Biometrics and building automation systems were the most attacked operational technology sectors at the beginning of 2025

In Q1 2025, malicious objects were blocked on 21.9% of ICS computers globally, according to a new report by Kaspersky ICS CERT (Industrial Control Systems Cyber Emergency Response Team). Regionally this share varied: from 10.7% in Northern Europe to 29.6% in Africa. From Q4 2024 to Q1 2025, the share of ICS computers on which malicious objects were blocked increased in Russia (by 0.9 p.p.), Central Asia (by 0.7 p.p.), South Asia (by 0.3 p.p.), Western Europe (by 0.2 p.p.), Northern Europe (by 0.1 p.p.) and Southern Europe (by 0.1 p.p.).

The share of ICS computers with blocked malicious objects, per region
Threats by industries
The biometrics sector was targeted more than any other industry vertical (malicious objects were blocked on 28.1% of ICS computers), followed by building automation (25%), electric power facilities (22,8%), construction facilities (22.4%), engineering equipment (21.7%), oil & gas facilities (17.8%), and manufacturing (17.6%).

Main threat sources
The OT cyberthreat landscape at the beginning of 2025 remained diverse, with threats spreading via the internet continuing as the main source of cyber risks to OT computers (these threats were blocked on 10.11% of ICS computers), followed by email clients (2.81%) and removable media at (0.52%).

“As the internet remains the primary source of threats to ICS computers, in the first quarter of 2025, the share of ICS computers attacked with malware spread via the internet increased for the first time since the beginning of 2023. The main categories of threats from the internet are denylisted internet resources, malicious scripts and phishing pages. Malicious scripts and phishing pages is the leading category of malware used for initial infection of ICS computers – they act as droppers of next-stage malware, such as spyware, crypto miners and ransomware. The rise in internet-based attacks on ICS highlights the critical need for advanced threat detection to counter sophisticated malware campaigns,” commented Evgeny Goncharov, Head of Kaspersky ICS CERT.

To keep OT computers protected from various threats, Kaspersky experts recommend:
• Conducting regular security assessments of OT systems to identify and eliminate possible cyber security issues.

• Establishing continuous vulnerability assessment and triage as a foundation for effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
• Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.

• Using EDR solutions such as Kaspersky Next EDR Expert for timely detection of sophisticated threats, investigation, and effective remediation of incidents.
• Improving the response to new and advanced malicious techniques by building and strengthening teams’ skills in incident prevention, detection, and response. Dedicated OT security trainings for IT security staff and OT personnel is one of the key measures helping to achieve this.

The full report on ICS threats for Q1 2025 is available by the link.

Related Posts

With the participation of experts, Invest-Gate issues its recommendations: “Fractional Real Estate: Unlocking New Frontiers of Property Investment in Egypt

LG Egypt Launches “Better Home” Initiative to Facilitate Marriage in Marsa Matrouh and Qena

Zoho Powers Up CRM for Everyone Platform with AI to Elevate Customer Experience in Egypt

QATAR SPORTS INVESTMENTS MARKS 14 YEARS OF TRANSFORMATIVE OWNERSHIP OF PARIS SAINT-GERMAIN

*Huawei Expands Free AI Learning Opportunities Across Egypt Signing 3 MoUs with of Al-Azhar, Egyptian-Russian and 6th of October Universities*

ECT AVIATION LAUNCHES TIME-CRITICAL CARGO ROUTES WITH THE BN2T-4S ISLANDER

International Financial Advisories Hotels & Resorts (IFA HR) rebrands its asset management division and creates new company Trilight Hospitality Asset Management

Savour a Delectable Afternoon Tea at Infinity Lounge in Rixos Marina Abu Dhabi

آخر الأخبار
وزير التموين يتابع انتظام منظومة الطحن وتطوير شركات المطاحن لدعم الأمن الغذائي تنمية المشروعات يقدم تمويل جديد للمشروعات المتناهية الصغر بـ 400 مليون جنيه من خلال شركة تساهيل اتفاق لفتح آفاق جديدة للاستثمار التعديني وتعزيز القيمة المضافة للثروات الطبيعية مجلس النواب يوافق من حيث المبدأ على قانون الإيجارات القديمة رئيس الوزراء يلتقى نظيره الجزائرى مستشفى أهل مصر للحروق يحذر من العدوى باعتبارها السبب الأبرز لمضاعفات مرضى الحروق المصرف المتحد ونقابة الصحفيين يوقعان ثاني بروتوكول تعاون للتوسع في خدمات التمويل العقاري نائبة وزيرة التضامن تترأس الوفد المشارك فى أعمال "الاجتماع العربي الإقليمي رفيع المستوى" بتونس وزيرة التخطيط والتنمية تعقد جلسة مباحثات موسعة مع نظيرتها الألمانية لمناقشة أولويات الشراكة بين البل... With the participation of experts, Invest-Gate issues its recommendations: “Fractional Real Estate: ... بمشاركة الخبراء..«إنفستجيت» تصدر توصياتها “الملكية الجزئية: آفاق جديدة للاستثمار العقاري في مصر «إنفوجراف» حول التعديلات المحدودة فى ضريبة القيمة المضافة ڤودافون مصر تتصدر تصنيف nPerf 2025 لأفضل أداء للإنترنت الثابت في مصر LG Egypt Launches “Better Home” Initiative to Facilitate Marriage in Marsa Matrouh and Qena إل جي مصر تطلق مبادرة “Better Home” لتيسير الزواج في مرسى مطروح وقنا رئيس البريد المصري تستقبل المدير التنفيذي لبريد كوت ديفوار  عمرو السمدوني: تسيير خطي شحن بنظام رورو مع السعودية وتركيا خطوة استراتيجية تدعم زيادة الصادرات شركة سيتي إيدج تكشف عن طرح مشروع إداري" برج ماسبيرو ميتروبوليس رئيس البورصة المصرية يلتقي مع قيادات شركات سوق الشركات الصغيرة والمتوسطة الأكاديمية العربية تستضيف نهائي كأس العالم للخماسي الحديث بمشاركة 30 دولة للمرة الخامسة علي التوالي