FrostyGoop: 2004 Is Calling

FrostyGoop: 2004 Is Calling

And Still Awaiting Calls To Replace Unauthenticated Protocols Today Dragos released information on ICS malware they are calling FrostyGoop. The key lines from the release are: "It is the first ICS-specific malware that uses Modbus communications to achieve an impact...

read more
The Next OT Security Product Market

The Next OT Security Product Market

The only OT security product market to date is OT Detection solutions (with a slice of asset inventory). It is led by Armis, Claroty, Dragos and Nozomi. There are another 5 credible vendors and 5 or more niche players. There has been a relatively large amount of...

read more
Hospitals Are Different

Hospitals Are Different

Hospitals and other medical facilities get lumped into OT and cyber/physical because they have software and firmware that is monitoring and controling physical equipment and processes. It’s not wrong, but I don’t think it’s helpful. The high level, high quality OT...

read more
Proposed Government Metric: Outage Pie Charts

Proposed Government Metric: Outage Pie Charts

This is fourth in a series of suggested metrics governments could (should?) use to measure OT security posture, incidents, and risk ... something desperately needed and consistently avoided. Metric 1: Impacted People Days Metric 2: Leading Indicator Metrics Metric 3:...

read more
Usually In My Top Ten … Set & Meet RTO

Usually In My Top Ten … Set & Meet RTO

Last week I wrote that creating an asset inventory typically isn’t in the early actions of an OT security program prioritized by efficient risk reduction. And I received a number of questions of what is on the short list. I’m not going to provide a list because it can...

read more
SEC: Incentives and Outcomes

SEC: Incentives and Outcomes

Show me the incentive; I’ll show you the outcome. Charlie Munger The SEC requirement for US public companies to disclose, in an 8K form, any cyber attacks that will have a material impact on the business went into effect in November, 2023. Unsurprisingly this has led...

read more
Proposed Government Metric – Internet Exposed OT

Proposed Government Metric – Internet Exposed OT

This is third in a series of suggested metrics governments could use to measure OT security posture, incidents, and risk ... something desperately needed and consistently avoided. Metric 1: Impacted People Days Metric 2: Leading Indicator Metrics Metric 3: Internet...

read more
Leading Indicator Metrics (Inspired by API RP 754)

Leading Indicator Metrics (Inspired by API RP 754)

Part 1 of this article is from my S4x24 Keynote: Believe!. Part 2 is the suggested related metrics for the US and other governments. Are some of you having trouble with Total Recordable Incident Rate? Or the SEC material incident rate? Or these outage pie charts. I...

read more

GET DALE'S ICS SECURITY NEWS & NOTES EMAIL EVERY FRIDAY

UPCOMING EVENTS

S4x24 ... 4 - 7 March 2024 in Miami South Beach

Save the date. For the biggest and most future focused on ICS Security Event.