybersecurity-edit (PDF, 2.31MB)

9 Oct 2024
BySANS Institute
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Securing the Sun: Impact-Effective Cybersecurity Controls for Solar SCADA

Research Paper

Based on research conducted with a custom-built lab emulating a utility-grade solar SCADA network, this paper details the greatest impact on a solar site, in the form of physical consequences to power generation capabilities.

  • 11 Jun 2026
  • Wesley D. Barrier

Sanitized in the Source: Removing Embedded Objects from PLC Projects with CDR

Research Paper

This research seeks to outline a methodology to sanitize supported PLC project files for security while also confirming their operational reliability.

  • 16 Apr 2026
  • James Turner

ICS Asset Inventory: Passive, or Active? Siemens S7-1200 PLCs

Research Paper

This research builds on previous research to determine what information can and cannot be gleaned solely from passive traffic analysis, specifically for a Siemens S7-1200 PLC.

  • 12 Mar 2026
  • Justin Wilson

Protecting OT’s Inherent Front-End Vulnerabilities: Legacy SQL Dependencies in Building Automation Systems Through the Lens of the SANS ICS Five Critical Controls

Research Paper

This research presents a practical method for building a Software Bill of Materials (SBOM) for BAS front ends, augmenting it with Shodan exposure analysis, classifying it in a risk heat map, and mitigating using the SANS ICS Five Controls, with an emphasis on Risk-Based Vulnerability Management and Defensible Architecture.

  • 9 Feb 2026
  • Tanner Green

Defensible IEC 61850 Substation Network Security Monitoring with Zeek

Research Paper

This study introduces a Zeek-based monitoring framework that leverages transport layer and layer two invariants, such as MAC and VLAN integrity, multicast group membership, traffic rates, and MMS connection behavior, to detect the most consequential precursors to substation misoperation.

  • 26 Jan 2026
  • Elliot Lee

Code Modularity as a Heuristic for Malware Design

Research Paper

Malware targeting industrial control systems (ICS) and critical infrastructure often exhibits a modular architecture, using a central loader to execute interchangeable payload modules.

  • 7 Nov 2025
  • Joseph Edwards

Structural Vulnerability: Autodesk Revit Server WAN Exposure Versus Cost of Autodesk Construction Cloud

Research Paper

Autodesk Revit Server, a critical collaboration tool in the architecture, engineering, and construction (AEC) industry, was designed to operate within trusted networks.

  • 7 Nov 2025
  • Joshua Hall

Privacy Protections: Are Stronger Laws Changing What We Reveal?

Research Paper

As U.S. states enact privacy laws aimed at giving consumers more control over their personal data, little is known about whether privacy legislation influences individuals’ willingness to disclose their identity on public platforms.

  • 26 Sep 2025
  • Katie Christensen

Forensic Investigation of Bluetooth-Based Credit Card Skimmers

Research Paper

Hidden Bluetooth Low Energy (BLE) credit skimmers are a growing threat to credit card fraud. Criminals can set up practical and inexpensive systems built on top of modules, such as the HM-19, to collect and transmit stolen data covertly across wireless channels.

  • 3 Sep 2025
  • John Passaro

A Pebble In the Ocean: Maximizing Log Fidelity In Container Environments

Research Paper

Log fidelity is crucial for Incident Response Teams to investigate and contain cyber incidents but can be difficult to optimize in containerized environments.

  • 17 Apr 2025
  • Zach Salva

Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender

Research Paper

Using the SANS ICS Cyber Kill Chain, the research implemented a representative ICS network to evaluate the effectiveness of security controls for use by small ICS defenders.

  • 14 Apr 2025
  • Oren Niskin

Unveiling the Dependency on Network Telemetry: Optimizing Lateral Movement Detection

Research Paper

This study investigates the dependency on network and endpoint telemetry for identifying lateral movement attacks, focusing on the Remote Services technique from MITRE ATT&CK.

  • 17 Jan 2025
  • Kyu Jin Therrien

Beyond Detection: Using Real Phishing Data to Gauge Security Training Program Success

Research Paper

This paper defines one method of network security monitoring in an organization to find these existing indicators.

  • 7 Jan 2025
  • Cory Keller

Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords

Research Paper

As digital threats grow increasingly sophisticated, traditional password-based authentication systems are proving inadequate, leaving enterprises vulnerable to phishing, credential stuffing, and other cyberattacks.

  • 23 Dec 2024
  • Rich Greene

Protecting the Poor: A Deep Dive into EBT Skimming and Solutions to Combat It

Research Paper

This paper examines why EBT cards are vulnerable to skimming and explores potential preventive measures.

  • 23 Dec 2024
  • Anthony Vespa

Industrial Control System Internal Network Security Monitoring with Open-Source Tools

Research Paper

Security vendors have made many advances in internal network security monitoring (INSM) in recent...

  • 5 Dec 2024
  • Charles Carroll

The Open-Source Trap: Unraveling Open-Source Threats in the Software Supply Chain

Research Paper

The risk to the software supply chain is increasingly clear, as breaches like SolarWinds, Equifax,...

  • 5 Dec 2024
  • Clayton Boozell

False Data Injection Attacks Against Distribution Automation Systems

Research Paper

Utility companies increasingly rely on automated switching to provide their customers with a...

  • 5 Dec 2024
  • Ryan McAndrews

Hook, Line, and Sinker: The Best Free Tools to Catch Phishing

Research Paper

Phishing has become a widespread threat that organizations and IT security teams face daily. As...

  • 5 Dec 2024
  • Corrina Taylor

Shedding Light on OT Anomalies: Parsing Proprietary OT Protocols with Zeek

Research Paper

Many traditional intrusion detection systems (IDS) may struggle with the unique devices and...

  • 9 Oct 2024
  • James Clee