New Study Reveals 92 of Industrial Sites at Risk from Unsecured Remote Access

DeNexus, a provider in end-to-end cyber risk management for operational technology (OT) in Industrial Enterprises and Critical Infrastructures with cyber-physical assets, today announced the results of a comprehensive analysis of 254 industrial sites across North America, Europe, and Australia has revealed that 92% of sites face significant cyber exposures related to remote services, with potential losses reaching up to $1.5 million per site. The study, conducted by DeNexus using their DeRISK platform, highlights the critical need for enhanced security measures in industrial remote access solutions.

Planning and forecasting security investments for existing and future data center facilities requires financial quantification of both physical and cyber risks. With this new capability, DeRISK’s models capture the facility’s physical security zones, the various access paths from zone to zone, the related physical access controls and their effectiveness, and the probability of a successful bypass that could result on a cyber event. With DeNexus, security leaders can understand physical and cyber exposures at their data center facilities, estimate the potential financial loss from a breach, and run “what-if” scenarios for various risk mitigation investments to strengthen physical and cyber defenses.

Key Findings include:

  • 88% of analyzed sites identified remote services (a MITRE ATT&CK® initial access vector) as their most significant cybersecurity risk
  • Manufacturing sector shows highest exposure, with average expected losses of $875,000
  • Renewable energy sector demonstrates lower but still significant risk, with expected losses around $150,000
  • Average annual expected loss related to remote services reaches $223,000 per site

To mitigate remote access vulnerabilities, DeNexus recommends implementing frequent vulnerability scanning and patching on at least a monthly basis, along with strict authentication measures including Multi-Factor Authentication. Organizations should also deploy just-in-time authorization for remote access, strengthen network segmentation between OT and IT systems, and maintain robust password management with regular updates and account lockout policies.

The study's timing is particularly relevant as recent research from Claroty in 2024 indicates that organizations are deploying too many remote access solutions within OT environments. This over-deployment creates excessive risk and operational challenges. Additionally, separate research by Takepoint Research found that remote services were the primary attack vector in 17 out of 24 major cyber-attacks on OT environments.

The full report includes a detailed analysis of risk exposures across different industrial sectors and provides comprehensive recommendations for securing remote access in industrial environments.

To access the full report, please visit https://blog.denexus.io/resources/data-report-remote-services

Featured

  • Human Risk Management: A Silver Bullet for Effective Security Awareness Training

    You would think in a world where cybersecurity breaches are frequently in the news, that it wouldn’t require much to convince CEOs and C-suite leaders of the value and importance of security awareness training (SAT). Unfortunately, that’s not always the case. Read Now

  • Windsor Port Authority Strengthens U.S.-Canada Border Waterway Safety, Security

    Windsor Port Authority, one of just 17 national ports created by the 1999 Canada Marine Act, has enhanced waterway safety and security across its jurisdiction on the U.S.-Canada border with state-of-the-art cameras from Axis Communications. These cameras, combined with radar solutions from Accipiter Radar Technologies Inc., provide the port with the visibility needed to prevent collisions, better detect illegal activity, and save lives along the river. Read Now

  • Survey: 84 Percent of Healthcare Organizations Spotted Cyberattack in Last 12 Months

    Netwrix, a vendor specializing in cybersecurity solutions focused on data and identity threats, surveyed 1,309 IT and security professionals globally and recently released findings for the healthcare sector based on the data collected. It reveals that 84% of organizations in the healthcare sector spotted a cyberattack on their infrastructure within the last 12 months. Phishing was the most common type of incident experienced on premises, similar to other industries. Read Now

  • Keynote Speakers Announced for ISC West 2025

    ISC West, hosted in collaboration with premier sponsor the Security Industry Association (SIA), unveiled its 2025 Keynote Series. Featuring a powerhouse lineup of experts in cybersecurity, retail security, and leadership, each keynote will offer invaluable insights into the challenges and opportunities transforming the field of security. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3