KasperskyThreat Intelligence

    Threat Intelligence ICS

    OT and critical-infrastructure threat intelligence from Kaspersky ICS CERT.

    Kaspersky ICS Threat Intelligence delivers a comprehensive understanding of industrial cybersecurity threats and vulnerabilities for efficient risk assessment, attack detection, investigation, and response. It is backed by Kaspersky ICS CERT — the first private CERT in industrial cybersecurity — and combines ICS-specific data feeds, reporting, and expert consultation. Faltrox operationalises it for the OT and critical-infrastructure part of your estate.

    Overview

    What Threat Intelligence ICS is

    Industrial control systems and critical infrastructure face threats that general intelligence does not cover — vulnerabilities in specific SCADA and ICS products, malware tailored to OT, and campaigns aimed at industrial organisations. Kaspersky ICS Threat Intelligence, delivered by the 30+ experts of Kaspersky ICS CERT, provides the tailored visibility needed to protect these environments.

    It comprises ICS Threat Data Feeds (hashes, vulnerability data, and OVAL definitions for automated detection in SCADA and industrial software), ICS Intelligence Reporting (APT and campaign reports, vulnerability advisories with mitigation, and threat-landscape reviews), and Ask the Analyst for ICS-specific expert consultation. Reports are delivered via the Threat Intelligence Portal or API. Faltrox applies it to safeguard your critical assets and the continuity of your technological processes.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    SCADA & ICS Systems

    Vulnerability data and OVAL definitions for automated detection in SCADA and industrial software.

    02

    Industrial Organisations

    Intelligence on malicious campaigns targeting industrial and critical-infrastructure organisations.

    03

    ICS Malware

    Analysis of malware tailored to OT environments and the techniques used against them.

    04

    ICS Vulnerabilities

    Verified, refined data on vulnerabilities in ICS software and hardware, with mitigation guidance.

    05

    Regulatory Standards

    Information on regulatory requirements and standards relevant to industrial cybersecurity.

    06

    Regional & Sector Trends

    Threat statistics and trends by region and industry for informed risk assessment.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Feed

      ICS Threat Data Feeds deliver hashes, vulnerability data, and OVAL definitions in machine-readable formats for automated detection.

    2. 02

      Detect

      Feeds integrate into your security tools to simplify and automate timely attack detection and vulnerability identification in OT.

    3. 03

      Report

      ICS Intelligence Reporting provides APT and campaign reports, vulnerability advisories, and threat-landscape reviews via the portal or API.

    4. 04

      Mitigate

      Advisories give actionable recommendations from Kaspersky ICS CERT to identify and mitigate vulnerabilities in your infrastructure.

    5. 05

      Consult

      Ask the Analyst provides expert guidance on specific ICS threats, vulnerabilities, and statistics tailored to your organisation.

    Capabilities

    Key capabilities

    ICS Hashes Data Feed

    A regularly updated stream of threat intelligence for ICS and OT to automate timely attack detection and investigation.

    ICS Vulnerability Data Feed

    Verified, refined data on vulnerabilities in ICS software and hardware in machine-readable format.

    OVAL Definitions Feed

    OVAL definitions for automated detection of known vulnerabilities in SCADA and industrial software.

    ICS Intelligence Reporting

    In-depth reports on APTs and campaigns targeting industrial organisations, with vulnerability analysis.

    Threat-Landscape Reviews

    Reports on significant changes to the ICS threat landscape, including regional and industry-specific information.

    Vulnerability Advisories

    Actionable mitigation recommendations from Kaspersky ICS CERT for vulnerabilities in your infrastructure.

    Ask the Analyst (ICS)

    Expert consultation on ICS reports, vulnerabilities, threat statistics, malware analysis, and regulatory requirements.

    ICS CERT Backing

    Delivered by the 30+ experts of Kaspersky ICS CERT, the first private CERT in industrial cybersecurity.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Threat Intelligence ICS for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why do OT environments need separate threat intelligence?

    General intelligence does not cover the specifics of industrial systems — vulnerabilities in particular SCADA and ICS products, OT-tailored malware, and campaigns aimed at industrial organisations. ICS Threat Intelligence is purpose-built for those, backed by the dedicated Kaspersky ICS CERT.

    02How do the ICS feeds integrate with our tools?

    They are delivered in machine-readable formats — including OVAL definitions for automated vulnerability detection in SCADA and industrial software — so they integrate into your security tools to automate attack detection and vulnerability identification in the OT environment.

    03What is in the ICS reporting?

    Reports on new APT and high-volume campaigns targeting industrial organisations, advisories on vulnerabilities in popular ICS products with mitigation guidance, and threat-landscape reviews including regional, country, and industry-specific information.

    04Can we ask ICS-specific questions?

    Yes — Ask the Analyst (ICS) gives you access to Kaspersky ICS CERT experts for guidance on specific ICS threats, vulnerabilities, threat statistics, malware analysis, and relevant regulations and standards.

    05How does Faltrox use it?

    We integrate the ICS feeds into your OT monitoring, apply the reporting and advisories to your risk assessment and hardening, and use Ask the Analyst where a specific ICS question arises — operationalising it for the industrial part of your estate alongside Embedded Systems Security.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us