{"id":4582,"date":"2023-11-10T16:49:10","date_gmt":"2023-11-10T03:49:10","guid":{"rendered":"https:\/\/ostermanresearch.com\/2023\/11\/10\/sans-2021\/"},"modified":"2025-03-11T06:37:49","modified_gmt":"2025-03-10T17:37:49","slug":"sans-2021","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2023\/11\/10\/sans-2021\/","title":{"rendered":"SANS report from 2021 on cybersecurity in OT\/ICS"},"content":{"rendered":"\n<p>In August 2021, SANS <a href=\"https:\/\/www.sans.org\/white-papers\/SANS-2021-Survey-OTICS-Cybersecurity\/\" target=\"_blank\" rel=\"noreferrer noopener\">published a report on cybersecurity<\/a> in OT (operational technology) and ICS (industrial control systems) environments. The findings are based on a survey of 480 organizations in relevant industries. <\/p>\n\n\n\n<p>Among many other things, respondents were asked if they&#8217;d experienced one or more security incidents involving their OT\/ICS environment over the previous 12 months. 15.1% said yes. See the graph on page 8. On the next page, there are two additional graphs &#8211; the number of incidents in the past 12 months (with 42.9% saying &#8220;less than 10&#8221;) and an assessment of how disruptive the incidents were (with only 9.5% saying &#8220;no impact\/disruption&#8221;).<\/p>\n\n\n\n<p>We often use something we call &#8220;midpoint analysis&#8221; in creating averages. This means looking at the distribution of answers for the various answer options, and multiplying the midpoint of each answer option (e.g., the midpoint of &#8220;1 to 5 hours&#8221; is 3 hours) by the frequency with which the respondent said &#8220;that&#8217;s me.&#8221; If 25% chose the 1-5 hours answer option, then the contribution to the overall midpoint is 3 hours x 25%, or 0.75 hours. Once we&#8217;ve done this for the remaining 75% of respondents, we sum the contribution of each answer option to get the overall midpoint.<\/p>\n\n\n\n<p>We ran this with the numbers for incidents and disruption in the SANS report &#8211; see below.   <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2023\/11\/sansanalysis2.png?ssl=1\" alt=\"\" class=\"wp-image-146\" \/><\/figure>\n\n\n\n<p>From the above, we&#8217;d state the following. For the 15.1% of respondents that suffered at least one security incident in the previous 12 months:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The midpoint number of incidents was <strong>64.3<\/strong> per organization.<\/li>\n\n\n\n<li>The midpoint percentage of disruption was <strong>32.1%<\/strong>, meaning that around one third of the affected process was disrupted or disabled.<\/li>\n\n\n\n<li>This is equivalent to <strong>20.65 incidents per year<\/strong> that are fully disruptive for some amount of time.<\/li>\n<\/ul>\n\n\n\n<p>For anyone responsible for an OT\/ICS environment, those are not numbers you want to see.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In August 2021, SANS published a report on cybersecurity in OT (operational technology) and ICS (industrial control systems) environments. The findings are based on a survey of 480 organizations in relevant industries. Among many other things, respondents were asked if they&#8217;d experienced one or more security incidents involving their OT\/ICS environment over the previous 12 [&hellip;]<\/p>\n","protected":false},"author":384585,"featured_media":4760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027491],"tags":[712027511],"class_list":["post-4582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-reports","tag-cybersecurity"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2023\/11\/sans2021.png?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1bU","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4582"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4582\/revisions"}],"predecessor-version":[{"id":4679,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4582\/revisions\/4679"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4760"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}