CyberzSOC

Publication detail
← Back to advisories & guidance

Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products ↗ source

January 13, 2025 FBI Alert
Co-sealed by: ASD/ACSC, BSI, CCCS, CISA, EPA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK, NSA, TSA

Summary

Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems. When security is not prioritized nor incorporated directly into OT products, it is difficult and costly for owners and operators2 to defend their OT assets against compromise. This Secure by Demand guide, authored by CISA with contributions from the following partners, describes how OT owners and operators should integrate security into their procurement process when purchasing industrial automation and control systems as well as other OT products. 1 CISA’s Secure by Design campaign urges technology providers to take ownership of their customers’ security outcomes by building cybersecurity into design and development. As part of CISA’s campaign, CISA and partners developed three core principles to guide software manufacturers in building software security into their design Principles and Approaches for Secure by Design Software. 2 European Union (EU) legislation refers to essential and important entities, such as critical infrastructures as well as entities in the manufacturing sector.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.