CA-ARMIS
Armis, the leading asset visibility and security company, today released new research identifying the riskiest devices that pose threats to critical infrastructure industries: manufacturing, utilities and transportation. Data analyzed from the Armis Asset Intelligence and Security Platform, which tracks over three billion assets, found that the operational technology (OT) and industrial control systems (ICS) devices that present the highest risk to these industries are engineering workstations, SCADA servers, automation servers, historians and programmable logic controllers (PLCs).
Prioritization and vulnerability management remains an issue
Armis research found that engineering workstations are the OT device that received the most attempts of attack in the industry in the past two months, followed by SCADA servers. Fifty-six percent of engineering workstations have at least one unpatched critical severity Common Vulnerabilities and Exposures (CVEs) and 16% are susceptible to at least one weaponized CVE, published more than 18 months ago.
Uninterruptible Power Supplies (UPS) are the third device type that suffered the most attack attempts in the past two months. Although critical for continuity in an event of power outage, data showed that 60% of UPS devices have at least one unpatched critical severity CVE, which, as we saw with TLStorm, could potentially lead criminals to cause physical damage to the device itself or other assets connected to it.
Programmable Logic Controllers (PLCs) are another example, with 41% having at least one unpatched critical severity CVE. These legacy devices are of high importance as, if attacked, could lead to the disruption of central operations, but the research highlighted they can be susceptible to high risk factors such as end of support hardware and end of support firmware.
A set of additional devices represent risk to manufacturing, transportation and utilities environments as they have at least one weaponized CVE published before January 2022: 85% of barcode readers, 32% of industrial managed switches, 28% of IP cameras and 10% of printers.
OT industries are characterized by having multiple locations, multiple lines of production and complex distribution lines with a vast amount of both managed and unmanaged devices on their networks. In that context, understanding where risk comes from and remediation is needed presents a significant challenge and can be an obstacle to vulnerability management, posing an entry point for malicious actors.
“In an ICS environment it's pretty common to have vulnerable devices, so professionals need to see what assets are on their network and additional intelligence on what those devices are actually doing,” said Nadir Izrael CTO and Co-founder of Armis. “Contextual data will enable teams to define what risk each device poses to the OT environment so that they can prioritize remediation of critical and/or weaponized vulnerabilities to quickly reduce the attack surface.”
There is a need for collaboration between OT and IT teams
OT industries have significantly changed in the past years due to the convergence of OT and Information Technology (IT). This alignment is driving a new phase for the Industrial Era and will enable cross-domain collaboration but, in practice, unified management of both environments has yet to take place. With OT teams focused on maintaining industrial control systems, mitigating risks to OT and ensuring overall integrity within operational environments, more IT focused duties have been left aside.
Four out of the five riskiest devices notably run Windows operating systems, showcasing how a basic understanding of asset risk and securing vulnerable assets is still a challenge for IT and OT teams.
Armis looked at device types and found that many are more exposed to malicious activity because they are using the SMBv.1 protocol, end of support operating systems and many open ports. SMBv.1 is a legacy, unencrypted and complicated protocol with vulnerabilities that have been targeted in the infamous Wannacry and NotPetya attacks. Security experts previously advised organizations to stop using it completely, but the data shows it is still preeminent in the field.
“From an organizational perspective, having a risk-based approach to vulnerability management must go hand in hand with OT and IT departments working together to help coordinate mitigation efforts,” continued Izrael. “Cross-departmental projects will help streamline process and resource management and achieve greater compliance and data security. Overall, to navigate the challenges of the new industrial era, security professionals need an IT/OT convergence security solution that shields all assets connected to the network.”
The Armis Unified Asset Intelligence Platform discovers all connected assets, maps out the communications and relationships between them, and adds contextual intelligence to help understand their context and the risk they may introduce to the business. It is purpose-built to protect both OT and IT environments and can ingest meaningful signals from hundreds of IT and OT platforms. Armis’ cloud-based threat detection engine uses machine learning and artificial intelligence to detect when a device is operating outside of its normal “known good” baseline and triggers an automated response for an easier management of the overall attack surface.
Armis was recognized by ISG as an OT Security Leader for the 3rd consecutive year in the 2022 report “ISG Provider Manufacturing Security Services: OT Security Solutions”. And was named a Representative Vendor for the 3rd consecutive year in the Gartner “Market Guide for Operational Technology Security.”
To see how Armis stops threats and protects global organizations such as Colgate-Palmolive and Fortive, and helps utilities, transportation and leading manufacturers stay online 24/7, 365 days a year, please visit: https://www.armis.com
Methodology
Armis calculated device risk by looking at all devices on the Armis Asset Intelligence and Security Platform and identifying which types have the highest-severity risk factor and/or Common Vulnerabilities and Exposures (CVEs). Additionally, business impact level and endpoint protections had a weighted influence.
About Armis
Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230612005040/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
TreeFrog Therapeutics Presents Delivery Strategy for Next Generation 3D Cell Therapy Format for Parkinson’s Disease at the 28th Annual ASGCT Meeting in New Orleans13.5.2025 08:00:00 CEST | Press release
TreeFrog Therapeutics is the first company to present publicly a clinical-ready delivery strategy for 3D format microtissues in cell therapy.After four years in development, the validated device and delivery strategy overcomes challenges of 3D formats and uses existing stereotactic components to support adoption through ease of delivery education. TreeFrog Therapeutics, a French biotech specializing in cell therapy is the first company to present a clinical-ready delivery strategy for 3D microtissues cell therapy. The validated approach was demonstrated for their 3D neural microtissues cell therapy treatment for Parkinson’s disease. Parkinson’s disease is the second most common neurodegenerative disorder after Alzheimer’s disease. It is a progressive disease characterized by the loss of dopaminergic neurons with a mix of motor symptoms (bradykinesia, rigidity, resting tremor) and non-motor symptoms (cognitive deficits, mood disorders, fatigue). Current treatments provide symptomatic re
Ohana Development Launches ‘Jacob & Co. Beachfront Living by Ohana,’ A Masterpiece of Beachfront Elegance in the UAE13.5.2025 08:00:00 CEST | Press release
Valued at USD 1.3 billion, the project offers world-class amenities, including a signature Jacob & Co. ceiling art timepiece, the largest of its kind globally. Ohana Development, the leading real estate developer renowned for its luxury properties, has launched ‘Jacob & Co. Beachfront Living by Ohana’ in partnership with luxury timepiece and jewellery house Jacob & Co. The project was revealed at Emirates Palace Mandarin Oriental, Abu Dhabi. Located in Al Jurf between Dubai and Abu Dhabi, this USD 1.3 billion development blends natural surroundings with exceptional artistry and craftsmanship. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250512533615/en/ Jacob & Co. Beachfront Living by Ohana. (Photo: AETOSWire) Jacob & Co. Beachfront Living by Ohana presents 457 residences comprising of sea-view apartments, villas, penthouses, Sky Mansions, and beachfront mansions—each capturing the spirit of refined coastal living. Pentho
Azafaros Secures € 132M in Oversubscribed Series B Financing to Advance Phase 3 Clinical Programs of Innovative Therapies in Lysosomal Storage Disorders13.5.2025 07:00:00 CEST | Press release
Financing round led by Jeito Capital and co-led by Forbion Growth, with participation from Seroba, Pictet Group and other existing investorsProceeds to fund two Phase 3 pivotal programs with nizubaglustat, lead asset in Niemann-Pick disease Type C (NPC) and GM1/GM2 gangliosidoses as well as expanding the Azafaros pipeline to other indicationsNizubaglustat has been awarded Orphan Drug Designation in both the US and Europe as well as Fast-track status in the US. The company expects to initiate both Phase 3 studies later this year Azafaros, a clinical-stage company focused on developing disease-modifying therapeutics to offer new treatment options to patients with rare lysosomal storage disorders, announces the completion of an oversubscribed €132M Series B financing led by Jeito Capital, co-led by Forbion Growth and with additional participation from Seroba, Pictet Group and existing investors Forbion Ventures, Schroders Capital and BioGeneration Ventures (BGV). This financing enables Az
Presidio Investors is Pleased to Announce the Addition of Christian Schütte as Its Newest Operating Partner12.5.2025 19:04:00 CEST | Press release
Christian brings more than 20 years of global experience in investment banking, private equity, and operational leadership, with a proven track record of driving transformational growth across industries. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250512473756/en/ Christian Schütte Christian began his career at J.P. Morgan in New York and London, where he worked in the M&A and Corporate Finance teams. He later joined Fortress Investment Group and was instrumental in launching its German operations. During his tenure, he helped raise over €1.5 billion in equity and managed a wide array of investments, including non-performing and performing loans, private and public companies. He went on to join EQT Group, where he focused on mid-market growth and succession investments. Notably, he led the consolidation of nine digital marketing agencies into a €100 million market leader, building one of the most comprehensive digital ma
Introducing Joblio – The Future of Ethical Recruitment12.5.2025 18:30:00 CEST | Press release
Joblio Launches to Revolutionize Ethical Recruitment and End Worker Exploitation Joblio, a global ethical recruitment platform, officially launches today to tackle the broken labor migration system—long plagued by exploitative intermediaries, high recruitment fees, and human rights abuses. With its tech-driven model, Joblio connects vetted workers with employers directly, eliminating unethical middlemen and ensuring cost-free hiring for migrant workers. Employers fund access to talent, but workers never pay—a key step in ending exploitation. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250512628048/en/ A Mission Rooted in Personal Experience Joblio is led by Jon Purizhansky, a refugee-turned-entrepreneur who experienced migration challenges firsthand. Forced to flee his home country as a young man, Jon faced the uncertainty and vulnerability that millions of migrant workers still encounter today. Now a globally recognized
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom