Contribute: New, Narrow, and Deep

(see opportunity at the bottom of article)

When I had an OT security consulting team from 2000 – 2020, I would tell every new member they should be recognized as best in world at something in OT security in less than three years. I would hand them a copy of Tom Peters’ Brand You 50 (a bit dated now, but still helpful), and we would map out a plan.

Some worked at it, achieved this lofty goal, and have reaped the benefits. Others either didn’t believe it was possible or didn’t want it badly enough. Nevertheless, working on it did help their personal brands and careers. Digital Bond alumni are doing great things in throughout the OT security world.

How do you achieve this best in world skills and reputation? You need to contribute, publish, and promote in an effort that is new, narrow, and deep.

New

Good news if you’re looking for a way to be THE expert: we still know very little about how to best reduce OT cyber related risk. We have assumptions and hypotheses that are not yet proven or even begun to be tested.

There are so many fresh areas that have received little beyond a surface treatment, and this is all before you add in AI. You should have no problem finding a project or effort that is covering new ground.

Narrow

This is the most important factor. What I have seen for 20+ years is people trying to make their name in this community cover the same old tropes. How OT is different than IT. The challenges of patching in OT. How OT incidents can result in death or catastrophic consequences. Sensational articles on the OT cyber incident du jour.

Now with AI these articles and infographics are becoming more frequent, longer, and more detailed. They rarely add anything meaningful to the discussion or your personal brand (unless you maintain a relentless cadence in which case you will gain influence with those new to the field over time).

The key is to find an area that is not yet explored and focus on that. It works. I did this in the 2004 – 2008 timeframe with IDS signatures and preprocessors for OT protocols. No one was doing it, so even relatively simple contributions were best in world. By 2006 I was turning down speaking engagements, getting USG research contracts, and was known as the person on this topic. It was new, so the competition for that crown was minimal.

A more recent example is Kristin King. A couple years back she decided to focus on OT security in the food industry, and she is now recognized as one of the leading experts in this. Her contribution is strong, and I’m not sure who is even in second place in creating content and advocating for this sector.

It could be a protocol, a vertical field, an unproven hypothesis, … It takes little more than brainstorming to identify possibilities. Then you need to select something that will hold your interest. It will take work over 2 to 3 years to be best in world and be recognized as best in world.

Deep

Now that you have your narrowed field of study, you have to go deep. You need to know more about it than anyone else.

It is essential, and difficult, to stay narrow and deep. There is a tendency to get tired of this niche. and expand it. Avoid this temptation until you are firmly established as best in world, and then you can consider expanding to something more or different. Instead of going broader, go deeper.

Contribute

If you are best in world and no one knows about … it can be intellectually satisfying, may help your employer, but likely won’t help your career.

I have met asset owner employees who know as much or more than anyone else on a topic and few have heard of them. This isn’t bad if you stay with that one company your whole career, but this is far from guaranteed.

You need to let your light shine. This will be publishing posts and articles. Speaking at events, which becomes very easy as your reputation as world’s best in xxx grows. My favorite is creating or contributing to a project.

Vivek Ponnada became well known in the OT security community from his work on the Top 20 Secure PLC Coding Practices. Well regarded projects like these typically end up with one or two people doing all the work. He volunteered and did focused work over time and promoted the effort. He was highly skilled before this project, and the project let many others know about Vivek and his talent.

Find something you are passionate about. Do the work for a couple of years. Promote the work. And you will build your personal brand quickly. This will lead to many opportunities for you to choose from.

Opportunity

The spark for this article is we are looking for 1 or 2 people to take over the OT Incident Impact Score project. Not the back end or technical side. Dan Ricci created and maintains this at impact.icsadvisoryproject.com. Dan graciously will continue to volunteer his services on this.

What we need is a couple of people to take over:

  1. The identification and loading of new OT security incidents, links, and details.
  2. Updating these incidents as more impact/consequence information becomes available.
  3. Taking in input on improving the OT Impact Score (as long as it stays true to the original goals)
  4. Promoting with the media and on social media the OT Impact Score, individual event scores, reports on trends, etc. (I can help you with this.)
  5. Speaking at events on the OT Impact Score. You would be the face(s) of this effort.

I’m not abandoning it. I will help and cheerlead, but we need one or two people that will take this on as one of their core missions.

Last Thought

I get contacted many times every month with an email or DM from someone new to the OT Security field wanting to “pick my brain” on the subject and their career. My advice is get a job in or adjacent to OT security and contribute to a new, narrow and deep effort.