Unsolicited Response Podcast

Informações:

Synopsis

Dale Peterson interviews guests who are pushing and prodding the ICS community to improve cyber security, as well as those in related fields with innovative ideas the ICS community should consider. Dale began his career as a NSA Cryptanalyst, has been securing ICS for over 15 years, and is the founder and program chair of the S4 Conference.

Episodes

  • Cyber-Physical Attacks with Marina Krotofil

    06/09/2023 Duration: 57min

    Marina Krotofil recently published the paper Industrial Control Systems: Engineering Foundations and Cyber-Physical Attack Lifecycle which is a detailed paper on cyber attacks that cause a physical impact on the system being monitored and controlled. It took Marina 1.5 years to write this paper, which is more accurately described as a short book. We discuss: the work she is doing to help Ukrainian critical infrastructure security during wartime what got Marina interested in cyber-physical security 10+ years ago the current understanding of cyber-physical in the OT security community Chapter 2: Engineering Foundations as a great intro for those in IT to understand basic automation principles Chapter 3: Very detailed explanation of a specific process (we don't spend much time on this) The Cyber-Physical Attack Lifecycle with emphasis on the Damage Loop. "Plant shutdown is risky for the attacker as it may instigate an investigation" Chapter 4.6 is a great conclusion  

  • SBOMs & CycloneDX with Steve Springett

    23/08/2023 Duration: 01h01min

    Steve Springett is the Chair of the OWASP CycloneDX Core Working Group. CycloneDX is one of the two main machine readable formats that SBOMs are being created in, although CycloneDX can capture all sorts of BOMs. In this episode we assume listeners know what a SBOM is and why it might be desired by a vendor and asset owner. The beginning of the show we cover some basics of CycloneDX If you know the basics, skip to 14:24 where we get into the details Statistics on who is generating and using CycloneDX SBOMs, and the impact of governement regulations on the use. Steve's view of the NTIA Minimum Elements for SBOM v. CycloneDX elements. How CycloneDX tries to capture the completeness of and confidence in the SBOM. The naming problem. CPE, CVE, NVD, SWID, PURL and more. Steve describes the problem and what he thinks is the way forward. Vulnerabilities ... and why Steve thinks VEX is a missed opportunity. Outdated component analysis (this could be very useful in a procurement decision) and more Links CycloneDX do

  • The OT Cybersecurity / Climate Nexus with Andy Bochman

    16/08/2023 Duration: 53min

    At S4x23 Andy Bochman gave a Main Stage performance on the OT Cybersecurity / Climate Nexus. It's a new idea and Dale wanted to dig into it and understand it better. The discussion looks at where there is a nexus/connection/overlap and where there may be parallel efforts where each side might learn from the other. Links Andy Bochman S4x23 Video Slide used in this episode Earlier episode with Dale and Andy discussing CCE S4x24 Call For Presentations

  • Water Sector Cyber Risk with Gus Serino

    09/08/2023 Duration: 50min

    Gus Serino worked at a large water utility before joining Dragos in 2019. We're talking water sector so it's obligatory to start with Oldsmar (2:20), but we don't talk cyber. Instead we go through the physical portion of the water system assuming the attacker is able to issue the command to the pump to dump a lot of sodium hydroxide into the water system and what would likely happen. Importantly Gus identifies the simple, unhackable solution to this threat. A hard wired PH sensor that will shut off the pump regardless of the commands from the ICS. After Oldsmar Dale and Gus discuss: how small and medium water systems should approach cyber risk the greater challenge to large water systems the EPA's early steps on cybersecurity and future regulation - surprises in moving from a water utility to Dragos what Gus's new I&C Secure company is doing 

  • One-Way, SAIDI & S4x24 CFP

    02/08/2023 Duration: 24min

    This is a solo-sode where Dale reviews two articles from July with comments on comments and additional thoughts. The final section is a must listen if you are going to submit to speak on the S4x24 Stage. The times below are so you can skip to what you are interested in. 1:29 One-Way Data Diodes and School Zones 10:15 SAIDI: What Cyber Incidents Should Be Excluded From Metrics 16:05 Do's and Don'ts For Your S4x24 CFP Submission Links Subscribe to Dale's Friday ICS Security News & Notes Info and Links for the S4x24 CFP

  • Interview with HD Moore

    26/07/2023 Duration: 35min

    HD Moore is most famous for his creation of the Metasploit penetration testing framework. It began in 2003 and hit the OT world in 2011. HD is now the Founder and CTO of RunZero, another cybersecurity startup that is starting to play in the OT Space.   In this episode we spend the first third of the show talking about Metasploit ... early reaction, OT modules, is Metasploit still necessary and useful today.   We then shift to creating asset inventories in IT and OT, which is what RunZero does. Why HD decided to run back into the cybersecurity startup world? How it started as a solo shop with HD writing all the code. How HD things Shodan and RunZero are different. What technique does RunZero use to 'scan'. A term that many fear in OT. Check out their approach to 'fragile devices'. The OT reaction to this type of scanning. What role uses the RunZero product?   Links RunZero website S4x24 Call For Presentations

  • US Dept of Energy's OT Defender Fellowship Program

    19/07/2023 Duration: 37min

    Dale is often critical of the US Government's efforts and programs to address OT cyber risk. So it's a pleasure to highlight a program that is working. Samantha Ravich, Chair of the Center on Cyber and Technology Innovation at the Foundation for the Defense of Democracies, joins Dale to discuss the US Department of Energy's OT Defender Fellowship Program. They begin by describing the program, its goals, what are ideal candidates for the program, and the early results from the first few cohorts. Then Timothy Pospisil of Nebraska Public Power District and part of the 2022 OT Defender Fellowship cohort joins the show to discuss his experience in the program. At the end we discuss how this could be expanded to address water, critical manufacturing and other sectors. Link OT Defender Fellowship Program

  • Eric Cosman On Dow, Open Automation, 62443 & More

    12/07/2023 Duration: 55min

    Eric Cosman had a 38 year career at Dow Chemical, was on the ISA 99 committee its inception, and then he retired. After retirement Eric joined ARC Advisory Group as a Contributing Consultant and got even more active with ISA. He is a long time co-chair of ISA99 and was President of ISA in 2020. Eric and Dale discuss: Dow's in house developed DCS and SIS: MOD Eric's top trend from 2022: The value of open automation and the Open Process Automation Forum ISA/IEC 62433 Eric's view they are "primarily engineering standards" What Eric thinks about the safety / security analogies His experience in being ISA President in the first year of COVID ISA as "the home of automation" Has ISA lost mindshare on ICS security standards to the US Government and training to SANS

  • ICS Security Quarter In Review Q2-2023

    05/07/2023 Duration: 01h24s

    Mark Hyman of Verge Management Group joins Dale to discuss the big 3 stories of Q2 along with their win, fail and predication. Big Stories The OT Security Layoffs (Mark is a recruiter specialized in ICS/OT security) Still No US National Cyber Director? The Merck NotPetya Insurance Claim Ruling Plus they both have a win, fail and prediction at the end.

  • Josh Corman - Healthcare Security, SBOMs & More

    28/06/2023 Duration: 01h04min

    Josh Corman is the VP of Cyber Safety Strategy at Claroty, was the Chief Strategist of the CISA COVID Task Force, and founder of I Am The Cavalry. Josh and I dive into Healthcare Security, SBOMs and other topics.  Can OT in healthcare be treated in a similar way as the factory, power plant, water treatment plant, ... ?  The first fatality due to a cyber attack on a hospital. Should we be focusing our efforts on reducing the impact if ransomware hits a healthcare facility? What is the equivalent to a steel reinforced cockpit door? The PATCH Act (included in the Omnibus bill passed in Dec 2022) requiring medical device manufactures to provide a SBOM and a patching program. What is it? What will be the impact of this? (BTW, Josh changed my mind on this as a start to a long term impact) Will the PATCH Act provisions delay approval of medical devices? How accurate and complete are vendor generated SBOMs today? How will this be solved? What will be the impact of SBOM mandates? Differing views on the importance to

  • OTCEP Panel - Secure PLC Coding Practices

    21/06/2023 Duration: 01h24min

    This episode is a replay of a lively panel from the Cyber Security Agency of Singapore's OT Cybersecurity Expert Panel (OTCEP) last year. It begins with a great introduction to the Top 20 Secure PLC Coding Practices by Sarah Fluchs. At the 35 minute mark the panel discussion begins. There was a lot more disagreement and back and forth than the typical panel. This gives you a variety of points of view and positions to consider. Paul Griswold moderated the panel of Dr. Ong Chen Hui, Joel Langill, Sarah Fluchs and Dale Peterson. Links Top 20 Secure PLC Coding Practices 2023 OTCEP Event Page, August 22 - 23 in Singapore S4x24 Call For Presentations

  • Metrics: How Effective Is A Security Control?

    17/05/2023 Duration: 49min

    How much does a security control reduce cyber risk? What control or mix of controls provides the most efficient cyber risk reduction? Tough questions that a team of researchers at INL and Sandia tried to answer in a project. Two of the researchers, Jay Johnson of Sandia and Jake Gentle of INL, join Dale on the show to talk about the metrics and results. The project was Cyber Resilience for Wind Installations, but the metrics and results are applicable to every sector. We get into the weeds on this episode and discuss: how they created the test environment the two attack scenarios (and why only two and how easy it would be to expand) the physical resilience score the cyber resilience score the results from four different mixes of security controls areas for further testing and improvement and a tiny bit about trying to calculate an Expected Benefit from Cybersecurity Investment, which is a bit like ROI and how much money to spend. Links • Video: https://www.youtube.com/watch?v=bBLbLUFKzIc • IEEE Access Jour

  • S4x23 Closing Panel

    10/05/2023 Duration: 40min

    Ralph Langner, Megan Samford and Zach Tudor join Dale Peterson on the S4 Main Stage to close out S4x23. This Closing Panel is always an attendee favorite as none of these four are afraid to take a strong and even unconventional stance on at OT security topic or issue.

  • Puesh Kumar, Director of CESER at US Dept of Energy

    03/05/2023 Duration: 32min

    Dale Peterson interview CESER Director Puesh Kumar on the S4x23 Main Stage. We discuss a number of CESER programs how they are measuring success, what has not worked, why they are doing some things industry is already doing and more. 5:30 Where is the CESER CRISP program (detection and information sharing) today? Has it stopped or reduced the impact (outages and others) of cyber attacks on the electric sector? How will they measure the success of this program? 10:40 What has CESER tried, thought it would work, and ended up failing?  14:05 CESER's CyTRICS program is testing vendor equipment? Why, does GE and Hitachi need help? And the results have been trivial vulnerabilities that could be found in hours. Why is CESER spending millions on this? 19:25 Cyber Informed Engineering (CIE) is it the same as Secure By Design? This is a long process, what will the early wins look like? Two years from now how will we know if we are succeeding? Maintaining a manual capability dominated the examples in the document, why h

  • Chris Blask: Cybersecurity Pioneer and Idea Man

    26/04/2023 Duration: 46min

    Chris Blask has a long career bringing new ideas to reality. He currently is Vice President of Strategy at Cybeats, who has a SBOM Studio product. Cybeats is different in that SBOM Studio does not create SBOMs. This requires SBOMs to be available from somewhere, and Dale & Chris spend a lot of the podcast talking about the SBOM market today and in the future. What percentage of the OT software solutions have SBOMs today? What will that number be in three years, five years, seven years? When will the top 10% asset owners be able to be get value worth the effort from SBOMs and related tools and information? What will the SBOM marketplace look like? the DBOM.io project Of course being Dale and Chris, they deviate into a lot of other topics. Such as Chris's quotes: “Security comes through transparency and automation” “2020, this is the last decade of cybersecurity” “the last decade when entirely new fields will be discovered” I think we have covered the field.

  • Edgard from Nozomi (Part 2)

    19/04/2023 Duration: 45min

    The August 2021 Unsolicited Response episode with Edgard Capdevielle, CEO of Nozomi Networks, was a fan favorite. So Dale invited Edgard back, like the first time it was a wide ranging and fun conversation. His budget analogy of OT security and a new child in the family was Dale's favorite part. They cover a lot of ground including: the OT visibility and detection market growth in the last two years whether he stands by his 2021 view that a company that does "X, Y, Z and OT security" doesn't really do OT security how much of the back end (non-sensor) part of the market is moving to the cloud now and what will it be in three years. Plus some disagreements / discussion on architecture budget muscle and momentum what sort of metrics should an asset owner use to determine the value of these OT visibility and detection solutions how is the US Government affecting the market Enjoy!

  • Interview with Gene Spafford

    12/04/2023 Duration: 30min

    Dale Peterson interviews cybersecurity legend Gene Spafford on the S4x23 Main Stage. Some of what they cover is: how to deal with securing legacy systems the incredibly productive 3 years of firsts including host IDS, network IDS, honeypot, network vulnerability scanner, and more. What led to this amazing production? The upcoming 25th year of CERIAS His new book Cybersecurity Myths and Misconceptions ... Avoiding the Hazards and Pitfalls that Derail Us and digging into some of those myths (Cyber Offense is Easier than Defense, Sharing More Threat Intel Will Make Things Better, Everyone Should Solve A Given Cybersecurity Problem In The Same Way)

  • ICS Security: Q1 in Review

    05/04/2023 Duration: 58min

    Marty Edwards joins Dale Peterson to discuss the big stories of the first quarter of 2023. The US National Cybersecurity Strategy ISA / ISASecure starting an OT Site Assessment Certification Ransomware Affecting Operations (indirectly) Marty and Dale then give their win and fail for Q1 and a prediction.

  • The OT SBOM Market

    29/03/2023 Duration: 50min

    Dale Peterson talks with Matt Wyckhouse, Founder and CEO, of Finite State about where the SBOM products and market is today and where it will go in the future. This discussion was informed by the SBOM Challenge at S4x23. Who is the primary buyer of SBOM products and services today? (Hint: Matt thinks that 80% of the code in a product is third party) How accurate are the products, and the Finite State product in particular, in creating a SBOM? How much is the value of a SBOM degraded if it is not perfect? If it is missing software or has inaccuracies? Are the offerings now a product? A semi-custom service that uses a developed product? (with an apt comparison to the detection market) What will the US Government do with all these SBOMs if they actually get them? If they get an exponential increase in software inventory and the patching and cyber maintenance burden. Will there be a separate/distinct OT SBOM market? Will there be a SBOM market in the long run or will it get subsumed in some sort of asset managem

  • Puesh Kumar - Director of Dept of Energy's CESER

    22/03/2023 Duration: 32min

    Dale Peterson interviewed Puesh Kumar on the S4x23 Main Stage. Puesh is the Director of the US Dept of Energy's Cybersecurity, Energy Security, & Emergency Response (CESER). The lead US Government OT cybersecurity agency in the energy sector. After Puesh gives a 3 minute overview on CESER, they dig into it. How are they measuring CRISP's detection and analysis progress? Has it stopped or limited the impact of any attacks? What is one of the CESER programs that didn't work and what did they learn from it? Why is the US Government testing products for GE, Hitachi and other large companies and questioning the results. The push for Cyber Informed Engineering and what success looks like Competing with industy and more ... CESER is tackling a lot so there was much to squeeze into 30 minutes

page 2 from 3