20/07/2026
📚 2026 Threat Landscape Series
📌 EP.6 — OT / ICS ATTACK
ภัยที่กระทบโรงงานไทย + สาธารณูปโภค
IT/OT Convergence Risk + Series B Wrap
━━━━━━━━━━━━━━━━━
🏭 OT Attack ไม่ใช่เรื่องโรงงานในยุโรป — ไทยโดนแล้วและจะโดนอีก
Operational Technology (OT) = ระบบควบคุมโรงงาน สายพาน หม้อน้ำ ไฟฟ้า น้ำประปา ระบบขนส่ง
ต่างจาก IT ตรงที่ downtime ของ OT = ผลิตภัณฑ์หยุด + ความปลอดภัยคนในโรงงานกระทบ + บางกรณี life-critical
ปี 2026 OT attack โผล่ขึ้น radar ของ threat actor มากขึ้น เพราะ:
1. OT เริ่มเชื่อม IT (IT/OT convergence) = surface กว้างขึ้น
2. OT ใหม่ใช้ protocol IP-based (not legacy serial) = exploit ง่ายขึ้น
3. Geopolitical tension = nation-state ให้ความสำคัญ OT เป็น target
━━━━━━━━━━━━━━━━━
🎯 เคสจริงที่สะท้อน
▫️ Colonial Pipeline (2021) — ransomware บน IT side ทำให้ต้อง shut OT pipeline สหรัฐฯ ขาดน้ำมัน 5 วัน
▫️ Viasat / KA-SAT (กุมภาพันธ์ 2022) — cyber attack ตัด internet ให้หน่วยทหารยูเครนเป็นหลัก และมี collateral damage ไปที่ wind turbine ใน Europe
▫️ Water Utility Attacks — Oldsmar (2021) พยายามเปลี่ยนระดับ sodium hydroxide, Aliquippa (2023) CyberAv3ngers เจาะ HMI ของ water authority
▫️ Thailand — มีรายงานภาคโรงงานและ critical infrastructure ถูกเล็ง และบางกรณีถูก ransomware ลาม
━━━━━━━━━━━━━━━━━
🔍 OT มี attack surface อะไรบ้าง
1️⃣ HMI (Human-Machine Interface)
หน้าจอควบคุมโรงงาน บางโรงงานยัง Windows XP / 7 + RDP exposed
2️⃣ PLC (Programmable Logic Controller)
อุปกรณ์ควบคุมเครื่องจักร — บาง model มี backdoor default credential
3️⃣ SCADA Server
ระบบ supervisory — ถ้า compromise = control plant operations ได้
4️⃣ Engineering Workstation
เครื่องที่ engineer ใช้โปรแกรม PLC — ถ้าโดน = inject logic ผิด
5️⃣ Historian Database
เก็บข้อมูลการผลิต — ถูกใช้เป็น pivot เข้า IT side
━━━━━━━━━━━━━━━━━
🛡 OT Security — ต่างจาก IT ยังไง
ในโลก IT: Confidentiality > Integrity > Availability
ในโลก OT: Availability > Integrity > Confidentiality
หมายความว่า OT รับ downtime ไม่ได้ — patch ยาก, MFA ยาก, ลง EDR ยาก
Defense strategy:
✅ Network Segmentation (Purdue Model / ISA-95)
✅ One-way data diode สำหรับ OT → IT
✅ OT-specific monitoring (Claroty, Nozomi, Dragos)
✅ Remote access via jump host + MFA + session recording
✅ Patch cycle ยาวกว่า IT (6-12 เดือน) แต่ต้องมี compensating control
✅ Vendor management เข้มงวด (OEM remote access)
━━━━━━━━━━━━━━━━━
🇹🇭 Thailand OT Reality
▫️ โรงงานไทยจำนวนมาก ยังใช้ flat network — IT + OT บน VLAN เดียว
▫️ Legacy HMI Windows XP/7 ยังเยอะ ไม่ได้ patch
▫️ Vendor remote support ผ่าน TeamViewer/AnyDesk ไม่มี MFA
▫️ ไม่มี OT asset inventory — ไม่รู้ว่ามีอะไรบ้างในโรงงาน
▫️ SOC ทั่วไปดูแค่ IT ไม่มี OT-specific detection
→ ต้องเริ่มจาก asset inventory + segmentation ก่อนอย่างอื่น
━━━━━━━━━━━━━━━━━
📋 OT Security Roadmap 6 เดือนแรก
Month 1-2: OT Asset Inventory + Network Map
Month 3: Segmentation IT/OT (firewall rule ชัด)
Month 4: Remote Access Jump Host + MFA + Logging
Month 5: OT Detection (passive monitoring first)
Month 6: Incident Response Playbook เฉพาะ OT
━━━━━━━━━━━━━━━━━
🎬 Series B Wrap
6 ตอนที่ผ่านมา เราเจาะภัยคุกคามที่องค์กรไทยควรรู้:
EP1 Threat Landscape Overview
EP2 Ransomware Groups
EP3 Phishing Thai-Targeted
EP4 Supply Chain Risk
EP5 Insider Threat
EP6 OT/ICS Attack (ตอนนี้)
ไม่มีองค์กรไหนรอดจากภัยเหล่านี้ได้ แต่องค์กรที่เตรียมตัวดี จะผ่านมันไปได้โดยไม่กลายเป็นข่าว
ตอนหน้าเปิด Series C — "CISO Playbook" สำหรับผู้บริหารที่ต้องตัดสินใจด้าน cyber 6 ตอน เจอกันในซีรีส์ใหม่ครับ
ถ้าอยากปรึกษา threat landscape เฉพาะสำหรับ industry ของคุณ ทักมาได้ที่ [email protected] ทีม CTI ของ ECOP ยินดีช่วยครับ