Analyzing New and Emerging Cyber Threats in Industrial Control Systems and Their Impact on Critical Infrastructure
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
Industrial Control Systems (ICS) consist of the backbone of critical infrastructure sectors such as energy, water, manufacturing, and transportation. With increasing Information Technology (IT) and Operational Technology (OT) convergence, ICS networks today experience a new range of cyber threats that exploit new technologies such as artificial intelligence (AI), Internet of Things (IoT), and 5G connectivity.
This study investigates the nature and impact of these emerging cyber threats through qualitative analysis of expert interviews. Ten highly experienced experts in ICS security, critical infrastructure operations, and threat intelligence were interviewed. Their comments were categorized through thematic analysis with NVivo into five overarching themes: (1) Emerging Cyber Threats, (2) ICS Vulnerabilities, (3) Impact on Critical Infrastructure, (4) Defense Mechanisms, and (5) Future Cybersecurity Challenges.
Key findings show that AI-driven ransomware, living off the Land attacks, and supply chain attacks are threats that are moving at a breakneck pace. Legacy systems, poor encryption, and insufficient proper real-time monitoring were some of the major ICS vulnerabilities identified. Real-world incidents in the form of power outages, freezing of systems, and safety risks triggered by cyberattacks on ICS were showcased by practitioners. Current measures like network segmentation, zero trust models, and behavior monitoring are present but typically meaningless without updated training and continuous support.
This study provides real-time understanding of the changing ICS threat landscape and offers actionable results to improve resilience. The results can inform policymakers and security professionals who are interested in safeguarding national infrastructure against sophisticated cyber-attacks.
Place, publisher, year, edition, pages
2025. , p. 88
Keywords [en]
ICS, Critical Infrastructure Security, Emerging Cyber Threats, IT/OT Convergence, AI-driven Malware, Supply Chain Attacks, Zero Trust Architecture, Defense-in-Depth, MITRE ATT&CK for ICS, Adaptive ICS Cyber-Security Process-Framework, Legacy Protocol Vulnerabilities, Human Factors & Skills Pipeline
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:ltu:diva-115031OAI: oai:DiVA.org:ltu-115031DiVA, id: diva2:2004333
Subject / course
Student thesis, at least 30 credits
Educational program
Information Security, master's level (120 credits)
Supervisors
Examiners
2025-10-072025-10-072025-10-21Bibliographically approved