Data Centre OT Security: One in Five Assets Exposed
Claroty research reported by Economic Times Data Centres indicates that nearly one in five operational assets across large data centres are one network step away from systems an attacker could reach. In the study of more than 750,000 cyber-physical-system assets, power distribution equipment and cooling systems stood out as the most exposed categories. The findings also point to persistent building-management and IoT risk: 88% of building-management systems communicated using insecure protocols, while 23% of IoT devices had known exploited vulnerabilities. The report reinforces the importance of exposure management, OT/IT segmentation, firmware hygiene, and continuous monitoring for facilities that depend on power, cooling, and automation controls.
Source: Economic Times Data Centres
New CISA–ACSC Guidance Focuses on Isolating Vital OT Systems
CISA, the Australian Signals Directorate’s Australian Cyber Security Centre, and partners have issued CI Fortify – Advice for isolating vital systems, guidance intended to help critical-infrastructure operators sustain essential services during cyber incidents or major disruptions. The guidance emphasizes planning isolation before an event occurs: identifying vital OT and enabling systems, mapping dependencies and external connections, defining isolation points, and testing staged isolation procedures. It also cautions that logical controls alone may not provide durable separation and encourages operators to account for the operational risks created when systems must run in a more isolated state.
Source: Security Measures Lab
CISA Publishes 11 New ICS Advisories Covering Industrial and Building Systems
A July 30 CISA advisory release included 11 new industrial-control-system advisories and one updated advisory. The affected products span industrial, building, communications, and protocol environments, including Johnson Controls OpenBlue Employee, Schneider Electric IGSS, Rockwell Automation CompactLogix and ControlLogix communications modules, Mitsubishi Electric CC-Link IE TSN, o6 Automation open62541, Watchfire Controller Software, and MZ Automation IEC protocol libraries. Asset owners should review the relevant vendor and CISA advisory details, determine product exposure, and apply mitigations in accordance with site-specific operational constraints.