Attackers used Facebook to promote AI generated ads to lure users to a malicious website. The ad claimed to convert still images into vivid videos. After the fake progress bar reached 100%, users got a downloadable ZIP archive, which containd the following:
Among the contents was an executable file deceptively named “Video Luma MachineAI.mp4.exe”, multiple Unicode no-break space characters (\xe2\xa0\x80) were used between .mp4 and .exe to impersonate a video file. The folder 5.0.0.1886 had both system and hidden attributes, making it invisible by default in file explorers.
When the user double-clicks the .exe file, it runs “Capcut.exe” located in the 5.0.0.1886 directory and then exits the current process.
“CapCut.exe” is a .NET executable. Upon running, it repeatedly accesses “https[:]//google.com”, then briefly pauses. It then proceeds to rename files in the 5.0.0.1886\software directory, meta becomes “image.exe” and Document.docx becomes install.bat. The renamed image.exe is actually WinRAR, and install.bat is then executed.
The batch script decodes Document.pdf into ppIuqewlq.rar, which is silently extracted using “image.exe” into %LOCALAPPDATA%\SoftwareHost, with the extraction password being TONGDUCKIEMDEVELOPER2025. The extracted content includes a Python runtime environment and its dependencies. The file srchost.exe is essentially “python.exe”:
Using srchost.exe, the malware downloads and executes remote code. The downloaded script uses exec() to execute a marshaled (serialized) Python object. The marshaled object is then decompiled for analysis:
The disassembled opcodes amount to over 60,000 lines, but most are garbage instructions designed to hinder analysis. The meaningful opcodes are in the last 500 lines. To facilitate analysis, AI tools are used to reconstruct the original Python code from these opcodes.
Although the AI-reconstructed code might differ from the original, it provides a helpful base for manual verification. Eventually, another marshaled object is uncovered, and the same decompilation method is applied to retrieve its source code.
The final code carries out data theft, targeting: Browser cookies, Browse history and saved credentials, Stored credit card information, Facebook login credentials and account data:
All stolen data is archived and sent to a Telegram bot before being deleted from the victim machine.
BlackLock ransomware (also known as El Dorado or Eldorado) emerged in March 2024 and operates under a Ransomware-as-a-Service (RaaS) model. It employs a double extortion strategy—encrypting data and stealing sensitive information—and targets Windows, VMware ESXi, and Linux environments. Victims span various industries and regions.
Sample Analysis
Summary
The sample requires administrator privilege to execute and must be run via the command line; it does not launch via double-click.
Upon execution, the following log is printed:
Ransom note content:HOW_RETURN_YOUR_DATA.TXT
Example of encrypted files:
Analysis
Windows Version
Supported optional parameters for execution:
Parameter
Description
-path
Specifies the file path to be encrypted
-skip-local
Specifies files to be excluded from encryption
-n <subnet>
Specifies shared resources in CIDR format, e.g., 192.168.5.0/24
-d <domain>
Specifies the domain
-u <username>
Specifies SMB account
-p <password>
Specifies SMB password
-skip-net
Skips encrypting shared directories
When provided with appropriate user credentials, it can encrypt files on shared networks using the SMB protocol.
Logs are transmitted via WebSockets to 173.44.141[.]152, with the Origin header set to “http://logger”
To eliminate traces, the Eldorado ransomware runs a PowerShell command to overwrite the encryptor executables with random bytes and then deletes the file. If the “-keep” parameter is specified, this action is skipped:
Digital transformations, acquisitions, and downsizing impact the organization’s attack surface.
Hackers using adversarial artificial intelligence (AI) and machine learning (ML) tools scan their targets’ attack surface for known vulnerabilities and security gaps within the organization’s digital footprint.
Organizations that invest in frequent vulnerability assessments against their internal and external attack surface experience a much lower risk of a successful cyberattack.
The Importance of Attack Surface Management
Any device, application, cloud instance, or network device becomes part of the attack surface. Organizations continue to expand their attack surface with new employees, new application portals, and cloud-based instances. Adding new devices, including phones, tablets, and PCs, extends the attack surface further. This ever-increasing dynamic became the purpose of internal and external attack surface management (attack surfaceM).
Organizations making strategic investments use asset management tools to help track network devices, servers, workstations, mobile devices, and cloud instances. Asset management also helps track new devices and retired items across the attack surface.
Blocking unapproved devices and unauthorized access to applications and cloud instances is key to reducing the attack surface’s vulnerabilities while improving the organization’s security posture.
What are the various attack surface categories?
Attack surfaces expand as organizations adjust their business objectives. C-level decisions, including improving customer service capabilities, can put the organization at significant risk. Incorporating more third-party cloud-based applications, leveraging outsourced remote call centers, and using employee-owned devices increases organizations’ risk, and attack surface remains the primary goal of attack surface management.
An attack surface risk is broken into subareas within the enterprise, including:
Network
Network devices, including switches, routers, firewalls, zero-trust architectures, and intrusion prevention solutions, all represent a portion of the enterprise attack surface. Like applications, these devices have vulnerabilities. Many device vulnerabilities impact the organization because most IT departments hesitate to remove them from the production network to apply a patch. This decision also increases the risk of exploitation.
Applications
Internally developed and externally hosted applications also extend the organization’s attack surface. Like network devices, critical applications also have several vulnerabilities that can be exploited across the entire attack surface. Organizations also face considerable risk of cyberattack and data theft by leveraging Software-as-a-Service (SaaS) applications. Organizations expand their attack surface by consuming these solutions, even if a third-party provider owns and manages the platform. Once their data resides within the SaaS-based application, this becomes part of their attack surface.
Cloud Instances
Thanks partly to VMware, Microsoft, and open source, cloud instances are relatively easy to spin up. Cloud instances become deployed and ready for usage with a few clicks or by leveraging a robotic process automation (RPA) script. Each additional cloud instance also extends the organization’s attack surface.
Virtual hosts supporting various digital attack surfaces, including data storage, applications, and cybersecurity tools, all have vulnerabilities. Organizations growing their cloud presence need to ensure the proper governance and cybersecurity protection controls become enabled on all cloud instances to help protect this attack surface.
Devices
Tracking mobile devices, tablets, Apple and Android watches, phones, and PCs fall under the Attack Surface Management program. These devices are susceptible to cyberattacks because they often lack frequent software updates, even when users set their devices to automatic update. Once employees, contractors, and partners access organization data and applications from their devices, increasing the attack surface creates a more excellent one.
Handing Dynamic Attack Surfaces
Dynamic attack surfaces continue to become a byproduct of successfully deployed automation. Organizations using automation to spin up virtual machines to increase website capacity create an additional attack surface. Automation also provides new applications to user devices or executes an uninstall. This automation process creates additional attack surfaces, especially if the application is new to the environment.
Effective attack surface management strategies must account for the dynamic nature of system-wide automation tools. Poorly designed automation tools cause security vulnerabilities in cloud environments and the latest risk levels.
Leveraging critical vulnerability assessments and continuous scanning helps organizations quickly identify the expansion of dynamic attack surfaces caused by automation.
Common Challenges Regarding Attack Surface Management
Rogue actions by corporate employees, contractors, and vendors include plugging in Wi-Fi routers, loading unapproved applications on an endpoint, or adding their Active Directory credentials to the administration group. These actions define shadow IT.
Shadow IT continues to drive up organizations’ risks. Without asset management tools or frequent vulnerability scanning to detect rogue devices and applications, organizations will continue to be exposed to cyberattacks.
Return-to-Office
Another dynamic facing IT executives is the confusion and mixed messaging surrounding return-to-office. Organizations requiring their employees to return to work continue to be a work in progress. Some employers have held the line and required everyone to return. Others have taken a wait-and-see approach and decided only to require employees to report to the office twice a week.
Either decision continues to place significant risk on the organization. Supporting people working from home, inside the physical office space, or between creates IT management and cybersecurity protection challenges.
Employees still access corporate systems and data from their homes, even with zero-trust architectures deployed, and they present substantial security risks. They also reluctantly return to the office and quietly plug unapproved devices into the corporate network, another shadow IT behavior.
Organizations coping with the compressing and expanding attack surfaces pressed IT leaders to make more capital and operational expense decisions, including deploying asset tracking solutions and executing more frequent risk assessments.
Practical Guidance for Implementing Attack Surface Reduction Strategies
Reducing attack surfaces requires a commitment from the C-level, board of directors, and all departments to work together. Leadership teams decide to acquire companies and approve the hiring of more employees. Departments have decided to sign with a SaaS-based application provider to help them deliver internal and external services from the cloud. The board of directors makes critical economic decisions for the firm, including purchasing buildings, agreeing with partners with a third-party firm, and ensuring the company stays in full compliance and meets all regulatory mandates. While these decisions help organizations grow their revenue. Revenue growth is essential to any organization. However, the growth of the attack surface may become more costly compared to the increase in revenues.
Here are examples to help organizations reduce their attack surfaces and risk:
Reduce Technology Complexity
Organizations still wanting to use outdated devices for accounting reasons create a significant problem. Keeping outdated and unperforming devices, applications, and networks operational creates unnecessary attack surfaces prone to cyberattacks. Organizations often purchase upgrade solutions to phase out legacy technology. While running dual solutions is not uncommon, this creates a larger attack surface as the legacy devices become taken out of service.
Adopt Zero Trust for Access Control Consolidation
Consolidation of access control, cloud-based access, and legacy VPN solutions need a transformation. Most of these outdated solutions grew partially because of the COVID-19 outbreak. Now that this life-changing event has subsided, organizations can make a positive difference in reducing their attack surfaces by standardizing on zero-trust strategy for all remote access, cloud-based access, and contractor access to sensitive corporate devices, applications, and systems.
Zero-trust network access (ZTNA), cloud access security broker (Cattack surfaceB), and software-defined vast area network (SD-WAN) all transform remote access into a single point of entry, secured and easy-to-manage strategy while reducing the organization’s attack surface.
Moving Ahead with Risk-based Vulnerability Scoring
Every element within the attack surface has vulnerabilities. Some have little consequence, and others could cause a complete zero-day attack. How these vulnerabilities obtain their risk scoring is dynamically changing.
Legacy risk scoring, which leverages the Common Vulnerability Scoring System (CVSS), struggles to assign the correct risk level even with exploited vulnerabilities.
Risk-based vulnerability management (RBVM) focuses on assigning a risk based on the impact on the organization. This process is critical because most organizations’ attack surfaces continue to become very dynamic, and the level of threat risk changes.
As organizations remediate their vulnerable systems, RBVM then applies a lower risk score for that section of the attack surface. CVSS didn’t have this ability because their scores were static.
Prioritizing Risks Based on Impact and Exploitability
Organizations do not have the luxury of upgrading every system to rid themselves of every vulnerability. Prioritizing the risk of exploitation, the ability to shrink the attack surface, and maintaining the highest state of readiness for all critical production systems is essential.
Enabling RBVM systems helps establish a fluid strategy for reporting which elements of the attack surface need the most attention regarding lowering the risk through remediation, enabling additional security tools, or complete upgrade and displacement to next-generation solutions and architecture.
The ultimate decision is whether the effort to remediate, enable, or replace an existing part of the attack surface is worth the risk in possible downtime and cost. The RBVM, along with executing vulnerability assessments, becomes the determining factor.
Getting rid of vulnerabilities with no positive reduction in risk or shrinkage in the attack surfaces isn’t the best use of funds or resources. The ideal decision is to focus on the highest priority risk areas to help shrink the attack surface.
Enforcing Endpoint Security and Compliance
Endpoint devices make up much of the attack surface.
“Investing in unified endpoint management (UEM) helps organizations enforce governance and compliance policies.”
UEM platforms play an essential role in helping organizations manage their endpoint assets. Identifying and managing the complete endpoint lifecycle helps reduce the attack surface while reducing the risk. A deployment of UEM also helps reduce the risk of shadow IT behavior.
Employee Cybersecurity and Attack Surface Training a Must
One of the core elements in reducing attack surface and shadow IT risk is employee training. Before organizations invested in employee training, most security operations teams rarely interacted with the rest of the company’s employees. Many of their activities were shrouded and seldom shared with the rest of the company.
Yet, by educating the users to become more aware of cyberattack risks when the organization’s attack surfaces, they will become more aware of their actions. For most, adding new software or plugging in a device may seem harmless to users; however, these actions increase the attack surface. Once the employees see insightful information from the security operations teams about the effects of expanding the organization’s attack surface, they will think twice about loading unapproved software on the devices.
The Importance of Vulnerability Assessments Against Attack Surfaces
CEOs and the board of directors want to know where within the organization the organization’s weaknesses and strengths are. The outcome of these surveys helps leaders make intelligence- and risk-based decisions.
People become an organization’s most significant vulnerability. Human error when configuring networks or applications, insider data thefts, or financial embezzlement could damage the organization’s reputation for several years.
Cyberattacks also weaken an organization even if it has next-generation defense tools.
Vulnerability assessments help C-levels and boards of directors better understand where cyberattacks or other business disruptions are most likely to occur within their attack surface. By knowing the high-risk areas, leaders can execute a plan to remediate and lower organizations’ risk.
Blind spots within the enterprise network, unused cloud instances, and poorly trained security operations personnel contribute to the organization’s risk. Vulnerability helps give much-needed insight into these and other risk factors. Continuous vulnerability strategies have become critical, especially if the organization is concerned about dynamic surface attacks.
Conclusion with Forward-Looking Recommendations
Vulnerability scanning needs to be part of everyday cybersecurity and attack surface management. Scanning only quarterly to meet a compliance mandate doesn’t reduce risk or shrink the attack surface.
Organizations leveraging vulnerabilities from cybersecurity firms like ForeNova benefit tremendously from the assessment engagements.
ForeNova delivers the most essential pillars from every assessment:
Identification of weakness within the organization’s cybersecurity protection capabilities benefit tremendously
Classify each risk with a risk-based scoring method
Prior analysis on which part of the attack surface is a higher risk
Offer remediation recommendations
Completing a vulnerability assessment helps organizations reduce risk, shrink their attack surface, and determine where to invest human resources and financial capital.
Advanced Persistent Threats, or APTs, are attacks that breach networks to gain access to valuable data. To put into scope the challenges Germany and others are facing, look no further than the growth in the APT protection market.
The Advanced Persistent Threat Protection market will reach $14.6 billion by 2025, with a CAGR of 16.1% from 2020 to 2025.
The market of cybersecurity solutions designed to address APT attacks is growing because the threat continues to expand across all industrial sectors and countries. Ransomware, Denial-of-Service (DoS) attacks, and intellectual property theft are attack vectors used by APTs.
ForeNova, a global provider of managed detection and response (MDR) services, understands the growing problem of APTs targeting high-value industries in Germany. These APTs focus on value data, including intellectual property theft.
German manufacturing firms look to MDR providers like ForeNova for help with 24/7 monitoring, automated incident response, and greater observability of APT threats.
Interested in learning more about ForeNova’s NovaMDR platform offering?
Click here to schedule a demo with the ForeNova engineering team today!
Impact of APTs on the Manufacturing Sector in Germany?
Bitkom announced a projected cost of 206 billion euros ($224 billion) for IT theft, data breaches, espionage, and sabotage in Germany during 2023. This report marks the third year in a row exceeding 200 billion euros, according to a survey of over 1,000 companies.
State-sponsored cyberattacks against high-value German manufacturing is second only to industrial espionage. Both attack vectors continue to increase in complexity and sophistication.
Buried within attack vectors resides complex automated kill chains leveraging adversarial AI tools. These kill chains combine several simulated attacks, including:
Distributed Denial of Service against edge architectures, including web portals, Zero-trust, and SASE-based instances.
Advanced email attacks against manufacturing site managers, production teams, and operations groups are very common.
Manufacturing in Germany continues to rise in ransomware attacks from email phishing with the endgame of extorting manufacturing firms, shutting down critical production systems, or redirecting global supply orders to the wrong suppliers.
The kill chain also contains social engineering attacks, physical intrusions, and constant threat of insider threats.
Rise in Insider Threats Within Manufacturing
Manufacturing firms face a dual challenge: Network users can exfiltrate crucial data, risking operational disruptions and production slowdowns while companies investigate these attacks.
Dealing with State-Sponsored APT Group
State-sponsored attacks bring an additional dimension to attack surfaces. China, Russia, North Korea, Vietnam, Nigeria, South Africa, and other nation-states all contribute to the APT nightmare globally.
ATP groups funded by nation-states present several challenges for cybersecurity teams across all industries. Most of these groups are well-funded, have access to state-sponsored cybersecurity research material and tools, and a resource pool of talent within these countries’ military forces.
This APT group has targeted German companies in sectors such as pharmaceuticals and technology and successfully stolen valuable intellectual property assets.
Chinese state-sponsored APT group conducts cyber espionage for national interests, employing sophisticated spear-phishing, malware, and zero-day vulnerabilities to target governments, businesses, and political entities globally.
Judgment Panda targets U.S, German, and Hong Kong political figures, critical infrastructure, and industrial manufacturing.
Which Manufacturing Industries in Germany Remain the Highest Value Targets for Hackers?
Previously, APT groups focused their cyberattack efforts on stealing money, committing financial fraud through email phishing, and leveraging ransomware to extort money from their victims.
APT groups that focus on efforts in the German manufacturing sectors do so with the ideas that operational disruptions, stealing intellectual property, and/or committing cyber attacks are far more profitable.
Manufacturers facing unplanned production outages face financial losses of between $900 and $17000 per minute. These same cyberattacks also cause a downstream problem with the supply chain supporting the manufacturing processes.
Hackers targeting high-value manufacturing may choose to embed malware into user devices, host-based application platforms, and robotic control units. These malware files go unnoticed because most devices and hosts receive infrequent software updates.
These well-placed malware files were more than likely introduced through an email phishing campaign.
Automotive
Like other German manufacturing firms, the German automotive industry continues to experience various cyberattacks against its employees, supply chain partners, and networks.
The Volkswagen data breach exposed the information of 800,000 EV customers. In addition to this security breach, Volkswagen also faced intellectual property theft. In 2015, hackers compromised nearly 19,000 documents related to Volkswagen’s research and development projects. However, the company did not report the event until 2024.
Chemical
Two former employees of Lanxess, a chemical factory, stole intellectual property, including trade secrets and information on constructing next-generation nuclear reactors.
The buyers of these trade secrets included a Chinese company that planned to use the stolen information to develop a competing product against Lanxess.
Machinery
Nation-state hackers and hacktivists globally target manufacturing businesses like VARTA.
In February 2024, hackers breached VARTA AG’s systems, disrupting global battery production and impacting its supply chain. Two weeks later, VARTA revealed the real threats and announced a temporary shutdown of IT systems and output for security reasons.
Pharmaceutical
APT 27, a Chinese hacker group known for attacking Western government agencies, also targeted BfV, a German pharmaceutical and technology Company.
“Besides stealing trade secrets and intellectual property, the hackers tried to penetrate customers’ and service providers’ networks to infiltrate several companies simultaneously.”
Researchers also found a new extortion group, Morpheus, active since December 12, 2024, claiming to have compromised Arrotex Pharmaceuticals (Australia) and PUS GmbH (Germany) through data theft.
The Role of Managed Detection and Response (MDR)
MDR providers like ForeNova are critical in preventing APT groups from becoming successful. ForeNova’s expertise in proactive monitoring, observability, automated incident response, and threat modeling helps protect clients from a wide range of cyberattacks.
NovaMDR, ForeNova’s groundbreaking service, ingests log data from endpoint devices, Microsoft M365, and other sources. Leveraging the AI and ML functions, NovaMDR processes the data in real time and helps detect attacks quickly. This quick reaction capability, combined with the log data processing and automated incident response, helps contain even the early signs of a ransomware attack.
NovaMDR’s ability to handle these early signs of action also reduces the human resource cost of incident response. Organizations that leverage firms like ForeNova can reallocate human capital resources to other parts of the organization.
Benefits of Implementing MDR in Manufacturing
Leveraging NovaMDR for manufacturing creates many positive engagement models. Automotive manufacturers seeking to comply with TISAX can leverage NovaMDR to help monitor critical cybersecurity controls protecting the various supply chain connections and applications required under this compliance mandate.
Chemical manufacturing firms in Germany could also use NovaMDR to monitor intrusion prevention tools, firewalls, and email systems that target Internet-of-things (IoT) devices that control chemical compound distribution systems, environmental controls, and flow control systems.
German machinery firms migrating to industrial 5.0 robotics and automation controls could benefit from having ForeNova monitor these devices. Hackers using ransomware malware attempt to gain control of the computer control units for these automated tools, which can shut down operations entirely. NovaMDR’s ability to process log data in real time and leverage automated incidents can protect machinery’s production line systems from cyberattacks.
Like her German manufacturing firms, pharmaceutical firms continue transforming their research platforms globally by promoting great interconnection and collaboration. This transformation comes with an inherent risk. Organizations working together to find a cure for AIDS and COVID-19 become subject to intellectual property theft from insiders. Contractors, disgruntled employees, or even competitors could be among these insiders.
NovaMDR’s ability to process M365 logs helps determine if someone is attempting to copy valuable data to a USB or using email to send files outbound.
Why ForeNova?
Germany has some of the world’s most advanced manufacturing techniques. However, over two-thirds of German companies have been affected by a security breach, as attackers, some suspected of being foreign spy agencies, seek to steal trade secrets.
ForeNova’s expertise in identifying early signs of a persistent threat through email, endpoint, or network channels helps lower the risk for their German manufacturing clients.
Combining the firm’s knowledge of global APT hacker groups, leveraging their artificial intelligence (AI) and machine learning (ML) defensive capabilities, and compliance reporting support, ForeNova continues to become a strategy service partner to help protect their clients in stopping ATP attacks and intellectual data theft.
The industrial 4.0 and 5.0 manufacturing industry continues to become fully automated, using robotics and additional advanced technology sensors with less human interaction. This strategy helps manufacturers become far more productive and profitable.
Yet, despite the technical advancements in interconnecting supply chains, remote monitoring, and artificial intelligence (AI) and machine learning (ML) for continuous production efficiency improvements. These new platforms create a much larger attack surface and more cyber risks. Hackers target manufacturing because most of their environment contains exposed vulnerabilities, a hesitancy to apply software patches, and outdated traditional security measures.
As manufacturers continue to extend their automation and industrial functions, managed detection and response (MDR) services supporting industrial 5.0 will be necessary to secure manufacturing systems and detect and prevent persistent threats, malicious activities, and other sophisticated attacks.
ForeNova, a global innovator in the MDR cybersecurity industry, continues to increase its advanced threat detection managed services offering to support manufacturing clients in the EU with the NovaMDR platform.
Are you interested in securing your manufacturing networks and systems from next generation cyberattacks, meeting regulatory requirements, and moving toward a more proactive approach to cybersecurity?
Risk and Reward Regarding Industrial 5.0 Automation
Industrial 5.0 factories drive collaboration between human-machine systems and artificial intelligence, which is necessary for global manufacturing to meet their business and financial demands. As more factories become interlocked with others, the need to standardize manufacturing processes, supply chains, and quality control is paramount.
Cyberattacks, including ransomware attacks, extortion, supply chain fraud, and production outages, curtail the expected efficiencies and financial gains the manufacturers expect.
Many manufacturers face the challenge of their services becoming obsolete without moving toward industrial 5.0 capabilities because of the threat landscape. Another critical challenge during the transition to industrial 5.0 is the cost and resources required to sustain their existing operational technology (OT), legacy industrial control systems (ICS), and SCADA systems.
Many of these legacy systems exist within a closed-loop network environment, and maintenance updates rarely happen. Manufacturers’ decision to connect these legacy systems and next-generation Internet of Things (IoT) devices opened the door for cyberattacks. Hackers scanning industrial systems now have a direct line to previously secured OT and ICS systems with no remote access and limited network visibility.
Most manufacturing transformations are not greenfield deployments. Manufacturers will keep existing technologies functioning while migrating to new solutions, including IoT devices, AI-based robotics, remote access, and continuous monitoring.
These advanced functions have also become liabilities for manufacturing firms.
Unique Cybersecurity Threats and Vulnerabilities in Manufacturing
The manufacturing environment’s location shielded legacy OT and ICS systems vulnerabilities from exposure to advanced threats, human error, and zero-day attacks. As these legacy systems become IoT devices, patching and remediation are necessary to prevent phishing attacks, unknown threats, and other potential risks.
The firmware size on IoT devices is negligible, and they only perform specific product functions. These devices rely on the network and platform infrastructure for cybersecurity protection. Hackers traditionally have targeted networking devices, firewalls, application platforms, identity management systems, and users. Targeting IoT devices is especially appealing since this type of an attack will shut down utility control units and automation factories in Germany and FinTech systems in the United States.
Factories relying on fewer human resources and more robotics, leveraging IoT devices, become even more risky, mainly because these devices are codependent on each other.
For example, an electric vehicle has close to 468 sensors running inside the car. Each sensor has a critical role in the vehicle’s functionality. Car manufacturers, like computer manufacturers, create constant firmware updates. These manufacturers leverage firmware-over-the-wire to transmit over 5G or LTE to deliver these patches.
These cars can now receive firmware updates directly from the Internet, which increases the risk to both the vehicle and the driver.
However, these IP-enabled sensors will become even more vulnerable to cyberattacks without the ability to receive firmware updates over the wire.
How does NIS2 align with the Manufacturing Sector?
“The EU’s NIS2 directive addresses increasing cyber threats by imposing strict security obligations on essential service operators, including manufacturing. Compliance is vital for protecting infrastructure, supply chains, and intellectual property.”
Annex II of the NIS2 directive outlines specific manufacturing sectors affected by its cybersecurity requirements:
Medical devices
Electrical equipment
Machinery and equipment
Motor vehicles
Computers, electronics, and optical equipment
Robotics
Outside in compiling with NIS2, manufacturers have several reasons to leverage this compliance framework to guide where they need to focus their cybersecurity protection efforts.
These relevant areas include:
Protection of Critical Infrastructure Against Cybersecurity Challenges
A recent study reveals that 80% of manufacturing firms have encountered at least one cybersecurity incident, highlighting the critical necessity for strong protective measures. These measures aim to avert severe disruptions in manufacturing processes, maintain uninterrupted production, and safeguard against substantial financial and reputational harm.
Increase Cybersecurity Protection for Supply Chains
A recent study found that 70% of organizations faced supply chain attacks last year, underscoring the need for enhanced security protocols. The NIS2 cybersecurity framework can mitigate risks by leveraging technology and solutions partners to help protect customer data.
Manufacturers can protect their digital landscape by securing supply chains, ensuring business continuity, and enhancing resilience.
Providing Robust Security During the Industrial 5.0 Transformation
A recent study shows that 75% of manufacturers have faced more cyber threats in recent years. NIS2 compliance requires strong cybersecurity measures and rapid incident response capabilities, ensuring innovations do not jeopardize sector security.
Protect Trade Secrets and Intellectual Property
Manufacturers can protect their intellectual assets from breaches and espionage using comprehensive protection strategies, including encryption, multi-factor authentication, and advanced intrusion detection systems to establish robust defenses against attackers.
Meet NIS2, GDPR, and other EU Compliance Mandates
NIS2 compliance is vital for key manufacturing entities. “Non-compliance may cause penalties of up to 10 million euros or 2% of annual revenue, severely damaging the organization’s reputation.”
Creating the Proper Cybersecurity Architecture for Protecting a Manufacturing Facility
Securing the network, adding advanced identity management, and private VLANS are nothing new in the manufacturing sector. However, to address the increase in attack velocity from AI-based adversarial attacks, manufacturers need to make far more investments in next-generation networks, security operations centers, real-time threat detection, and advanced threat intelligence architectures to meet these challenges.
Zero-Trust Security Strategies
However complex, manufacturers recognize the critical importance of Zero-trust, especially with the increase in remote access into industrial 5.0 platforms, hosts, and devices. Zero-trust centralized all access to devices and hosts while serving human and machine-based authentication. This security protection layer also blocks direct connection access to industrial 5.0 robotic devices, water control units, solar farm devices, and other OT related functions.
Advanced Email Security Powered by AI
Sophisticated threats, including email phishing, continue to be among the manufacturing sector’s most challenging cyberattacks. Hackers using spear phishing techniques develop well-crafted email messages loaded with malicious links and malware and leverage language, attempting to lure factory managers, supply chain administrators, and plant operations teams to click on these messages.
Ransomware-as-a-service leverages email phishing as the delivery for their attack tools. Manufacturing firms must upgrade to AI-powered email security to help protect human and machine-leveraging emails to communicate status updates.
Updated Endpoint Detection
Endpoint security tools are widespread within traditional enterprise environments. Industrial control units leveraging Linux, macOS, and Microsoft Windows must add an endpoint agent to protect these critical hosts.
Data Protection
Industrial 5.0 platforms generate considerable data, including applications, robotics, and IoT devices. Protecting this data is critical for manufacturing because this content is essential for leveraging AI and ML capabilities for better platform operations and decision-making.
Managed Detection and Response Services (MDR)
MDR for manufacturing continues to gain importance, specifically for firms that struggle to migrate to industrial 5.0 architectures. MDR helps provide continuous monitoring, automated incident response, and remediation capabilities for legacy security devices and next-generation cybersecurity controls.
Why ForeNova?
ForeNova helps manufacturers protect their existing and future factories with various managed service solutions. By leveraging their NovaMDR platform, ForeNova brings together network, endpoint, and host-based security controls reporting a unified management console center. This console provides automated incident response, captures critical attack data, launches remediation capabilities, and provides reporting for compliance requirements.
The NovaMDR platform extended several additional capabilities, including 24×7 monitoring and access to security platform books, all delivered within an affordable cost model.
ForeNova’s expertise in NIS2 compliance and extensive experience supporting the German automotive industry’s TISAX compliance framework also benefits clients in the EU.
As the name implies, observability is organizations’ ability to visualize and capture complex issues and potential threats throughout their networks, cloud environments, and applications. Traditional continuous monitoring, powered by artificial intelligence (AI) and machine learning (ML), relies on processed telemetry, rules, and policies to detect and respond. Observability is about giving the organization additional real-time insight before detecting security incidents.
Spotting potential issues and gaining more comprehensive visibility allows companies to resolve them quickly.
Are you planning to increase your enterprise’s observability? Partnering with a reputable cybersecurity company, such as Forenova, enhances threat detection and provides valuable insights.
Click here to schedule a demo of the NovaMDR platform today from the team at Forenova.
What is Cybersecurity Observability?
Observability starts with deploying technology to expand the ability to collect telemetry from all enterprise devices, applications, systems, and data sources. By capturing a vast amount of telemetry, this function provides the enterprise with the means to see more of their environment in a simplified manner.
Observability is quickly becoming critical in helping organizations improve their key performance indicators, including Mean-time-to-detect (MTTD) and Mean-Time-To-Resolve (MTTR). Organizations leverage observability to help increase the speed and efficiency in resolving threats.
This increase in speed to detect and resolve becomes a critical component supporting threat detection. This support for detection also helps support the organization’s need to meet compliance mandates. Observability tools are crucial for organizations to comply with privacy and legal mandates, including GDPR, HIPAA, and PCI DSS.
Migration to Advanced Observability
Advanced observability enhances traditional monitoring through sophisticated data analysis. This evolution is driven by greater adoption of advanced threat detection technologies, more advanced endpoint detection and response capabilities, and increases in better threat intelligence sources.
AI also plays a critical role by becoming more embedded with observability tools. Real-time monitoring, faster data processing, and constant evolution for organizations wanting to move from a reactive to a proactive security posture recognize the importance of observability’s technology advancement for cybersecurity.
Importance of Observability in Cybersecurity
Observability is critical in improving even automated incident response powered by AI. Collecting all telemetry, cybersecurity-related or not, helps provide far greater early visibility to future events. SecOps teams leveraging actionable insights from observability can now feed this telemetry into their LLM tools to help improve incident response automation.
Observability is quickly becoming critical in helping organizations improve their key performance indicators, including Mean-time-to-detect (MTTD) and Mean-Time-To-Resolve (MTTR). Organizations leverage observability to help increase the speed and efficiency in resolving threats.
How does Observability Enhance Proactive Threat Detection?
A critical enhancement to current threat detection capabilities comes from actionable insights created by observability tools. These actionable insights help provide visibility to anomalies happening in real time. This early warning ability becomes a critical data source for threat detection solutions.
Thus, observability helps prevent minor anomalies from escalating into significant incidents. Observability enhanced current detection functions by delivering actionable insights. Without observability, the SecOps team continues to deal with alert fatigue from increased attack velocity.
Leveraging Observability to Solve Alert Fatigue
Alert fatigue even among the managed service community is a problem. SecOps engineers must become far more engaged on attack incidents cause this high-valued team to burn-out and quit their profession.
Observability’s actionable insights help improve SecOps workflows to help reduce the manual incident response intervention by their engineers.
These insights fed directly into the detection layer helps provide far more deeply analysis of an anomaly behavior. This knowledge interjection improves automation, speeds up response times, and provides a much faster end-result analysis that feeds into the threat intelligence and modeling tools.
By fully automating these workflows, SecOps engineers can focus on more strategy projects and a higher level of overwatch.
Real-time Insights and Analysis
Observability detects threats and enables preventive controls by tracking infrastructure vulnerabilities. Organizations receive alerts to address these issues before attackers exploit them.
Improving an organization’s security posture reduces risks by preventing incidents and closing potential attack gaps.
Integration of Observability in MDR Services
Observability must cover all infrastructure, from cloud to on-premises, ensuring no cybersecurity blind spots and minimizing undetected vulnerabilities. This holistic view enables teams to act against threats, enhancing organizational cyber resilience.
Another critical aspect of merging observability into managed detection and response (MDR) by collecting valuable additional telemetry from high-value enterprise assets, including customer data, public-facing websites, and internal intellectual property.
This advanced collection progress enhances incident response by providing actionable data for security events. Security teams with timely, data-driven insights can respond faster to minimize potential damage, creating a cohesive approach to threat management.
Observability offers detailed data critical for incident analysis to MDR platforms like NovaMDR.
What are the Challenges of Observability When Working with MDRs?
Observability tools deliver value regarding providing actionable insight. Like other cybersecurity tools, observability solutions generate considerable telemetry data. This additional data collection can overwhelm many organizations not prepared to receive, store, process, and remove telemetry information in due course. Organizations that invest in observability recognize this as a very sizable expense. A complete enterprise-wide solution requires capital for licensing, implementation, and hiring experienced engineers or contracting out to an MDR provider.
Another element of observability is the challenges requiring privacy and consideration of regulations. Observability’s core focus is to collect vast amounts of data to help provide valuable actionable insights for cybersecurity and application performance.
Organizations must establish governance policies to ensure this new capability collects data while respecting users’ privacy and not jeopardizing compliance mandates or regulatory issues.
Data Migration From Several Sources
Integrating data from various sources into a single observability system is complex and requires careful management to avoid overloading IT infrastructure and to ensure data integrity. Simplifying this integration is essential for timely monitoring and action.
Observability requires an extensive amount of data to be relevant. Data sources originating from different areas within the enterprise. Collecting too much data continues to be a reason for resistance to installing observability tools.
Balancing Cost and Value
Observability delivers optimal value to an organization, especially considering the increase in the volume of adversarial AI attacks. Organizations must extend their governance frameworks to better realize the cost of collecting observability telemetry and the meaningful impact this tool has on improving MTTD and other KPIs.
Organizations considering observability need to consider starting with a smaller subset of tools with a measurable expectation regarding improving the organization’s current and future cybersecurity posture.
The initial observability deployment helps establish a critical guardrail by targeting specific high-value corporate assets. This protection will help limit the data collected from key resources and the insights gained. SecOps will view this additional stream using their extended detection and response (XDR) tools. This will help them evaluate whether the cost of the additional telemetry provided the expected value in improving the organization’s security posture.
Global Shortage of Talent Still A Challenge
Observability tools need skilled personnel for data collection and analysis. Because of a shortage of cybersecurity skills, many organizations struggle with implementation and ongoing security operations of observability tools and data.
MDR providers like Forenova have access to talented and experienced security operations engineers who can assist clients with their cybersecurity detection, prevention, and response journeys.
Future Trends in Cybersecurity Observability and MDR
Observability’s initial rollout followed similar paths to other advanced tools. Many tools use proprietary formats, data schemes, and user interface workflows.
One expected change to observability marketing is the adoption of Open Telemetry, or OTel. OTel is an open standard for collecting and routing telemetry data into open-source observability tools.
Open-source observability tools will continue to impact the industry positively. Organizations that want to collect telemetry from various assets can leverage platforms supporting the OTel framework. Open-source observability also helps organizations build their initial governance framework.
Open-source observability also integrates well with MDR providers like Forenova. By leveraging OTel formatting, Forenova extends the ability to ingest observability telemetry into the NovaMDR platform to complement its existing AI-powered incident response automation functionality.
Why Forenova?
Forenova, an award-winning managed detection and response (MDR) provider based in the European Union (EU), understands the criticality of stopping advanced cyber threats and seeing the constant changes in the cybersecurity landscape.
Preventing advanced attacks powered by adversarial AI requires layers of prevention technologies combined with expertise in security operations. Without proper visibility into networks and corporate digital assets, hackers will continue taking over devices, hijacking applications, and stealing data.
Want more helpful information about your company’s systems? Observability continues to become a strategy investment and focus for organizations witnessing dramatic increases in complex cyberattacks. Forenova’s continued innovation in managed detection and response offerings also recognizes the importance of greater visibility in enhancing automated incident and response offers embedded within their NovaMDR offering.
Immer up to date!
Abonnieren Sie unseren Newsletter und erhalten Sie wertvolle Branchen-Insights, Produkt-Updates und aktuelle Analysen von ForeNova direkt in Ihr Postfach.
* Datenschutzrichtlinie
Wir verwenden Brevo als unsere Marketing-Plattform. Indem Sie das Formular absenden, erklären Sie sich einverstanden, dass die von Ihnen angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden, gemäß den Datenschutzrichtlinien von Brevo.
Please wait while you are redirected to the right page...
When you visit our website, ForeNova and third parties can place cookies on your computer. These cookies are
used to improve your website experience and provide more personalized services to you, both on this website
and through other media. To find out more about the cookies we use, see our
Privacy Policy.
If you reject all cookies, except one strictly necessary cookie, we
won't track your information when you visit our site. In order to comply with your preferences, we'll have to
use just one tiny cookie so that you're not asked to make this choice again.