الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Biometrics and building automation systems were the most attacked operational technology sectors at the beginning of 2025

In Q1 2025, malicious objects were blocked on 21.9% of ICS computers globally, according to a new report by Kaspersky ICS CERT (Industrial Control Systems Cyber Emergency Response Team). Regionally this share varied: from 10.7% in Northern Europe to 29.6% in Africa. From Q4 2024 to Q1 2025, the share of ICS computers on which malicious objects were blocked increased in Russia (by 0.9 p.p.), Central Asia (by 0.7 p.p.), South Asia (by 0.3 p.p.), Western Europe (by 0.2 p.p.), Northern Europe (by 0.1 p.p.) and Southern Europe (by 0.1 p.p.).

The share of ICS computers with blocked malicious objects, per region
Threats by industries
The biometrics sector was targeted more than any other industry vertical (malicious objects were blocked on 28.1% of ICS computers), followed by building automation (25%), electric power facilities (22,8%), construction facilities (22.4%), engineering equipment (21.7%), oil & gas facilities (17.8%), and manufacturing (17.6%).

Main threat sources
The OT cyberthreat landscape at the beginning of 2025 remained diverse, with threats spreading via the internet continuing as the main source of cyber risks to OT computers (these threats were blocked on 10.11% of ICS computers), followed by email clients (2.81%) and removable media at (0.52%).

“As the internet remains the primary source of threats to ICS computers, in the first quarter of 2025, the share of ICS computers attacked with malware spread via the internet increased for the first time since the beginning of 2023. The main categories of threats from the internet are denylisted internet resources, malicious scripts and phishing pages. Malicious scripts and phishing pages is the leading category of malware used for initial infection of ICS computers – they act as droppers of next-stage malware, such as spyware, crypto miners and ransomware. The rise in internet-based attacks on ICS highlights the critical need for advanced threat detection to counter sophisticated malware campaigns,” commented Evgeny Goncharov, Head of Kaspersky ICS CERT.

To keep OT computers protected from various threats, Kaspersky experts recommend:
• Conducting regular security assessments of OT systems to identify and eliminate possible cyber security issues.

• Establishing continuous vulnerability assessment and triage as a foundation for effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
• Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.

• Using EDR solutions such as Kaspersky Next EDR Expert for timely detection of sophisticated threats, investigation, and effective remediation of incidents.
• Improving the response to new and advanced malicious techniques by building and strengthening teams’ skills in incident prevention, detection, and response. Dedicated OT security trainings for IT security staff and OT personnel is one of the key measures helping to achieve this.

The full report on ICS threats for Q1 2025 is available by the link.

Related Posts

Orange Egypt Officially Launches 5G Services in Egypt

Sawiris Foundation Signs an MoU with AFD, Essam and May Allam Foundation, and the Louis Dreyfus Foundation to Develop Agricultural Solutions

DoubleTree by Hilton Resort & Spa Marjan Island Announces Four Key Leadership Appointments

Forbes Middle East and Beltone Holding to Launch the Top Advisors & Investors Summit in Egypt

CDF Champions Cultural Entrepreneurship and Strategic Investment at Expo 2025 Osaka

6. A One-Million-EGP Smartwatch? CardoO

A targeted attack mimics communication from company CEO to steal funds

Ajna Developments Launches New Residential-Hotel Project in New Cairo in Partnership with Prime Hospitality Management Group

آخر الأخبار
اجازة العيد زمان ودلوقتي .. شيماء الهواري تقدم اولي حلقات برنامج حياة عاجل.. الرئيس السيسي يصدق على تعديلات قوانين مجلسي النواب والشيوخ وتقسيم الدوائر الانتخابية البترول تنعى البطل خالد محمد شوقي شهيد حريق بنزينة العاشر من رمضان الطرق والكبارى: حدوث انفصال جزئي مفاجئ محدود بالطبان الترابي بطريق إسنا/ الأقصر الزراعي الغربي عند م... افتتاح مركز زوار قلعة قايتباي بالإسكندرية بعد الانتهاء من تجهيزه سفير الهند: نسعى لربط شركات التكنولوجيا الهندية بمصر والأسواق العالمية شديد الحرارة.. تفاصيل حالة الطقس غدًا الإثنين وفاة سائق شاحنة البنزين بالعاشر من رمضان داخل المستشفي متأثرا بإصابته مصرللطيران تبدأ جسرها الجوي غدًا لعودة حجاج بيت الله الحرام لأرض الوطن اتصال هاتفي بين وزير الخارجية والهجرة ونظيره التركي وزير الزراعة يستعرض مع رئيس "الخدمات البيطرية" الخطط الاحترازية لحماية الثروة الحيوانية من الأمراض بعثة حج "الجمعيات الأهلية" تتابع إقامة الحجاج في منى خلال أيام التشريق الشباب والرياضة: 4.3 مليون مواطن ترددوا على مراكز الشباب ثاني أيام عيد الأضحى الأمين العام للمجلس الأعلى للآثار يتفقد "المقاصير الجنوبية" بمعبد الأخ منو وأعمال الحفائر الأثرية وزير المالية: موازنة طموحة لتمويل مبادرات «المساندة الاقتصادية» للأنشطة الصناعية والتصديرية وزير المالية: ٧٨ مليار جنيه لتحفيز القطاع الخاص على زيادة الإنتاج والتصدير وزير الكهرباء يتابع تقارير الأداء لمراكز خدمة العملاء ومنظومة الخدمات والشكاوى خلال أيام عيد الأضحى اقتصادي يكشف مكاسب ارتفاع تحويلات المصريين بالخارج لـ 26.4 مليار دولار خلال 9 شهور غرفة السياحة تشيد باحترافية «الماسية» في خدمة حجاج البري والخمس نجوم حصاد العام المالي (2024/2025) للتصنيفات الدولية