← Back to advisories & guidance
January 13, 2025
FBI
Alert
Co-sealed by: ASD/ACSC, BSI, CCCS, CISA, EPA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK, NSA, TSA
Summary
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems. When security is not prioritized nor incorporated directly into OT products, it is difficult and costly for owners and operators2 to defend their OT assets against compromise. This Secure by Demand guide, authored by CISA with contributions from the following partners, describes how OT owners and operators should integrate security into their procurement process when purchasing industrial automation and control systems as well as other OT products. 1 CISA’s Secure by Design campaign urges technology providers to take ownership of their customers’ security outcomes by building cybersecurity into design and development. As part of CISA’s campaign, CISA and partners developed three core principles to guide software manufacturers in building software security into their design Principles and Approaches for Secure by Design Software. 2 European Union (EU) legislation refers to essential and important entities, such as critical infrastructures as well as entities in the manufacturing sector.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.