CNI
"Even when security teams have full visibility of their domains there are often systems that can’t be patched or updated... CNI providers have to think in terms of decades for their security and operations"
Claroty's Andrew Lintell warns that 27 different timelines for NIS2 and a lack of cohesion are creating a "massive risk"
Meanwhile... "leadership deprioritized the treatment of a vulnerability their own cybersecurity team identified".
CISA has just two federal staff and five contractor staff working on its OT-specific threat hunting and/or incident response services...
"Almost no information is currently available to indicate how an organization is preparing for future cyber-physical challenges. This has to change."