Critical infrastructure’s hidden CPS security blind spots

Why-state-actors-are-counting-on-your-blind-spots

ISJ hears exclusively from Andrew Lintell, General Manager of EMEA at Claroty about how cyber-physical systems are leaving critical infrastructure exposed.

In a recent speech delivered at the RUSI Annual Security Lecture, NCSC CEO Richard Horne revealed that the organisation had managed more than 200 incidents affecting critical national infrastructure and its supporting ecosystem over the course of just 11 months.

Three-quarters of those incidents were believed to be linked to state actors.

That figure should give pause to every operator responsible for securing the systems that underpin the daily operations of national life.

State-backed attackers are targeting critical infrastructure with increasing sophistication, and many of the organisations in their crosshairs cannot accurately account for what is running on their own networks.

Cyber-physical systems (CPS), the connected devices and equipment that directly control physical processes everywhere from energy grids to manufacturing plants, sit at the heart of that exposure.

These are the systems that, if disrupted, cause blackouts, production shutdowns and failures in healthcare delivery, which is precisely why state actors want to reach them.

And in too many cases, the organisations responsible for protecting them cannot account for what they have.

Operators fear state actors – but struggle to close security gaps

The threat Richard Horne described has been building for some time.

Geopolitical instability has been steadily widening the attack surface facing critical infrastructure operators, and the organisations responsible for protecting those environments know it.

Our research found that almost half (49%) of cybersecurity professionals responsible for CPS security report that supply chain changes driven by shifting global economic policies and geopolitical tensions were increasing their cybersecurity risk.

A further 67% said they were reconsidering their supply chain geography entirely in response to that uncertainty.

Yet despite that awareness, organisations are struggling to translate concern into control.

Reducing cyber-risk to key assets and processes and understanding their overall risk exposure are top concerns in the year ahead.

Often, the reason comes down to something more fundamental than strategy or investment: the accuracy of the asset data organisations rely on.

Claroty’s research team analysed a dataset of 17 million cyber-physical systems assets and found 88% do not transmit an exact product code from data collection, while 76% transmit codes that differ from the vendor’s official record.

Why are CPS inventories so full of holes?

The root cause lies in how these devices were built: designed for decades of operational reliability rather than network transparency, with naming conventions added as an afterthought.

76% of models have multiple name variants depending on the protocol or integration querying them, and 33% present differently when other protocols are used.

The same physical device can appear as an entirely different asset based on how it is being observed.

Operating system (OS) information is similarly unreliable.

Nearly half (41%) of CPS devices have no OS version available, and 24% have no OS name at all.

This makes accurate vulnerability correlation effectively impossible.

The problem flows into CVE advisories, the industry-standard mechanism for disclosing vulnerabilities, which are built from the same incomplete vendor data.

Security teams are left inferring whether a device is affected and forced to act on that inference as fact.

No additional investment in security tooling resolves this.

Many organisations have invested heavily in asset discovery and still struggle with visibility.

The cause is structural, rooted in how CPS devices communicate and it requires a different kind of solution.

What do these CPS blind spots mean?

The operational consequences of broken asset data are serious in any environment.

In critical national infrastructure, they are potentially catastrophic.

When state-backed actors are actively targeting the systems that control physical processes, the inability to accurately identify those systems is a debilitating shortcoming.

It determines whether a vulnerability gets patched before it is exploited, whether a threat alert is correctly attributed and whether a security team can respond with confidence or is forced to act on incomplete information.

The physical dimension matters here in a way pure IT security does not capture.

CPS also present another layer of risk rarely seen in other fields.

A missed vulnerability in an energy management system, an unpatched water treatment controller or an unidentified device in a hospital’s clinical infrastructure can lead to far more than data loss including operational disruption, service failure and risk to public safety.

There is also a less visible cost.

Our research found that 23% of security professionals cite unclear ROI on existing cybersecurity investments as an operational concern.

When the asset data underpinning a security programme is unreliable, teams cannot accurately demonstrate what those investments are protecting or make a credible case for future ones.

Why accurate identification lets operators build on solid ground

Addressing the visibility gap begins not with deploying additional tools but with resolving the data quality problem those tools depend on.

Accurate asset identification means establishing not just that a device exists, but what it is, what process it supports and what the consequences would be if it were taken offline or compromised.

That contextual understanding is what transforms an asset inventory from a list into a risk management tool for maintaining operational resilience.

It enables security teams to move away from treating all devices as equally important and towards prioritising based on operational impact.

The priority is knowing which systems, if disrupted, would halt a production line, take a ward offline or interrupt power distribution.

In environments facing the level of threat Richard Horne described, that prioritisation is absolutely essential.

Tackling this issue effectively has a marked impact on operations.

Our research applied AI-driven mapping techniques to one major OEM’s device catalogue, improving product code identification from 4% to 83%.

Following that improvement, 56% of devices received new or updated firmware recommendations and vulnerability identification accuracy improved by 25%.

Those numbers represent the concrete difference between a security programme operating on guesswork and one operating on reliable foundations.

The systems state actors most want to disrupt are the same ones communities depend on for power, clean water and medical care.

Defending them needs a focused plan and steady investment, but the foundations depend on an accurate picture of what is actually there.

Until these invisible assets are found and secured, our CPS remains critically vulnerable.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox