Unsolicited Response Podcast: Recent Episodes

Dale Peterson: ICS Security Catalyst and S4 Conference Chair

Dale Peterson interviews the innovators in ICS / SCADA cyber security as well as the top talent in related fields. It is the podcast for those who want more information similar to what is presented at the annual S4 event each January in Miami South Beach.

View Details

Dale Peterson speaks with Joel Langill, the SCADAHacker, about his new training course entitled Conducting Threat, Vulnerability, and Risk Assessments For ICS. A two day version of this course will be offered prior to S4x25.

Of course Dale and Joel jump around a bit on training, the workforce and other items. Take a listen.

View Details

Stewart Baker is one of the preeminent lawyers on topics of cyber law with an impressive career in and out of government. Stewart also hosts the Cyberlaw podcast.

The Biden administration is contending that vendors should be held liable for security deficiencies in their products.

Assuming this is turned into law and/or executive orders, what does it mean? What can we learn from other liability law to inform us what would be required for a vendor to be held liable for a security issue? How would the judgment / damages be determined.

Dale's note: We talk about the SEC charges against SolarWinds in this interview.

View Details

Dale Peterson interviews Rob Lee on the S4 Main Stage. They cover a lot of ground and Rob is never shy about sharing his opinions and analysis. They discuss:

  • Rob’s first S4
  • PIPEDREAM deployed v. employed distinction … and why 2 years later is it still the most dangerous ICS malware?
  • Are we really more homogenous?
  • What makes a group something that Rob/Dragos tracks as an ICS focused attacker?
  • If the answer to intel is do the basics, do I need intel?
  • What ICS specific data was VOLTZITE exfiltrating?
  • What countries are targeting critical infrastructure? Is it realistic to expect any country to not target its adversaries CI?
  • Threat actors focused on manufacturing
  • How should an asset owner measure the effectiveness of their detection solution?

View Details

Chris Hughes and Nikki Robinson recently wrote the book Effective Vulnerability Management. Dale and Chris discuss the topic and book including:

  • The definition and scope of vulnerabilities. It’s much more than coding errors that need patches.
  • Are ICS protocols lacking authentication “vulnerabilities”
  • The reality that most organizations have 100’s of thousands of unpatched vulnerabilities. Some statistics and will this change.
  • Ways to prioritize what vulnerabilities you address.
  • The SSVC decision tree approach that was introduced at S4 as Never, Next, Now
  • Tooling … vulnerability management, software configuration, ticketing, remediation.
  • And much more.

Links:

  • Effective Vulnerability Management, https://www.amazon.com/Effective-Vulnerability-Management-Vulnerable-Ecosystem/dp/1394221207/
  • Dale’s ICS-Patch Decision Tree, https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf

View Details

Waterfall Security Solutions and ICSSTRIVE put out an annual threat report that Dale Peterson believes is the best in OT. Why? It only includes incidents that had physical consequences on systems monitored and controlled by OT.

Dale and Andrew discuss:

  • What is in and out of scope for the report.
  • The breakdown of the 68 incidents that occurred in 2023 by industry sector, cause, threat actor and more.
  • The impact reporting requirements may have on these numbers in the future.
  • What percentage of OT cyber incidents with physical consequences are made public.
  • Ransomware on IT causing physical consequences, exfil v. encryption, and what asset owners should do given this represents 80% of the known incidents in the report.
  • And more.

Links:

  • 2024 Threat Report: https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/2024-threat-report-ot-cyberattacks-with-physical-consequences/
  • ICSSTRIVE: https://icsstrive.com
  • S4 Events YouTube Channel: https://youtube.com/s4events

View Details

Patrick Miller has OT cybersecurity experience as an asset owner, PacificCorp. As a regulator and one of the first NERC CIP auditors with WECC. As a community organizer creating and leading EnergySec and the BeerISAC. And as an entrepreneur creating and leading a number of consulting practices. He is currently the Founder of Ampyx Cyber.

In this episode Patrick and Dale discuss:

  • Why Patrick changed the company name and selected Talinn as the location for the new European office.
  • The major differences in approaches to OT cybersecurity and risk management between Europe and the US. (more than just regulatory differences)
  • What has the EU learned or improved on regulation from NERC CIP.
  • What is the current state of NERC CIP regulatory risk? Are the regulated entities understanding and meeting the standards’ requirements?
  • The challenge of slow NERC CIP modifications, eg virtualization and cloud.
  • Bad standard & good regulator v. good standard & bad regulator.
  • Should water follow the NERC CIP model as recommended by AWWA?
  • How Patrick is dealing with AI.

Links

  • Ampyx Cyber: https://ampyxcyber.com
  • Patrick’s Critical Assets Podcast: https://amperesec.com/podcast
  • Subscribe to Dale’s ICS Security Friday News & Notes: https://friday.dale-peterson.com/signup
  • Advertise on Unsolicited Response: https://dale-peterson.com/advertising/

View Details

Emma Stewart joins Dale to discuss the 3 big OT & ICS security stories from the first quarter. They end by giving their win, fail and prediction for Q1.

View Details

In this solosode episode Dale reviews the status of his three predictions from the Q1, 2 and 3 quarter in review episodes and answers a listener question.

View Details

Dale is joined by Steve Pozza, CISA Section Chief of Operational Resilience, and Tom Millar, CISA Branch Chief of Resilience, to discuss some of CISA's security services for asset owners. They discuss:

  • The Internet accessible attack surface enumeration and vulnerability scanning surface.
  • Asset owners can buy products or services to do this. Why is the government doing this?
  • What CISA is doing with this attack surface data?
  • How is CISA measuring the success of this service offering?
  • Other broadly available services and tools, the cybersecurity performance goals (CPG assessment) ~500 done in 2023 (and their thinking about self-assessments), Malcom traffic analysis tool, and a couple of other tools.

Links

  • CISA Vulnerability Scanning Services
  • Malcolm Tool

View Details

Andrew Ginter published his third book this year: Engineering-Grade OT Security. Dale interviews Andrew on the book including:

  • Who was the target reader that Andrew wrote the book for?
  • Do (should) professional engineers lose their licenses for poor and dangerous cybersecurity design and deployments?
  • The use of the term engineering grade, and how he defines it.
  • Unhackable protection and safety controls as a major part of engineering grade.
  • Unidirectional (one-way) network devices as the only security control listed as engineering grade. Is one-way from the enterprise network to the OT network engineering grade?
  • Given the ICSSTRIVE/Waterfall report that 75% of all cyber incidents affecting operations are due to ransomware on IT, should asset owners prioritize address this issue or engineering grade security first?
  • What is keeping Andrew working rather than retiring

Links

  • Complete this form to get a free copy of the book

View Details

This week is a Dale Peterson solosode.

Updates and Announcements

Dale provides updates about S4x24 ticket sales and announces the Women In ICS Security program and sponsor package.

Main Topics

  1. Asset Inventory in Cybersecurity: Dale challenges the common security mantra "You can't protect what you don't know," using examples from both physical and cyber domains. He notes many of the comments on this week's article missed the main point, and he gives hints on the next two asset inventory articles.
  2. Legal and Regulatory Issues in Cybersecurity: Dale emphasizes the importance of domain expertise whether it be cybersecurity or the legal profession. He previews upcoming keynote interviews with legal experts and advises cybersecurity professionals against making legal analyses without proper expertise.
  3. Artificial Intelligence in Cybersecurity: Dale reveals that most AI submissions for S4 were broad and hand wavy. This isn't wrong, but most have heard this info by now. He then discusses the need for focusing on specific, real-world applications of AI and stresses the importance of measurable improvements in this age of experimentation.

View Details

Kelly joins Dale to discuss her new book Security Chaos Engineering: Sustaining Resilience in Software and Systems. Kelly points out the second part of the title is the most descriptive, and she is not a big fan of the Chaos term that has taken hold.

They discuss:

  • A quick description of Security Chaos Engineering
  • Is there similarity or overlap with the CCE or CIE approach?
  • The value of decision trees
  • Her view of checklists of security controls like CISA's CPG
  • Lesson 1 - "Start in Nonproduction environments"
  • The experiment / scientific method approach and how it can start small
  • The Danger Zone: tight coupling and complex interactions
  • How should ICS use Chaos Engineering

View Details

Don Weber joins Dale Peterson to describe his IACS STAR Methodology to score the risk of a vulnerability to an ICS (or IACS in 62443-speak). It is a modification of the OWASP Risk Rating Methodology. Don has modified some of the 16-factors to create IACS STAR. The methodology and code is available on GitHub and a calculator is available on line.

Don and Dale discuss:

  • What Don likes about the OWASP Risk Rating
  • Potential issues with putting numbers to SME judgment
  • Differences between IACS STAR and the OWASP Risk Rating
  • The weighting of the 16 factors
  • The future of IACS STAR

Links

Slides Discussed In The Show: https://dale-peterson.com/wp-content/uploads/2023/10/IACS-STAR.pdf

IACS STAR GitHub Repo: https://github.com/cutaway-security/IACS_STAR_Methodology

IACS STAR Calculator: https://iacs-star-calculator.com/iacs_star_calculator.html

Cutaway Security Website: https://www.cutawaysecurity.com

ICS-Patch Decision Tree: https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf

View Details

Dave Whitehead, CEO of SEL, joins Dale on the show to talk about:

  • The new SEL printed circuit board (PCB) factory in Idaho. Why they bucked the trend and did this. The benefits, the ROI, and more.
  • SEL's position on providing SBOMs to customers and their internal use of SBOMs - Where leaders tend to go wrong.
  • Substation shootings
  • Market acceptance of SEL's Blueframe virtual platform

Links

  • Dave Whitehead's previous appearance on the Unsolicited Response Show
  • Want to advertise on the Unsolicited Response Show in 2024?

View Details

Dale and Nicole Sundin of Axio discuss CRQ, how to deal with the precision challenge, Axio's prioritization of impact, ransomware on IT affecting operations as an example, and more.

They also discuss UX and the single pane of glass.

Links

Axio web site

View Details

Former Congressman and Presidential candidate Will Hurd is a rarity with a tech background in someone who was elected to the US Congress, and even rarer in someone running for President. Will graduated Texas A&M with Computer Science degree. Worked as a Senior Adviser to the cybersecurity company FusionX, which was acquired by Accenture. More recently he was on the board of OpenAI.

This is probably one of the most technical interviews with a Presidential candidate you will hear. Dale asks Will:

  • How he would rate CISA's performance (he co-sponsored the bill to create CISA)?
  • Does the Executive Branch have the authority required to secure critical infrastructure?
  • His views on Cyber Command / DoD policy of "defend forward"?
  • The current level of Congress's technical literacy?
  • What type of cybersecurity legislation, if any, Congress should pass?

View Details

Patrick Miller of Ampere Industrial Security joins Dale to discuss the three big stories of the quarter and give their win, fail and prediction.

Stories

  1. US National Cybersecurity Strategy Implementation Plan + CISA 2024-2026 Strategic Plan
  2. The cybersecurity / OT cybersecurity vendor market news. We just had Cisco buy Splunk, plus the Dragos "extension", and SCADAfence selling to Honeywell. Seems like some tough times.
  3. Ransomware again … Port of Nagoya, Clorox, hospitals, CISA Ransomware Vulnerability Notification Service

Links

  • S4x24 Ticket Sales
  • Ampere Industrial Security
  • Critical Assets Podcast

View Details

Dale Peterson was recently interviewed by Jay Johnson of Sandia and Tom Tansy of the Sunspec Alliance as part of their distributed energy resources (DER) Sunspec webinar series. We covered a lot of issues and Dale was not shy in throwing out some analysis and opinions. After 5 minutes discussing the S4x24 ticket process, the topics discussed: * How DER will deal with the complex, large number of users and stakeholders PKI environment. * The Sunspec device security specification and the benefits of a limited, key set of security controls. * What is the role of government regulation to solve DER security issues? * The potential power of the utility companies to levy requirements and be a choke point for access. * The Patch Act, FDA and DER. * shift left and product liability due to security flaws * and more

View Details

Marina Krotofil recently published the paper Industrial Control Systems: Engineering Foundations and Cyber-Physical Attack Lifecycle which is a detailed paper on cyber attacks that cause a physical impact on the system being monitored and controlled. It took Marina 1.5 years to write this paper, which is more accurately described as a short book. We discuss:

  • the work she is doing to help Ukrainian critical infrastructure security during wartime
  • what got Marina interested in cyber-physical security 10+ years ago
  • the current understanding of cyber-physical in the OT security community
  • Chapter 2: Engineering Foundations as a great intro for those in IT to understand basic automation principles
  • Chapter 3: Very detailed explanation of a specific process (we don't spend much time on this)
  • The Cyber-Physical Attack Lifecycle with emphasis on the Damage Loop. "Plant shutdown is risky for the attacker as it may instigate an investigation"
  • Chapter 4.6 is a great conclusion

View Details

Steve Springett is the Chair of the OWASP CycloneDX Core Working Group. CycloneDX is one of the two main machine readable formats that SBOMs are being created in, although CycloneDX can capture all sorts of BOMs.

In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX

If you know the basics, skip to 14:24 where we get into the details

  • Statistics on who is generating and using CycloneDX SBOMs, and the impact of governement regulations on the use.
  • Steve's view of the NTIA Minimum Elements for SBOM v. CycloneDX elements.
  • How CycloneDX tries to capture the completeness of and confidence in the SBOM.
  • The naming problem. CPE, CVE, NVD, SWID, PURL and more. Steve describes the problem and what he thinks is the way forward.
  • Vulnerabilities ... and why Steve thinks VEX is a missed opportunity.
  • Outdated component analysis (this could be very useful in a procurement decision)
  • and more

Links

CycloneDX document: Authoritative Guide To SBOM

ICS-Patch (what to patch when in ICS / risk based decision tree)

S4x24 CFP

View Details

At S4x23 Andy Bochman gave a Main Stage performance on the OT Cybersecurity / Climate Nexus. It's a new idea and Dale wanted to dig into it and understand it better. The discussion looks at where there is a nexus/connection/overlap and where there may be parallel efforts where each side might learn from the other.

Links

Andy Bochman S4x23 Video

Slide used in this episode

Earlier episode with Dale and Andy discussing CCE

S4x24 Call For Presentations

View Details

Gus Serino worked at a large water utility before joining Dragos in 2019. We're talking water sector so it's obligatory to start with Oldsmar (2:20), but we don't talk cyber. Instead we go through the physical portion of the water system assuming the attacker is able to issue the command to the pump to dump a lot of sodium hydroxide into the water system and what would likely happen. Importantly Gus identifies the simple, unhackable solution to this threat. A hard wired PH sensor that will shut off the pump regardless of the commands from the ICS.

After Oldsmar Dale and Gus discuss:

  • how small and medium water systems should approach cyber risk
  • the greater challenge to large water systems
  • the EPA's early steps on cybersecurity and future regulation - surprises in moving from a water utility to Dragos
  • what Gus's new I&C Secure company is doing

View Details

This is a solo-sode where Dale reviews two articles from July with comments on comments and additional thoughts. The final section is a must listen if you are going to submit to speak on the S4x24 Stage. The times below are so you can skip to what you are interested in.

1:29 One-Way Data Diodes and School Zones

10:15 SAIDI: What Cyber Incidents Should Be Excluded From Metrics

16:05 Do's and Don'ts For Your S4x24 CFP Submission

Links

Subscribe to Dale's Friday ICS Security News & Notes

Info and Links for the S4x24 CFP

View Details

HD Moore is most famous for his creation of the Metasploit penetration testing framework. It began in 2003 and hit the OT world in 2011. HD is now the Founder and CTO of RunZero, another cybersecurity startup that is starting to play in the OT Space.   In this episode we spend the first third of the show talking about Metasploit ... early reaction, OT modules, is Metasploit still necessary and useful today.   We then shift to creating asset inventories in IT and OT, which is what RunZero does. * Why HD decided to run back into the cybersecurity startup world? * How it started as a solo shop with HD writing all the code. * How HD things Shodan and RunZero are different. * What technique does RunZero use to 'scan'. A term that many fear in OT. Check out their approach to 'fragile devices'. * The OT reaction to this type of scanning. * What role uses the RunZero product?

Links RunZero website S4x24 Call For Presentations

View Details

Dale is often critical of the US Government's efforts and programs to address OT cyber risk. So it's a pleasure to highlight a program that is working.

Samantha Ravich, Chair of the Center on Cyber and Technology Innovation at the Foundation for the Defense of Democracies, joins Dale to discuss the US Department of Energy's OT Defender Fellowship Program.

They begin by describing the program, its goals, what are ideal candidates for the program, and the early results from the first few cohorts. Then Timothy Pospisil of Nebraska Public Power District and part of the 2022 OT Defender Fellowship cohort joins the show to discuss his experience in the program.

At the end we discuss how this could be expanded to address water, critical manufacturing and other sectors.

Link

OT Defender Fellowship Program

View Details

Eric Cosman had a 38 year career at Dow Chemical, was on the ISA 99 committee its inception, and then he retired. After retirement Eric joined ARC Advisory Group as a Contributing Consultant and got even more active with ISA. He is a long time co-chair of ISA99 and was President of ISA in 2020. Eric and Dale discuss: * Dow's in house developed DCS and SIS: MOD * Eric's top trend from 2022: The value of open automation and the Open Process Automation Forum * ISA/IEC 62433 + Eric's view they are "primarily engineering standards" + What Eric thinks about the safety / security analogies + His experience in being ISA President in the first year of COVID + ISA as "the home of automation" + Has ISA lost mindshare on ICS security standards to the US Government and training to SANS

View Details

Mark Hyman of Verge Management Group joins Dale to discuss the big 3 stories of Q2 along with their win, fail and predication.

Big Stories

  1. The OT Security Layoffs (Mark is a recruiter specialized in ICS/OT security)
  2. Still No US National Cyber Director?
  3. The Merck NotPetya Insurance Claim Ruling

Plus they both have a win, fail and prediction at the end.

View Details

Josh Corman is the VP of Cyber Safety Strategy at Claroty, was the Chief Strategist of the CISA COVID Task Force, and founder of I Am The Cavalry. Josh and I dive into Healthcare Security, SBOMs and other topics. 

  • Can OT in healthcare be treated in a similar way as the factory, power plant, water treatment plant, ... ?
  • The first fatality due to a cyber attack on a hospital.
  • Should we be focusing our efforts on reducing the impact if ransomware hits a healthcare facility? What is the equivalent to a steel reinforced cockpit door?
  • The PATCH Act (included in the Omnibus bill passed in Dec 2022) requiring medical device manufactures to provide a SBOM and a patching program. What is it? What will be the impact of this? (BTW, Josh changed my mind on this as a start to a long term impact)
  • Will the PATCH Act provisions delay approval of medical devices?
  • How accurate and complete are vendor generated SBOMs today? How will this be solved?
  • What will be the impact of SBOM mandates?
  • Differing views on the importance to society of attacks and outages in the agriculture / food industry
  • I Am The Cavalry turns 10.

We will need to have Josh back for a Part 2.

View Details

This episode is a replay of a lively panel from the Cyber Security Agency of Singapore's OT Cybersecurity Expert Panel (OTCEP) last year. It begins with a great introduction to the Top 20 Secure PLC Coding Practices by Sarah Fluchs. At the 35 minute mark the panel discussion begins. There was a lot more disagreement and back and forth than the typical panel. This gives you a variety of points of view and positions to consider.

Paul Griswold moderated the panel of Dr. Ong Chen Hui, Joel Langill, Sarah Fluchs and Dale Peterson.

Links

  • Top 20 Secure PLC Coding Practices
  • 2023 OTCEP Event Page, August 22 - 23 in Singapore
  • S4x24 Call For Presentations

View Details

How much does a security control reduce cyber risk? What control or mix of controls provides the most efficient cyber risk reduction? Tough questions that a team of researchers at INL and Sandia tried to answer in a project.

Two of the researchers, Jay Johnson of Sandia and Jake Gentle of INL, join Dale on the show to talk about the metrics and results. The project was Cyber Resilience for Wind Installations, but the metrics and results are applicable to every sector. We get into the weeds on this episode and discuss:

  • how they created the test environment
  • the two attack scenarios (and why only two and how easy it would be to expand)
  • the physical resilience score
  • the cyber resilience score
  • the results from four different mixes of security controls
  • areas for further testing and improvement
  • and a tiny bit about trying to calculate an Expected Benefit from Cybersecurity Investment, which is a bit like ROI and how much money to spend.

Links

• Video: https://www.youtube.com/watch?v=bBLbLUFKzIc

• IEEE Access Journal Paper: https://ieeexplore.ieee.org/document/10043706

• POWER magazine article: https://www.powermag.com/cyber-resilience-for-wind-power-installations/

• 2-page flyer: https://www.researchgate.net/publication/367074443_Cyber_Resilience_for_Wind_Installations_A_Cyber_Resilient_Reference_Architecture

• Final project report: https://www.researchgate.net/publication/368599508_Hardening_Wind_Energy_Systems_from_Cyber_Threats-Final_Project_Report

View Details

Ralph Langner, Megan Samford and Zach Tudor join Dale Peterson on the S4 Main Stage to close out S4x23. This Closing Panel is always an attendee favorite as none of these four are afraid to take a strong and even unconventional stance on at OT security topic or issue.

View Details

Dale Peterson interview CESER Director Puesh Kumar on the S4x23 Main Stage. We discuss a number of CESER programs how they are measuring success, what has not worked, why they are doing some things industry is already doing and more.

5:30 Where is the CESER CRISP program (detection and information sharing) today? Has it stopped or reduced the impact (outages and others) of cyber attacks on the electric sector? How will they measure the success of this program?

10:40 What has CESER tried, thought it would work, and ended up failing? 

14:05 CESER's CyTRICS program is testing vendor equipment? Why, does GE and Hitachi need help? And the results have been trivial vulnerabilities that could be found in hours. Why is CESER spending millions on this?

19:25 Cyber Informed Engineering (CIE) is it the same as Secure By Design? This is a long process, what will the early wins look like? Two years from now how will we know if we are succeeding? Maintaining a manual capability dominated the examples in the document, why hasn't this been highlighted in the program? How can we accelerate this?

25:20 Clean Energy Cyber Accelerator is looking at solutions (OT detection and MFA remote access to OT) that are well established with vendor offerings and asset owner deployments. Why is CECA doing this and trying to accomplish?

View Details

Chris Blask has a long career bringing new ideas to reality. He currently is Vice President of Strategy at Cybeats, who has a SBOM Studio product.

Cybeats is different in that SBOM Studio does not create SBOMs. This requires SBOMs to be available from somewhere, and Dale & Chris spend a lot of the podcast talking about the SBOM market today and in the future.

  • What percentage of the OT software solutions have SBOMs today? What will that number be in three years, five years, seven years?
  • When will the top 10% asset owners be able to be get value worth the effort from SBOMs and related tools and information?
  • What will the SBOM marketplace look like?
  • the DBOM.io project

Of course being Dale and Chris, they deviate into a lot of other topics. Such as Chris's quotes:

  • “Security comes through transparency and automation”
  • “2020, this is the last decade of cybersecurity” “the last decade when entirely new fields will be discovered” I think we have covered the field.

View Details

The August 2021 Unsolicited Response episode with Edgard Capdevielle, CEO of Nozomi Networks, was a fan favorite. So Dale invited Edgard back, like the first time it was a wide ranging and fun conversation. His budget analogy of OT security and a new child in the family was Dale's favorite part.

They cover a lot of ground including:

  • the OT visibility and detection market growth in the last two years
  • whether he stands by his 2021 view that a company that does "X, Y, Z and OT security" doesn't really do OT security
  • how much of the back end (non-sensor) part of the market is moving to the cloud now and what will it be in three years. Plus some disagreements / discussion on architecture
  • budget muscle and momentum
  • what sort of metrics should an asset owner use to determine the value of these OT visibility and detection solutions
  • how is the US Government affecting the market Enjoy!

View Details

Dale Peterson interviews cybersecurity legend Gene Spafford on the S4x23 Main Stage. Some of what they cover is:

  • how to deal with securing legacy systems
  • the incredibly productive 3 years of firsts including host IDS, network IDS, honeypot, network vulnerability scanner, and more. What led to this amazing production?
  • The upcoming 25th year of CERIAS
  • His new book Cybersecurity Myths and Misconceptions ... Avoiding the Hazards and Pitfalls that Derail Us and digging into some of those myths (Cyber Offense is Easier than Defense, Sharing More Threat Intel Will Make Things Better, Everyone Should Solve A Given Cybersecurity Problem In The Same Way)

View Details

Marty Edwards joins Dale Peterson to discuss the big stories of the first quarter of 2023.

  • The US National Cybersecurity Strategy
  • ISA / ISASecure starting an OT Site Assessment Certification
  • Ransomware Affecting Operations (indirectly)

Marty and Dale then give their win and fail for Q1 and a prediction.

View Details

Dale Peterson talks with Matt Wyckhouse, Founder and CEO, of Finite State about where the SBOM products and market is today and where it will go in the future. This discussion was informed by the SBOM Challenge at S4x23.

  • Who is the primary buyer of SBOM products and services today? (Hint: Matt thinks that 80% of the code in a product is third party)
  • How accurate are the products, and the Finite State product in particular, in creating a SBOM?
  • How much is the value of a SBOM degraded if it is not perfect? If it is missing software or has inaccuracies?
  • Are the offerings now a product? A semi-custom service that uses a developed product? (with an apt comparison to the detection market)
  • What will the US Government do with all these SBOMs if they actually get them? If they get an exponential increase in software inventory and the patching and cyber maintenance burden.
  • Will there be a separate/distinct OT SBOM market? Will there be a SBOM market in the long run or will it get subsumed in some sort of asset management market?
  • Early thoughts on the SBOM marketplace (a place to collect and distribute and respond to queries on SBOMs)
  • Where is the industry / products now on VEX?
  • Do configuration files belong in a SBOM?
  • Surprise data points from the SBOM Challenge

View Details

Dale Peterson interviewed Puesh Kumar on the S4x23 Main Stage. Puesh is the Director of the US Dept of Energy's Cybersecurity, Energy Security, & Emergency Response (CESER). The lead US Government OT cybersecurity agency in the energy sector.

After Puesh gives a 3 minute overview on CESER, they dig into it.

  • How are they measuring CRISP's detection and analysis progress? Has it stopped or limited the impact of any attacks?
  • What is one of the CESER programs that didn't work and what did they learn from it?
  • Why is the US Government testing products for GE, Hitachi and other large companies and questioning the results.
  • The push for Cyber Informed Engineering and what success looks like
  • Competing with industy
  • and more ... CESER is tackling a lot so there was much to squeeze into 30 minutes

View Details

Steve Mustard took his 30 years of experience and wrote Industrial Cybersecurity: Case Studies and Best Practices, published by ISA. After talking about who the book is for and the writing process, Dale and Steve dig into the details. 

Given Steve's longtime involvement and leadership with ISA, it's not surprising the book leans heavily on ISA/IEC 62443. They talk chapters on architecture, certification, optimism / pessimism, risk management and a fundamental misunderstanding of IT by OT. Some agreement, some disagreement, and always a civil discourse.

View Details

Dale's interview with Michael Fischerkeller, co-author of the bood Cyber Persistence Theory. The first half of the interview digs into Cyber Persistence Theory.

  • Why Michael believes cyber is a new and third strategic environment (in addition to conventional and nuclear)
  • What is meant by cyber being an environment of exploitation and not coercion
  • The theory's different use of initiative and why the theory believes it is the important element to winning ("initiative rather than restraint is necessitated")
  • How a series of smaller, fait accompli, actions that are not responded to can have a strategic-level cumulative effect

The second half of the interview looks at what the world will look like and what asset owners should do if multiple nations believe in and act on this Cyber Persistence Theory.

  • Michael argues it already is in place and the US is late to the game
  • Persistence presence in critical infrastructure would not "cross the threshold"
  • How organizations will reach a cyber agreed competition
  • Will this be escalatory (Michael says no)

Dale believes this is an incredibly important theory to understand because it is taking hold in the world's major powers.

Links

Cyber Persistence Theory book

View Details

Matt Morris and Mark Mattei of 1898 & Co. joined Dale to talk OT Managed Security Services as 1898 recently introduced an OT Managed Threat Protection and Response service. The discussion included:

  • what they are monitoring in the OT environment
  • the OT MSP competitive landscape (OT detection vendors, ICS vendors, large consulting vendors, ...)
  • can you / should you monitor OT separate from IT
  • how 1898 deals with competing partners (such as Claroty, Dragos and Nozomi) that they resell and install and competing against them for MSP
  • the active response and threat hunting services and how that is accepted in the generally conservative
  • and more

View Details

Bill Fehrman is the CEO of Berkshire Hathaway Energy, co-chair of the Electricity Subsector Coordinating Council, and chair of the E-ISAC.

The major topics Dale and Bill discuss include:

  • The US Government / Electric Sector information sharing program around detection information and threat intel. Have they stopped or reduced the impact of attacks? What are the metrics they are using to determine if these resources are worth it?
  • How is the industry and BHE positioned to recovery from a major outage due to a cyber attack? The mutual assistance agreements in the electric sector … the transformer and critical sparing programs. BHE has drills that take away technology and see if they can still deliver power.
  • Who will pay for all this cyber risk reduction? Will there be rate increases due to these efforts? Does customer demand for climate change actions or security actions drive investment? Be required for investment? What does he think of the FERC incentives to get utilities to invest in security?
  • Is the single point person representing the electric sector, now Bill, by design and a good idea?

View Details

Tom VanNorman and Don Weber join Dale to describe the ICS Capture The Flag competition they will be running at S4x23, Feb 13 - 16 in Miami South Beach.

S4x23 web site

View Details

Donna Cusimano, Kim Legelis, and Saltanat Mashirov join Dale Peterson to talk about the Women In ICS Security Program at S4x23, Feb 13-16 in Miami South Beach. (see s4xevents.com/women).

These are three of a team of volunteers that have put together important career, education, and networking opportunities for the 100 free Women in ICS Security ticket holders and another ~150 women who will attend on a paid ticket. Really impressed and looking forward to seeing what this will accomplish.

View Details

Ralph Langner joins Dale on the Unsolicited Response Show to discuss Asset Management. They begin with the need for more exploration in OT, and more failures. After that they tackle:

  • Why Ralph decided to shift his company and focus from consulting / speaking to product

  • Is his OT Base, and asset management, a security product?

  • What are the elements of asset management? Do they all belong in one product?

  • OT, asset management and other, with ServiceNow and other enterprise solutions dealing with ticketing and human process management (this was Dale's favorite part of the show)

  • Power BI integration, dashboards what are they good for?

  • Other asset management integrations including OT detection solutions

As with any conversation with Ralph (and Dale) there are plenty of analysis and opinions that may be out of the mainstream.

Enjoy

Links

  • Langner's OT Base

  • Ralph's TED Talk on Stuxnet

  • Ralph's S4x12 Stuxnet Deep Dive

  • Robust Control System Networks

  • To Kill A Centrifuge

  • Art Manion, Dale and Ralph on Automating Patch Analysis

  • Dale's ICS-Patch Decision Tree (What to patch when in ICS)

View Details

Dino Busalachi of Velta Technology talks to Dale about a 2021 security patch to DCOM that broke a number of ICS systems including Rockwell Automation and Siemens. Microsoft had a registry setting that disabled the patch and the incompatibility problem, but this ability to disable the patch goes away on 14 March 2023.

Of course this topic leads us down the patching in ICS rabbit hole, hopefully with some informed and helpful information. 

View Details

On the latest #unsolicitedresponse show I talk with Jim Hempstead, Managing Director of Moody's Global Project & Infrastructure Finance Group with Moody's Investor Services, about OT Cyber Risk and how this impacts Credit Ratings. 

  • What Moody's does and what became of the cyber risk effort at Moody's owned Visible Risk

  • Moody's analysis of cyber insurance market including some cyber loss ratio numbers

  • Why Moody's believes USG disclosure and regulations are "Credit Positive"

  • Why Moody's has electric, gas and water utilities as "very high risk" in their heat map (despite minimal loss data)

And more. Several times in the show Dale asks Jim to explain some terms.

View Details

Dale Peterson gives his thoughts on the top 3 ICS security stories in Sept 2022, and he gives his wins, fails, and predictions for the month.

View Details

On this episode of the Unsolicited Response show, Dale Peterson is joined by Kevin Morley of the American Water Works Association and Joel Cox of West Yost Associates to talk about ICS security and the Water Sector.

  • what makes the water sector unique?

  • does this uniqueness lead to early and better use of the cloud for operations?

  • how did the community deal with Oldsmar?

  • why in the world would the water sector want to follow the NERC CIP model?

View Details

Dale Peterson shares his thoughts on SBOMS in OT in three main areas:

1) The S4 SBOM Challenge ... it's three goals and what we hope to learn from it.

2) Near term, now and for the next 2 years, wins for asset owners and SBOMs.

3) What will determine the winners in the SBOM marketplace, early analysis. 

Links:

S4x23 Tickets

S4x23 Hotel Info

SBOM Challenge

Dale's SBOM Content Page

View Details

The tables were turned as David Whitehead of SEL interviewed Dale Peterson on Dave's Schweitzer Drive show.

  • How Dale got into cybersecurity and the ICS security world

  • How has the threat and security posture changed in the last 10 or 20 securities

  • Dale's view on the core problem that is not being addressed and the wasted resources being applied to good security practice rather than risk

  • What areas of ICS security research Dale is most excited about

  • And a bit about S4

Links:

S4x23 Website

Schweitzer Drive Podcast

View Details

In this solosode, Dale Peterson gives his thoughts on three stories from August as well as a win and fail for the month. Stories this month:

  1. South Staffs water hack and opportunity for water sector
  2. Lloyds market bulletin overreaction vis-a-vis cyber war exclusions
  3. QNX forensics tool

View Details

Freight and passenger rail is another industry sector that relies on ICS for safety and services. It has its own language, consequences and standards. 

In this episode, Dale Peterson speaks with Miki Shifman of Cylus. Most of the episode digs into how rail systems work and the key areas to secure. They cover the TS-50701 standard and TSA's regulations in the US, among other things.

The episode concludes with a discussion of the Cylus OT Detection product designed for rail. The big question is a sector specific focus a big enough moat to keep out the big 3 OT detection vendors.

View Details

Dale Peterson talks with Mikko Hypponen about his new book: If It's Smart, It's Vulnerable.

As with all books, Dale asks who Mikko wrote the book for, who is the intended reader. Then they dig into some of the interesting parts for the security professional including:

  • What security tasks should we expect users to do (and why security training fails)
  • Whose responsible for IoT/IIoT cybersecurity? How are we going to succeed in security IoT, and what regulation might work?
  • Hypponen's Law: If It's Smart, It's Vulnerable
  • Cyber Deterrence
  • Why have their been so few cyber attacks on critical infrastructure?

and more.

Links

  • If It's Smart, It's Vulnerable book
  • S4x23 Call For Presentations

View Details

Unsolicited Response Month In Review show for June 2022. This is a replay of the live episode.

This month's stories:

  1. Dragos (Rob Lee/Bloomberg and Dragos OT-CERT)
  2. OT:ICEFALL w/ Daniel Dos Santos
  3. Dept of Energy's Cyber-Informed Engineering Strategy Document

Plus my win, fail & prediction for the month

Links:

  • S4x23 Call For Presentations
  • Bloomberg Article on Rob Lee
  • Rob Lee's Response to Bloomberg Article
  • OT:ICEFALL
  • Eric Byres' Comments on OT:ICEFALL
  • Dept of Energy CIE Strategy Document
  • Demystifying The Myth of the 85% paper
  • Google Project Zero Article
  • Dick Brooks / REA Patent

View Details

Dale Peterson interviewed Richard Seiersen, author of new book The Metrics Manifesto: Confronting Security With Data.

  • For security controls - what would I see that would show me it is working? How do I measure the effectiveness and efficiency of my security controls?
  • Why is so much of the book code, and can the book be valuable if you don't go through the code?
  • A lot of time spent on categories of metrics: burndown and survival, arrival and escapes, and wait time
  • Most of the examples in the book are vuln prevention and remediation ... how will the statistics deal with increases due to SBOMs? ... how to address vulnerabilities with very different related risk?
  • How to address the CISO wanting a single dashboard with OT and IT metrics with very different risk related to those metrics?
  • The concept of value of / return on control and how some CISOs are dealing with cyber risk
  • Using SME beliefs as data
  • and a lot more

Links

  • The Metrics Manifesto
  • The book's site with code and other info
  • Richard Seiersen's S4x18 video: How To Measure Anything In Cybersecurity Risk

View Details

Phil Venables joins Dale to discuss OT's use, today and in the future, of cloud and edge services. They focus on reliability, security and use cases. The end of the episode focuses on how leadership views security. Phil writes some of the most interesting articles on security at philvenables.com.

Check out the links below for some of Dale's recent favorites.

Defense in Depth

Resilience is about Capabilities, Not Plans

If Accounting were like Cybersecurity

Organizational Politics

Also check out the S4x23 CFP

View Details

Dale's weekly article originally published on 21 June 2022.

View Details

The Debate Question: Cyber Insurance Will Play A Major Role In OT Cyber Risk Management In The Next 3 To 5 Years Debating The Pro Case: Monica Tigleanu of MunichRe Speciality Insurance

Debating The Con Case: David White of Axio

(Note - The debaters were charged with making the most compelling case for their position. In some cases this doesn't represent their views).

Links

S4x23 Call For Presenations

View Details

Dale talks with Jason Christopher, a SANS Certified Instructor, who along with Dean Parsons created the new course SANS ICS418: ICS Security Essentials For Managers. They cover a lot of ground including:

  • What manager this course was designed for?
  • Why does a course for managers need a VM and course labs
  • The significant portion of the course addressing metrics. Why, what kind, for whom?
  • Does it address consequence reduction, working with engineers
  • What sort of team building and management advice is included
  • How is the course given? Live? Online?

Links

ICS418 Course Info

View Details

This is a solosode with Dale covering the two top stories from the month plus a win, fail and prediction.

Links

  • Schneider Electric SAAS on Azure for DERMS
  • Emerson ZEDI for water press release.
  • Dept of Transportion document on proposed fine for Colonial Pipeline.
  • ICS version of Backdoors & Breaches card deck.

View Details

This is the audio from my interview with Dave Lewis, a Global Advisory CISO at Cisco, on the S4x22 Main Stage.

Dave has experience securing both IT and OT (he worked for electric utilities in Canada). Even more interesting is he talks every week with a wide variety of CISO's. 

It's a wide ranging discussion that hits a lot of different areas on how to work and communicate best with CISO's and executive management on ICS security and cyber risk.

View Details

My weekly article. Originally published on 24 May 2022.

View Details

Zach Tudor of INL and Megan Samford of Schneider Electric join Dale Peterson on stage to close out S4x22. They discuss:

  • What the ICS security community isn't talking about that we need to pay more attention to.
  • OT cyber workforce issues.
  • What should we draw from the OT malware that came out in early 2022 and the response?
  • The SBOM market.
  • And more

View Details

My weekly article, originally published on 17 May 2022.

View Details

Unsolicited Response host Dale Peterson has been skeptical of the cost/benefit of accessing the electrical signals between Level 0 and Level 1 and creating a separate network to send that data to a platform for comparison to data at higher levels and analysis. This is a core part of SIGA's offering.

Dale and Ilan discuss what it actually does and doesn't do. What percentage of the Level 0 device communication needs to be monitored to get this information? The cost per sensor. And more. In the end they don't reach the same conclusion, but the decision points are clearer.

They finish discussing the back end processing for process variable anomaly detection, and how SIGA plans to compete with large vendors (GE, Siemens, ...), Azure and AWS, PI and specialized system vendors who have developed models.

Links

SIGA OT Security Site

Dale's Pivot To Process Variable Anomaly Detection article

View Details

Dale's weekly article points out the conflict in thinking and posture in miminizing and maximizing surface area. A minimization strategy can help security and hurt creativity. Seems about right with what we see.

View Details

Daniel Kapellmann Zafra of Mandiant joins Dale to talk about April's three big stories:

  1. INCONTOLLER / PIPEDREAM

  2. INDUSTROYER2

  3. JCDC ICS

Then they give wins, fails and predictions with a first appearance of conspiracy Dale.

View Details

Dale's weekly article also read on this podcast feed.

View Details

S4 Founder Dale Peterson interviews CISA Director Jen Easterly on the S4x22 Main Stage, 20 April 2022. Start: What are CISA's major goals in ICS Security for 2022/23 and how will they measure progress? Jen goes over people, process and partnerships goals, and highlights the hiring they are doing in the ICS security area. Also, Jen announces the new JCDC ICS.

17:38 When will the Shields Up come down? Since Shields Up is mostly basic cyber hygiene will there be a Shields Way Up?

23:30 Does Jen believe regulation is required to secure private industry owned critical infrastructure? And of course a lot of other things came up in the course of this half hour interview.

View Details

Some quick info on the release of S4x22 content and then my weekly article published on 24 April 2022.

Links:

S4x22 Video Release Schedule

View Details

David White, Co-Founder and CEO of Axio, joins Dale on the Unsolicited Response show to discuss cyber risk quantification. Axio makes the bold statement, "Quick time to value: quantify risk in hours not months; board reports readily available in minutes".

Dale digs in on their approach do to this, how they deal with the likelihood challenge, and how the process differs for OT as opposed to IT. The issue of deciding where to put the next dollar is a thread through the entire conversation.

They finish talking about how risk questionnaires and other methods will be used by the cyber insurance industry today and in the next 3 - 5 years.

View Details

Dale Peterson's guest on the Unsolicited Response show is Sergio Caltagirone, VP of Threat Intel at Dragos.  

  • What is good threat intel?
  • How does threat intel "reduce harm by reducing operational meantime to recovery"?
  • Should an asset owner care about the various threat actors named by Dragos, Mandiant and others?
  • Does it matter if it was Petrovite or Erythracite?
  • Why are the top recommendations in Dragos and other threat intel annual reports the typical, same as they always are, recommendations? What is the value if this is the case?
  • What does an asset owner need to have in place to make use of threat intel?
  • How does threat intel deal with the fact we are very bad at calculating or predicting likelihood?
  • Why did you feel the new Journal of Threat Intelligence and Incident Response was needed?

Links:

  • Dragos 2021 Year In Review
  • Webinar with Sergio on 2021 Year In Review
  • Sergio's Threat Intel Class at the Threat Intelligence Academy
  • S4x22, April 19-21 in Miami South Beach

View Details

My weekly article originally published on 15 March 2022.

View Details

Dan Geer and Olav Lysne join Dale Peterson to discuss Cyber Nationalism and how this will affect ICS asset owners and ICS vendors should and will deal with increased pressure by nation states to insert back doors and other weaknesses in ICS.

  • Why would a vendor even consider cooperating with a government asking for a special favor?
  • What are some of the different levels of cooperation?
  • The benefits of deniability, and what is the likely business impact if the vendor is caught.
  • How is a global vendor to deal with multiple knocks on the door from competing 'teams'. Does the vendor need to pick a side?
  • How should asset owners view a solution from a vendor coming from a different 'team'? Should they assume there is a way the team could compromise their system?

View Details

Dale Peterson's weekly article suggests we develop a list of actions to take when the threat has a significant increase. He provides some examples of what should and should not be on that list.

Subscribe to Dale's ICS Security Friday News & Notes

View Details

Chris Sistrunk joins Dale Peterson to discuss the month's big 3 stories.

  1. Urkraine from an ICS preparation standpoint.

  2. DHS's new Cyber Safety Review Board

  3. What to take from ICSsec vendor annual / semi-annual activity reports

Plus wins, fails and predictions.

View Details

My weekly article originally published on 2/22/22.

View Details

Two cyber insurance underwriters, Monica Tigleanu of Munich Re and Paul Gooch of Tokio Marine Kiln, join Dale Peterson on the Unsolicited Response show to talk cyber insurance.

Most of the episode discusses exclusions. Recently we had the high profile ruling that Merck's property policy in fact covered NotPetya losses because there was not a cyber exclusion statement.

The more interesting and important discussion is around the four recommended exclusions related to cyber war for cyber insurance policies that Lloyd's Market Association issued. These will likely by used by many in the Lloyd's syndicate and will affect other insurers. We look at the language around cyber operations, attribution, and other key terms.

Then the last part of the podcast talks about how insurers will be looking to set cyber insurance rates. How do they determine the cyber security posture of a potential insured.

It's an area that cybersecurity pro's in OT, and IT, need to understand better if they are part of cyber risk discussions.

Links

Merck's NotPetya Insurance Claim

Lloyd's Market Association Cyber War Exclusions

Dale's ICS Security: Friday News & Notes

View Details

My weekly article suggests that Level 0 / 1 monitoring and detection vendors should pivot to process variable anomaly detection.

Subscribe to my ICS Security - Friday News & Notes

View Details

Tom Alrich dives deep on the items he works and writes about. For a long time it was NERC CIP, and he recently added SBOMs to his repertoire. We go deep and I think the business model portion may be the best and most accessible part of the episode.

1:21 The 2 main SBOM formats. There differences and what will win.

12:30 VEX ... identifying what vulnerabilities in the SBOM are exploitable

24:00 What EO 14028 will require the USG to do with SBOMs in August

34:00 Who and how SBOMs will be provided and used. Business models.

Links

Tom Alrich's Blog

Tom's Who Should Be Responsible article

Subscribe to Dale's ICS Security - Friday News & Notes

View Details

My article from 8 Feb 2022 looks at what the two most successful OT security product segments have in common.

View Details

Tom Pace, who co-founded Netrise.io with Michael Scott, joins Dale Peterson to discuss Firmware Security Testing. There is a lot of firmware in ICS -- PLC's and other controllers, instruments, network infrastructure, etc. They spend some time discussing the elements that are tested and then dive into how a product vendor and asset owner might use this type of testing. And the key question is whether there will be enduring and important product differentiation. Check out S4x21, April 19-21 in Miami South Beach

View Details

Dale's weekly article covers the importance of some serious security testing of four popular OPC UA stacks that will take place at Pwn2Own Miami at S4x22.

The last Pwn2Own Miami awarded $280K for 0days in ICS targets.

View Details

We've been busy with the date change for S4x22, so here is a great replay of the S4x20 closing panel. Ralph and Zach have a ton of experience and make it a lot of fun.

View Details

Dale's weekly article dives into the Merck / Ace American case on NotPetya damages covereage.

Check out S4x22, April 19-21 in Miami South Beach

View Details

With the recent cyber activities and near hostilities in Ukraine I thought it would be a good time to replay my S4x20 Main Stage interview with Andy Greenberg, author of Sandworm: A New Era of Cyberwar and the Hunt for the Kremin's Most Dangerous Hackers.

Check Out S4x22: April 19-21 in Miami South Beach

View Details

Dale's weekly article looks at a new feature in Industrial Defender that measures risk per endpoint. Right direction, and the calculation needs to be more than a cyber hygiene measure.

Subscribe to Dale's ICS Security - Friday News & Notes

View Details

Industrial Cybersecurity, listed as 2nd Edition but actually a completely new Volume 2 is 1027 pages on Security Monitoring, Threat Hunting and Security Assessments and Intel. In this episode, Dale Peterson talks with its author Pascal Ackerman.

Links

Industrial Cybersecurity Volume 1

Industrial Cybersecurity Volume 2

View Details

Dale's weekly article looks back at the dichotomy of must never go down and don't touch it or it might go down. And how a reduction of fragility can be a good metric of your next cyber risk reduction expenditure in ICS.

View Details

The first live episode of the year covered the top three things Dale Peterson will be watching in 2022. Not predictions. More areas  that could go in many different directions. The three are:

  • CISA Activities and Metrics

  • SW/FW/SBOM Product & Service Business Models

  • Cyber Insurance

The episode included two guests who    talked about what they will be watching in 2022.

View Details

The Year Of descriptors are done retrospectively and looking forward. This episode looks at three ideas of what 2021 was the year of, and six ideas of what 2022 might be the year of. Related to OT and ICS Security, of course.

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

The final podcast episode of 2021 includes two articles that summarize the year. The first is on Perspective and the second is Progress.

Enjoy the holidays and thanks for your support of the show.

View Details

At the end of the ICS Security Month In Reviews episodes my guest and I give a win, fail and prediction. In this episode we replay those predictions and assess if we were right, wrong or the answer is still pending.

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

Dale Peterson's articles from Dec 7th and 14th.

  • Failing Business (Home) Continuity Plans

  • VC's, OT Security and Criticality

View Details

Dale Peterson joined Clint Bodungen and Pascal Ackerman on the OT Exposed - Raw show on YouTube. They broadcast this live on Friday afternoons, and it has the Friday afternoon vibe.

The first ~12 minutes are a bit on Dale's entry into the field and S4. Then they discuss maturity models, what to do when, and future technologies that will make a difference in the next 2 - 5 years.

View Details

Patrick Miller of Ampere joins Dale to discuss the months top 3 stories plus give their wins, fails and predictions. Stories:

  1. The water sector proposing a NERC/FERC CIP approach to cybersecurity regulation.

  2. GridEx VI

  3. INL adding another large engineering firm to their CCE program.

View Details

My market update identifies the biggest challenge for the Big 3 pure plays, the enterprise acquirers, and the niche pure plays in the OT Visibility & Detection Market.

View Details

This is from back when S4 was in a case study room that sat 60 and everyone could see and talk to everyone. Michael Toecker took the pro, Billy Rios the con. They had five minutes each and then you'll hear from many of the attendees who are the pioneers in ICSsec.

And in some quarters this debate still rages on.

View Details

This is from a two-part article originally published on Nov 9th and Nov 16th. It addresses the first six levels. 

Many, if not most, asset owners bypass at least four of the first six levels.

View Details

A recording of Dale Peterson's 30-minute Keynote at the Fortinet OT Symposium - Manufacturing Day.

View Details

Clay Carter, VP and Head of Product Security at Xylem, joins Dale Peterson to discuss the top 3 stories of the month and give their win, fail and prediction. The stories:

  • what did CISA's Water & Wastewater Alert mean to those sectors and a broader discussion on what would be helpful to those sectors.
  • Drago's raising $200M at a post money valuation of $1.7B.
  • Shodan Trends and how it could be used by asset owners and potentially .gov.

View Details

This article was originally published on the Tripwire Guest Author page. It highlights an early fail of mine and what I learned.

View Details

Peter Lund of Industrial Defender joins Dale to discuss SOAR in ICS.

  • Examples of early big wins for SOAR in ICS
  • Can you mix and match your SIEM and SOAR from different vendors?
  • Partial v Full Automation ... will there always be a person in the loop? - Does SOAR need to be customized for OT to be of real use in OT?

They finish the conversation with a bit on Industrial Defender's recently announced OT Machine Learning Language.

Check Out The S4x22 Agenda

View Details

My weekly article looks at the work and risk related to cyber maintenance of the ICS edge devices (when they get the needed DPI)

Check out the S4x22 Agenda

View Details

  • Susan Peterson Sturm and Dale Peterson talked about the future at Cognite's Ignite event. They discussed:
  • what changes can we expect when architectures base on the Purdue mode are dying
  • trust and restricted capabilities between service providers and assets owners
  • how data ops coming online now can help secure OT and leverage IT / OT convergence
  • cultural convergence - the promise of process variable anomaly detection

Check Out S4x22

View Details

Dale's weekly article published on 19 October 2021.

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

This episode dives deep into the risk score methodology of Radiflow's Ciara product. It attempts to use interview, asset inventory, and simulation to identify a risk score for a zone or site. It also then uses simulation to determine what security controls would most improve the risk score / reduce risk. Obviously this is a detailed talk on a specific vendor approach, so if that sort of thing bothers you this episode might not be for you.   We also talk about whether the visibility / detection product segment will be separate from the OT cyber risk product, and we end with a discussion of how a company the size of Radiflow competes with the Claroty/Dragos/Nozomi of the world that have raised $100M+.

View Details

My weekly article. The cybersecurity team needs to be careful about overselling the supply chain cybersecurity risk in an environment where real, large supply chain disruptions are occurring. 

My article originally published on 12 October 2021.

View Details

Joel Langill joins Dale in this Live episode. The stories:

  • CISA's Performance Goals and Objectives for Critical Infrastructure ICS (and a bit on TSA's 2nd Security Directive)

  • Moody's moving from Visible Risk to Bitsight for Cyber Security Ratings, and the difficulty to create and possible use of Cyber Security Ratings

  • Who performs what tasks in "OT"

Plus Wins, Fails and Predictions.

Links:

S4x22: https://s4xevents.com

Joel's Training: https://icscsi.org

View Details

In my weekly article published on 5 Oct 2021, I muse on how hard it is to discuss the zero trust concept in OT when there seems to be no effort to address the Total Trust or Trust All nature of PLC's, Controllers and other Level 1 devices.

View Details

Mark Hyman, a recruiter with the Verge Management Group who focuses on OT / ICS Security candidates, joined Dale Peterson on the Unsolicited Response Show to answer listeners questions on starting and growing an ICS Security Career.

There were three main areas of questioning:

1) Getting Into The ICS Security Field

2) Career Growth For An Experienced ICS Security Professional

3) Working With Recruiters

View Details

Prior to 2021 there was a substantial amount of ICS security standards and guidelines. The Biden administration has tripled down on this. To what effect?

View Details

And Maybe Fewer OT Security Professionals My weekly article published on 21 Sept 2021.

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

This episode has two announcements:

  1. Dale will begin market coverage and analyis of the OT SBOM market. He describes the market, the players and his plans.
  2. Wednesday of S4x22 will be Women In ICS Security Wednesday. Dale describes the events that day, the free ticket for that day, and suggestions for vendors who want to support the effort.

Subscribe to ICS Security: Friday News & Notes

View Details

Dale Peterson's weekly article published on 14 Sep 2021.

Sign Up To Dale's ICS Security - Friday News and Notes

View Details

In this episode Dale describes in 22 minutes what he likes and doesn't like about the new, Version 3 of API 1164 Pipeline Control Systems Security Standard. And more importantly whether you should spend $200 to buy a copy.

Subscribe to Dale's ICS Security - Friday News & Notes

View Details

In his weekly article, Dale discusses the increase in claims, rates and a silly exclusion attempt by his own carrier to deal with this.

It's too early to count cyber insurance as a risk reduction failure, and the insurance industry has found ways to deal with similar new product challenges.

View Details

Matt Wyckhouse, CEO and Founder of Finite State, joined Dale Peterson to discuss the top three stories of the month and give a win, fail and prediction.

The first 6:30 Dale announces tickets for S4x22 are on sale and some of the changes to the three stages along the No Limits theme.

6:31 Topic 1 - QNX and Blackberry Vulnerabilities … their impact on OT and IIoT and what an asset owner should do about them.

27:00 Topic 2:  Cyberspace Solarium Annual Report talking about progress to meeting objectives over the last year, https://www.solarium.gov/public-communications/2021-annual-report-on-implementation

38:05 Topic 3 - Sinclair's poll on asset owner's view of IEC 62443 Security Levels, https://otcybersecurity.blog/2021/08/19/results-from-the-poll/

44:21 Wins, Fails and Predictions

Other Links

  • S4x22 Tickets https://universe.com/s4x22

  • Earlier podcast episode with Matt Wyckhouse https://dale-peterson.com/2020/06/16/podcast-matt-wyckhouse-of-finitestate/ 

  • Finite State site https://finitestate.io 

View Details

My article orginally published on 31 August 2021.

If convergence, once started, is a powerful force in one direction, then why wouldn’t most of the functionality of the OT visibility/detection management platforms be converged into their enterprise equivalents, such as Splunk or ServiceNow.

S4x22 Tickets Go On Sale Sep 1 at Midnight EDT

View Details

Dale interviewed Edgard Capdevielle, CEO of Nozomi Networks, on how he sees the OT Visibility and Detection market and what Nozomi plans on doing with the $100M raised. The discussion includes:

  • Why Nozomi chose another funding round rather than getting acquired?
  • How Edgard believes the OT security market will segment very differently than the IT security market did?
  • What Nozomi meant in describing the round as pre-IPO. Will they IPO in the next two years?
  • What will Nozomi do with the $100M raised?
  • Looking back over the last five years, what was a tremendous surprise on the upside and what was something you thought would happen but didn’t?
  • Market timing being the most important factor in a product’s success.
  • Actively searching for and planning for convergence, and how convergence is a one-way street.
  • What will the market look like in 3 years with percentages for SaaS, MSSP and on-prem for this product category?
  • Does Edgard believe a channel can sell and support a product in this category in 2021? (He said yes and 80% of their business is run through channels since 2020)
  • Does Edgard think the non-pure OT plays, like Forescout, Tenable, Cisco, etc., will be significant competitors in OT security?
  • Does convergence with Splunk, ServiceNow and others mean the OT security solutions like Nozomi will be of lesser value to an asset owner?
  • What is the rate and future for asset owner cloud adoption for OT.

Sign Up for Dale's ICS Security: Friday News & Notes

View Details

You Must Understand Your Organization's Risk Management Do you want support and funding for your ICS security initiatives? Then you need to understand what executives view as high, unacceptable consequences that believably could be caused by a cyber or cyber/physical incident. Go to executives claiming a calamity for something that is considered a non-desirable, but acceptable consequence and your credibility will be damaged.

Dale's article from 24 August 2021.

Subscribe to Dale's ICS Security: Friday News and Notes

View Details

Dave Whitehead, CEO of SEL, joins Dale on this episode. They discuss a wide variety of topics including: * Early memories of working with Ed Schweitzer as a young engineer, being a CEO with the legend still there, and what SEL when Ed Schweitzer decides to slow down. * SEL Security Products profitability today and in the future. * Dealing with customers who don't want to secure their systems. * SEL's high level of vertical integration including a new plant to manufacture PCB's and its impact on supply chain security. * Dave and Dale's initial meeting over a vulnerability disclosure and how SEL deals with vulnerabilities today (direct disclosure to customers, not via a CERT). * Are SEL customers updating their software/firmware when security issues are found? * How does SEL decide what older products to add security features, such as signed firmware verified on the device, to?

Links

SEL Security Solutions

Dave's Schweitzer Drive Podcast

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

Dale's weekly article published on 17 August 2021.

Subscribe to ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/

View Details

Dale Peterson's weekly article published on 10 May 2021 discusses what will be required to get the benefits from SBOM's potential. Some come with low effort, and some will require major effort, new vendors and new business models.

Tweet Me: @digitalbond

View Details

Eric Byres of aDolus joins Dale Peterson on the Unsolicited Response Show to discuss the Biden Administration's actions on improving ICS security.

The first half of the show discusses the National Security Memorandum on ICS Security issued on July 28th. What it means for asset owners sending monitored data to the USG, the impact of a set of goals and controls, and the urging of Congress to pass legislation to give the Executive Branch universal across critical infrastructure ICS regulatory authority.

Links

National Security Memorandum

Background Briefing on NSM

The second half focuses on Executive Order 14028 issued earlier in the year. aDolus has put out a very useful timeline that tracks all of the deliverables. Eric focuses on the supply chain measures and how this might impact asset owners and ICS vendors.

Links

aDolus EO 14028 Timeline

aDolus blog series on EO14028

Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/

View Details

A slow month for ICS security news and a shorter, 30-minute solo-sode. Dale covers the 3 top stories and gives his win and fail of the month.

View Details

Dale's weekly article originally published on 27 July 2021.

TweetMe: @digitalbond.com

Subscribe To Dale's ICS Security Friday News & Notes at https://friday.dale-peterson.com/signup

View Details

Claroty raised $140M in a Series D round and recently announced their Claroty Edge product. In this episode, Dale interviews Grant Geyer, Chief Product Officer at Claroty. Most of the time is spent discussing Claroty Edge, what it is and isn't. The last third of the show they discuss what Claroty will do with the recently raised money. Links: Claroty Edge: https://www.claroty.com/claroty-edge/

Claroty Press Release on Series D: https://www.claroty.com/resource/claroty-secures-140-million-financial-round-establishing-leadership-position-in-hyper-growth-industrial-cybersecurity-market/

Sign up for Dale's ICS Security: Friday News and Notes at https://friday.dale-peterson.com/signup/

View Details

It's summer, and I'm on vacation. So here is a light, breezy article to not take too seriously. Below is my non-scientific, highly US influenced, filter bubble warning, rankings of the ICS buzzwords rated by popularity and impact. Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/

View Details

This is another episode with the founders of great ICS companies. Dr. J. Patrick Kennedy founded OSIsoft in 1980 and grew it to dominate the historian / data broker segment of the ICS market. OSIsoft was sold in 2021 to AVEVA for $5B. In this show we talk about:

  • 1:55 The starting and first decade of OSIsoft
  • 18:24 OSIsoft's motivation to focus on security before most other companies
  • 35:20 The acquisition decision and future

Subscribe to Dale's ICS Security - Friday News & Notes at https://friday/dale-peterson.com/signup/

View Details

Dale's weekly article from 13 July 2021 covers the ICSsec communities love to argue over broad terms and when it helps and hinders communication.

Subscribe to Dale's ICS Security - Friday News & Notes email at https://friday.dale-peterson.com/signup/

View Details

A recent article by Jay Healey and Robert Jervis, The Escalation Inversion and Other Oddities of Situational Cyber Stability, breaks down four mechanisms in which cyber activities could be used and result in a stabilizing or destablizing.

Dale talks with Jay about the article, escalation due to cyber, and the current state and future of cyber norms.

Subscribe to Dale's ICS Security Friday News & Notes email at https://friday.dale-peterson.com/signup/ 

View Details

Now that we are starting to have secure ICS protocol options and deployments, its time to get serious about key management. The de facto use of self-signed certificates only provide illusory security. Key management in ICS can be simple and the community should start with simple.

Subscribe to Dale's ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup/

View Details

Marc Ayala of 1898 & Co. joins Dale to discuss the month's top stories in ICS security and give their wins, fails and predictions. 

Subscribe to Dale's ICS Security: Friday News & Notes email at https://friday.dale-peterson.com/signup/

View Details

Alternate Title: Will We Require A Few OT Security Controls And Claim Victory? My weekly article published on 29 June 2021.

Signup for my ICS Security: Friday News and Notes email

View Details

The tables were turned when Jannis Stemmann and Simeon Mussler of Bosch CyberCompare interviewed me for a long form German interview series. They graciously allowed me to record the audio as well for this show.

There is a short discussion on the S4x22 Call For Presentations and the Basic Sponsor application at the start. The interview begins at 4:20.

Subscribe to my ICS Security: Friday News & Notes.

View Details

Dale's weekly article covers Claroty's $140M D Round and what it means for the detection space.

Subscribe To Dale's ICS Security: Friday News And Notes.

View Details

Dale interviews the two project leaders of a global community effort to create a Top 20 Secure PLC Coding Practices. We cover:

  • who it's for
  • examples of types/categories of the practices
  • some of the ways it can be used
  • what following the practices will and will not accomplish
  • how you can help make a difference

The document and supporting information is available at https://plc-security.com and the twitter is @secureplc.

Subscribe to my ICS Security: Friday News & Notes at https://friday.dale-peterson.com/signup

View Details

My article from 15 June 2021. 

It began with Jake Brodsky's S4x20 session on tips and tricks he had learned in his long career with a water utility to improve the resiliency, maintenance and security of a PLC and the underlying physical process. Today, it results in the release of Version 1.0 of the Top 20 Secure PLC Coding Practices with one of the least restrictive licenses for use, distribution and modification you will ever see. We want this Top 20 list to be used. Listen for more ...

Subscribe to Dale's ICS Security: Friday News & Notes

View Details

You know IT / OT integration is getting serious when the popular IT apps and services add OT extensions. The latest is ServiceNow's new OT Management Product.

James Destro of ServiceNow joins Dale Peterson on the Unsolicited Response show to talk about two main things.

1) How does OT Management get the OT asset inventory information? (and what is the single source of truth for OT asset inventory)

2) Once the OT asset inventory is in ServiceNow what types of workflows are envisioned that would be a big benefit to the asset owner.

Links:

Operational Technology Management 1-pager: https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/solution-brief/uc-operational-technology-management-manufacturing.pdf

Detailed documentation of the Operational Technology Classes: https://docs.servicenow.com/bundle/quebec-servicenow-platform/page/product/configuration-management/concept/cmdb-ci-class-models-operation-technology.html

Asset Inventory Integrations: https://store.servicenow.com/sn_appstore_store.do#!/store/integrations?freeTrial=service_graph_certified&offeredby=servicenow%253Bpartners

Signup For Dale's Friday News & Notes at https://friday.dale-peterson.com/signup

View Details

ICS-Patch leverages the CERT/CC SSVC Decision Tree approach for determining what patches are important and a patching cadence. One of the most important customizations is all of the factors can either be pulled from an asset inventory or a CVSS feed. This means the evaluation of 10's or 100's of thousand asset/patch pairs can be automated and an ASAP, Scheduled, Defer answer provided.

  • Links: ICS-Patch Paper: https://dale-peterson.com/wp-content/...
  • S4x19 How To Fix CVSS Session: https://youtu.be/-6cThOCm9co
  • S4x20 SSVC Session: https://youtu.be/AvKLZZh8NG4

Tweetme: @digitalbond

Subscribe to My Friday News & Notes: https://friday.dale-peterson.com/signup

View Details

This is Dale Peterson's weekly article originally published on 1 June 2021. Following the article Dale describes what we are looking for in S4 sessions and provides tips on what to do and not to do to increase your chances of getting on the S4x22 Stage.

S4x22 Call For Presentations: s4xevents.com/cfp

Subscribe to Dale's Friday News & Notes friday.dale-peterson.com/signup

View Details

Rob Lee of Dragos joins Dale Peterson on the Unsolicited Response show to discuss:

The Biden Administration efforts on OT Cybersecurity. What they are; the pro's and con's of these efforts; and where they might be successful.

Rob and Dale talk about their disagreement on where Detection products, and to a lesser extent threat intel, like Dragos and others offer should be considered in relation to other security controls and solutions.

The prospects for an entry level and mid level ICS Security Professional in 2021 and the upcoming years.

Subscribe to Dale's ICS Security Friday News and Note: https://friday.dale-peterson.com/signup

View Details

Dale's weekly article published on 25 May 2021 talks is triggered by a World Economic Forum report that on Resilience in the Oil and Gas sector.

Tweetme: @digitalbond

Sign Up For My Newsletter: https://friday.dale-peterson.com/signup

View Details

The episode begins with some announcements then

4:15 - Dale's Monologue/Rant on the Colonial Pipeline Incident. The increase it brings in attention, resources and expectations on a macro level. And the real action asset owners should be taking for this specific set of circumstances.

12:20 - Joel Langill joins the show and brings his experience on pipelines systems and their operations, plus a quick discussion on his new training.

30:45 - Rob Caldwell joins Joel and Dale. We talk about incident response in OT, and then answer questions from the LinkedIn and YouTube audience.

Links:

  • Joel's S4x19 Session Video on an ICS Investigation
  • Joel's ICSCSI training site
  • FireEye article on OT systems being added to malware kill lists

View Details

Six months since my Dec 2020 update ... the biggest change is major demand drivers; where is the Claroty and Nozomi funding round? and big cloud / enterprise products and services continue to introduce and up their offerings.

My weekly article published 18 May 2021.

Subscribe to my ICS Security: Friday News & Notes email: friday.dale-peterson.com/signup

View Details

Dale Peterson talks with Ulf Lindqvist and Laura Tinnel of SRI International about the recent LOGIIC report on the (in)security of safety instrumentations systems. Particularly the IMS/AMS components that configure and manage smart instruments.

They go over the three main findings, which are deadly serious and two have actionable mitigations.

They finish with a discussion of why there is not a hard recommendation to not allow the IMS/AMS to be on or accessible from the PCN.

Get the report at: https://www.logiic.org

See the S4x15 video on testing 114 DTM's at: https://youtu.be/qbno2woz7p4

Subscribe to Dale's ICS Security Friday News & Notes at: https://friday.dale-peterson.com/signup

View Details

The Colonial Pipeline incident highlights the need for an Enterprise Network Compromised Playbook. This and two other must haves are described in this article orginally published on 11 May 2021.

View Details

Patrick Miller joins Dale Peterson to discuss the months top three stories and then give their prediction, win and fail for the month. The stories

1) What to make of the US Government's efforts in ICS security in the first 100 days of the Biden administration.

2) The Pulse Secure VPN vulnerabilities and active exploitation, the impact on ICS asset owners, and what should be done.

3) ICS Security Training ... with Joel Langill back in the game Patrick and Dale look at the offerings.

TweetMe: @digitalbond

Get my Friday News & Notes: https://friday.dale-peterson.com/signup

View Details

Dale's article published on 4 May 2021. It shows how the Industrial Edge parallels Level 1 devices in capabilities using AWS as an example. And leaves a hanging question at the end. 

TweetMe: @digitalbond

Sign Up For My Friday Newsletter at https://friday.dale-peterson.com/signup

View Details

The ICS CYBERSEC 2021 event in Israel challenged speakers by limiting sessions to ten minutes. So Dale Peterson went with the theme and focused on how doing less in two important areas can actually help improve OT and ICS security.

1) Requiring less of engineers and operators (security is not everyone's responsibility)

2) Less cyber hygiene, more efficient risk reduction driven action

TweetMe: @digitalbond

Sign Up To My Friday Newsletter: https://friday.dale-peterson.com/signup

View Details

Hope, 1 Step Backwards, and Business Models Dale's article originally published on 27 April 2020

Subscribe to my Friday ICS Security News & Notes email

TweetMe: @digitalbond

View Details

Here is a debate between Eric Byres and me from S4x14, January 2014 that centers on the most important issue of Level 1 / PLC insecurity.

The question in the debate: Is Eric Byres a SCADA Apologist or a SCADA Realist?

You will see from the clips at the start there was disagreement on stage between the two friends.

It came down to then, and in 2021, on whether you believe the fact that PLC's are insecure by design / lack authentication / will do whatever they are told by legitimate user or attacker is a problem that needs to be prioritized and can be addressed in the short run.

I add about six minutes of 2021 comments at the start and then 6:20 the debate starts. At 30:50 you get questions from the audience, and it is fun to see all the ICS security pioneers in the smaller S4 room mixing it up.

Tweet Me! @digitalbond

My Weekly Newsletter: friday.dale-peterson.com/signup

View Details

Last week a Bloomberg article covered the Biden Administration's plan for a 100-day sprint to secure the power grid. I'll comment on the three focus areas the article lays out and more broadly on 100-day efforts.

This is my article originally published on 20 April 2021.

Tweet Me! @digitalbond

My Weekly Newsletter: friday.dale-peterson.com/signup

View Details

Rapid 7 recently made a "Strategic Investment" in SCADAfence's $12M B round and announced integration with the SCADAfence product. Dale Peterson interviews Justin Prince of Rapid 7 on their OT vision, what the integration will and won't do, where the Rapid 7 solution will sit, and future product directions. You can use your judgment on the status and completeness of the Rapid7 OT offerings.

Then at 37:05 Mark Hyman, an OT Security recruiter with Verge Management Group, joins Dale to answer some OT Security job hunting questions that came in after Dale's recent article on solving the OT Cybersecurity Staffing challenge.

Subscribe to my Friday ICS Security News & Notes email.

View Details

Short Review This is a book that an ICS security professional should give to friends and family to read so they know why they do what they do. Nicole guides the lay person through her compelling journey to understand the 0day market and its impact on the security of the systems we all rely on. The ICSsec pro will find it to be interesting except for the parts on ICS / critical infrastructure where it is a historical fiction ... historical incidents extrapolated to their most dire possible results rather than presented in their true context.

Detailed Review This was a very difficult book to review. I'm conflicted because the story is engaging and will keep the lay person turning the pages. The 0day market through line is well told, and the theme and major points Nicole is making are clear and compelling. And yet the parts I know in detail, ICS security and critical infrastructure, are portrayed in a light that is misleading, and even deliberately misleading. Misleading because a lay reader, including government policymakers, would almost certainly conclude the US critical infrastructure at this moment is compromised and a click or two away from the Russians, or other adversaries, causing a major catastrophe.

The Story ... The Positive

Imagine you are trying to tell your Mom or Dad, your Husband/Wife/Partner, your close friend about cybersecurity risk and how it could affect their lives, their communities and their country or region. This is hard. If you get into the technical details you will lose them. If you try to add too much nuance (HT: RLee) you will lose them. There needs to be a captivating story that makes the non-technical audience keep reading even if they don't care about the tech.

Nicole has succeeded in this area by inserting herself into the story. She is not the heroine of the story. Instead she is the observer, the Nick Carraway from The Great Gatsby, who is observing the players in the 0day world who are neither pure heroes nor pure villains. She begins her journey naively at S4x13 in Miami Beach and investigates for over seven years. Never actually reaching a point of knowing the market, and yet she describes what she knows and what cannot be known.

The best parts of the book are when Nicole is an active character, walking through the world and talking to the players. You feel her frustration, fear, intimidation, dread and disgust. You want her to come out the other side with some answers or even the answer. Although to her credit she does not force a solution. The ending is actually more muddled than the beginning. It makes for a less satisfying journey, and it is more accurate.

Nicole's journey is the highlight of the book. The reason why you can recommend it to your Mom or Dad. It would have been even better for the lay reader had she not tried to add in the history, the details. It does not go deep into the technical details like Kim Zetter's Countdown to Zero Day, which can be viewed as a positive or negative. My view is if you are not going to push for technical accuracy, then less is better. Still the book is an interesting read as my family members can attest.

The Theme

I'm sympathetic with the theme that the US Government's focus on offense, in this book primarily the accumulation of 0days, has made the world more dangerous. We see this offense focus clearly and unapologeticly stated by NSA and Cyber Command across multiple leaders. The dominance of offensive theory and capabilities makes for a less stable world.

My hope for any policy makers reading this book is they reject the current philosophy of "we can't defend so we need to be able to attack first and potentially cause even greater damage". Nicole repeatedly shows where US actions to buy 0days resulted in an unexpected and negative result.

What is less certain is whether the 0day market was inevitable whether the US participated, or even led, in the early years. Nicole bemoans that "the cyberarms market was an incoherent mess". There were buyers and sellers reaching agreement, so it was not an incoherent mess. It was unregulated and led to undesirable outcomes in the past and likely in the future. However unless there are agreed upon cyber norms, similar to biological and chemical weapons, this was and is to be expected.

The Technical ... The Negative

I'm only qualified to comment on the ICS / Critical Infrastructure part of the book. My guess though is if you are part of the Vulnerability Equities Process (VEP), 0day market, Ecko Party, ... the parts of the book that discuss your area will be frustrating. I say this because anyone reading the ICS / Critical Infrastructure part of the book would come out with an incorrect understanding of the current capability of Russia and other adversaries to cause a catastrophic event using existing deployed exploits of the US critical infrastructure.

There is not a lot of factual detail in the book, again good for the lay person reader, and therefore creating an errata list wouldn't be a compelling case. In the ICS area, there was one major mistake on page 297:

It was an act of unprecedented digital cruelty, but the Russians stopped just short of taking lives. Six hours later, they flipped the power back on in Ukraine, just long enough to send their neighbor, and Kyiv's backers in Washington a clear message: "We can torch you".

This clearly implies that the Russians stopped their attack and turned the power back on in Ukraine. What actually happened was the Ukrainians went out to the substations and manually brought them back on line and operated them manually for many months. The SCADA system was down for about a year. Nicole was right that a "clear message" was sent.

This error on its own in a 400-page book would not be an issue. The issue is that every incident is presented in its worst possible light. Often not wrong by a strict parsing of the text, but misleading. A great example is Wolf Creek Nuclear plant on page 397:

the Russians were inside our nuclear plants ... The code made clear that Russia's hackers had breached the most alarming target of all: Wolf Creek, the 1200 mega-watt nuclear power plant near Burlington, Kansas. This was no espionage attack. The Russians were mapping out the plant's networks for a future attack; they had already compromised the industrial engineers who maintain direct access to the reactor controls ... And the goal wasn't to stop the boom. It was to trigger one.

Although she doesn't state it, this quote and the surrounding text would almost certainly be read as the Russians were in the nuclear control and safety systems. The reality is that an adversary had breached the office network at the Wolf Creek Nuclear Power Plant, but they had not yet been able to breach the ICS that controlled the nuclear plant nor the safety systems that would need to fail to cause "the boom".

Nicole wrote on page 392, "The technical community will argue I have overgeneralized and oversimplified, and indeed, some of the issues and solutions are highly technical and better left to them." When I had my interview with Nicole and wrote this review, this sentence kept running through my mind. After much introspection and consideration of this point, I do believe that this Wolf Creek example and many others in the book would lead the lay person to an incorrect understanding of the current state.

How different would a reader's understanding be if the Wolf Creek incident would have said the Russians were just outside the control and safety systems. Yes, they were knocking on the doors where accounting, HR, and other office functions take place, but they had not yet gotten in to plant operations or safety systems.

Another specific example is related to the Bowman Avenue Sluice Gate. To her credit Nicole notes in an early section that this is not Arthur R. Bowman dam in Oregon. However in the concluding chapter she writes,

"We've caught Iranian hackers rifling through our dams."

An Internet connected, ~5 meter wide, ~1 meter high sluice gate that keeps a neighborhood from flooding a couple of times a year is not a national security event and not worth noting as a reason for perilous concern in the concluding chapter.

Beyond the ICS security specifics, and probably more important, are the unsubstantiated contentions that the Russians and adversaries are in our systems and a click away from causing a catastrophic event. There are many in the book's text and in the interviews.

  • Page 297 "By now, Russian hackers were so deeply embedded in the American grid and critical infrastructure, they were only one step from taking everything down".
  • Pivot Podcast "Russia's in our government networks, they are in the grid, they've gotten into the power plants, we've seen them break into nuclear plants" "the worst case scenario is just one more minute away is because no one has actually used these accesses to turn off the power yet; it's two clicks away."
  • Page 380: "Russia invisibly worked their way into an untold number of nuclear and power plants around the country."

There are many more examples where the book's clear message is that the adversaries, Russians, Chinese, North Koreans, Iranians are able to cause a critical infrastructure catastrophe. The facts don't indicate this. As noted in the summary, Nicole has taken historical incidents and either extrapolated them to their most hysterical or left out the a sentence or two that would give the reader the correct impression. This approach is consistent throughout the text.

If the goal is to grab the lay reader by the shoulders and shake them saying this is important, it is a successful deception. Still it is nearly as scary without the hyperbole.

Recommendations

The final chapter includes a set of recommendations that are underwhelming. Vendors need to have a security development lifecycle (SDL) and put out better systems. The end users, the people need to be more security aware. In this area I don't fault Nicole because there are not easy answers. It might have been better to leave this chapter off.

One interesting suggestion was on Page 398:

We could start by passing laws with real teeth that mandate, for instance, that critical infrastructure operators refrain from using old, unsupported software; that they conduct regular penetration tests, that they don't reuse manufacturers' passwords; that they turn on multifactor authentication; and that they airgap the most critical systems.

This is NERC CIP, sans the air gap, that has been around for a decade plus.

End If you've made it to the end of this book review, I hope you understand where the book succeeds and fails. Who it is written for, and who it is not written for. You and I are not the intended audience. The journey is compelling; the themes are on target; and maybe we should not get too upset that the specifics go beyond reality and are taken to their most extreme possibility.

Subscribe to my Friday ICS Security News & Notes email.

View Details

Dale Peterson interviews NY Times Reporter and author of the book This Is How They Tell Me The World Ends.

Some of the highlights include:

4:00 - the story of how Nicole began her 0day journey at a dinner at S4x13

19:42 - was the 0day market inevitable?

26:05 - how incentives have caused the problem and good help solve the problem

30:30 - the ICS / critical infrastructure attack detail in the book For regular followers, the last part is the most applicable.

This book was not written though for the ICS security pro, so some of the earlier discussion may help you understand who the intended reader is and the message Nicole is trying to get out there.

Subscribe to my Friday ICS Security News & Notes email.

View Details

Three answers.

1. Women

Women represent 51% of the population and 57% of the college graduates in the US. They comprise less than 10% of the OT Security workforce.

Solving the problem could be as simple as adding women to the OT Security workforce until they reach close to their population percentage. Encouraging and recruiting them into the field, and treating them fairly once they are in, is key. (Of course the OT Security community should be welcoming to all and any addition will help with the shortage in the workforce. Women are singled out in this answer due to the numerical impact.)

2. Stop Searching For Unicorns

The OT Security unicorn has domain specific engineering, automation, IT and IT security skills and experience. OT Security unicorns do exist. I’ve seen a few. They are rare, and not the answer to the OT security workforce problem. Instead find people with one of those skills, an ability to learn, good communication skills so they can supplement the knowledge areas they lack, and a desire to be in OT Security.

3. Hire OT Security Professionals

Asset owners' OT Security programs fail when they try to force engineers and others in Operations to work on OT Security 10 or 20 percent of their time. Partially because they already have more than 100% allocated to existing job functions.

Asset owners' OT Security programs fail when they force an engineer and others in Operations to work primarily on OT Security when they don't want to. Engineers are fully capable of being OT Security pro's, if they want to. However, most would prefer to do the job they trained for and enjoy.

OT Security is a profession.

One last thought, this is not an OT v IT or OT is different than IT issue. There are many specializations under the big umbrella that is called IT. As Patrick Miller says, "it's all T". You need a workforce trained on the appropriate technology.

Subscribe to my Friday ICS Security News & Notes email.

View Details

Maggie Morganti joined Dale Peterson on the show to discuss how International Humanitarian Law (IHL), which almost all countries subscribe to, would treat cyber attacks on critical infrastructure.

  • The terms distinction and proportionality (the latter is very important and is on the proportion of civilian to military damage) and how they affect what is permissible under IHL
  • How sabotage like Stuxnet or Triton is treated by IHL, and the concept of behind enemy lines - Does IHL mean anything when the most capable players do not agree or exhibit restrictions?
  • And a lot more

This is a hard issue and important topic, and Maggie’s master’s thesis is the basis of the discussion.

Links Preparation and Persistence Paper 

Video of Dale's comparison of cyber conflict situation to pre World War I cult of the offensive 

View Details

Part 1: Awareness of Purdue Level 0 and 1 (In)Security

Part 2: Properly Prioritizing Level 0 and Level 1 Security

In this third and final article in my Level 0 / Level 1 security series the focus is on the appropriate security controls.

Sensors and Sensor Data The security concern with sensors is that the sensor data will be incorrect and lead to incorrect control decisions. Sensors fail for a variety of reasons unrelated to a cyber attack, so this is not a new issue. However, an attacker with engineering skills and automation skills is more likely to know what type of false data could lead to high consequence control decision errors. A simple example would be spoofing the data so the Operator and logic thinks everything is operating normally, when in fact the process is entering a bad state.

Bad sensor data could be injected at the sensor itself (Level 0), communication networks between sensor and PLC (Level 1), at the PLC, communications between the PLC and the Level 2 computers, or in the ICS applications at Level 2. As noted in Part 2, the exposure to a cyber attack is greatest where the device or network has an IP stack.

Ideally we would like to have authentication of the source and sensor data integrity along each step of this communication path, and hopefully we will eventually get to having this. In the meantime, the solution where the risk of false Level 0 sensor data is unacceptable is process variable anomaly detection (PVAD) on reported sensor data.

The best example to date of this is GE's Digital Ghost, originally shown at S4x19. GE had a digital twin of a GE turbine and the control system. After training the twin with data from operations, GE was able to identify when specific sensor data did not make sense based on the state of the process reported by other sensors. Digital Ghost then calculated what the nonsensical sensor value should be and sent that to the actual control system where it could be considered by the Operator or automatically corrected in the HMI and system.

Importantly this solution deals with bad sensor data regardless of the cause, sensor failure, cyber attack or other.

The GE example is in some ways the simplest one. GE makes the physical product, the control system, often deploys the solution, and has a somewhat standard deployment. It's why they had digital twins for these turbines before the term digital twin existed. The growing benefits of digital twins is leading to exponential growth in their deployments across vendors and integrators, and the ability for this data to be used for PVAD is another benefit.

The other method for detecting sensor data errors today is to have a separate Level 0 monitoring network and compare the sensor data reported up to Level 2 with the data received on the Level 0 monitoring network. Vendors such as SIGA OT Solutions, Cynalytica, Fortiphyd, Mission Secure and others are offering this. Importantly, some are also touting PVAD capabilities which obviates the need for this new monitoring.

The cost of deploying and monitoring a second network for something with the lowest exposure to cyber attackers is difficult to justify from an efficient risk reduction criterion. I have been interested in the possibility of monitoring only a small percentage, perhaps 5% or less, of the Level 0 sensors through a separate network. Could machine learning identify what 5% of the sensors could detect a Level 0 cyber attack? It likely wouldn't be as simple as selecting the most critical 5% of the sensors. I imagine it would be sensors distributed over the process and with certain correlation results related to high consequence events. This is a good research project.

As noted in Part 2, new sensors with an IP stack should have the same security controls as listed in the actuators below.

Actuators Actuators are the end point that demonstrates the insecure by design problem. They will do whatever they are told to do, within their operationally deployed capabilities, regardless of the source of the command.

There is no authentication of the source of the command. There is no authentication of the integrity of the command. This is what the security controls need to change.

(Remember from Part 2, adding security controls to new or legacy serial interfaced actuators is deferred, look at it again in 3 to 5 years.) These recommendations apply to new actuators with an IP stack and are the minimal set.

  1. Signed Firmware / Secure Boot - This is to prevent simple DoS / brick attacks with a corrupted firmware upload, as well as more sophisticated attacks that actually put attack code or hooks in the firmware. The beauty of this control is it requires no user action. (And no this would not have stopped the SolarWinds incident or anything else that has compromised the vendor's firmware creation and issuing process).
  2. An administrator role and login capability where over the network actuator administration is possible.
  3. Authentication of any control commands - Until recently this would have required a vendor to come up with a proprietary solution. Now there is CIP Secure, Modbus/TCP Security, and other ICS and IIoT protocol security. For better or worse, most of the security consists of wrapping the protocol in TLS. This does require some PKI / key management to be effective. At a minimum the vendors should start with something simple, and less than perfect, where part of the commissioning is to put an asset owner signed certificate on each actuator.

The wrap-it-in-TLS decision does add complexity to the Level 0 security problem. If Level 1 is doing anything more than forwarding packets, it will need to decrypt the wrapped packet, and then potentially encrypt it again to send on to Level 2 or other Level 1 devices.

Of course there are many more security controls that could be specified and could be helpful. Others who leap from insecure by design to secure by design lean heavily on the importance of security development lifecycle (SDL) requirements. The fuzz testing of the protocol stack's that began in the '00 decade helped a great deal with protocol stack robustness and will only help the vendor with the product lifecycle. This list of three security controls is the bare minimum in terms of addressing the insecure by design problem.

PLC's (and Other Level 1 Devices) That Communicate With Actuators New PLC's are Priority 1 in the Level 0 / Level 1 security decision tree for adding security. Upgrades to high and medium consequence legacy PLC's are Priorities 2 and 3. The security controls listed for actuators are required for PLC's as well. In addition, they should have security event logs and the ability to store and forward these event logs.

Nice to have, premium options for these devices include:

  • A deep packet inspection firewall to restrict access to the device from Levels 1 and 2. This is the Tofino, M-Guard, OTfuse or similar integrated into the Ethernet card or somewhere else on the PLC. The only thing stopping this option is the business case.
  • PLC endpoint protection - this is an area ripe for research. What is the equivalent of anti-virus for a Level 1 device. We have had proposed sessions for S4, that were pulled back, that would look at the logic / program upload for attack code before loading it.

Conclusions This three part article series can be summarized as follows:

  1. The ICS Security Community understands that Level 0 and almost all Level 1 devices lack authentication. Access sensor data can be modified, and control commands that reach the device will be accepted.
  2. The risk of the lack of authentication varies at Level 0 and Level 1 based on the exposure and capabilities of the device. While we would like to have cyber security throughout the entire ICS, it is important to prioritize efforts where we will achieve the most efficient risk reduction.
  3. Process variable anomaly detection (PVAD) is the most effective way in the short and medium term to detect and address bad sensor data.
  4. Authentication of the firmware, administrative actions, and control commands are the most important security controls to add to the Level 1 and Level 0 devices in the decision tree specified priority order.

Subscribe to my ICS Security: Friday News & Notes email.

View Details

Jason Christopher is the lead author of the new paper: Industrial Cyber Risk Management. Dale Peterson interviews Jason on this episode of the Unsolicited Response show. They discuss

  • How industrial cyber risk fits into the business risk management strategy
  • The proposed addition of resilience to the industrial cyber risk equation
  • How much an asset owner needs to know about threat to perform effective cyber risk management (and how often it changes)
  • When quantitative risk management will be feasible for industrial cyber risk
  • The paper's proposed double heat map.

Links Industrial Cyber Risk Management whitepaper discussed in this episode

Subscribe to my ICS Security: Friday News Notes email.

View Details

We have resolved the issue on whether the ICS security community knows that almost all Purdue Reference Model Level 0 and Level 1 devices, and the protocols that communicate with them, lack authentication. They know this. The next question is what to do about it from an OT / ICS risk management perspective. I'll break the answer into two parts. This article will cover efficient risk reduction prioritization, and next week's article will cover the recommended security controls.

In a perfect world with unlimited resources, all Level 0 and Level 1 devices would have a set of security controls. New devices would come with the security controls and deployed devices would be upgraded. Since resources are limited and ICS cybersecurity risk reduction options are plentiful, deciding the priority of risk reduction actions is important.

This is similar to evaluating the risk reduction provided in applying security patches in ICS. It is a good security practice to apply all security patches that mitigate vulnerabilities. However as shown in ICS-Patch: What To Patch When In ICS, there is a large variance in the risk reduction achieved in various asset / patch pairs. The small percentage of patches that result in significant risk reduction should be applied asap, and the large percentage of patches that result in almost no risk reduction should be deferred and applied primarily when needed to keep the product in a supported state.

Similar to ICS-Patch, a decision tree is a good way to look at the prioritization of securing Level 0 and Level 1 devices, see diagram below.

Exposure is the most important factor in determining ICS risk reduction. It was the first decision point in ICS-Patch, and it's the first decision point in determining the risk reduction achieved in securing Level 0 and Level 1 devices. How easy will it be for an attacker to access, and therefore be able to compromise, the device or the communication to and from the device?

Factor: Exposure... Level 0 or Level 1?

Securing Level 1 provides a leveraged security point with significantly more efficient risk reduction than securing Level 0. The PLC, RTU, Controller or other device at Level 1 typically communicates with many sensors and actuators. It can be a perimeter security device that stops or limits attacks from reaching the Level 0 device from untrusted networks.

Falsified or bad sensor data is often given as a reason to secure Level 0. Yes, a compromised Level 0 sensor could send back incorrect data that could lead to an incorrect and consequential control action or inaction. However, a compromised Level 1 device connected to that sensor could also provide falsified or bad sensor data for that sensor. The compromised Level 1 device could additionally falsify sensor data for all other sensors it is connected to, send rogue commands to all actuators it is connected to, and alter any of its process logic.

Prioritizing Level 1 security over Level 0 security is similar to prioritizing a firewall to limit enterprise and Internet communication from reaching the ICS over securing the Level 1 devices.

Factor: Exposure... Ethernet Port / IP Stack?

If a Level 0 or Level 1 device has an Ethernet port and an IP protocol stack, it is much more likely to be attacked and compromised through cyber means than if it does not.

There are two reasons for this. First, the IP stack makes it much easier to route attacks to the device. As we know the air gap is almost always a myth. IP based networks are connected to share information, and this provides a potential attack path to the device if it has an IP address. Second, most of the attack tools, as well as almost all of the attacks and attack attempts to date have tried to compromise ICS cyber assets via this interface.

Can a Level 0 or Level 1 device with an "analog" or "serial" interface be accessed? Yes. It could be reached from an IP network through a serial-to-ethernet gateway, and this gateway is a better, again from an efficient risk reduction standpoint, place to put cybersecurity. This is the location where you should apply your security controls, whether it be through an industrial security gateway or other means.

And yes, a serial Level 0 device can be accessed by physically connecting to the serial network. This often, but not always, requires close physical proximity to the device and physical attacks on the device or process are typically easier than cyber attacks with this access.

This will be a contentious point with some, and I'm not arguing against security in all devices. The point is we will achieve greater risk reduction by securing the devices in each level that have an IP address than securing those that do not have an IP address, and they should be prioritized.

Factor: New or Legacy

I used the Will Rogers quote "if you find yourself in a hole, stop digging" in a recent article on the legacy system problem. Any new devices with an IP address should have security. At Level 1 there are a small, but growing list of devices with the basic security functions that will be described in next week's article.

If the choices available for purchase lack security then you should either insure there is an acceptable upgrade path to add security or plan on a much shorter lifecycle than usual, such as 2 to 5 years rather than decades.

Which only leaves the question of what to do with legacy devices with an IP address.

Factor: Impact

Legacy Level 0 devices with an IP address fall into the defer category. Even looking 5 years out it is hard to find a case where an efficient risk reduction approach would lead to replacing or adding on security to these devices.

Legacy Level 1 devices with an IP address should be upgraded or replaced in the order of the impact of compromise of their availability and integrity. In general, Level 1 devices that are involved in control, changing the physical component, should be prioritized over Level 1 devices that are connected solely to sensors. There are a number of ways to detect bad sensor data. That said, there are examples where bad sensor data would be difficult to detect and would lead to high consequence actions, and this would lead to PLC's associated with these sensors being prioritized.

Level 0 and Level 1 Security's Position In An ICS Security Program The decision tree in this article prioritizes the order to add security in the Level 0 / Level 1 category to address the insecure by design problem. It does not describe when this issue should be addressed in relation to all of the other potential ICS cyber risk reduction activities. It is easy to identify activities that provide more and less risk reduction than addressing the Level 0 or Level 1 security issue. Some examples:

Greater Risk Reduction Than Addressing Level 0/1 Insecure By Design

  • Enterprise / ICS Security Perimeter
  • Two-factor authentication for remote access
  • Ability to recover minimum required ICS cyber assets
  • Large scale consequence reduction

Less Risk Reduction Than Addressing Level 0/1 Insecure By Design

  • Majority of security patching inside the ICS security perimeter (Defer category in ICS-Patch)
  • Individual Operator accounts in a 24/7 control room
  • ICS application security controls at Level 2.

Next Week: Appropriate Security Controls for Level 0 and Level 1

Subscribe to my ICS Security: Friday News & Notes email.

View Details

This is a slightly edited version of the LinkedIn Live and YouTube Live show Dale Peterson recorded on March 17th. Dale begans talking about the Level 0 issue and was joined partway into the conversation by Ron Fabela. They talk about the awareness of insecure by design that exists in almost all Level 0 devices, the risk related to this, how asset owners are and should be looking at this, and more.

Then the last ten minutes Dale talks about his two favorite Incident Response Tabletop Exercises and what you should expect when you do a TTX.

View Details

Solving a problem typically begins with awareness that there is a problem. Back at S4x12 a group of researchers under the Project Basecamp banner demonstrated that most PLC's (Purdue Level 1 devices) were both insecure by design and ridden with exploitable bugs, as well how an attacker could leverage these issues. Nine years later I believe the issue is known in the ICS security community, even if it is just beginning to be solved.

Similarly, ICSsec pioneer Joe Weiss has been on a content blitz the last three years pointing out that Purdue Level 0 devices, sensors and actuators, do not have any security. Primarily with the example that false process sensor data could be presented to the control system. He has asserted that the ICS security community does not know this, most recently in a post SANS ICS Security Summit article.

there appeared to be a general acceptance that Level 0,1 devices were uncompromised, authenticated, and correct. That is wrong Joe and I had a back and forth on LinkedIn on whether this misconception was present in the S4 audience, SANS ICS Security Summit audience, and ICS security community in general. My belief was lack of security at Levels 0 and 1 was common knowledge in the ICSsec community and the only disagreements are the prioritization of addressing this issue amongst the large number of issues and how it should be addressed. We tried to answer this disagreement with a poll.

The same poll in my Friday Newsletter had 147 responses with 98% answering False. It is likely that there is some overlap in the respondents to the two polls. 97% is clear evidence that the ICS security community understands there is not security at Level 0, and I'm certain they also know it is exceedingly rare at Level 1.

This does not mean there is no awareness problem. Security professionals coming in from the IT security world often do not know and are surprised to learn this. The bigger problem is when asset owner executives are unaware of this because it can lead to spending a lot of money and effort on good practice security controls that have little impact on risk. It is incumbent on Operations and OT Security to inform executives of risks and the best risk reduction options.

What I'm still uncertain of is how well known the insecure-by-design Level 0/1 problem is in the ICS involved engineering community. I'd like to believe that similar to the ICS security community this is common knowledge. I don't have an audience of engineers who are not involved in ICS security. Any readers with the right audience want to run a poll?

Next Week: The Solution To Level 0 / Level 1 Lack Of Security Problem

Subscribe to my ICS Security: Friday News & Notes email.

View Details

Cplane.ai and ExxonMobil recently completed a pilot project showing how orchestration could simplify the deployment of a complex, multi-vendor system. This was actually a test of both Orchestration and the Open Process Automation (OPA) Forum's work.

John Casey of Cplane.ai joined Dale Peterson on the show to explain exactly what the pilot project did and how orchestration could be useful in the Operation and Evolve phases of a ICS lifecycle. Orchestration is common in the enterprise, particularly in large telecom, and new to the ICS world.

John helps Dale grapple with the concept, and there is a bit at the end about the industrial edge.

Links * Dale's interview with Steve Bitar on OPA * Cplane.ai video on the pilot project * Cplane.ai white paper on the pilot project

View Details

If you find yourself in a hole, stop digging. Will Rogers The large amount of insecure legacy ICS and long ICS lifetimes mean we will need to live with this security risk for years / decades. We can argue about how long it should take to replace the deployed insecure-by-design ICS, but there is no disagreement that it is a huge problem. A big hole. Which is why it is so disappointing that we keep digging.

This was brought to mind again in a tweet from Joe Weiss's session at the SANS ICS Security Summit last week.

The key is that less sentence correctly pointing out that almost all systems deployed today add to the "legacy system" problem because they still have insecure-by-design PLC's / controllers and are using ICS protocols lacking authentication.

Back in 2013 in my S4 introduction (see video clip below), I bemoaned the fact we have been hearing it will take decades to address the legacy system security problem in ICS every year since I was first involved back in 2000. By 2013, we had made virtually no progress in dealing with insecure-by-design Level 1 devices or unauthenticated ICS protocols. We were still decades away from solving it, and the problem had gotten much larger with more "legacy systems" being installed over those 13 years.

The theme of S4x13 was NOW!, and the tag line was "If not us, who? If not now, when?"

https://youtu.be/bZLbm7J2E8o

It's now eight years after the NOW! themed S4x13 event, and we can look at what has occurred over those eight years optimistically or pessimistically.

The pessimist's side is easier. Over those eight years 99%+ of the ICS deployed have insecure-by-design PLC's/Level 1 devices and use unauthenticated ICS protocols. Access inside the perimeter = compromise only limited by the engineering and automation skills of the attacker, and the capabilities of the Level 0 connected devices. We have increased the 'legacy system' problem with eight years of ICS deployments. We are still digging that hole.

The optimist's side is some of the Level 1 device vendors and some of the ICS protocol groups have addressed the problem. There are now encrypted and authenticated versions of many ICS protocols. There are also now PLC's that have signed firmware, secure boot, support for secure ICS protocols, and authentication of operation and administrative functions.

Is it perfect? Of course it isn't. In some cases these PLC's carry with them a lot of legacy code. It's analogous to the Microsoft challenge after Bill Gates' Secure Computing memo. Yes, there can be a lot of improvement in the short run, and there is still a multi-year grind until that old legacy code is replaced.

It's The Asset Owners' Turn Some of the key vendors have invested in development to have, at a minimum, a non-insecure-by-design offering. And more are near release. Now it is the asset owners' turn. The asset owners have to show they want to move away from insecure-by-design systems and reduce the associated ICS cyber risk.

Is circa 2021 when we stop digging the hole? Stop increasing the "legacy system" problem?

It is too soon to tell, but early signs show very little uptake to the available security capabilities. Asset owners aren't asking for them, integrators are designing them in, and vendors aren't pushing them. Features such as signed firmware do not require asset owner action and will be a clear win, but the secure protocols and user / device authentication do. They add complexity to the project and ongoing operation. The features often make the product more expensive as well.

The answer is likely, if security is deployed at all, to be sector and asset owner size specific. There may be a sector, such as large petrochemical, that may adopt this move away from insecure-by-design while other sectors continue with the status quo. Even this limited progress would be a big step forward as we have seen other ICS security practices trickle down from more security conscious sectors to the less security conscious sectors.

If the asset owners don't purchase and deploy the more secure versions, then there is little impetus for a for-profit vendor to spend resources developing, marketing and supporting security features.

The other option would be for the regulators to step in and require ICS being sold into certain sectors have certain security features. This would be difficult to do well, and it's a whole other article.

View Details

Bryan Owen of OSIsoft joins Dale to discuss all that when on in February. Top stories include:

  • Attacks and Outages: Oldsmar, Solarwinds fallout, ERCOT/Texas and China's efforts on the Indian power sector

  • Ruben Santamarta's research on IoT Software Development Kits

  • What does GE backing out of the ICS security product market mean.

Plus wins, fails and predictions.

View Details

I recently stumbled upon a McKinsey article from October 2019 that more elegantly, in McKinsey speak, made the argument against "cyber hygiene" than I do.

View Details

This was a very revealing panel on how the VC world is viewing the ICS security space. Many strong statements and feelings about where we are and what the future will be. 

The VC's were Bob Ackerman of AllegisCyber and Sameer Reddy of Energy Impact Partners. Both funds are active in the ICS security space.

Links Hack The Capitol

AllegisCyber

Energy Impact Partners

View Details

Dale's weekly article published on 23 Feb 2022. He dives into why it is so difficult to value these companies, and the disconnect between any value investing analysis and the actual, what someone will pay, market valuation.

View Details

Total Power by Kyle Mills is a story about a successful cyber/physical attack on the US electric grid, the impact of a prolonged outage, and the effort to bring the power back and catch the bad guys. What impressed me most about the fun read is it pulled some key facts out of the mountain of grid-hacking FUD so that it was much more plausible than a typical work of fiction, and much reporting.

I couldn't get the author on, but I got another author in the genre and the person who recommended I read the book on the podcast, Bob Peterson aka my Dad. We talk about the plausibility, how authors do their research, how much detail to include in a work of fiction, the Mitch Rapp character created by Vince Flynn, and some other things in this short, fun episode.

Links - Total Power By Kyle Mills

  • The Syndicate's Church and Deniable Justice by R.D. Peterson

View Details

This week's Unsolicited Response Show focuses on the issue that women are vastly underrepresented in ICS security and what we need to do to change this both in numbers and career paths and prospects. Kelly Jackson Higgins joins me to co-host this episode, and we have great guests including:

  • Kristin Demoranville
  • MJ Emanuel
  • Najo Ifield
  • Najla Lindsey
  • Megan Samford

We've seen lots of progress and growth in the women in ICS community, and I actually could have had many more great guests on the episode. Still their is much to do to make the community more open and inclusive and supportive to those entering the field.

View Details

Chapter 2 of Nicole Perlroth's new book was a dinner at S4x13 that I hosted. This article is my recollection of that dinner.

View Details

The ICS security product vendors tend to focus on a product segment, firewall, data-diode, detection, ..., Bayshore Networks is unique in that they have the closest thing to a full line of ICS security products. This is being grown further with their recent acquisition of GE's OpShield technology.

Dale Peterson talks with CEO Kevin Senator about the strategy, individual product segments, and why GE and Bayshore did this detail. It is admittedly a bit commercial as Kevin touts the company, products and strategy. Dale asks some tough questions, and Kevin gives some candid answers.

View Details

Dale Peterson interviews authors Andrew Bochman and Sarah Freemen of Idaho National Laboratory (INL) about their just published book Countering Cyber Sabotage - Introducing Consequence-driven, Cyber-informed Engineering (CCE).

The CCE methodology has been discussed by the INL team for over two years to great interest in the ICS security community. Now there is a book that describes it in some of the detail the industry was craving.

Dale begins with a 3-minute review and then dives into the interview. They start their discussion with who the book was for, their hopes for readers who finish the book, the stats on CCE, CCE training and certification and more on the program INL is rolling out. Then the discussion shifts to a detailed Q&A on the four phases of CCE. If you have any interest in determining what should be done next in reducing ICS risk, then this is a must watch episode.

Get Countering Cyber Sabotage on Amazon

View Details

I missed recording my weekly article last week so this episode includes the articles from Jan 28th and Feb 4th.

Tweet Me! @digitalbond Friday Newsletter: https://mailchi.mp/f53b1c8c2da0/friday

View Details

One of my favorite interviews is with founders who have persevered to build companies over decades. This one is with Eddie Habibi, the founder of PAS. 

We go over his 27 year journey to uncover some of the lessons learned and how he sees the future of ICS security.

Links: PAS Web Site

Hexagon Acquisition Press Release

S4x21 Charity Water Campaign

S4x20 Video

The Detection Market

Ask A Question

View Details

The ZDI team brought Pwn2Own to ICS with Pwn2Own Miami at S4x20. They awarded almost $300K to researchers who were able to find and exploit 0day vulnerabilities in important ICS applications. Applications such as HMI and EWS from Rockwell Automation and Schneider Electric, OPC UA, TMW's DNP3 stack and more.

In this episode I talk with Brian Gorenc and Abdul-Aziz Hariri about the competition. Why they do it? What it achieves? And what happened?

0:00 My brief discussion on which patches matter and which don't

8:12 My interview with Brian and Abdul

47:47 ZDI's video wrap up of the event

Tweet Me! @digitalbond Friday Newsletter: https://mailchi.mp/f53b1c8c2da0/friday

View Details

A new technical paper forecasting vulnerabilities should help you answer this question.

View Details

Dale and Corey discuss the value of a normalized, taxonomized approach to SIEM, which Dr. Anton Chuvakin has famously claimed is doom to fail. Corey is sympathetic to this view and tries to explain it to Dale.

The alternative is gathering and creating a data lake with more log data and pcaps that can be used by threat hunters and customized rules.

The conversation continues with what types of integration would be helpful between the OT detection products and whatever is used for organization wide detection and response, the packet encryption challenge, and the preference to just buy a product.

You can submit your audio question on this episode or other OT and ICS Security topics to the show by going to dale-peterson.com and clicking on "Record Your Question".