The bulk of the discussion is on the need, implementation, and metrics related to CISA's ruthless prioritization of efforts and resources. What CISA and US critical infrastructure must do, and what they won't have the resources to do.
]]>The bulk of the discussion is on the need, implementation, and metrics related to CISA's ruthless prioritization of efforts and resources. What CISA and US critical infrastructure must do, and what they won't have the resources to do.
]]>In this 90 minute long conversation format, we will try to bring some enlightenment to this question with a specially curated group of 9 S4x25 attendees.
About The Long Conversation Format
Two people begin the discussion on stage. After 10 minutes a third person will tap one of the participants on the shoulder and replace them in the conversation. This continues for the 90 minutes. Participants are on stage for 20 minutes talking to two different people for 10 minutes each.
]]>In this 90 minute long conversation format, we will try to bring some enlightenment to this question with a specially curated group of 9 S4x25 attendees.
About The Long Conversation Format
Two people begin the discussion on stage. After 10 minutes a third person will tap one of the participants on the shoulder and replace them in the conversation. This continues for the 90 minutes. Participants are on stage for 20 minutes talking to two different people for 10 minutes each.
]]>Of course Dale and Joel jump around a bit on training, the workforce and other items. Take a listen.
]]>Of course Dale and Joel jump around a bit on training, the workforce and other items. Take a listen.
]]>The Biden administration is contending that vendors should be held liable for security deficiencies in their products.
Assuming this is turned into law and/or executive orders, what does it mean? What can we learn from other liability law to inform us what would be required for a vendor to be held liable for a security issue? How would the judgment / damages be determined.
Dale's note: We talk about the SEC charges against SolarWinds in this interview.
]]>The Biden administration is contending that vendors should be held liable for security deficiencies in their products.
Assuming this is turned into law and/or executive orders, what does it mean? What can we learn from other liability law to inform us what would be required for a vendor to be held liable for a security issue? How would the judgment / damages be determined.
Dale's note: We talk about the SEC charges against SolarWinds in this interview.
]]>The definition and scope of vulnerabilities. It's much more than coding errors that need patches.
Are ICS protocols lacking authentication "vulnerabilities"
The reality that most organizations have 100's of thousands of unpatched vulnerabilities. Some statistics and will this change.
Ways to prioritize what vulnerabilities you address.
The SSVC decision tree approach that was introduced at S4 as Never, Next, Now
Tooling … vulnerability management, software configuration, ticketing, remediation.
And much more.
Links:
Effective Vulnerability Management, https://www.amazon.com/Effective-Vulnerability-Management-Vulnerable-Ecosystem/dp/1394221207/
Dale's ICS-Patch Decision Tree, https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf
]]>
The definition and scope of vulnerabilities. It's much more than coding errors that need patches.
Are ICS protocols lacking authentication "vulnerabilities"
The reality that most organizations have 100's of thousands of unpatched vulnerabilities. Some statistics and will this change.
Ways to prioritize what vulnerabilities you address.
The SSVC decision tree approach that was introduced at S4 as Never, Next, Now
Tooling … vulnerability management, software configuration, ticketing, remediation.
And much more.
Links:
Effective Vulnerability Management, https://www.amazon.com/Effective-Vulnerability-Management-Vulnerable-Ecosystem/dp/1394221207/
Dale's ICS-Patch Decision Tree, https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf
]]>
Dale and Andrew discuss:
What is in and out of scope for the report.
The breakdown of the 68 incidents that occurred in 2023 by industry sector, cause, threat actor and more.
The impact reporting requirements may have on these numbers in the future.
What percentage of OT cyber incidents with physical consequences are made public.
Ransomware on IT causing physical consequences, exfil v. encryption, and what asset owners should do given this represents 80% of the known incidents in the report.
And more.
Links:
2024 Threat Report: https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/2024-threat-report-ot-cyberattacks-with-physical-consequences/
ICSSTRIVE: https://icsstrive.com
S4 Events YouTube Channel: https://youtube.com/s4events
Dale and Andrew discuss:
What is in and out of scope for the report.
The breakdown of the 68 incidents that occurred in 2023 by industry sector, cause, threat actor and more.
The impact reporting requirements may have on these numbers in the future.
What percentage of OT cyber incidents with physical consequences are made public.
Ransomware on IT causing physical consequences, exfil v. encryption, and what asset owners should do given this represents 80% of the known incidents in the report.
And more.
Links:
2024 Threat Report: https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/2024-threat-report-ot-cyberattacks-with-physical-consequences/
ICSSTRIVE: https://icsstrive.com
S4 Events YouTube Channel: https://youtube.com/s4events
In this episode Patrick and Dale discuss:
Why Patrick changed the company name and selected Talinn as the location for the new European office.
The major differences in approaches to OT cybersecurity and risk management between Europe and the US. (more than just regulatory differences)
What has the EU learned or improved on regulation from NERC CIP.
What is the current state of NERC CIP regulatory risk? Are the regulated entities understanding and meeting the standards' requirements?
The challenge of slow NERC CIP modifications, eg virtualization and cloud.
Bad standard & good regulator v. good standard & bad regulator.
Should water follow the NERC CIP model as recommended by AWWA?
How Patrick is dealing with AI.
Links
Ampyx Cyber: https://ampyxcyber.com
Patrick's Critical Assets Podcast: https://amperesec.com/podcast
Subscribe to Dale's ICS Security Friday News & Notes: https://friday.dale-peterson.com/signup
Advertise on Unsolicited Response: https://dale-peterson.com/advertising/
]]>
In this episode Patrick and Dale discuss:
Why Patrick changed the company name and selected Talinn as the location for the new European office.
The major differences in approaches to OT cybersecurity and risk management between Europe and the US. (more than just regulatory differences)
What has the EU learned or improved on regulation from NERC CIP.
What is the current state of NERC CIP regulatory risk? Are the regulated entities understanding and meeting the standards' requirements?
The challenge of slow NERC CIP modifications, eg virtualization and cloud.
Bad standard & good regulator v. good standard & bad regulator.
Should water follow the NERC CIP model as recommended by AWWA?
How Patrick is dealing with AI.
Links
Ampyx Cyber: https://ampyxcyber.com
Patrick's Critical Assets Podcast: https://amperesec.com/podcast
Subscribe to Dale's ICS Security Friday News & Notes: https://friday.dale-peterson.com/signup
Advertise on Unsolicited Response: https://dale-peterson.com/advertising/
]]>
Links
]]>Links
]]>Links
Links
Updates and Announcements
Dale provides updates about S4x24 ticket sales and announces the Women In ICS Security program and sponsor package.
Main Topics
Updates and Announcements
Dale provides updates about S4x24 ticket sales and announces the Women In ICS Security program and sponsor package.
Main Topics
They discuss:
They discuss:
Don and Dale discuss:
Links
Slides Discussed In The Show: https://dale-peterson.com/wp-content/uploads/2023/10/IACS-STAR.pdf
IACS STAR GitHub Repo: https://github.com/cutaway-security/IACS_STAR_Methodology
IACS STAR Calculator: https://iacs-star-calculator.com/iacs_star_calculator.html
Cutaway Security Website: https://www.cutawaysecurity.com
ICS-Patch Decision Tree: https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf
]]>
Don and Dale discuss:
Links
Slides Discussed In The Show: https://dale-peterson.com/wp-content/uploads/2023/10/IACS-STAR.pdf
IACS STAR GitHub Repo: https://github.com/cutaway-security/IACS_STAR_Methodology
IACS STAR Calculator: https://iacs-star-calculator.com/iacs_star_calculator.html
Cutaway Security Website: https://www.cutawaysecurity.com
ICS-Patch Decision Tree: https://dale-peterson.com/wp-content/uploads/2020/10/ICS-Patch-0_1.pdf
]]>
Links
]]>Links
]]>They also discuss UX and the single pane of glass.
Links
]]>They also discuss UX and the single pane of glass.
Links
]]>This is probably one of the most technical interviews with a Presidential candidate you will hear. Dale asks Will:
This is probably one of the most technical interviews with a Presidential candidate you will hear. Dale asks Will:
Stories
Links
]]>
Stories
Links
]]>
In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX
If you know the basics, skip to 14:24 where we get into the details
Links
CycloneDX document: Authoritative Guide To SBOM
ICS-Patch (what to patch when in ICS / risk based decision tree)
]]>In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX
If you know the basics, skip to 14:24 where we get into the details
Links
CycloneDX document: Authoritative Guide To SBOM
ICS-Patch (what to patch when in ICS / risk based decision tree)
]]>Links
]]>Links
]]>After Oldsmar Dale and Gus discuss:
After Oldsmar Dale and Gus discuss:
1:29 One-Way Data Diodes and School Zones
10:15 SAIDI: What Cyber Incidents Should Be Excluded From Metrics
16:05 Do's and Don'ts For Your S4x24 CFP Submission
Links
]]>1:29 One-Way Data Diodes and School Zones
10:15 SAIDI: What Cyber Incidents Should Be Excluded From Metrics
16:05 Do's and Don'ts For Your S4x24 CFP Submission
Links
]]>Samantha Ravich, Chair of the Center on Cyber and Technology Innovation at the Foundation for the Defense of Democracies, joins Dale to discuss the US Department of Energy's OT Defender Fellowship Program.
They begin by describing the program, its goals, what are ideal candidates for the program, and the early results from the first few cohorts. Then Timothy Pospisil of Nebraska Public Power District and part of the 2022 OT Defender Fellowship cohort joins the show to discuss his experience in the program.
At the end we discuss how this could be expanded to address water, critical manufacturing and other sectors.
Link
]]>Samantha Ravich, Chair of the Center on Cyber and Technology Innovation at the Foundation for the Defense of Democracies, joins Dale to discuss the US Department of Energy's OT Defender Fellowship Program.
They begin by describing the program, its goals, what are ideal candidates for the program, and the early results from the first few cohorts. Then Timothy Pospisil of Nebraska Public Power District and part of the 2022 OT Defender Fellowship cohort joins the show to discuss his experience in the program.
At the end we discuss how this could be expanded to address water, critical manufacturing and other sectors.
Link
]]>Big Stories
Plus they both have a win, fail and prediction at the end.
]]>Big Stories
Plus they both have a win, fail and prediction at the end.
]]>We will need to have Josh back for a Part 2.
]]>
We will need to have Josh back for a Part 2.
]]>
Paul Griswold moderated the panel of Dr. Ong Chen Hui, Joel Langill, Sarah Fluchs and Dale Peterson.
Links
Paul Griswold moderated the panel of Dr. Ong Chen Hui, Joel Langill, Sarah Fluchs and Dale Peterson.
Links
Two of the researchers, Jay Johnson of Sandia and Jake Gentle of INL, join Dale on the show to talk about the metrics and results. The project was Cyber Resilience for Wind Installations, but the metrics and results are applicable to every sector. We get into the weeds on this episode and discuss:
Links
• Video: https://www.youtube.com/watch?
• IEEE Access Journal Paper: https://ieeexplore.ieee.org/
• POWER magazine article: https://www.powermag.com/
• 2-page flyer: https://www.researchgate.net/
• Final project report: https://www.researchgate.net/
Two of the researchers, Jay Johnson of Sandia and Jake Gentle of INL, join Dale on the show to talk about the metrics and results. The project was Cyber Resilience for Wind Installations, but the metrics and results are applicable to every sector. We get into the weeds on this episode and discuss:
Links
• Video: https://www.youtube.com/watch?v=bBLbLUFKzIc
• IEEE Access Journal Paper: https://ieeexplore.ieee.org/document/10043706
• POWER magazine article: https://www.powermag.com/cyber-resilience-for-wind-power-installations/
• 2-page flyer: https://www.researchgate.net/publication/367074443_Cyber_Resilience_for_Wind_Installations_A_Cyber_Resilient_Reference_Architecture
• Final project report: https://www.researchgate.net/publication/368599508_Hardening_Wind_Energy_Systems_from_Cyber_Threats-Final_Project_Report
]]>5:30 Where is the CESER CRISP program (detection and information sharing) today? Has it stopped or reduced the impact (outages and others) of cyber attacks on the electric sector? How will they measure the success of this program?
10:40 What has CESER tried, thought it would work, and ended up failing?
14:05 CESER's CyTRICS program is testing vendor equipment? Why, does GE and Hitachi need help? And the results have been trivial vulnerabilities that could be found in hours. Why is CESER spending millions on this?
19:25 Cyber Informed Engineering (CIE) is it the same as Secure By Design? This is a long process, what will the early wins look like? Two years from now how will we know if we are succeeding? Maintaining a manual capability dominated the examples in the document, why hasn't this been highlighted in the program? How can we accelerate this?
25:20 Clean Energy Cyber Accelerator is looking at solutions (OT detection and MFA remote access to OT) that are well established with vendor offerings and asset owner deployments. Why is CECA doing this and trying to accomplish?
]]>
5:30 Where is the CESER CRISP program (detection and information sharing) today? Has it stopped or reduced the impact (outages and others) of cyber attacks on the electric sector? How will they measure the success of this program?
10:40 What has CESER tried, thought it would work, and ended up failing?
14:05 CESER's CyTRICS program is testing vendor equipment? Why, does GE and Hitachi need help? And the results have been trivial vulnerabilities that could be found in hours. Why is CESER spending millions on this?
19:25 Cyber Informed Engineering (CIE) is it the same as Secure By Design? This is a long process, what will the early wins look like? Two years from now how will we know if we are succeeding? Maintaining a manual capability dominated the examples in the document, why hasn't this been highlighted in the program? How can we accelerate this?
25:20 Clean Energy Cyber Accelerator is looking at solutions (OT detection and MFA remote access to OT) that are well established with vendor offerings and asset owner deployments. Why is CECA doing this and trying to accomplish?
]]>
Cybeats is different in that SBOM Studio does not create SBOMs. This requires SBOMs to be available from somewhere, and Dale & Chris spend a lot of the podcast talking about the SBOM market today and in the future.
Of course being Dale and Chris, they deviate into a lot of other topics. Such as Chris's quotes:
Cybeats is different in that SBOM Studio does not create SBOMs. This requires SBOMs to be available from somewhere, and Dale & Chris spend a lot of the podcast talking about the SBOM market today and in the future.
Of course being Dale and Chris, they deviate into a lot of other topics. Such as Chris's quotes:
They cover a lot of ground including:
They cover a lot of ground including:
Marty and Dale then give their win and fail for Q1 and a prediction.
]]>Marty and Dale then give their win and fail for Q1 and a prediction.
]]>After Puesh gives a 3 minute overview on CESER, they dig into it.
After Puesh gives a 3 minute overview on CESER, they dig into it.
Given Steve's longtime involvement and leadership with ISA, it's not surprising the book leans heavily on ISA/IEC 62443. They talk chapters on architecture, certification, optimism / pessimism, risk management and a fundamental misunderstanding of IT by OT. Some agreement, some disagreement, and always a civil discourse.
]]>Given Steve's longtime involvement and leadership with ISA, it's not surprising the book leans heavily on ISA/IEC 62443. They talk chapters on architecture, certification, optimism / pessimism, risk management and a fundamental misunderstanding of IT by OT. Some agreement, some disagreement, and always a civil discourse.
]]>The second half of the interview looks at what the world will look like and what asset owners should do if multiple nations believe in and act on this Cyber Persistence Theory.
Dale believes this is an incredibly important theory to understand because it is taking hold in the world's major powers.
Links
]]>The second half of the interview looks at what the world will look like and what asset owners should do if multiple nations believe in and act on this Cyber Persistence Theory.
Dale believes this is an incredibly important theory to understand because it is taking hold in the world's major powers.
Links
]]>The major topics Dale and Bill discuss include:
The major topics Dale and Bill discuss include: