The Forescout Technologies 2024 Threat Roundup Report states that security incidents affecting critical infrastructure have grown by 668 percent since 2022.
Research for the report by Forescout Vedere Labs highlights key trends from 2024, including threat actors, vulnerabilities, exploits, top targets, and attacker locations, while drawing comparisons to 2023 and offering insights and strategic recommendations.
The findings are based on an analysis of 900 million attacks and include:
- Web applications were the most attacked service type followed by remote management protocols.
- Attacks on web applications increased from 26% in 2022 and 2023 to 41% in 2024, with most attacks consisting of either scanning or exploit attempts. The increase represents a shift from mostly credential-based attacks to exploits on perimeter devices and applications.
- Accounts associated with databases are the most attacked. IoT device credentials consist of 6% of attacks (e.g., routers, cameras, DVRs, industrial and network equipment).
- Exploits against network infrastructure devices became the second most popular category.
- Exploits against web applications rose from 36% in 2023 to 56% in 2024.
- Network infrastructure devices (routers, firewalls, VPNs, etc.) are the second largest category and increased from 3% (2022) to 11% (2023) and now 14% (2024).
- The percentage of exploited vulnerabilities not in CISA’s Known Exploited Vulnerabilities (KEV) increased from 65% to 73%.
- Attackers are constantly scanning popular OT protocols, with 79% targeting industrial automation, 12% on power sector, and the remaining on building automation. Building automation increased from 2% in 2023 to 9% in 2024.
- Most attacks are opportunistic, with a heavy interest in Modbus (33% in 2023 to 40% in 2024) and more fragmented interest in a lot of other protocols.
- U.S. is the biggest critical infrastructure target, with incidents increasing across sectors.
- Based on data from the European Repository of Cyber Incidents, since 2022, reported security incidents in critical infrastructure worldwide have grown by 668 percent.
- There were 10% more incidents for critical infrastructure sectors than in 2023 and more than half of all incidents (57%) affected critical infrastructure sectors.
- Healthcare was the top targeted sector in 2023 (24%) and 2024 (17%), followed by financial services (17%) and government (10%).
- The US is the biggest target. Top targets after the US are Europe (Germany, France, Spain, Italy and the UK) and Asia (Japan, India, Korea, Taiwan, Singapore).
- The top three countries targeted by the most threat actors are United States, Germany and India.






