What’s Happening At ICS & IT Security Conferences

In the last two months Bryan Owen attended the SANS ICS Security Summit, DHS ICSJWG, RSA, OSIsoft’s PI World, and LOGIIC (Oil/Gas/Gov consortium). Since most listeners like me aren’t able to attend these events I thought we could find out what’s...

Press Coverage of ICS Security

This was a fun panel discussion on the S4x18 Main Stage with Kelly Jackson Higgins of Dark Reading and Jim Finkle of Reuters. http://traffic.libsyn.com/unsolicitedresponse/PressPanel.mp3 We covered a lot of grounds in a frank discussion including: Who is your reader?...

PODCAST: IATROGENICS – HARM DONE BY THE HEALER

Nassim Taleb discusses the concept of Iatrogenics in his book Antifragile. It is commonly applied to medicine, but Taleb applies it to the financial market and proposes it could be applied to other areas. We had a panel at S4x18 that dug into the issue of how to determine when security controls are doing more harm than good.

I was joined on stage by Jake Brodsky and Joel Langill. Jake is famously conservative when it comes to applying security controls, and Joel is a big proponent of some security controls that Jake would pass on. And all three of us are highly opinionated, so it made for an interesting discussion.

S4x18 Debate: Enterprise SOC or OT SOC?

S4x18 Debate: Enterprise SOC or OT SOC?

This was a great debate from S4x18. Many owner / operators have an Enterprise Secure Operations Center (SOC), and they are considering how best to handle OT incident detection and response. There are two main approaches: 1. Add OT data and incident response capabilities to an Enterprise SOC or 2. Set up and run a SOC dedicated to the OT environment.

PODCAST: ICS DETECTION CHALLENGE INTERVIEWS

PODCAST: ICS DETECTION CHALLENGE INTERVIEWS

Dale Peterson interviews the ICS Detection Challenge Winner – Claroty and the runners up – Nozomi and Security Matters. They discuss where the competitors did well, how the products are likely to improve in the future, and what the future direction of the ICS product detection category is likely to be.

PODCAST: ICS DETECTION CHALLENGE ANALYSIS

The ICS Detection Challenge at S4x18 last January pitted Claroty, Gravwell, Nozomi and Security Matters in a competition to determine who could create the most complete asset inventory and who could do the best job detecting attacks through passive ICS network monitoring only. Dale Peterson and Eric Byres discuss the packets used in the test and analyze the results. What this product category can and cannot do. The last 15 minutes talking about the future of the ICS Detection product category.

MEDICAL CYBERSECURITY & DENSE VULNERABILITIES

After quickly agreeing that vulnerabilities in medical devices & software are dense, Dale Peterson and Josh Corman discuss where time and money should be spent on improving Medical Sector cybersecurity. Does the find and patch vulns make sense when the vulns are dense? Why does a hospital shut down for a week when a single application has an exploited vuln? How is the FDA doing in forcing change? What can we expect in the future. This and more in this episode.

DAN GEER INTERVIEW AT S4x18

DAN GEER INTERVIEW AT S4x18

I had the pleasure of interviewing Dan Geer on the S4x18 Main Stage for 30 minutes. He typically speaks from prepared papers, so an interview is a bit unique, and his papers provided plenty of topics and questions....

2018 PLANS: PODCAST, S4, CONSULTING & YOUR CAREER

Dale Peterson talks about the 2018 plans for this podcast, S4 and his consulting in this shorter 13-minute episode. He also talks about Digital Bond alumni spread throughout the industry and how this is likely the best time in ICS security for career opportunities and...

The ICS Security Stories We Tell And Love

We, the ICS community, have some mantras: It will take decades to fix the ICS security problemOperations Technology (OT) is different than Information Technology (IT)You can’t do X, Y or Z in ICS because … which is followed by a variety of reasons such as...