{"id":37780,"date":"2020-10-21T22:00:35","date_gmt":"2020-10-21T22:00:35","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=92110"},"modified":"2020-10-21T22:00:35","modified_gmt":"2020-10-21T22:00:35","slug":"addressing-cybersecurity-risk-in-industrial-iot-and-ot","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/","title":{"rendered":"Addressing cybersecurity risk in industrial IoT and OT"},"content":{"rendered":"<p>As the industrial Internet of Things (IIoT) and operational technology (OT) continue to evolve and grow, so too, do the responsibilities of the Chief Information Security Officer (CISO). The CISO now needs to mitigate risks from cloud-connected machinery, warehouse systems, and smart devices scattered among hundreds of workstations. Managing those security risks includes the need to ensure safety in manufacturing, <a href=\"https:\/\/cyberx-labs.com\/blog\/how-to-translate-safety-into-security\/\" target=\"_blank\" rel=\"noopener noreferrer\">oil and gas facilities<\/a>, public utilities, transportation, civic infrastructure, and more.<\/p>\n<p>Analysts predict that we\u2019ll have roughly <a href=\"https:\/\/www.statista.com\/statistics\/1101442\/iot-number-of-connected-devices-worldwide\/\" target=\"_blank\" rel=\"noopener noreferrer\">21.5 billion IoT devices<\/a> connected worldwide in 2025, drastically increasing the surface area for attacks. Because embedded devices often go unpatched, CISO\u2019s need new strategies to mitigate IIoT\/OT risks that differ in crucial ways from those found in information technology (IT). The difference needs to be understood by your Board of Directors (BoD) and leadership team. Costly production outages, safety failures with injuries or loss of life, environmental damage leading to liability\u2014all are potentially disastrous scenarios that have moved IIoT and OT to the center of cyber threat management.<\/p>\n<h2>An evolving threat landscape<\/h2>\n<p>Both IIoT and OT are considered cyber-physical systems (CPS); meaning, they encompass both the digital and physical worlds. This makes any CPS a desirable target for adversaries seeking to cause environmental contamination or operational disruption. As recent history shows, such attacks are already underway. Examples include the <a href=\"https:\/\/www.darkreading.com\/operations\/industrial-safety-systems-in-the-bullseye\/d\/d-id\/1330912\" target=\"_blank\" rel=\"noopener noreferrer\">TRITON attack<\/a>\u2014intended to cause a serious safety incident\u2014on a Middle East chemical facility and the <a href=\"https:\/\/www.wired.com\/2016\/03\/inside-cunning-unprecedented-hack-ukraines-power-grid\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ukrainian electrical-grid attacks<\/a>. In 2017, ransomware dubbed <a href=\"https:\/\/www.wired.com\/story\/notpetya-cyberattack-ukraine-russia-code-crashed-the-world\/\" target=\"_blank\" rel=\"noopener noreferrer\">NotPetya<\/a> paralyzed the mighty Maersk shipping line and nearly halted close to a fifth of the world\u2019s shipping capacity. It also spread to pharma giant Merck, FedEx, and numerous European firms before boomeranging back to Russia to attack the state oil company, Rosneft.<\/p>\n<p>In 2019, Microsoft observed a <a href=\"https:\/\/msrc-blog.microsoft.com\/2019\/08\/05\/corporate-iot-a-path-to-intrusion\/\" target=\"_blank\" rel=\"noopener noreferrer\">Russian state-sponsored attack using IoT smart devices<\/a>\u2014a VOIP phone, an office printer, and a video decoder\u2014as entry points into corporate networks, from which they attempted to elevate privileges. Attackers have even compromised <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/hackers-use-smart-building-access-control-systems-to-launch-ddos-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">building access control systems<\/a> to move into corporate networks using distributed denial-of-service (DDoS) attacks; wherein, a computer system is overwhelmed and crashed with an onslaught of traffic.<\/p>\n<h2>The current model<\/h2>\n<p>Since the 1990\u2019s, the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Purdue_Enterprise_Reference_Architecture\" target=\"_blank\" rel=\"noopener noreferrer\">Purdue Enterprise Reference Architecture<\/a> (PERA), aka the Purdue Model, has been the standard model for organizing (and segregating) enterprise and industrial control system (ICS) network functions. PERA divides the enterprise into various \u201cLevels,\u201d with each representing a subset of systems. Security controls between each level are typified by a \u201cdemilitarized zone\u201d (DMZ) and a firewall.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-92112 size-medium alignright\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/10\/Picture2-300x196.jpg\" alt width=\"300\" height=\"196\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/10\/Picture2-300x196.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/10\/Picture2-768x502.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/10\/Picture2-200x130.jpg 200w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/10\/Picture2.jpg 821w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\"><\/p>\n<p>Conventional approaches restrict downward access to Level 3 from Levels 4, 5 (and the internet). Heading upward, only Layer 2 or 3 can communicate with Layers 4 and 5, and the lowest two Levels (machinery and process) must keep their data and communications within the organization\u2019s OT.<\/p>\n<p>But in our IIoT era, data no longer flows in a hierarchical fashion as prescribed by the Purdue Model. With the rise of edge computing, smart sensors, and controllers (Levels O, 1) now bypass firewalls and communicate directly with the cloud, creating new risks for system exposure.<\/p>\n<p>Modernizing this model with <a href=\"https:\/\/cyberx-labs.com\/video\/cyberx-webinar-practical-zero-trust-strategies-for-iot-ot-network-defenders\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zero Trust<\/a> principles at Levels 4 and 5 can help bring an organization\u2019s IIoT\/OT into full compliance for the cloud era.<\/p>\n<h2>A new strategy<\/h2>\n<p><a href=\"https:\/\/inl.gov\/cce\/\" target=\"_blank\" rel=\"noopener noreferrer\">Consequence-driven cyber-informed engineering<\/a> (CCE) is a new methodology designed by Idaho National Labs (INL) to address the unique risks posed by IIoT\/OT. Unlike conventual approaches to cybersecurity, CCE views consequence as the first aspect of risk management and proactively engineers for potential impacts. Based on CCE, there are <a href=\"https:\/\/cyberx-labs.com\/resources\/sans-webinar-cce-inl-new-approach-securing-critical-industrial-infrastructure\/\" target=\"_blank\" rel=\"noopener noreferrer\">four steps<\/a> that your organization\u2014public or private\u2014should prioritize:<\/p>\n<ol>\n<li><strong>Identify your \u201ccrown jewel\u201d processes:<\/strong> Concentrate on protecting critical \u201cmust-not-fail\u201d functions whose failure could cause safety, operational, or environmental damage.<\/li>\n<li><strong>Map your digital estate:<\/strong> Examine all the digital pathways that could be exploited by adversaries. Identify all of your connected assets\u2014IT, IoT, building management systems (BMS), OT, smart personal devices\u2014and understand who has access to what, including vendors, maintenance people, and remote workers.<\/li>\n<li><strong>Spotlight likely attack paths:<\/strong> Analyze vulnerabilities to determine attack routes leading to your crown jewel processes, including possible social engineering schemes and physical access to your facilities.<\/li>\n<li><strong>Mitigate and protect: <\/strong>Prioritize options that allow you to \u201cengineer out\u201d cyber risks that present the highest consequences. Implement Zero Trust segmentation policies to separate IIoT and OT devices from other networks. Reduce the number of internet-accessible entry points and patch vulnerabilities in likely attack paths.<\/li>\n<\/ol>\n<h2>Making the case in real terms<\/h2>\n<p>Your leadership and BoD have a vested interest in seeing a return on investment (ROI) for any new software or hardware. Usually, the type of ROI they want and expect is increased revenue. But returns on security software often can\u2019t be seen in a quarterly statement. That means cybersecurity professionals have to <a href=\"https:\/\/cyberx-labs.com\/webinars\/sans-webinar-a-cisos-perspective-on-presenting-ot-risk-to-the-board\/\" target=\"_blank\" rel=\"noopener noreferrer\">present a solid case<\/a>. Here are some straightforward benefits to investing in IIoT\/OT cybersecurity software that you can take into the boardroom:<\/p>\n<ul>\n<li><strong>Prevent safety or environmental costs:<\/strong>&nbsp;Security failures at chemical, mining, oil, transportation, or other industrial facilities can cause consequences more dire than an IT breach. Lives can be lost, and costs incurred from toxic clean-up, legal liability, and brand damage can reach into the hundreds of millions.<\/li>\n<li><strong>Minimize downtime:<\/strong>&nbsp;As the NotPetya and <a href=\"https:\/\/www.wired.com\/story\/lockergoga-ransomware-crippling-industrial-firms\/\" target=\"_blank\" rel=\"noopener noreferrer\">LockerGoga<\/a> attacks demonstrated, downtime incurs real financial losses that affect everyone\u2014from plant personnel all the way up to shareholders.<\/li>\n<li><strong>Stop IP theft:<\/strong>&nbsp;Companies in the pharmaceutical industry, energy production, defense, high-tech, and others spend millions on research and development. Losses from having their intellectual property stolen by nation states or competitors can also be measured in the millions.<\/li>\n<li><strong>Avoid regulatory fines: <\/strong>Industries such as pharmaceuticals, oil\/gas, transportation, and <a href=\"https:\/\/cyberx-labs.com\/webinars\/sans-webinar-securing-unmanaged-iot-devices-in-healthcare-life-sciences\/\" target=\"_blank\" rel=\"noopener noreferrer\">healthcare<\/a> are heavily regulated. Therefore, they are vulnerable to large fines if a security breach in IIoT\/OT causes environmental damage or loss of life.<\/li>\n<\/ul>\n<h2>The way forward<\/h2>\n<p>For today\u2019s CISO, securing the digital estate now means being accountable for all digital security\u2014IT, OT, IIoT, BMS, and more. This requires an integrated approach\u2014embracing people, processes, and technology. A good checklist to start with includes:<\/p>\n<ul>\n<li>Enable IT and OT teams to embrace their common goal\u2014supporting the organization.<\/li>\n<li>Bring your IT security people onsite so they can understand how OT processes function.<\/li>\n<li>Show OT personnel how visibility helps the cybersecurity team increase safety and efficiency.<\/li>\n<li><a href=\"https:\/\/cyberx-labs.com\/video\/bringing-it-ot-together-expert-roundtable\/#gf_12\" target=\"_blank\" rel=\"noopener noreferrer\">Bring OT and IT together<\/a> to find shared solutions.<\/li>\n<\/ul>\n<p>With attackers now pivoting across both IT and OT environments, Microsoft developed <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/#product-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Defender for IoT<\/a> to integrate seamlessly with <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sentinel\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Sentinel<\/a> and <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sphere\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Sphere<\/a>\u2014making it easy to track threats across your entire enterprise. Azure Defender for IoT utilizes:<\/p>\n<ul>\n<li>Automated asset discovery for both new greenfield and legacy unmanaged IoT\/OT devices.<\/li>\n<li>Vulnerability management to identify IIoT\/OT risks, detect unauthorized changes, and prioritize mitigation.<\/li>\n<li>IIoT\/OT-aware behavioral analytics to detect advanced threats faster and more accurately.<\/li>\n<li>Integration with Azure Sentinel and third-party solutions like other SIEMs, ticketing, and CMDBs.<\/li>\n<\/ul>\n<p>Azure Defender for IoT makes it easier to see and mitigate risks and present those risks to your BoD. Microsoft invests more than USD1 billion annually on cybersecurity research, which is why Azure has more <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-home?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\">compliance certifications<\/a> than any other cloud provider.<\/p>\n<p>Plain language and concrete examples go far when making the case for IIoT\/OT security software. Your organization should define what it will\u2014and more importantly, will not\u2014tolerate as operational risks. For example: \u201cWe tolerate no risk to human life or safety\u201d; \u201cno permanent damage to the ecosystem\u201d; \u201cno downtime that will cost jobs.\u201d Given the potential for damages incurred from downtime, injuries, environmental liability, or tarnishing your brand, an investment in cybersecurity software for IIoT\/OT makes both financial and ethical sense.<\/p>\n<p>To learn more about Microsoft Security solutions, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener noreferrer\">visit our website<\/a>.&nbsp; Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/10\/21\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the industrial Internet of Things (IIoT) and operational technology (OT) continue to evolve and grow, so too, do the responsibilities of the Chief Information Security Officer (CISO). The CISO now needs to mitigate risks from cloud-connected machinery, warehouse systems, and smart devices scattered among hundreds of workstations. Managing those security risks includes the need&#8230;<br \/>\nThe post Addressing cybersecurity risk in industrial IoT and OT appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":37781,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,77,236,1064],"class_list":["post-37780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-iot","tag-iot-security","tag-security-intelligence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-21T22:00:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"196\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Addressing cybersecurity risk in industrial IoT and OT\",\"datePublished\":\"2020-10-21T22:00:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/\"},\"wordCount\":1319,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg\",\"keywords\":[\"Cybersecurity\",\"IoT\",\"IoT security\",\"Security Intelligence\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/\",\"name\":\"Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg\",\"datePublished\":\"2020-10-21T22:00:35+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg\",\"width\":300,\"height\":196},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Addressing cybersecurity risk in industrial IoT and OT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/","og_locale":"en_US","og_type":"article","og_title":"Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-10-21T22:00:35+00:00","og_image":[{"width":300,"height":196,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Addressing cybersecurity risk in industrial IoT and OT","datePublished":"2020-10-21T22:00:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/"},"wordCount":1319,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg","keywords":["Cybersecurity","IoT","IoT security","Security Intelligence"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/","url":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/","name":"Addressing cybersecurity risk in industrial IoT and OT 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg","datePublished":"2020-10-21T22:00:35+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/addressing-cybersecurity-risk-in-industrial-iot-and-ot.jpg","width":300,"height":196},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/addressing-cybersecurity-risk-in-industrial-iot-and-ot\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Addressing cybersecurity risk in industrial IoT and OT"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=37780"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37780\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/37781"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=37780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=37780"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=37780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}