Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Eric Knapp, Chief Technology Officer of
Operational Technology at OPSWAT
As we rapidly approach 2025, the adoption of cloud
technologies in Industrial Control Systems (ICS) and Operational Technology
(OT) environments will continue to increase rapidly. Indeed, the 2024 SANS
ICS/OT Cybersecurity Report showed that 26% of organizations are already
leveraging cloud solutions-a 15% rise from previous years. It’s unlikely
to slow down; the latest forecast from Gartner, Inc. predicts worldwide
spending on public cloud services to reach $723.4 billion in 2025, an increase of 21.5%.
This shift towards cloud adoption brings more flexibility and scalability-but
it also exposes these critical systems to new and different cyber risks. To
address and overcome these challenges, organizations must take a comprehensive
and balanced approach to cybersecurity.
Surge in Cloud Adoption and Risk
The need to continuously transfer critical data out of
industrial control and automation systems and into centralized IT systems
continues to grow. The increasing shift to move these business functions into
the cloud introduces additional risk, increasing the exposure of sensitive OT
data. Worse, if implemented poorly, OT systems could be completely exposed.
Operators end up living a recurring OT nightmare and wake up in a cold sweat
after finding their own OT assets on Shodan.
Is this just a fever-dream? Unfortunately, no. Over the
course of 2024, the Cybersecurity and Infrastructure Security Agency (CISA) has
continued to warn that state-sponsored actors have compromised and maintained
persistent access to critical infrastructure in the United States. So, if you’re going to transfer data from OT
to IT, that network connection needs to be very carefully implemented.
One way to ensure secure communication is to channel all
devices that regularly interact with cloud services through strict network
security controls such as data diodes, which allow for safe, one-way
data transfer. That means that there is no possibility for data to return to
the source network, creating a physical separation that eliminates the risk of
cyberattacks that could otherwise transmit across a two-way communication link.
The hardware-based structure of data diodes makes them immune to software bugs
and malicious code, keeping senders safe from incoming malware while still
enabling organizations to safely transfer critical OT data to IT systems for
analysis and business intelligence.
Of course, organizations also require remote access into OT
environments to perform maintenance, upgrades, and other types of tasks. By
creating a hard airgap, we create a paradox: we need to get into the network,
but data can only flow out. Solving this paradox requires organizations to use
separate, secure pathways that have been tailored to
allow only specific OT tasks and restrict access to authorized personnel only.
To address both the surge in cloud adoption and the related risks of
communicating securely across these environments, 2025 will see a surge in adoption
of both data diodes and secure remote access pathways.
Rise in AI-Driven Cyber Threats
Many headlines have already been written about
cybercriminals using AI technologies to carry out more frequent and more
sophisticated cyber-attacks in the year ahead. From automating sophisticated
attacks, such as deepfake-driven phishing and adaptive malware capable of
evading traditional security measures, organizations must be prepared to detect
and counter a continuous onslaught of attacks that vary in execution and skill
level.
Despite these anticipated new attack capabilities, the SANS
2024 State of ICS/OT Cybersecurity Report showed that much of the ICS workforce
has less than five years of experience and over half of them lack formal
cybersecurity credentials. Most are ill-prepared to identify and defend against
sophisticated malicious actors. The SANS 2024 report also showed that only 25%
of organizations had allocated a significant portion of their budget toward
workforce training, recruitment, and retention, however. In 2025, more
organizations must and will focus on these initiatives and take a comprehensive
approach to managing and securing their cloud connections.
With a larger attack surface, new considerations and
controls around information flow, and an increase in the frequency and
capability of cyber threats, the need for specialized OT cybersecurity
personnel has grown even higher.
No More
“Technology du Jour”
As we race towards 2025, organizations will build a balanced
and comprehensive approach to ICS/OT security rather than relying on a single
“technology du jour” to save the day. This approach will require some
strategic investment, including:
- Providing safe, one-way
data transfers for devices that regularly interact with cloud services - Separate, secure pathways
tailored for specific OT tasks and restricted to authorized personnel to
perform maintenance, upgrades, and other tasks - Prioritization of and
investment in security training for IT and OT staff to address the
existing and emerging threats in cloud-based and cloud-connected ICS/OT
systems
By implementing these tools and strategies, organizations
can better protect their ICS/OT environments as they transition fully to the
cloud or adopt hybrid and multi-cloud strategies, while also addressing the
critical skills gap in the industry. As we move into 2025, organizations will
invest in these critical controls to manage cloud connections in ICS and OT
systems effectively and securely.
##
ABOUT THE AUTHOR
Eric Knapp is CTO of OT at OPSWAT and
focuses on the organization’s industrial product engineering, product marketing
and cybersecurity strategy. He previously served as Chief Engineer and Fellow
at Honeywell Industrial Cyber Security. He is a recognized expert in industrial
control systems cybersecurity, and is the author of “Industrial Network
Security,” and co-author of “Applied Cyber Security for Smart Grids.” Eric has
over 20 years of experience in Information Security, specializing in industrial
automation, security analytics, and risk management in both enterprise and
industrial networks. He has held leadership positions at NitroSecurity, Intel
Security, and Wurldtech, and is active on numerous industry boards and
committees.





