The first distributed cyberattack on multiple U.S. water systems indicates a coordinated Iranian campaign targeting programmable logic controllers, potentially linked through shared infrastructure or a systems integrator.
Germany integrates physical protective measures against drone attacks on electrical power, water, communications and transport infrastructure for the first time through the KRITIS Umbrella Law and NIS2 implementation.
CISA and international authorities recommend physical or tiered network isolation for OT systems of critical infrastructure with regular full tests and manual operation in an isolated state.
SOC practices for OT and ICS environments require specialized architectural models and organizational adaptations to meet regulatory requirements such as the NIS2 Directive while ensuring the availability of critical systems.
Logistics networks with weak security governance become preferred targets for organized theft rings, as cyber-enabled freight theft offers lower risk with higher yields than traditional retail theft.
Approximately 29,500 German entities must register with their competent authority by July 2024 in accordance with the NIS2 Directive to demonstrate legal compliance.
Iran-backed hackers manipulate PLC project files to alter operational parameters and disable safety logics while operators remain unaware of the anomalies.
Dutch companies must implement the NIS2 Directive from 15 August 2024, affecting approximately 8,000 organizations and mandating strict cybersecurity standards.
Zero-Trust verification of user identity and device trustworthiness reduces the attack surface on critical infrastructure that exploits stolen or compromised accounts.
Austria requires critical entities through the RKEG to conduct risk analyses, develop resilience plans, and report security incidents to the Interior Ministry.