“Misconfigurations are extremely common in Cyber-Physical Systems, from IoT to operational technology and industrial control systems,” said Sonu Shankar, Chief Strategy Officer of Phosphorus.
- Remove default credentials and harden configurations.
- Disable unused services and implement access control.
- Update regularly and automate patching, prioritizing patching of known exploited vulnerabilities.[2]
- Reduce, restrict, audit, and monitor administrative accounts and privileges.
Nearly all of the critical recommendations that NSA and CISA encouraged companies to implement represent capabilities that Phosphorus has long addressed through its best-of-breed Unified xIoT Security Management & Breach Prevention Platform. It is the industry’s only CPS Protection Platform covering the entire security and management lifecycle for xIoT devices–including OT/ICS, IoT, IIoT and IoMT Cyber-Physical Systems.
Phosphorus’s Unified xIoT Security Management & Breach Prevention Platform provides seamless, full-scope coverage through its unique ability to directly communicate with all xIoT devices in their native protocols.
- CPS Discovery – Accurate device discovery is the crucial first step for addressing vulnerable devices, but most organizations undercount their total xIoT device footprint by 40–60%. Phosphorus’s platform is powered by the industry’s first and only scalable Intelligent Active Discovery (IAD) engine which achieves 100% device certainty the first time, assessing CPS assets up to 98% faster than traditional passive scanners and is up to 95% more efficient (lighter) than legacy active scanners. Equally critical, it is safe to use across the full range of CPS asset classes, including highly sensitive OT and ICS devices.
- CPS Risk Assessment – Phosphorus’s unique approach means that a complete set of high-fidelity “Device Metadata” is provided across device families, determined only by direct interaction with the CPS asset. In addition to in-depth device details, the platform’s evidence-based risk assessment capability collects over 3X more data points from xIoT assets than other services – including high-fidelity analysis of device posture, status of device credentials, current firmware version and CVEs, certificate status, risky configurations, device End of Life status, banned devices, and more.
- CPS Hardening & Remediation – By leveraging the ability to directly communicate with any CPS device, Phosphorus has developed a completely new approach to protecting CPS assets by providing proactive security management and breach prevention across the complete CPS estate by automating the remediation of the biggest IoT, OT/ICS, IoMT, and IIoT device vulnerabilities – including changing default passwords and establishing periodic password rotations, updating out-of-date device firmware (including unpatched CVEs), checking for out-of-date device certificates, fixing risky configurations, and more. The Phosphorus platform satisfies the NSA/CISA top mitigation recommendations.
Author
Phosphorus Cybersecurity
Phosphorus Cybersecurity® is the leading xTended Security of Things™ platform designed to find, fix, and monitor the rapidly growing and often unmonitored Things of the enterprise xIoT landscape.