الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Biometrics and building automation systems were the most attacked operational technology sectors at the beginning of 2025

In Q1 2025, malicious objects were blocked on 21.9% of ICS computers globally, according to a new report by Kaspersky ICS CERT (Industrial Control Systems Cyber Emergency Response Team). Regionally this share varied: from 10.7% in Northern Europe to 29.6% in Africa. From Q4 2024 to Q1 2025, the share of ICS computers on which malicious objects were blocked increased in Russia (by 0.9 p.p.), Central Asia (by 0.7 p.p.), South Asia (by 0.3 p.p.), Western Europe (by 0.2 p.p.), Northern Europe (by 0.1 p.p.) and Southern Europe (by 0.1 p.p.).

The share of ICS computers with blocked malicious objects, per region
Threats by industries
The biometrics sector was targeted more than any other industry vertical (malicious objects were blocked on 28.1% of ICS computers), followed by building automation (25%), electric power facilities (22,8%), construction facilities (22.4%), engineering equipment (21.7%), oil & gas facilities (17.8%), and manufacturing (17.6%).

Main threat sources
The OT cyberthreat landscape at the beginning of 2025 remained diverse, with threats spreading via the internet continuing as the main source of cyber risks to OT computers (these threats were blocked on 10.11% of ICS computers), followed by email clients (2.81%) and removable media at (0.52%).

“As the internet remains the primary source of threats to ICS computers, in the first quarter of 2025, the share of ICS computers attacked with malware spread via the internet increased for the first time since the beginning of 2023. The main categories of threats from the internet are denylisted internet resources, malicious scripts and phishing pages. Malicious scripts and phishing pages is the leading category of malware used for initial infection of ICS computers – they act as droppers of next-stage malware, such as spyware, crypto miners and ransomware. The rise in internet-based attacks on ICS highlights the critical need for advanced threat detection to counter sophisticated malware campaigns,” commented Evgeny Goncharov, Head of Kaspersky ICS CERT.

To keep OT computers protected from various threats, Kaspersky experts recommend:
• Conducting regular security assessments of OT systems to identify and eliminate possible cyber security issues.

• Establishing continuous vulnerability assessment and triage as a foundation for effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
• Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.

• Using EDR solutions such as Kaspersky Next EDR Expert for timely detection of sophisticated threats, investigation, and effective remediation of incidents.
• Improving the response to new and advanced malicious techniques by building and strengthening teams’ skills in incident prevention, detection, and response. Dedicated OT security trainings for IT security staff and OT personnel is one of the key measures helping to achieve this.

The full report on ICS threats for Q1 2025 is available by the link.

Related Posts

realme C75x combines highest protection with the flagship IP69 certification and a standout position in the 7K segment

Honor of Kings evolves into Honor of Kings Plus to reflect the scale of the new update

Clean Air Begins at Home: QNET Urges Action on Indoor Air Pollution

CASIO Middle East & Africa Marks Six Decades of Calculator Legacy

Tetra Pak Celebrates the National Day of Sweden 2025 at the Swedish Embassy in Cairo

Digital detox: How to take a safe break from screens

New ‘industrial sunbelt’ set to overtake the world’s biggest economies in clean industry race

: Zoho Launches Zia Hubs to Empower MENA Businesses to Extract Intelligence from Unstructured Data

آخر الأخبار
realme C75x combines highest protection with the flagship IP69 certification and a standout position... هاتف realme C75x يأتي بمزايا رائدة، مع أعلى مستوى مقاومة للماء بشهادة IP69 الرئيس السيسى ورئيس وزراء اليونان يؤكدان أهمية تشكيل حكومة ليبية جديدة موحدة لعبة Honor of Kings تستعد لإطلاق أضخم تحديث في تاريخها Honor of Kings evolves into Honor of Kings Plus to reflect the scale of the new update فيليب موريس مصر تطلق جهاز IQOS ILUMA i في قفزة تكنولوجية جديدة نحو مستقبل خالٍ من الدخان نجاح كبير للدورة ال 15 من EGYPT CAR OF THE YEAR Award Clean Air Begins at Home: QNET Urges Action on Indoor Air Pollution الهواء النظيف يبدأ من المنزل: كيونت تدعو لاتخاذ إجراءات لمواجهة تلوث الهواء الداخلي وزير الكهرباء والطاقة المتجددة يتابع ربط محطتي محولات جرزا وغرب بكر رئيس الوزراء يتابع إجراءات ترشيد استهلاك الكهرباء في الحي الحكومي بالعاصمة الإدارية "صوت الهمم" .. منصة من الإمارات تفتح نافذة جديدة للإعلام العالمي بقيادة أصحاب الهمم شركة «Next Developments» تُطلق مشروعها الجديد( 52walk way ) بغرب القاهرة بنك مصر يتبنى رعاية 19 اتحاداً رياضياً دعماً للرياضة المصرية أمنكس إنترناشيونال تطلق حواسيب HOT Systems فائقة لتلبية متطلبات المستخدمين المحترفين بنك QNB مصر يعزز رصيده بـعدة جوائز دولية مرموقة خلال 2025 كونستانس للفنادق والمنتجعات تنضم إلى نخبة الضيافة العالمية بالشراكة مع Forbes Travel Guide المحكمة العربية للتحكيم تطلق مؤتمر الوعي الوطني للشباب بالتعاون مع وزارة الشباب تزامنًا مع ذكرى 30 ي... وزيرة البيئة تستقبل محافظ الوادي الجديد لبحث تعزيز فرص الاستثمار في تدوير المخلفات الزراعية وزير الثقافة ومحافظ شمال سيناء يفتتحان بيت ثقافة قاطية ببئر العبد بعد تطويره ورفع كفاءته