In its inaugural annual risk assessment, the Cyber and Infrastructure Security Centre (CISC) has underscored the heightened vulnerabilities in critical infrastructure resulting from the merging of operational technology (OT) and information technology (IT). This convergence, the CISC’s Critical Infrastructure Annual Review [pdf] noted, is compounded by the proliferation of the Internet of Things (IoT), which introduces a potential avenue for lateral movement between systems, with the potential for devastating cascading consequences.
The report also emphasized that the integration of third-party inputs, information sharing, and data analytics within critical infrastructure due to IoT adoption raises concerns. Furthermore, the eagerness of companies to embrace digital transformation is outpacing our collective cyber literacy and security practices, according to the CISC.
Another troubling aspect identified by the CISC is the concealment of malicious code within critical infrastructure networks, creating a potential threat for future exploitation. Removing such identified code can inadvertently alert adversaries, making it challenging to fully assess and mitigate this hidden danger. The review cited an instance in North America where possibly malicious code was discovered within critical infrastructure networks, including those supporting power, communication, and water supply.
The CISC is also wary of the risks arising from individuals, including “disgruntled employees” who may be recruited by foreign intelligence services through job advertisements on the dark web. Additionally, the shift towards remote work is presenting challenges, as offsite connectivity can reduce the detectability of and make it easier for trusted insiders to access and potentially transfer local data to third parties.


