Dale Peterson interviews the innovators in ICS / SCADA cyber security as well as the top talent in related fields. It is the podcast for those who want more information similar to what is presented at the annual S4 event each January in Miami South Beach.
Dale Peterson speaks with Joel Langill, the SCADAHacker, about his new training course entitled Conducting Threat, Vulnerability, and Risk Assessments For ICS. A two day version of this course will be offered prior to S4x25.
Of course Dale and Joel jump around a bit on training, the workforce and other items. Take a listen.
Stewart Baker is one of the preeminent lawyers on topics of cyber law with an impressive career in and out of government. Stewart also hosts the Cyberlaw podcast.
The Biden administration is contending that vendors should be held liable for security deficiencies in their products.
Assuming this is turned into law and/or executive orders, what does it mean? What can we learn from other liability law to inform us what would be required for a vendor to be held liable for a security issue? How would the judgment / damages be determined.
Dale's note: We talk about the SEC charges against SolarWinds in this interview.
Dale Peterson interviews Rob Lee on the S4 Main Stage. They cover a lot of ground and Rob is never shy about sharing his opinions and analysis. They discuss:
Chris Hughes and Nikki Robinson recently wrote the book Effective Vulnerability Management. Dale and Chris discuss the topic and book including:
Links:
Waterfall Security Solutions and ICSSTRIVE put out an annual threat report that Dale Peterson believes is the best in OT. Why? It only includes incidents that had physical consequences on systems monitored and controlled by OT.
Dale and Andrew discuss:
Links:
Patrick Miller has OT cybersecurity experience as an asset owner, PacificCorp. As a regulator and one of the first NERC CIP auditors with WECC. As a community organizer creating and leading EnergySec and the BeerISAC. And as an entrepreneur creating and leading a number of consulting practices. He is currently the Founder of Ampyx Cyber.
In this episode Patrick and Dale discuss:
Links
Emma Stewart joins Dale to discuss the 3 big OT & ICS security stories from the first quarter. They end by giving their win, fail and prediction for Q1.
In this solosode episode Dale reviews the status of his three predictions from the Q1, 2 and 3 quarter in review episodes and answers a listener question.
Dale is joined by Steve Pozza, CISA Section Chief of Operational Resilience, and Tom Millar, CISA Branch Chief of Resilience, to discuss some of CISA's security services for asset owners. They discuss:
Links
Andrew Ginter published his third book this year: Engineering-Grade OT Security. Dale interviews Andrew on the book including:
Links
This week is a Dale Peterson solosode.
Updates and Announcements
Dale provides updates about S4x24 ticket sales and announces the Women In ICS Security program and sponsor package.
Main Topics
Kelly joins Dale to discuss her new book Security Chaos Engineering: Sustaining Resilience in Software and Systems. Kelly points out the second part of the title is the most descriptive, and she is not a big fan of the Chaos term that has taken hold.
They discuss:
Don Weber joins Dale Peterson to describe his IACS STAR Methodology to score the risk of a vulnerability to an ICS (or IACS in 62443-speak). It is a modification of the OWASP Risk Rating Methodology. Don has modified some of the 16-factors to create IACS STAR. The methodology and code is available on GitHub and a calculator is available on line.
Don and Dale discuss:
Links
Slides Discussed In The Show: https://dale-peterson.com/wp-content/uploads/2023/10/IACS-STAR.pdf
IACS STAR GitHub Repo: https://github.com/cutaway-security/IACS_STAR_Methodology
IACS STAR Calculator: https://iacs-star-calculator.com/iacs_star_calculator.html
Cutaway Security Website: https://www.cutawaysecurity.com
ICS-Patch Decision Tree: https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf
Dave Whitehead, CEO of SEL, joins Dale on the show to talk about:
Links
Dale and Nicole Sundin of Axio discuss CRQ, how to deal with the precision challenge, Axio's prioritization of impact, ransomware on IT affecting operations as an example, and more.
They also discuss UX and the single pane of glass.
Links
Axio web site
Former Congressman and Presidential candidate Will Hurd is a rarity with a tech background in someone who was elected to the US Congress, and even rarer in someone running for President. Will graduated Texas A&M with Computer Science degree. Worked as a Senior Adviser to the cybersecurity company FusionX, which was acquired by Accenture. More recently he was on the board of OpenAI.
This is probably one of the most technical interviews with a Presidential candidate you will hear. Dale asks Will:
Patrick Miller of Ampere Industrial Security joins Dale to discuss the three big stories of the quarter and give their win, fail and prediction.
Stories
Links
Dale Peterson was recently interviewed by Jay Johnson of Sandia and Tom Tansy of the Sunspec Alliance as part of their distributed energy resources (DER) Sunspec webinar series. We covered a lot of issues and Dale was not shy in throwing out some analysis and opinions. After 5 minutes discussing the S4x24 ticket process, the topics discussed: * How DER will deal with the complex, large number of users and stakeholders PKI environment. * The Sunspec device security specification and the benefits of a limited, key set of security controls. * What is the role of government regulation to solve DER security issues? * The potential power of the utility companies to levy requirements and be a choke point for access. * The Patch Act, FDA and DER. * shift left and product liability due to security flaws * and more
Marina Krotofil recently published the paper Industrial Control Systems: Engineering Foundations and Cyber-Physical Attack Lifecycle which is a detailed paper on cyber attacks that cause a physical impact on the system being monitored and controlled. It took Marina 1.5 years to write this paper, which is more accurately described as a short book. We discuss:
Steve Springett is the Chair of the OWASP CycloneDX Core Working Group. CycloneDX is one of the two main machine readable formats that SBOMs are being created in, although CycloneDX can capture all sorts of BOMs.
In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX
If you know the basics, skip to 14:24 where we get into the details
Links
CycloneDX document: Authoritative Guide To SBOM
ICS-Patch (what to patch when in ICS / risk based decision tree)
S4x24 CFP
At S4x23 Andy Bochman gave a Main Stage performance on the OT Cybersecurity / Climate Nexus. It's a new idea and Dale wanted to dig into it and understand it better. The discussion looks at where there is a nexus/connection/overlap and where there may be parallel efforts where each side might learn from the other.
Links
Andy Bochman S4x23 Video
Slide used in this episode
Earlier episode with Dale and Andy discussing CCE
S4x24 Call For Presentations
Gus Serino worked at a large water utility before joining Dragos in 2019. We're talking water sector so it's obligatory to start with Oldsmar (2:20), but we don't talk cyber. Instead we go through the physical portion of the water system assuming the attacker is able to issue the command to the pump to dump a lot of sodium hydroxide into the water system and what would likely happen. Importantly Gus identifies the simple, unhackable solution to this threat. A hard wired PH sensor that will shut off the pump regardless of the commands from the ICS.
After Oldsmar Dale and Gus discuss:
This is a solo-sode where Dale reviews two articles from July with comments on comments and additional thoughts. The final section is a must listen if you are going to submit to speak on the S4x24 Stage. The times below are so you can skip to what you are interested in.
1:29 One-Way Data Diodes and School Zones
10:15 SAIDI: What Cyber Incidents Should Be Excluded From Metrics
16:05 Do's and Don'ts For Your S4x24 CFP Submission
Links
Subscribe to Dale's Friday ICS Security News & Notes
Info and Links for the S4x24 CFP
HD Moore is most famous for his creation of the Metasploit penetration testing framework. It began in 2003 and hit the OT world in 2011. HD is now the Founder and CTO of RunZero, another cybersecurity startup that is starting to play in the OT Space. In this episode we spend the first third of the show talking about Metasploit ... early reaction, OT modules, is Metasploit still necessary and useful today. We then shift to creating asset inventories in IT and OT, which is what RunZero does. * Why HD decided to run back into the cybersecurity startup world? * How it started as a solo shop with HD writing all the code. * How HD things Shodan and RunZero are different. * What technique does RunZero use to 'scan'. A term that many fear in OT. Check out their approach to 'fragile devices'. * The OT reaction to this type of scanning. * What role uses the RunZero product?
Links RunZero website S4x24 Call For Presentations
Dale is often critical of the US Government's efforts and programs to address OT cyber risk. So it's a pleasure to highlight a program that is working.
Samantha Ravich, Chair of the Center on Cyber and Technology Innovation at the Foundation for the Defense of Democracies, joins Dale to discuss the US Department of Energy's OT Defender Fellowship Program.
They begin by describing the program, its goals, what are ideal candidates for the program, and the early results from the first few cohorts. Then Timothy Pospisil of Nebraska Public Power District and part of the 2022 OT Defender Fellowship cohort joins the show to discuss his experience in the program.
At the end we discuss how this could be expanded to address water, critical manufacturing and other sectors.
Link
OT Defender Fellowship Program
Eric Cosman had a 38 year career at Dow Chemical, was on the ISA 99 committee its inception, and then he retired. After retirement Eric joined ARC Advisory Group as a Contributing Consultant and got even more active with ISA. He is a long time co-chair of ISA99 and was President of ISA in 2020. Eric and Dale discuss: * Dow's in house developed DCS and SIS: MOD * Eric's top trend from 2022: The value of open automation and the Open Process Automation Forum * ISA/IEC 62433 + Eric's view they are "primarily engineering standards" + What Eric thinks about the safety / security analogies + His experience in being ISA President in the first year of COVID + ISA as "the home of automation" + Has ISA lost mindshare on ICS security standards to the US Government and training to SANS
Mark Hyman of Verge Management Group joins Dale to discuss the big 3 stories of Q2 along with their win, fail and predication.
Big Stories
Plus they both have a win, fail and prediction at the end.
Josh Corman is the VP of Cyber Safety Strategy at Claroty, was the Chief Strategist of the CISA COVID Task Force, and founder of I Am The Cavalry. Josh and I dive into Healthcare Security, SBOMs and other topics.
We will need to have Josh back for a Part 2.
This episode is a replay of a lively panel from the Cyber Security Agency of Singapore's OT Cybersecurity Expert Panel (OTCEP) last year. It begins with a great introduction to the Top 20 Secure PLC Coding Practices by Sarah Fluchs. At the 35 minute mark the panel discussion begins. There was a lot more disagreement and back and forth than the typical panel. This gives you a variety of points of view and positions to consider.
Paul Griswold moderated the panel of Dr. Ong Chen Hui, Joel Langill, Sarah Fluchs and Dale Peterson.
Links
How much does a security control reduce cyber risk? What control or mix of controls provides the most efficient cyber risk reduction? Tough questions that a team of researchers at INL and Sandia tried to answer in a project.
Two of the researchers, Jay Johnson of Sandia and Jake Gentle of INL, join Dale on the show to talk about the metrics and results. The project was Cyber Resilience for Wind Installations, but the metrics and results are applicable to every sector. We get into the weeds on this episode and discuss:
Links
• Video: https://www.youtube.com/watch?v=bBLbLUFKzIc
• IEEE Access Journal Paper: https://ieeexplore.ieee.org/document/10043706
• POWER magazine article: https://www.powermag.com/cyber-resilience-for-wind-power-installations/
• 2-page flyer: https://www.researchgate.net/publication/367074443_Cyber_Resilience_for_Wind_Installations_A_Cyber_Resilient_Reference_Architecture
• Final project report: https://www.researchgate.net/publication/368599508_Hardening_Wind_Energy_Systems_from_Cyber_Threats-Final_Project_Report
Ralph Langner, Megan Samford and Zach Tudor join Dale Peterson on the S4 Main Stage to close out S4x23. This Closing Panel is always an attendee favorite as none of these four are afraid to take a strong and even unconventional stance on at OT security topic or issue.
Dale Peterson interview CESER Director Puesh Kumar on the S4x23 Main Stage. We discuss a number of CESER programs how they are measuring success, what has not worked, why they are doing some things industry is already doing and more.
5:30 Where is the CESER CRISP program (detection and information sharing) today? Has it stopped or reduced the impact (outages and others) of cyber attacks on the electric sector? How will they measure the success of this program?
10:40 What has CESER tried, thought it would work, and ended up failing?
14:05 CESER's CyTRICS program is testing vendor equipment? Why, does GE and Hitachi need help? And the results have been trivial vulnerabilities that could be found in hours. Why is CESER spending millions on this?
19:25 Cyber Informed Engineering (CIE) is it the same as Secure By Design? This is a long process, what will the early wins look like? Two years from now how will we know if we are succeeding? Maintaining a manual capability dominated the examples in the document, why hasn't this been highlighted in the program? How can we accelerate this?
25:20 Clean Energy Cyber Accelerator is looking at solutions (OT detection and MFA remote access to OT) that are well established with vendor offerings and asset owner deployments. Why is CECA doing this and trying to accomplish?
Chris Blask has a long career bringing new ideas to reality. He currently is Vice President of Strategy at Cybeats, who has a SBOM Studio product.
Cybeats is different in that SBOM Studio does not create SBOMs. This requires SBOMs to be available from somewhere, and Dale & Chris spend a lot of the podcast talking about the SBOM market today and in the future.
Of course being Dale and Chris, they deviate into a lot of other topics. Such as Chris's quotes:
The August 2021 Unsolicited Response episode with Edgard Capdevielle, CEO of Nozomi Networks, was a fan favorite. So Dale invited Edgard back, like the first time it was a wide ranging and fun conversation. His budget analogy of OT security and a new child in the family was Dale's favorite part.
They cover a lot of ground including:
Dale Peterson interviews cybersecurity legend Gene Spafford on the S4x23 Main Stage. Some of what they cover is:
Marty Edwards joins Dale Peterson to discuss the big stories of the first quarter of 2023.
Marty and Dale then give their win and fail for Q1 and a prediction.
Dale Peterson talks with Matt Wyckhouse, Founder and CEO, of Finite State about where the SBOM products and market is today and where it will go in the future. This discussion was informed by the SBOM Challenge at S4x23.
Dale Peterson interviewed Puesh Kumar on the S4x23 Main Stage. Puesh is the Director of the US Dept of Energy's Cybersecurity, Energy Security, & Emergency Response (CESER). The lead US Government OT cybersecurity agency in the energy sector.
After Puesh gives a 3 minute overview on CESER, they dig into it.
Steve Mustard took his 30 years of experience and wrote Industrial Cybersecurity: Case Studies and Best Practices, published by ISA. After talking about who the book is for and the writing process, Dale and Steve dig into the details.
Given Steve's longtime involvement and leadership with ISA, it's not surprising the book leans heavily on ISA/IEC 62443. They talk chapters on architecture, certification, optimism / pessimism, risk management and a fundamental misunderstanding of IT by OT. Some agreement, some disagreement, and always a civil discourse.
Dale's interview with Michael Fischerkeller, co-author of the bood Cyber Persistence Theory. The first half of the interview digs into Cyber Persistence Theory.
The second half of the interview looks at what the world will look like and what asset owners should do if multiple nations believe in and act on this Cyber Persistence Theory.
Dale believes this is an incredibly important theory to understand because it is taking hold in the world's major powers.
Links
Cyber Persistence Theory book
Matt Morris and Mark Mattei of 1898 & Co. joined Dale to talk OT Managed Security Services as 1898 recently introduced an OT Managed Threat Protection and Response service. The discussion included:
Bill Fehrman is the CEO of Berkshire Hathaway Energy, co-chair of the Electricity Subsector Coordinating Council, and chair of the E-ISAC.
The major topics Dale and Bill discuss include:
Tom VanNorman and Don Weber join Dale to describe the ICS Capture The Flag competition they will be running at S4x23, Feb 13 - 16 in Miami South Beach.
S4x23 web site
Donna Cusimano, Kim Legelis, and Saltanat Mashirov join Dale Peterson to talk about the Women In ICS Security Program at S4x23, Feb 13-16 in Miami South Beach. (see s4xevents.com/women).
These are three of a team of volunteers that have put together important career, education, and networking opportunities for the 100 free Women in ICS Security ticket holders and another ~150 women who will attend on a paid ticket. Really impressed and looking forward to seeing what this will accomplish.
Ralph Langner joins Dale on the Unsolicited Response Show to discuss Asset Management. They begin with the need for more exploration in OT, and more failures. After that they tackle:
Why Ralph decided to shift his company and focus from consulting / speaking to product
Is his OT Base, and asset management, a security product?
What are the elements of asset management? Do they all belong in one product?
OT, asset management and other, with ServiceNow and other enterprise solutions dealing with ticketing and human process management (this was Dale's favorite part of the show)
Power BI integration, dashboards what are they good for?
Other asset management integrations including OT detection solutions
As with any conversation with Ralph (and Dale) there are plenty of analysis and opinions that may be out of the mainstream.
Enjoy
Links
Langner's OT Base
Ralph's TED Talk on Stuxnet
Ralph's S4x12 Stuxnet Deep Dive
Robust Control System Networks
To Kill A Centrifuge
Art Manion, Dale and Ralph on Automating Patch Analysis
Dale's ICS-Patch Decision Tree (What to patch when in ICS)
Dino Busalachi of Velta Technology talks to Dale about a 2021 security patch to DCOM that broke a number of ICS systems including Rockwell Automation and Siemens. Microsoft had a registry setting that disabled the patch and the incompatibility problem, but this ability to disable the patch goes away on 14 March 2023.
Of course this topic leads us down the patching in ICS rabbit hole, hopefully with some informed and helpful information.
On the latest #unsolicitedresponse show I talk with Jim Hempstead, Managing Director of Moody's Global Project & Infrastructure Finance Group with Moody's Investor Services, about OT Cyber Risk and how this impacts Credit Ratings.
What Moody's does and what became of the cyber risk effort at Moody's owned Visible Risk
Moody's analysis of cyber insurance market including some cyber loss ratio numbers
Why Moody's believes USG disclosure and regulations are "Credit Positive"
Why Moody's has electric, gas and water utilities as "very high risk" in their heat map (despite minimal loss data)
And more. Several times in the show Dale asks Jim to explain some terms.
Dale Peterson gives his thoughts on the top 3 ICS security stories in Sept 2022, and he gives his wins, fails, and predictions for the month.
On this episode of the Unsolicited Response show, Dale Peterson is joined by Kevin Morley of the American Water Works Association and Joel Cox of West Yost Associates to talk about ICS security and the Water Sector.
what makes the water sector unique?
does this uniqueness lead to early and better use of the cloud for operations?
how did the community deal with Oldsmar?
why in the world would the water sector want to follow the NERC CIP model?
Dale Peterson shares his thoughts on SBOMS in OT in three main areas:
1) The S4 SBOM Challenge ... it's three goals and what we hope to learn from it.
2) Near term, now and for the next 2 years, wins for asset owners and SBOMs.
3) What will determine the winners in the SBOM marketplace, early analysis.
Links:
S4x23 Tickets
S4x23 Hotel Info
SBOM Challenge
Dale's SBOM Content Page
The tables were turned as David Whitehead of SEL interviewed Dale Peterson on Dave's Schweitzer Drive show.
How Dale got into cybersecurity and the ICS security world
How has the threat and security posture changed in the last 10 or 20 securities
Dale's view on the core problem that is not being addressed and the wasted resources being applied to good security practice rather than risk
What areas of ICS security research Dale is most excited about
And a bit about S4
Links:
S4x23 Website
Schweitzer Drive Podcast
In this solosode, Dale Peterson gives his thoughts on three stories from August as well as a win and fail for the month. Stories this month:
Freight and passenger rail is another industry sector that relies on ICS for safety and services. It has its own language, consequences and standards.
In this episode, Dale Peterson speaks with Miki Shifman of Cylus. Most of the episode digs into how rail systems work and the key areas to secure. They cover the TS-50701 standard and TSA's regulations in the US, among other things.
The episode concludes with a discussion of the Cylus OT Detection product designed for rail. The big question is a sector specific focus a big enough moat to keep out the big 3 OT detection vendors.
Dale Peterson talks with Mikko Hypponen about his new book: If It's Smart, It's Vulnerable.
As with all books, Dale asks who Mikko wrote the book for, who is the intended reader. Then they dig into some of the interesting parts for the security professional including:
and more.
Links
Unsolicited Response Month In Review show for June 2022. This is a replay of the live episode.
This month's stories:
Plus my win, fail & prediction for the month
Links:
Dale Peterson interviewed Richard Seiersen, author of new book The Metrics Manifesto: Confronting Security With Data.
Links
Phil Venables joins Dale to discuss OT's use, today and in the future, of cloud and edge services. They focus on reliability, security and use cases. The end of the episode focuses on how leadership views security. Phil writes some of the most interesting articles on security at philvenables.com.
Check out the links below for some of Dale's recent favorites.
Defense in Depth
Resilience is about Capabilities, Not Plans
If Accounting were like Cybersecurity
Organizational Politics
Also check out the S4x23 CFP
The Debate Question: Cyber Insurance Will Play A Major Role In OT Cyber Risk Management In The Next 3 To 5 Years Debating The Pro Case: Monica Tigleanu of MunichRe Speciality Insurance
Debating The Con Case: David White of Axio
(Note - The debaters were charged with making the most compelling case for their position. In some cases this doesn't represent their views).
Links
S4x23 Call For Presenations
Dale talks with Jason Christopher, a SANS Certified Instructor, who along with Dean Parsons created the new course SANS ICS418: ICS Security Essentials For Managers. They cover a lot of ground including:
Links
ICS418 Course Info
This is a solosode with Dale covering the two top stories from the month plus a win, fail and prediction.
Links
This is the audio from my interview with Dave Lewis, a Global Advisory CISO at Cisco, on the S4x22 Main Stage.
Dave has experience securing both IT and OT (he worked for electric utilities in Canada). Even more interesting is he talks every week with a wide variety of CISO's.
It's a wide ranging discussion that hits a lot of different areas on how to work and communicate best with CISO's and executive management on ICS security and cyber risk.
Zach Tudor of INL and Megan Samford of Schneider Electric join Dale Peterson on stage to close out S4x22. They discuss:
Unsolicited Response host Dale Peterson has been skeptical of the cost/benefit of accessing the electrical signals between Level 0 and Level 1 and creating a separate network to send that data to a platform for comparison to data at higher levels and analysis. This is a core part of SIGA's offering.
Dale and Ilan discuss what it actually does and doesn't do. What percentage of the Level 0 device communication needs to be monitored to get this information? The cost per sensor. And more. In the end they don't reach the same conclusion, but the decision points are clearer.
They finish discussing the back end processing for process variable anomaly detection, and how SIGA plans to compete with large vendors (GE, Siemens, ...), Azure and AWS, PI and specialized system vendors who have developed models.
Links
SIGA OT Security Site
Dale's Pivot To Process Variable Anomaly Detection article
Dale's weekly article points out the conflict in thinking and posture in miminizing and maximizing surface area. A minimization strategy can help security and hurt creativity. Seems about right with what we see.
Daniel Kapellmann Zafra of Mandiant joins Dale to talk about April's three big stories:
INCONTOLLER / PIPEDREAM
INDUSTROYER2
JCDC ICS
Then they give wins, fails and predictions with a first appearance of conspiracy Dale.
S4 Founder Dale Peterson interviews CISA Director Jen Easterly on the S4x22 Main Stage, 20 April 2022. Start: What are CISA's major goals in ICS Security for 2022/23 and how will they measure progress? Jen goes over people, process and partnerships goals, and highlights the hiring they are doing in the ICS security area. Also, Jen announces the new JCDC ICS.
17:38 When will the Shields Up come down? Since Shields Up is mostly basic cyber hygiene will there be a Shields Way Up?
23:30 Does Jen believe regulation is required to secure private industry owned critical infrastructure? And of course a lot of other things came up in the course of this half hour interview.
Some quick info on the release of S4x22 content and then my weekly article published on 24 April 2022.
Links:
S4x22 Video Release Schedule
David White, Co-Founder and CEO of Axio, joins Dale on the Unsolicited Response show to discuss cyber risk quantification. Axio makes the bold statement, "Quick time to value: quantify risk in hours not months; board reports readily available in minutes".
Dale digs in on their approach do to this, how they deal with the likelihood challenge, and how the process differs for OT as opposed to IT. The issue of deciding where to put the next dollar is a thread through the entire conversation.
They finish talking about how risk questionnaires and other methods will be used by the cyber insurance industry today and in the next 3 - 5 years.
Dale Peterson's guest on the Unsolicited Response show is Sergio Caltagirone, VP of Threat Intel at Dragos.
Links:
Dan Geer and Olav Lysne join Dale Peterson to discuss Cyber Nationalism and how this will affect ICS asset owners and ICS vendors should and will deal with increased pressure by nation states to insert back doors and other weaknesses in ICS.
Dale Peterson's weekly article suggests we develop a list of actions to take when the threat has a significant increase. He provides some examples of what should and should not be on that list.
Subscribe to Dale's ICS Security Friday News & Notes
Chris Sistrunk joins Dale Peterson to discuss the month's big 3 stories.
Urkraine from an ICS preparation standpoint.
DHS's new Cyber Safety Review Board
What to take from ICSsec vendor annual / semi-annual activity reports
Plus wins, fails and predictions.
Two cyber insurance underwriters, Monica Tigleanu of Munich Re and Paul Gooch of Tokio Marine Kiln, join Dale Peterson on the Unsolicited Response show to talk cyber insurance.
Most of the episode discusses exclusions. Recently we had the high profile ruling that Merck's property policy in fact covered NotPetya losses because there was not a cyber exclusion statement.
The more interesting and important discussion is around the four recommended exclusions related to cyber war for cyber insurance policies that Lloyd's Market Association issued. These will likely by used by many in the Lloyd's syndicate and will affect other insurers. We look at the language around cyber operations, attribution, and other key terms.
Then the last part of the podcast talks about how insurers will be looking to set cyber insurance rates. How do they determine the cyber security posture of a potential insured.
It's an area that cybersecurity pro's in OT, and IT, need to understand better if they are part of cyber risk discussions.
Links
Merck's NotPetya Insurance Claim
Lloyd's Market Association Cyber War Exclusions
Dale's ICS Security: Friday News & Notes
My weekly article suggests that Level 0 / 1 monitoring and detection vendors should pivot to process variable anomaly detection.
Subscribe to my ICS Security - Friday News & Notes
Tom Alrich dives deep on the items he works and writes about. For a long time it was NERC CIP, and he recently added SBOMs to his repertoire. We go deep and I think the business model portion may be the best and most accessible part of the episode.
1:21 The 2 main SBOM formats. There differences and what will win.
12:30 VEX ... identifying what vulnerabilities in the SBOM are exploitable
24:00 What EO 14028 will require the USG to do with SBOMs in August
34:00 Who and how SBOMs will be provided and used. Business models.
Links
Tom Alrich's Blog
Tom's Who Should Be Responsible article
Subscribe to Dale's ICS Security - Friday News & Notes
My article from 8 Feb 2022 looks at what the two most successful OT security product segments have in common.
Tom Pace, who co-founded Netrise.io with Michael Scott, joins Dale Peterson to discuss Firmware Security Testing. There is a lot of firmware in ICS -- PLC's and other controllers, instruments, network infrastructure, etc. They spend some time discussing the elements that are tested and then dive into how a product vendor and asset owner might use this type of testing. And the key question is whether there will be enduring and important product differentiation. Check out S4x21, April 19-21 in Miami South Beach
Dale's weekly article covers the importance of some serious security testing of four popular OPC UA stacks that will take place at Pwn2Own Miami at S4x22.
The last Pwn2Own Miami awarded $280K for 0days in ICS targets.
We've been busy with the date change for S4x22, so here is a great replay of the S4x20 closing panel. Ralph and Zach have a ton of experience and make it a lot of fun.
Dale's weekly article dives into the Merck / Ace American case on NotPetya damages covereage.
Check out S4x22, April 19-21 in Miami South Beach
With the recent cyber activities and near hostilities in Ukraine I thought it would be a good time to replay my S4x20 Main Stage interview with Andy Greenberg, author of Sandworm: A New Era of Cyberwar and the Hunt for the Kremin's Most Dangerous Hackers.
Check Out S4x22: April 19-21 in Miami South Beach
Dale's weekly article looks at a new feature in Industrial Defender that measures risk per endpoint. Right direction, and the calculation needs to be more than a cyber hygiene measure.
Subscribe to Dale's ICS Security - Friday News & Notes
Industrial Cybersecurity, listed as 2nd Edition but actually a completely new Volume 2 is 1027 pages on Security Monitoring, Threat Hunting and Security Assessments and Intel. In this episode, Dale Peterson talks with its author Pascal Ackerman.
Links
Industrial Cybersecurity Volume 1
Industrial Cybersecurity Volume 2
Dale's weekly article looks back at the dichotomy of must never go down and don't touch it or it might go down. And how a reduction of fragility can be a good metric of your next cyber risk reduction expenditure in ICS.
The first live episode of the year covered the top three things Dale Peterson will be watching in 2022. Not predictions. More areas that could go in many different directions. The three are:
CISA Activities and Metrics
SW/FW/SBOM Product & Service Business Models
Cyber Insurance
The episode included two guests who talked about what they will be watching in 2022.
The Year Of descriptors are done retrospectively and looking forward. This episode looks at three ideas of what 2021 was the year of, and six ideas of what 2022 might be the year of. Related to OT and ICS Security, of course.
Subscribe to Dale's ICS Security: Friday News & Notes
The final podcast episode of 2021 includes two articles that summarize the year. The first is on Perspective and the second is Progress.
Enjoy the holidays and thanks for your support of the show.
At the end of the ICS Security Month In Reviews episodes my guest and I give a win, fail and prediction. In this episode we replay those predictions and assess if we were right, wrong or the answer is still pending.
Subscribe to Dale's ICS Security: Friday News & Notes
Dale Peterson's articles from Dec 7th and 14th.
Failing Business (Home) Continuity Plans
VC's, OT Security and Criticality
Dale Peterson joined Clint Bodungen and Pascal Ackerman on the OT Exposed - Raw show on YouTube. They broadcast this live on Friday afternoons, and it has the Friday afternoon vibe.
The first ~12 minutes are a bit on Dale's entry into the field and S4. Then they discuss maturity models, what to do when, and future technologies that will make a difference in the next 2 - 5 years.
Patrick Miller of Ampere joins Dale to discuss the months top 3 stories plus give their wins, fails and predictions. Stories:
The water sector proposing a NERC/FERC CIP approach to cybersecurity regulation.
GridEx VI
INL adding another large engineering firm to their CCE program.
My market update identifies the biggest challenge for the Big 3 pure plays, the enterprise acquirers, and the niche pure plays in the OT Visibility & Detection Market.
This is from back when S4 was in a case study room that sat 60 and everyone could see and talk to everyone. Michael Toecker took the pro, Billy Rios the con. They had five minutes each and then you'll hear from many of the attendees who are the pioneers in ICSsec.
And in some quarters this debate still rages on.
This is from a two-part article originally published on Nov 9th and Nov 16th. It addresses the first six levels.
Many, if not most, asset owners bypass at least four of the first six levels.
A recording of Dale Peterson's 30-minute Keynote at the Fortinet OT Symposium - Manufacturing Day.
Clay Carter, VP and Head of Product Security at Xylem, joins Dale Peterson to discuss the top 3 stories of the month and give their win, fail and prediction. The stories:
This article was originally published on the Tripwire Guest Author page. It highlights an early fail of mine and what I learned.
Peter Lund of Industrial Defender joins Dale to discuss SOAR in ICS.
They finish the conversation with a bit on Industrial Defender's recently announced OT Machine Learning Language.
Check Out The S4x22 Agenda
My weekly article looks at the work and risk related to cyber maintenance of the ICS edge devices (when they get the needed DPI)
Check out the S4x22 Agenda
Check Out S4x22
Dale's weekly article published on 19 October 2021.
Subscribe to Dale's ICS Security: Friday News & Notes
This episode dives deep into the risk score methodology of Radiflow's Ciara product. It attempts to use interview, asset inventory, and simulation to identify a risk score for a zone or site. It also then uses simulation to determine what security controls would most improve the risk score / reduce risk. Obviously this is a detailed talk on a specific vendor approach, so if that sort of thing bothers you this episode might not be for you. We also talk about whether the visibility / detection product segment will be separate from the OT cyber risk product, and we end with a discussion of how a company the size of Radiflow competes with the Claroty/Dragos/Nozomi of the world that have raised $100M+.
My weekly article. The cybersecurity team needs to be careful about overselling the supply chain cybersecurity risk in an environment where real, large supply chain disruptions are occurring.
My article originally published on 12 October 2021.
Joel Langill joins Dale in this Live episode. The stories:
CISA's Performance Goals and Objectives for Critical Infrastructure ICS (and a bit on TSA's 2nd Security Directive)
Moody's moving from Visible Risk to Bitsight for Cyber Security Ratings, and the difficulty to create and possible use of Cyber Security Ratings
Who performs what tasks in "OT"
Plus Wins, Fails and Predictions.
Links:
S4x22: https://s4xevents.com
Joel's Training: https://icscsi.org
In my weekly article published on 5 Oct 2021, I muse on how hard it is to discuss the zero trust concept in OT when there seems to be no effort to address the Total Trust or Trust All nature of PLC's, Controllers and other Level 1 devices.
Mark Hyman, a recruiter with the Verge Management Group who focuses on OT / ICS Security candidates, joined Dale Peterson on the Unsolicited Response Show to answer listeners questions on starting and growing an ICS Security Career.
There were three main areas of questioning:
1) Getting Into The ICS Security Field
2) Career Growth For An Experienced ICS Security Professional
3) Working With Recruiters
Prior to 2021 there was a substantial amount of ICS security standards and guidelines. The Biden administration has tripled down on this. To what effect?
And Maybe Fewer OT Security Professionals My weekly article published on 21 Sept 2021.
Subscribe to Dale's ICS Security: Friday News & Notes
This episode has two announcements:
Subscribe to ICS Security: Friday News & Notes
Dale Peterson's weekly article published on 14 Sep 2021.
Sign Up To Dale's ICS Security - Friday News and Notes
In this episode Dale describes in 22 minutes what he likes and doesn't like about the new, Version 3 of API 1164 Pipeline Control Systems Security Standard. And more importantly whether you should spend $200 to buy a copy.
Subscribe to Dale's ICS Security - Friday News & Notes
In his weekly article, Dale discusses the increase in claims, rates and a silly exclusion attempt by his own carrier to deal with this.
It's too early to count cyber insurance as a risk reduction failure, and the insurance industry has found ways to deal with similar new product challenges.
Matt Wyckhouse, CEO and Founder of Finite State, joined Dale Peterson to discuss the top three stories of the month and give a win, fail and prediction.
The first 6:30 Dale announces tickets for S4x22 are on sale and some of the changes to the three stages along the No Limits theme.
6:31 Topic 1 - QNX and Blackberry Vulnerabilities … their impact on OT and IIoT and what an asset owner should do about them.
27:00 Topic 2: Cyberspace Solarium Annual Report talking about progress to meeting objectives over the last year, https://www.solarium.gov/public-communications/2021-annual-report-on-implementation
38:05 Topic 3 - Sinclair's poll on asset owner's view of IEC 62443 Security Levels, https://otcybersecurity.blog/2021/08/19/results-from-the-poll/
44:21 Wins, Fails and Predictions
Other Links
S4x22 Tickets https://universe.com/s4x22
Earlier podcast episode with Matt Wyckhouse https://dale-peterson.com/2020/06/16/podcast-matt-wyckhouse-of-finitestate/
Finite State site https://finitestate.io
My article orginally published on 31 August 2021.
If convergence, once started, is a powerful force in one direction, then why wouldn’t most of the functionality of the OT visibility/detection management platforms be converged into their enterprise equivalents, such as Splunk or ServiceNow.
S4x22 Tickets Go On Sale Sep 1 at Midnight EDT
Dale interviewed Edgard Capdevielle, CEO of Nozomi Networks, on how he sees the OT Visibility and Detection market and what Nozomi plans on doing with the $100M raised. The discussion includes:
Sign Up for Dale's ICS Security: Friday News & Notes
You Must Understand Your Organization's Risk Management Do you want support and funding for your ICS security initiatives? Then you need to understand what executives view as high, unacceptable consequences that believably could be caused by a cyber or cyber/physical incident. Go to executives claiming a calamity for something that is considered a non-desirable, but acceptable consequence and your credibility will be damaged.
Dale's article from 24 August 2021.
Subscribe to Dale's ICS Security: Friday News and Notes
Dave Whitehead, CEO of SEL, joins Dale on this episode. They discuss a wide variety of topics including: * Early memories of working with Ed Schweitzer as a young engineer, being a CEO with the legend still there, and what SEL when Ed Schweitzer decides to slow down. * SEL Security Products profitability today and in the future. * Dealing with customers who don't want to secure their systems. * SEL's high level of vertical integration including a new plant to manufacture PCB's and its impact on supply chain security. * Dave and Dale's initial meeting over a vulnerability disclosure and how SEL deals with vulnerabilities today (direct disclosure to customers, not via a CERT). * Are SEL customers updating their software/firmware when security issues are found? * How does SEL decide what older products to add security features, such as signed firmware verified on the device, to?
Links
SEL Security Solutions
Dave's Schweitzer Drive Podcast
Subscribe to Dale's ICS Security: Friday News & Notes
Dale's weekly article published on 17 August 2021.
Subscribe to ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/
Dale Peterson's weekly article published on 10 May 2021 discusses what will be required to get the benefits from SBOM's potential. Some come with low effort, and some will require major effort, new vendors and new business models.
Tweet Me: @digitalbond
Eric Byres of aDolus joins Dale Peterson on the Unsolicited Response Show to discuss the Biden Administration's actions on improving ICS security.
The first half of the show discusses the National Security Memorandum on ICS Security issued on July 28th. What it means for asset owners sending monitored data to the USG, the impact of a set of goals and controls, and the urging of Congress to pass legislation to give the Executive Branch universal across critical infrastructure ICS regulatory authority.
Links
National Security Memorandum
Background Briefing on NSM
The second half focuses on Executive Order 14028 issued earlier in the year. aDolus has put out a very useful timeline that tracks all of the deliverables. Eric focuses on the supply chain measures and how this might impact asset owners and ICS vendors.
Links
aDolus EO 14028 Timeline
aDolus blog series on EO14028
Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/
A slow month for ICS security news and a shorter, 30-minute solo-sode. Dale covers the 3 top stories and gives his win and fail of the month.
Dale's weekly article originally published on 27 July 2021.
TweetMe: @digitalbond.com
Subscribe To Dale's ICS Security Friday News & Notes at https://friday.dale-peterson.com/signup
Claroty raised $140M in a Series D round and recently announced their Claroty Edge product. In this episode, Dale interviews Grant Geyer, Chief Product Officer at Claroty. Most of the time is spent discussing Claroty Edge, what it is and isn't. The last third of the show they discuss what Claroty will do with the recently raised money. Links: Claroty Edge: https://www.claroty.com/claroty-edge/
Claroty Press Release on Series D: https://www.claroty.com/resource/claroty-secures-140-million-financial-round-establishing-leadership-position-in-hyper-growth-industrial-cybersecurity-market/
Sign up for Dale's ICS Security: Friday News and Notes at https://friday.dale-peterson.com/signup/
It's summer, and I'm on vacation. So here is a light, breezy article to not take too seriously. Below is my non-scientific, highly US influenced, filter bubble warning, rankings of the ICS buzzwords rated by popularity and impact. Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/
This is another episode with the founders of great ICS companies. Dr. J. Patrick Kennedy founded OSIsoft in 1980 and grew it to dominate the historian / data broker segment of the ICS market. OSIsoft was sold in 2021 to AVEVA for $5B. In this show we talk about:
Subscribe to Dale's ICS Security - Friday News & Notes at https://friday/dale-peterson.com/signup/
Dale's weekly article from 13 July 2021 covers the ICSsec communities love to argue over broad terms and when it helps and hinders communication.
Subscribe to Dale's ICS Security - Friday News & Notes email at https://friday.dale-peterson.com/signup/
A recent article by Jay Healey and Robert Jervis, The Escalation Inversion and Other Oddities of Situational Cyber Stability, breaks down four mechanisms in which cyber activities could be used and result in a stabilizing or destablizing.
Dale talks with Jay about the article, escalation due to cyber, and the current state and future of cyber norms.
Subscribe to Dale's ICS Security Friday News & Notes email at https://friday.dale-peterson.com/signup/
Now that we are starting to have secure ICS protocol options and deployments, its time to get serious about key management. The de facto use of self-signed certificates only provide illusory security. Key management in ICS can be simple and the community should start with simple.
Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/
Marc Ayala of 1898 & Co. joins Dale to discuss the month's top stories in ICS security and give their wins, fails and predictions.
Subscribe to Dale's ICS Security: Friday News & Notes email at https://friday.dale-peterson.com/signup/
Alternate Title: Will We Require A Few OT Security Controls And Claim Victory? My weekly article published on 29 June 2021.
Signup for my ICS Security: Friday News and Notes email
The tables were turned when Jannis Stemmann and Simeon Mussler of Bosch CyberCompare interviewed me for a long form German interview series. They graciously allowed me to record the audio as well for this show.
There is a short discussion on the S4x22 Call For Presentations and the Basic Sponsor application at the start. The interview begins at 4:20.
Subscribe to my ICS Security: Friday News & Notes.
Dale's weekly article covers Claroty's $140M D Round and what it means for the detection space.
Subscribe To Dale's ICS Security: Friday News And Notes.
Dale interviews the two project leaders of a global community effort to create a Top 20 Secure PLC Coding Practices. We cover:
The document and supporting information is available at https://plc-security.com and the twitter is @secureplc.
Subscribe to my ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup
My article from 15 June 2021.
It began with Jake Brodsky's S4x20 session on tips and tricks he had learned in his long career with a water utility to improve the resiliency, maintenance and security of a PLC and the underlying physical process. Today, it results in the release of Version 1.0 of the Top 20 Secure PLC Coding Practices with one of the least restrictive licenses for use, distribution and modification you will ever see. We want this Top 20 list to be used. Listen for more ...
Subscribe to Dale's ICS Security: Friday News & Notes
You know IT / OT integration is getting serious when the popular IT apps and services add OT extensions. The latest is ServiceNow's new OT Management Product.
James Destro of ServiceNow joins Dale Peterson on the Unsolicited Response show to talk about two main things.
1) How does OT Management get the OT asset inventory information? (and what is the single source of truth for OT asset inventory)
2) Once the OT asset inventory is in ServiceNow what types of workflows are envisioned that would be a big benefit to the asset owner.
Links:
Operational Technology Management 1-pager: https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/solution-brief/uc-operational-technology-management-manufacturing.pdf
Detailed documentation of the Operational Technology Classes: https://docs.servicenow.com/bundle/quebec-servicenow-platform/page/product/configuration-management/concept/cmdb-ci-class-models-operation-technology.html
Asset Inventory Integrations: https://store.servicenow.com/sn_appstore_store.do#!/store/integrations?freeTrial=service_graph_certified&offeredby=servicenow%253Bpartners
Signup For Dale's Friday News & Notes at https://friday.dale-peterson.com/signup
ICS-Patch leverages the CERT/CC SSVC Decision Tree approach for determining what patches are important and a patching cadence. One of the most important customizations is all of the factors can either be pulled from an asset inventory or a CVSS feed. This means the evaluation of 10's or 100's of thousand asset/patch pairs can be automated and an ASAP, Scheduled, Defer answer provided.
Tweetme: @digitalbond
Subscribe to My Friday News & Notes: https://friday.dale-peterson.com/signup
This is Dale Peterson's weekly article originally published on 1 June 2021. Following the article Dale describes what we are looking for in S4 sessions and provides tips on what to do and not to do to increase your chances of getting on the S4x22 Stage.
S4x22 Call For Presentations: s4xevents.com/cfp
Subscribe to Dale's Friday News & Notes friday.dale-peterson.com/signup
Rob Lee of Dragos joins Dale Peterson on the Unsolicited Response show to discuss:
The Biden Administration efforts on OT Cybersecurity. What they are; the pro's and con's of these efforts; and where they might be successful.
Rob and Dale talk about their disagreement on where Detection products, and to a lesser extent threat intel, like Dragos and others offer should be considered in relation to other security controls and solutions.
The prospects for an entry level and mid level ICS Security Professional in 2021 and the upcoming years.
Subscribe to Dale's ICS Security Friday News and Note: https://friday.dale-peterson.com/signup
Dale's weekly article published on 25 May 2021 talks is triggered by a World Economic Forum report that on Resilience in the Oil and Gas sector.
Tweetme: @digitalbond
Sign Up For My Newsletter: https://friday.dale-peterson.com/signup
The episode begins with some announcements then
4:15 - Dale's Monologue/Rant on the Colonial Pipeline Incident. The increase it brings in attention, resources and expectations on a macro level. And the real action asset owners should be taking for this specific set of circumstances.
12:20 - Joel Langill joins the show and brings his experience on pipelines systems and their operations, plus a quick discussion on his new training.
30:45 - Rob Caldwell joins Joel and Dale. We talk about incident response in OT, and then answer questions from the LinkedIn and YouTube audience.
Links:
Six months since my Dec 2020 update ... the biggest change is major demand drivers; where is the Claroty and Nozomi funding round? and big cloud / enterprise products and services continue to introduce and up their offerings.
My weekly article published 18 May 2021.
Subscribe to my ICS Security: Friday News & Notes email: friday.dale-peterson.com/signup
Dale Peterson talks with Ulf Lindqvist and Laura Tinnel of SRI International about the recent LOGIIC report on the (in)security of safety instrumentations systems. Particularly the IMS/AMS components that configure and manage smart instruments.
They go over the three main findings, which are deadly serious and two have actionable mitigations.
They finish with a discussion of why there is not a hard recommendation to not allow the IMS/AMS to be on or accessible from the PCN.
Get the report at: https://www.logiic.org
See the S4x15 video on testing 114 DTM's at: https://youtu.be/qbno2woz7p4
Subscribe to Dale's ICS Security Friday News & Notes at: https://friday.dale-peterson.com/signup
The Colonial Pipeline incident highlights the need for an Enterprise Network Compromised Playbook. This and two other must haves are described in this article orginally published on 11 May 2021.
Patrick Miller joins Dale Peterson to discuss the months top three stories and then give their prediction, win and fail for the month. The stories
1) What to make of the US Government's efforts in ICS security in the first 100 days of the Biden administration.
2) The Pulse Secure VPN vulnerabilities and active exploitation, the impact on ICS asset owners, and what should be done.
3) ICS Security Training ... with Joel Langill back in the game Patrick and Dale look at the offerings.
TweetMe: @digitalbond
Get my Friday News & Notes: https://friday.dale-peterson.com/signup
Dale's article published on 4 May 2021. It shows how the Industrial Edge parallels Level 1 devices in capabilities using AWS as an example. And leaves a hanging question at the end.
TweetMe: @digitalbond
Sign Up For My Friday Newsletter at https://friday.dale-peterson.com/signup
The ICS CYBERSEC 2021 event in Israel challenged speakers by limiting sessions to ten minutes. So Dale Peterson went with the theme and focused on how doing less in two important areas can actually help improve OT and ICS security.
1) Requiring less of engineers and operators (security is not everyone's responsibility)
2) Less cyber hygiene, more efficient risk reduction driven action
TweetMe: @digitalbond
Sign Up To My Friday Newsletter: https://friday.dale-peterson.com/signup
Hope, 1 Step Backwards, and Business Models Dale's article originally published on 27 April 2020
Subscribe to my Friday ICS Security News & Notes email
TweetMe: @digitalbond
Here is a debate between Eric Byres and me from S4x14, January 2014 that centers on the most important issue of Level 1 / PLC insecurity.
The question in the debate: Is Eric Byres a SCADA Apologist or a SCADA Realist?
You will see from the clips at the start there was disagreement on stage between the two friends.
It came down to then, and in 2021, on whether you believe the fact that PLC's are insecure by design / lack authentication / will do whatever they are told by legitimate user or attacker is a problem that needs to be prioritized and can be addressed in the short run.
I add about six minutes of 2021 comments at the start and then 6:20 the debate starts. At 30:50 you get questions from the audience, and it is fun to see all the ICS security pioneers in the smaller S4 room mixing it up.
Tweet Me! @digitalbond
My Weekly Newsletter: friday.dale-peterson.com/signup
Last week a Bloomberg article covered the Biden Administration's plan for a 100-day sprint to secure the power grid. I'll comment on the three focus areas the article lays out and more broadly on 100-day efforts.
This is my article originally published on 20 April 2021.
Tweet Me! @digitalbond
My Weekly Newsletter: friday.dale-peterson.com/signup
Rapid 7 recently made a "Strategic Investment" in SCADAfence's $12M B round and announced integration with the SCADAfence product. Dale Peterson interviews Justin Prince of Rapid 7 on their OT vision, what the integration will and won't do, where the Rapid 7 solution will sit, and future product directions. You can use your judgment on the status and completeness of the Rapid7 OT offerings.
Then at 37:05 Mark Hyman, an OT Security recruiter with Verge Management Group, joins Dale to answer some OT Security job hunting questions that came in after Dale's recent article on solving the OT Cybersecurity Staffing challenge.
Subscribe to my Friday ICS Security News & Notes email.
Short Review This is a book that an ICS security professional should give to friends and family to read so they know why they do what they do. Nicole guides the lay person through her compelling journey to understand the 0day market and its impact on the security of the systems we all rely on. The ICSsec pro will find it to be interesting except for the parts on ICS / critical infrastructure where it is a historical fiction ... historical incidents extrapolated to their most dire possible results rather than presented in their true context.
Detailed Review This was a very difficult book to review. I'm conflicted because the story is engaging and will keep the lay person turning the pages. The 0day market through line is well told, and the theme and major points Nicole is making are clear and compelling. And yet the parts I know in detail, ICS security and critical infrastructure, are portrayed in a light that is misleading, and even deliberately misleading. Misleading because a lay reader, including government policymakers, would almost certainly conclude the US critical infrastructure at this moment is compromised and a click or two away from the Russians, or other adversaries, causing a major catastrophe.
The Story ... The Positive
Imagine you are trying to tell your Mom or Dad, your Husband/Wife/Partner, your close friend about cybersecurity risk and how it could affect their lives, their communities and their country or region. This is hard. If you get into the technical details you will lose them. If you try to add too much nuance (HT: RLee) you will lose them. There needs to be a captivating story that makes the non-technical audience keep reading even if they don't care about the tech.
Nicole has succeeded in this area by inserting herself into the story. She is not the heroine of the story. Instead she is the observer, the Nick Carraway from The Great Gatsby, who is observing the players in the 0day world who are neither pure heroes nor pure villains. She begins her journey naively at S4x13 in Miami Beach and investigates for over seven years. Never actually reaching a point of knowing the market, and yet she describes what she knows and what cannot be known.
The best parts of the book are when Nicole is an active character, walking through the world and talking to the players. You feel her frustration, fear, intimidation, dread and disgust. You want her to come out the other side with some answers or even the answer. Although to her credit she does not force a solution. The ending is actually more muddled than the beginning. It makes for a less satisfying journey, and it is more accurate.
Nicole's journey is the highlight of the book. The reason why you can recommend it to your Mom or Dad. It would have been even better for the lay reader had she not tried to add in the history, the details. It does not go deep into the technical details like Kim Zetter's Countdown to Zero Day, which can be viewed as a positive or negative. My view is if you are not going to push for technical accuracy, then less is better. Still the book is an interesting read as my family members can attest.
The Theme
I'm sympathetic with the theme that the US Government's focus on offense, in this book primarily the accumulation of 0days, has made the world more dangerous. We see this offense focus clearly and unapologeticly stated by NSA and Cyber Command across multiple leaders. The dominance of offensive theory and capabilities makes for a less stable world.
My hope for any policy makers reading this book is they reject the current philosophy of "we can't defend so we need to be able to attack first and potentially cause even greater damage". Nicole repeatedly shows where US actions to buy 0days resulted in an unexpected and negative result.
What is less certain is whether the 0day market was inevitable whether the US participated, or even led, in the early years. Nicole bemoans that "the cyberarms market was an incoherent mess". There were buyers and sellers reaching agreement, so it was not an incoherent mess. It was unregulated and led to undesirable outcomes in the past and likely in the future. However unless there are agreed upon cyber norms, similar to biological and chemical weapons, this was and is to be expected.
The Technical ... The Negative
I'm only qualified to comment on the ICS / Critical Infrastructure part of the book. My guess though is if you are part of the Vulnerability Equities Process (VEP), 0day market, Ecko Party, ... the parts of the book that discuss your area will be frustrating. I say this because anyone reading the ICS / Critical Infrastructure part of the book would come out with an incorrect understanding of the current capability of Russia and other adversaries to cause a catastrophic event using existing deployed exploits of the US critical infrastructure.
There is not a lot of factual detail in the book, again good for the lay person reader, and therefore creating an errata list wouldn't be a compelling case. In the ICS area, there was one major mistake on page 297:
It was an act of unprecedented digital cruelty, but the Russians stopped just short of taking lives. Six hours later, they flipped the power back on in Ukraine, just long enough to send their neighbor, and Kyiv's backers in Washington a clear message: "We can torch you".
This clearly implies that the Russians stopped their attack and turned the power back on in Ukraine. What actually happened was the Ukrainians went out to the substations and manually brought them back on line and operated them manually for many months. The SCADA system was down for about a year. Nicole was right that a "clear message" was sent.
This error on its own in a 400-page book would not be an issue. The issue is that every incident is presented in its worst possible light. Often not wrong by a strict parsing of the text, but misleading. A great example is Wolf Creek Nuclear plant on page 397:
the Russians were inside our nuclear plants ... The code made clear that Russia's hackers had breached the most alarming target of all: Wolf Creek, the 1200 mega-watt nuclear power plant near Burlington, Kansas. This was no espionage attack. The Russians were mapping out the plant's networks for a future attack; they had already compromised the industrial engineers who maintain direct access to the reactor controls ... And the goal wasn't to stop the boom. It was to trigger one.
Although she doesn't state it, this quote and the surrounding text would almost certainly be read as the Russians were in the nuclear control and safety systems. The reality is that an adversary had breached the office network at the Wolf Creek Nuclear Power Plant, but they had not yet been able to breach the ICS that controlled the nuclear plant nor the safety systems that would need to fail to cause "the boom".
Nicole wrote on page 392, "The technical community will argue I have overgeneralized and oversimplified, and indeed, some of the issues and solutions are highly technical and better left to them." When I had my interview with Nicole and wrote this review, this sentence kept running through my mind. After much introspection and consideration of this point, I do believe that this Wolf Creek example and many others in the book would lead the lay person to an incorrect understanding of the current state.
How different would a reader's understanding be if the Wolf Creek incident would have said the Russians were just outside the control and safety systems. Yes, they were knocking on the doors where accounting, HR, and other office functions take place, but they had not yet gotten in to plant operations or safety systems.
Another specific example is related to the Bowman Avenue Sluice Gate. To her credit Nicole notes in an early section that this is not Arthur R. Bowman dam in Oregon. However in the concluding chapter she writes,
"We've caught Iranian hackers rifling through our dams."
An Internet connected, ~5 meter wide, ~1 meter high sluice gate that keeps a neighborhood from flooding a couple of times a year is not a national security event and not worth noting as a reason for perilous concern in the concluding chapter.
Beyond the ICS security specifics, and probably more important, are the unsubstantiated contentions that the Russians and adversaries are in our systems and a click away from causing a catastrophic event. There are many in the book's text and in the interviews.
There are many more examples where the book's clear message is that the adversaries, Russians, Chinese, North Koreans, Iranians are able to cause a critical infrastructure catastrophe. The facts don't indicate this. As noted in the summary, Nicole has taken historical incidents and either extrapolated them to their most hysterical or left out the a sentence or two that would give the reader the correct impression. This approach is consistent throughout the text.
If the goal is to grab the lay reader by the shoulders and shake them saying this is important, it is a successful deception. Still it is nearly as scary without the hyperbole.
Recommendations
The final chapter includes a set of recommendations that are underwhelming. Vendors need to have a security development lifecycle (SDL) and put out better systems. The end users, the people need to be more security aware. In this area I don't fault Nicole because there are not easy answers. It might have been better to leave this chapter off.
One interesting suggestion was on Page 398:
We could start by passing laws with real teeth that mandate, for instance, that critical infrastructure operators refrain from using old, unsupported software; that they conduct regular penetration tests, that they don't reuse manufacturers' passwords; that they turn on multifactor authentication; and that they airgap the most critical systems.
This is NERC CIP, sans the air gap, that has been around for a decade plus.
End If you've made it to the end of this book review, I hope you understand where the book succeeds and fails. Who it is written for, and who it is not written for. You and I are not the intended audience. The journey is compelling; the themes are on target; and maybe we should not get too upset that the specifics go beyond reality and are taken to their most extreme possibility.
Subscribe to my Friday ICS Security News & Notes email.
Dale Peterson interviews NY Times Reporter and author of the book This Is How They Tell Me The World Ends.
Some of the highlights include:
4:00 - the story of how Nicole began her 0day journey at a dinner at S4x13
19:42 - was the 0day market inevitable?
26:05 - how incentives have caused the problem and good help solve the problem
30:30 - the ICS / critical infrastructure attack detail in the book For regular followers, the last part is the most applicable.
This book was not written though for the ICS security pro, so some of the earlier discussion may help you understand who the intended reader is and the message Nicole is trying to get out there.
Subscribe to my Friday ICS Security News & Notes email.
Three answers.
1. Women
Women represent 51% of the population and 57% of the college graduates in the US. They comprise less than 10% of the OT Security workforce.
Solving the problem could be as simple as adding women to the OT Security workforce until they reach close to their population percentage. Encouraging and recruiting them into the field, and treating them fairly once they are in, is key. (Of course the OT Security community should be welcoming to all and any addition will help with the shortage in the workforce. Women are singled out in this answer due to the numerical impact.)
2. Stop Searching For Unicorns
The OT Security unicorn has domain specific engineering, automation, IT and IT security skills and experience. OT Security unicorns do exist. I’ve seen a few. They are rare, and not the answer to the OT security workforce problem. Instead find people with one of those skills, an ability to learn, good communication skills so they can supplement the knowledge areas they lack, and a desire to be in OT Security.
3. Hire OT Security Professionals
Asset owners' OT Security programs fail when they try to force engineers and others in Operations to work on OT Security 10 or 20 percent of their time. Partially because they already have more than 100% allocated to existing job functions.
Asset owners' OT Security programs fail when they force an engineer and others in Operations to work primarily on OT Security when they don't want to. Engineers are fully capable of being OT Security pro's, if they want to. However, most would prefer to do the job they trained for and enjoy.
OT Security is a profession.
One last thought, this is not an OT v IT or OT is different than IT issue. There are many specializations under the big umbrella that is called IT. As Patrick Miller says, "it's all T". You need a workforce trained on the appropriate technology.
Subscribe to my Friday ICS Security News & Notes email.
Maggie Morganti joined Dale Peterson on the show to discuss how International Humanitarian Law (IHL), which almost all countries subscribe to, would treat cyber attacks on critical infrastructure.
This is a hard issue and important topic, and Maggie’s master’s thesis is the basis of the discussion.
Links Preparation and Persistence Paper
Video of Dale's comparison of cyber conflict situation to pre World War I cult of the offensive
Part 1: Awareness of Purdue Level 0 and 1 (In)Security
Part 2: Properly Prioritizing Level 0 and Level 1 Security
In this third and final article in my Level 0 / Level 1 security series the focus is on the appropriate security controls.
Sensors and Sensor Data The security concern with sensors is that the sensor data will be incorrect and lead to incorrect control decisions. Sensors fail for a variety of reasons unrelated to a cyber attack, so this is not a new issue. However, an attacker with engineering skills and automation skills is more likely to know what type of false data could lead to high consequence control decision errors. A simple example would be spoofing the data so the Operator and logic thinks everything is operating normally, when in fact the process is entering a bad state.
Bad sensor data could be injected at the sensor itself (Level 0), communication networks between sensor and PLC (Level 1), at the PLC, communications between the PLC and the Level 2 computers, or in the ICS applications at Level 2. As noted in Part 2, the exposure to a cyber attack is greatest where the device or network has an IP stack.
Ideally we would like to have authentication of the source and sensor data integrity along each step of this communication path, and hopefully we will eventually get to having this. In the meantime, the solution where the risk of false Level 0 sensor data is unacceptable is process variable anomaly detection (PVAD) on reported sensor data.
The best example to date of this is GE's Digital Ghost, originally shown at S4x19. GE had a digital twin of a GE turbine and the control system. After training the twin with data from operations, GE was able to identify when specific sensor data did not make sense based on the state of the process reported by other sensors. Digital Ghost then calculated what the nonsensical sensor value should be and sent that to the actual control system where it could be considered by the Operator or automatically corrected in the HMI and system.
Importantly this solution deals with bad sensor data regardless of the cause, sensor failure, cyber attack or other.
The GE example is in some ways the simplest one. GE makes the physical product, the control system, often deploys the solution, and has a somewhat standard deployment. It's why they had digital twins for these turbines before the term digital twin existed. The growing benefits of digital twins is leading to exponential growth in their deployments across vendors and integrators, and the ability for this data to be used for PVAD is another benefit.
The other method for detecting sensor data errors today is to have a separate Level 0 monitoring network and compare the sensor data reported up to Level 2 with the data received on the Level 0 monitoring network. Vendors such as SIGA OT Solutions, Cynalytica, Fortiphyd, Mission Secure and others are offering this. Importantly, some are also touting PVAD capabilities which obviates the need for this new monitoring.
The cost of deploying and monitoring a second network for something with the lowest exposure to cyber attackers is difficult to justify from an efficient risk reduction criterion. I have been interested in the possibility of monitoring only a small percentage, perhaps 5% or less, of the Level 0 sensors through a separate network. Could machine learning identify what 5% of the sensors could detect a Level 0 cyber attack? It likely wouldn't be as simple as selecting the most critical 5% of the sensors. I imagine it would be sensors distributed over the process and with certain correlation results related to high consequence events. This is a good research project.
As noted in Part 2, new sensors with an IP stack should have the same security controls as listed in the actuators below.
Actuators Actuators are the end point that demonstrates the insecure by design problem. They will do whatever they are told to do, within their operationally deployed capabilities, regardless of the source of the command.
There is no authentication of the source of the command. There is no authentication of the integrity of the command. This is what the security controls need to change.
(Remember from Part 2, adding security controls to new or legacy serial interfaced actuators is deferred, look at it again in 3 to 5 years.) These recommendations apply to new actuators with an IP stack and are the minimal set.
The wrap-it-in-TLS decision does add complexity to the Level 0 security problem. If Level 1 is doing anything more than forwarding packets, it will need to decrypt the wrapped packet, and then potentially encrypt it again to send on to Level 2 or other Level 1 devices.
Of course there are many more security controls that could be specified and could be helpful. Others who leap from insecure by design to secure by design lean heavily on the importance of security development lifecycle (SDL) requirements. The fuzz testing of the protocol stack's that began in the '00 decade helped a great deal with protocol stack robustness and will only help the vendor with the product lifecycle. This list of three security controls is the bare minimum in terms of addressing the insecure by design problem.
PLC's (and Other Level 1 Devices) That Communicate With Actuators New PLC's are Priority 1 in the Level 0 / Level 1 security decision tree for adding security. Upgrades to high and medium consequence legacy PLC's are Priorities 2 and 3. The security controls listed for actuators are required for PLC's as well. In addition, they should have security event logs and the ability to store and forward these event logs.
Nice to have, premium options for these devices include:
Conclusions This three part article series can be summarized as follows:
Subscribe to my ICS Security: Friday News & Notes email.
Jason Christopher is the lead author of the new paper: Industrial Cyber Risk Management. Dale Peterson interviews Jason on this episode of the Unsolicited Response show. They discuss
Links Industrial Cyber Risk Management whitepaper discussed in this episode
Subscribe to my ICS Security: Friday News Notes email.
We have resolved the issue on whether the ICS security community knows that almost all Purdue Reference Model Level 0 and Level 1 devices, and the protocols that communicate with them, lack authentication. They know this. The next question is what to do about it from an OT / ICS risk management perspective. I'll break the answer into two parts. This article will cover efficient risk reduction prioritization, and next week's article will cover the recommended security controls.
In a perfect world with unlimited resources, all Level 0 and Level 1 devices would have a set of security controls. New devices would come with the security controls and deployed devices would be upgraded. Since resources are limited and ICS cybersecurity risk reduction options are plentiful, deciding the priority of risk reduction actions is important.
This is similar to evaluating the risk reduction provided in applying security patches in ICS. It is a good security practice to apply all security patches that mitigate vulnerabilities. However as shown in ICS-Patch: What To Patch When In ICS, there is a large variance in the risk reduction achieved in various asset / patch pairs. The small percentage of patches that result in significant risk reduction should be applied asap, and the large percentage of patches that result in almost no risk reduction should be deferred and applied primarily when needed to keep the product in a supported state.
Similar to ICS-Patch, a decision tree is a good way to look at the prioritization of securing Level 0 and Level 1 devices, see diagram below.
Exposure is the most important factor in determining ICS risk reduction. It was the first decision point in ICS-Patch, and it's the first decision point in determining the risk reduction achieved in securing Level 0 and Level 1 devices. How easy will it be for an attacker to access, and therefore be able to compromise, the device or the communication to and from the device?
Factor: Exposure... Level 0 or Level 1?
Securing Level 1 provides a leveraged security point with significantly more efficient risk reduction than securing Level 0. The PLC, RTU, Controller or other device at Level 1 typically communicates with many sensors and actuators. It can be a perimeter security device that stops or limits attacks from reaching the Level 0 device from untrusted networks.
Falsified or bad sensor data is often given as a reason to secure Level 0. Yes, a compromised Level 0 sensor could send back incorrect data that could lead to an incorrect and consequential control action or inaction. However, a compromised Level 1 device connected to that sensor could also provide falsified or bad sensor data for that sensor. The compromised Level 1 device could additionally falsify sensor data for all other sensors it is connected to, send rogue commands to all actuators it is connected to, and alter any of its process logic.
Prioritizing Level 1 security over Level 0 security is similar to prioritizing a firewall to limit enterprise and Internet communication from reaching the ICS over securing the Level 1 devices.
Factor: Exposure... Ethernet Port / IP Stack?
If a Level 0 or Level 1 device has an Ethernet port and an IP protocol stack, it is much more likely to be attacked and compromised through cyber means than if it does not.
There are two reasons for this. First, the IP stack makes it much easier to route attacks to the device. As we know the air gap is almost always a myth. IP based networks are connected to share information, and this provides a potential attack path to the device if it has an IP address. Second, most of the attack tools, as well as almost all of the attacks and attack attempts to date have tried to compromise ICS cyber assets via this interface.
Can a Level 0 or Level 1 device with an "analog" or "serial" interface be accessed? Yes. It could be reached from an IP network through a serial-to-ethernet gateway, and this gateway is a better, again from an efficient risk reduction standpoint, place to put cybersecurity. This is the location where you should apply your security controls, whether it be through an industrial security gateway or other means.
And yes, a serial Level 0 device can be accessed by physically connecting to the serial network. This often, but not always, requires close physical proximity to the device and physical attacks on the device or process are typically easier than cyber attacks with this access.
This will be a contentious point with some, and I'm not arguing against security in all devices. The point is we will achieve greater risk reduction by securing the devices in each level that have an IP address than securing those that do not have an IP address, and they should be prioritized.
Factor: New or Legacy
I used the Will Rogers quote "if you find yourself in a hole, stop digging" in a recent article on the legacy system problem. Any new devices with an IP address should have security. At Level 1 there are a small, but growing list of devices with the basic security functions that will be described in next week's article.
If the choices available for purchase lack security then you should either insure there is an acceptable upgrade path to add security or plan on a much shorter lifecycle than usual, such as 2 to 5 years rather than decades.
Which only leaves the question of what to do with legacy devices with an IP address.
Factor: Impact
Legacy Level 0 devices with an IP address fall into the defer category. Even looking 5 years out it is hard to find a case where an efficient risk reduction approach would lead to replacing or adding on security to these devices.
Legacy Level 1 devices with an IP address should be upgraded or replaced in the order of the impact of compromise of their availability and integrity. In general, Level 1 devices that are involved in control, changing the physical component, should be prioritized over Level 1 devices that are connected solely to sensors. There are a number of ways to detect bad sensor data. That said, there are examples where bad sensor data would be difficult to detect and would lead to high consequence actions, and this would lead to PLC's associated with these sensors being prioritized.
Level 0 and Level 1 Security's Position In An ICS Security Program The decision tree in this article prioritizes the order to add security in the Level 0 / Level 1 category to address the insecure by design problem. It does not describe when this issue should be addressed in relation to all of the other potential ICS cyber risk reduction activities. It is easy to identify activities that provide more and less risk reduction than addressing the Level 0 or Level 1 security issue. Some examples:
Greater Risk Reduction Than Addressing Level 0/1 Insecure By Design
Less Risk Reduction Than Addressing Level 0/1 Insecure By Design
Next Week: Appropriate Security Controls for Level 0 and Level 1
Subscribe to my ICS Security: Friday News & Notes email.
This is a slightly edited version of the LinkedIn Live and YouTube Live show Dale Peterson recorded on March 17th. Dale begans talking about the Level 0 issue and was joined partway into the conversation by Ron Fabela. They talk about the awareness of insecure by design that exists in almost all Level 0 devices, the risk related to this, how asset owners are and should be looking at this, and more.
Then the last ten minutes Dale talks about his two favorite Incident Response Tabletop Exercises and what you should expect when you do a TTX.
Solving a problem typically begins with awareness that there is a problem. Back at S4x12 a group of researchers under the Project Basecamp banner demonstrated that most PLC's (Purdue Level 1 devices) were both insecure by design and ridden with exploitable bugs, as well how an attacker could leverage these issues. Nine years later I believe the issue is known in the ICS security community, even if it is just beginning to be solved.
Similarly, ICSsec pioneer Joe Weiss has been on a content blitz the last three years pointing out that Purdue Level 0 devices, sensors and actuators, do not have any security. Primarily with the example that false process sensor data could be presented to the control system. He has asserted that the ICS security community does not know this, most recently in a post SANS ICS Security Summit article.
there appeared to be a general acceptance that Level 0,1 devices were uncompromised, authenticated, and correct. That is wrong Joe and I had a back and forth on LinkedIn on whether this misconception was present in the S4 audience, SANS ICS Security Summit audience, and ICS security community in general. My belief was lack of security at Levels 0 and 1 was common knowledge in the ICSsec community and the only disagreements are the prioritization of addressing this issue amongst the large number of issues and how it should be addressed. We tried to answer this disagreement with a poll.
The same poll in my Friday Newsletter had 147 responses with 98% answering False. It is likely that there is some overlap in the respondents to the two polls. 97% is clear evidence that the ICS security community understands there is not security at Level 0, and I'm certain they also know it is exceedingly rare at Level 1.
This does not mean there is no awareness problem. Security professionals coming in from the IT security world often do not know and are surprised to learn this. The bigger problem is when asset owner executives are unaware of this because it can lead to spending a lot of money and effort on good practice security controls that have little impact on risk. It is incumbent on Operations and OT Security to inform executives of risks and the best risk reduction options.
What I'm still uncertain of is how well known the insecure-by-design Level 0/1 problem is in the ICS involved engineering community. I'd like to believe that similar to the ICS security community this is common knowledge. I don't have an audience of engineers who are not involved in ICS security. Any readers with the right audience want to run a poll?
Next Week: The Solution To Level 0 / Level 1 Lack Of Security Problem
Subscribe to my ICS Security: Friday News & Notes email.
Cplane.ai and ExxonMobil recently completed a pilot project showing how orchestration could simplify the deployment of a complex, multi-vendor system. This was actually a test of both Orchestration and the Open Process Automation (OPA) Forum's work.
John Casey of Cplane.ai joined Dale Peterson on the show to explain exactly what the pilot project did and how orchestration could be useful in the Operation and Evolve phases of a ICS lifecycle. Orchestration is common in the enterprise, particularly in large telecom, and new to the ICS world.
John helps Dale grapple with the concept, and there is a bit at the end about the industrial edge.
Links * Dale's interview with Steve Bitar on OPA * Cplane.ai video on the pilot project * Cplane.ai white paper on the pilot project
If you find yourself in a hole, stop digging. Will Rogers The large amount of insecure legacy ICS and long ICS lifetimes mean we will need to live with this security risk for years / decades. We can argue about how long it should take to replace the deployed insecure-by-design ICS, but there is no disagreement that it is a huge problem. A big hole. Which is why it is so disappointing that we keep digging.
This was brought to mind again in a tweet from Joe Weiss's session at the SANS ICS Security Summit last week.
The key is that less sentence correctly pointing out that almost all systems deployed today add to the "legacy system" problem because they still have insecure-by-design PLC's / controllers and are using ICS protocols lacking authentication.
Back in 2013 in my S4 introduction (see video clip below), I bemoaned the fact we have been hearing it will take decades to address the legacy system security problem in ICS every year since I was first involved back in 2000. By 2013, we had made virtually no progress in dealing with insecure-by-design Level 1 devices or unauthenticated ICS protocols. We were still decades away from solving it, and the problem had gotten much larger with more "legacy systems" being installed over those 13 years.
The theme of S4x13 was NOW!, and the tag line was "If not us, who? If not now, when?"
https://youtu.be/bZLbm7J2E8o
It's now eight years after the NOW! themed S4x13 event, and we can look at what has occurred over those eight years optimistically or pessimistically.
The pessimist's side is easier. Over those eight years 99%+ of the ICS deployed have insecure-by-design PLC's/Level 1 devices and use unauthenticated ICS protocols. Access inside the perimeter = compromise only limited by the engineering and automation skills of the attacker, and the capabilities of the Level 0 connected devices. We have increased the 'legacy system' problem with eight years of ICS deployments. We are still digging that hole.
The optimist's side is some of the Level 1 device vendors and some of the ICS protocol groups have addressed the problem. There are now encrypted and authenticated versions of many ICS protocols. There are also now PLC's that have signed firmware, secure boot, support for secure ICS protocols, and authentication of operation and administrative functions.
Is it perfect? Of course it isn't. In some cases these PLC's carry with them a lot of legacy code. It's analogous to the Microsoft challenge after Bill Gates' Secure Computing memo. Yes, there can be a lot of improvement in the short run, and there is still a multi-year grind until that old legacy code is replaced.
It's The Asset Owners' Turn Some of the key vendors have invested in development to have, at a minimum, a non-insecure-by-design offering. And more are near release. Now it is the asset owners' turn. The asset owners have to show they want to move away from insecure-by-design systems and reduce the associated ICS cyber risk.
Is circa 2021 when we stop digging the hole? Stop increasing the "legacy system" problem?
It is too soon to tell, but early signs show very little uptake to the available security capabilities. Asset owners aren't asking for them, integrators are designing them in, and vendors aren't pushing them. Features such as signed firmware do not require asset owner action and will be a clear win, but the secure protocols and user / device authentication do. They add complexity to the project and ongoing operation. The features often make the product more expensive as well.
The answer is likely, if security is deployed at all, to be sector and asset owner size specific. There may be a sector, such as large petrochemical, that may adopt this move away from insecure-by-design while other sectors continue with the status quo. Even this limited progress would be a big step forward as we have seen other ICS security practices trickle down from more security conscious sectors to the less security conscious sectors.
If the asset owners don't purchase and deploy the more secure versions, then there is little impetus for a for-profit vendor to spend resources developing, marketing and supporting security features.
The other option would be for the regulators to step in and require ICS being sold into certain sectors have certain security features. This would be difficult to do well, and it's a whole other article.
Bryan Owen of OSIsoft joins Dale to discuss all that when on in February. Top stories include:
Attacks and Outages: Oldsmar, Solarwinds fallout, ERCOT/Texas and China's efforts on the Indian power sector
Ruben Santamarta's research on IoT Software Development Kits
What does GE backing out of the ICS security product market mean.
Plus wins, fails and predictions.
I recently stumbled upon a McKinsey article from October 2019 that more elegantly, in McKinsey speak, made the argument against "cyber hygiene" than I do.
This was a very revealing panel on how the VC world is viewing the ICS security space. Many strong statements and feelings about where we are and what the future will be.
The VC's were Bob Ackerman of AllegisCyber and Sameer Reddy of Energy Impact Partners. Both funds are active in the ICS security space.
Links Hack The Capitol
AllegisCyber
Energy Impact Partners
Dale's weekly article published on 23 Feb 2022. He dives into why it is so difficult to value these companies, and the disconnect between any value investing analysis and the actual, what someone will pay, market valuation.
Total Power by Kyle Mills is a story about a successful cyber/physical attack on the US electric grid, the impact of a prolonged outage, and the effort to bring the power back and catch the bad guys. What impressed me most about the fun read is it pulled some key facts out of the mountain of grid-hacking FUD so that it was much more plausible than a typical work of fiction, and much reporting.
I couldn't get the author on, but I got another author in the genre and the person who recommended I read the book on the podcast, Bob Peterson aka my Dad. We talk about the plausibility, how authors do their research, how much detail to include in a work of fiction, the Mitch Rapp character created by Vince Flynn, and some other things in this short, fun episode.
Links - Total Power By Kyle Mills
This week's Unsolicited Response Show focuses on the issue that women are vastly underrepresented in ICS security and what we need to do to change this both in numbers and career paths and prospects. Kelly Jackson Higgins joins me to co-host this episode, and we have great guests including:
We've seen lots of progress and growth in the women in ICS community, and I actually could have had many more great guests on the episode. Still their is much to do to make the community more open and inclusive and supportive to those entering the field.
Chapter 2 of Nicole Perlroth's new book was a dinner at S4x13 that I hosted. This article is my recollection of that dinner.
The ICS security product vendors tend to focus on a product segment, firewall, data-diode, detection, ..., Bayshore Networks is unique in that they have the closest thing to a full line of ICS security products. This is being grown further with their recent acquisition of GE's OpShield technology.
Dale Peterson talks with CEO Kevin Senator about the strategy, individual product segments, and why GE and Bayshore did this detail. It is admittedly a bit commercial as Kevin touts the company, products and strategy. Dale asks some tough questions, and Kevin gives some candid answers.
Dale Peterson interviews authors Andrew Bochman and Sarah Freemen of Idaho National Laboratory (INL) about their just published book Countering Cyber Sabotage - Introducing Consequence-driven, Cyber-informed Engineering (CCE).
The CCE methodology has been discussed by the INL team for over two years to great interest in the ICS security community. Now there is a book that describes it in some of the detail the industry was craving.
Dale begins with a 3-minute review and then dives into the interview. They start their discussion with who the book was for, their hopes for readers who finish the book, the stats on CCE, CCE training and certification and more on the program INL is rolling out. Then the discussion shifts to a detailed Q&A on the four phases of CCE. If you have any interest in determining what should be done next in reducing ICS risk, then this is a must watch episode.
Get Countering Cyber Sabotage on Amazon
I missed recording my weekly article last week so this episode includes the articles from Jan 28th and Feb 4th.
Tweet Me! @digitalbond Friday Newsletter: https://mailchi.mp/f53b1c8c2da0/friday
One of my favorite interviews is with founders who have persevered to build companies over decades. This one is with Eddie Habibi, the founder of PAS.
We go over his 27 year journey to uncover some of the lessons learned and how he sees the future of ICS security.
Links: PAS Web Site
Hexagon Acquisition Press Release
S4x21 Charity Water Campaign
S4x20 Video
The Detection Market
Ask A Question
The ZDI team brought Pwn2Own to ICS with Pwn2Own Miami at S4x20. They awarded almost $300K to researchers who were able to find and exploit 0day vulnerabilities in important ICS applications. Applications such as HMI and EWS from Rockwell Automation and Schneider Electric, OPC UA, TMW's DNP3 stack and more.
In this episode I talk with Brian Gorenc and Abdul-Aziz Hariri about the competition. Why they do it? What it achieves? And what happened?
0:00 My brief discussion on which patches matter and which don't
8:12 My interview with Brian and Abdul
47:47 ZDI's video wrap up of the event
Tweet Me! @digitalbond Friday Newsletter: https://mailchi.mp/f53b1c8c2da0/friday
A new technical paper forecasting vulnerabilities should help you answer this question.
Dale and Corey discuss the value of a normalized, taxonomized approach to SIEM, which Dr. Anton Chuvakin has famously claimed is doom to fail. Corey is sympathetic to this view and tries to explain it to Dale.
The alternative is gathering and creating a data lake with more log data and pcaps that can be used by threat hunters and customized rules.
The conversation continues with what types of integration would be helpful between the OT detection products and whatever is used for organization wide detection and response, the packet encryption challenge, and the preference to just buy a product.
You can submit your audio question on this episode or other OT and ICS Security topics to the show by going to dale-peterson.com and clicking on "Record Your Question".