
Control Loop: The OT Cybersecurity Podcast · 2024-06-05 · 16 min
Key moments - from our scoring
Substance score
36 / 100
Five dimensions, 20 points each
This episode addresses the accelerating regulatory landscape for operational technology security across critical infrastructure. The briefing covers three major developments: the UK's proposed legislation to ban ransomware payments for critical infrastructure entities (with reporting requirements and licensing for non-critical infrastructure), the EPA's enforcement push on water utility cybersecurity following inspections revealing 70% non-compliance with Safe Drinking Water Act requirements, and Rockwell Automation's urgent advisory to disconnect ICS devices not designed for Internet connectivity. The guest interview with Kimberly Graham, VP of Product Management at Dragos, provides deep context on NERC SIP 15 (Internal Network Security Monitoring), the newest NERC standard requiring monitoring within security zones, not just at perimeters. Graham explains the three-to-five-year implementation timeline for high/medium control centers and medium BES cyber systems, positioning this as a natural evolution of regulatory requirements. She emphasizes the collaborative nature of standards development and the value of information-sharing communities (ISACs, industry groups) in driving consistent implementation across regulated entities.
NERC SIP 15, also called INSM (Internal Network Security Monitoring), is a new standard requiring organizations to monitor network traffic and anomalous activity within trusted zones and electronic security perimeters, not just at perimeter boundaries. Ratification occurs in July 2024, with compliance required for high and medium control centers in 36 months and all medium BES cyber systems in 60 months.
The EPA found that over 70% of water systems inspected do not fully comply with Safe Drinking Water Act cybersecurity requirements, with critical vulnerabilities including default passwords and easily compromised single-login systems.
No; the proposed UK law would ban ransomware payments for critical infrastructure entities but would require non-critical infrastructure entities to obtain licenses before paying a ransom.
Longer timelines are intentional to allow testing and preparation without introducing excessive change to critical infrastructure environments that must remain stable and reliable.
Rockwell is urging customers to disconnect ICS devices that are not specifically designed for Internet connectivity from the public Internet to reduce attack surface and exposure to external threat actors.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is split between news recaps (which add no original analysis beyond quoting agency press releases) and a surface-level regulatory explainer that covers well-known frameworks without generating novel operational takeaways. The few concrete details - INSM timelines, zone-to-zone monitoring progression - are the only real substance.
This is fairly typical because in these types of environments, you don't want to be introducing a lot of change without time to do testing and preparation.
the more that folks talk and collaborate and work together, the more alignment we see
There are no contrarian or first-principles arguments anywhere in the episode. The regulatory compliance discussion follows a completely predictable narrative arc (new standard extends old standard, industries will follow each other's lead), and the news segment is a straight read of existing public advisories with no original commentary.
So it's kind of a natural progression. So we don't have any, there's not many published statements saying that's the direction that everyone is going.
I think we can look at where different industries are moving and then apply that to other industries. So it's not always going to be exactly one-to-one.
Kimberly Graham holds a senior product title at a credible OT security firm (Dragos), giving her legitimate industry standing, but she repeatedly and explicitly disclaims expertise in the regulatory domain being discussed, which is the entire subject of the interview. This limits the depth she can credibly deliver.
I'm not an expert on NERC SIP or TSA or so on, but I do work with a lot of people who are
I'm not enough of an expert to dive into the whole review process
A handful of concrete data points exist - the 70% EPA non-compliance figure, the 36-month and 60-month INSM implementation timelines, and the July ratification date - but the interview portion lacks named customer examples, dollar figures, or detailed case evidence. The news segment cites real advisories but only paraphrases them.
over 70%, do not fully comply with requirements in the Safe Drinking Water Act, and that some of those systems have critical cybersecurity vulnerabilities, such as default passwords
in 36 months, it goes into effect for all high and medium. Control centers have to be compliant. and then in basically 60 months, so five years, then everyone else has to be compliant
The host asks broad, open-ended questions with no meaningful follow-up or pushback. Questions like 'Is it possible to look into a crystal ball?' and the 'needle between collaborative and adversarial' framing are soft and imprecise, and the guest's non-expert disclaimers are never probed or redirected to someone who could answer more definitively.
Is it possible to look into a crystal ball and see where we're headed?
I guess I'm trying to understand if you have collaborative on one side and adversarial on the other. Imagine a needle between the two of those.
Computed from the transcript - who did the talking, and the words that came up most.
UK will propose law to ban ransom payments for critical infrastructure entities. EPA outlines enforcement measures to protect water utilities against cyberattacks. Rockwell advises customers to disconnect ICS devices from the internet. Senator Vance asks CISA for information on Volt Typhoon. Guest Kimberly Graham of Dragos joins Dave to discuss regulatory compliance issues. Programming Note. Control Loop is going on a temporary hiatus. Thank you for being a loyal listener. N2K CyberWire will be back soon with more ICS/OT news and analysis that you rely on. Please stay tuned for more updates. Control Loop Audience Survey. Please take a moment to fill out our super quick survey. It’s only 5 short questions. Thanks! Control Loop News Brief. UK will propose law to ban ransom payments for critical infrastructure entities. Exclusive: UK to propose mandatory reporting for ransomware attacks and licensing regime for all payments (The Record) EPA outlines enforcement measures to protect water utilities against cyberattacks.
Transcribed and scored by The B2B Podcast Index.
You're listening to the Cyber Wire Network, powered by N2K. It's June 5th, 2024, and you're listening to Control Loop. In today's OT cybersecurity briefing, the UK will propose a law to ban ransom payments for critical infrastructure entities. The EPA outlines enforcement measures to protect water utilities against cyber attacks.
Rockwell advises customers to disconnect ICS devices from the Internet. Senator Vance asks CISA for information on Volt Typhoon. Our guest is Dragos' Vice President of Product Management, Kimberly Graham. Kim and I discuss regulatory compliance issues.
The United Kingdom will propose a law that would ban critical infrastructure entities from making ransomware payments, the record reports. The UK hopes this will remove incentives for ransomware gangs to target these entities. The law would also require all ransomware victims to report attacks, and non-critical infrastructure entities will need to obtain licenses before paying a ransom. The proposed legislation is still in very early stages and likely won't move forward until after the next general election later this year.
The record notes, however, that even if the proposals are not immediately implemented, they mark a dramatic development in how governments around the world are responding to the ransomware crisis. The U.S. Environmental Protection Agency last week outlined enforcement measures to help water utilities defend against cyberattacks.
The EPA says it's issuing the alert because threats to and attacks on the nation's water system have increased in frequency and severity to a point where additional action is needed. The agency added, Recent EPA inspections have revealed that the majority of water systems inspected, over 70%, do not fully comply with requirements in the Safe Drinking Water Act, and that some of those systems have critical cybersecurity vulnerabilities, such as default passwords that have not been updated and single logins that can easily be compromised.
Rockwell Automation has issued an advisory urging customers to ensure that ICS devices that aren't specifically designed for Internet connectivity are disconnected from the web. The company stated, Due to heightened geopolitical tensions and adversarial cyber activity globally, Rockwell Automation is issuing this notice urging all customers to take immediate action to assess whether they have devices facing the public Internet. and, if so, urgently remove that connectivity for devices not specifically designed for public Internet connectivity.
Rockwell adds, removing that connectivity as a proactive step reduces attack surface and can immediately reduce exposure to unauthorized and malicious cyber activity from external threat actors. U.S. Senator J.
D. Vance, a Republican from Ohio, wrote a letter to CISA Director Jen Easterly, requesting information on CISA understanding of and response to the Chinese threat actor Volt Typhoon targeting of U critical infrastructure entities Vance inquired about how Volt Typhoon gained access to the infrastructure entities, how many entities were affected, and if additional infrastructure sectors were targeted beyond those disclosed by CISA. Vance also asked which ISACs are aware of Volt Typhoon's activities and how many Volt typhoon-related calls were received by CISA's 24-7 Operations Center since the beginning of 2023.
Kimberly Graham is Dragos' Vice President of Product Management. I recently caught up with her for insights on regulatory compliance issues. There's already a lot of existing regulatory compliance in various industries. And what we've been noticing lately is kind of an alignment of some of these different forms of compliance.
So different industries are in different places, depending on where they are and what information or system they have to protect. So if you look at the TSA security directive, that's focused on building network security monitoring, but building it around the zone-to-zone communications, communications between trusted zones. Very similar to regulations that exist inside of NERC SIP already as well, which has been in place longer than the TSA security directive. And then when you look at some newer regulations like NERC SIP 15, which is called INSM, Internal Network Security Monitoring, the focus there is internal.
So moving beyond just monitoring your communications and traffic between security zones, you need to monitor within a security zone, like in the language of NERC SIP, your electronic security perimeter. Well, before we dig into INSM, can you give me your insights on where organizations stand right now in terms of being able to comply with what's being demanded of them? It depends on the organization and the industry. In the very highly regulated industries, most folks are keeping up because they have to.
per the regulations, there are audits that are in place that enforce that they have these types of features. And in the case of industries like the electric sector, where we have INSM, they're given a lot of time to prepare. So we're looking at implementation within the next three to five years for INSM, meaning that there is time to prepare to make sure that you are ready for the enforcement of those regulations. I see.
Well, let's dig into INSM. I mean, And for folks who might not be familiar with it, how do you describe it? It's basically an extension of the existing regulations that are in place. So it is its own standard now.
So it's a new standard called SIP 15. It ensures that there's monitoring of network traffic and anomalous activity within the trusted zones. So that can be the electronic security perimeter. Basically, within these networks, instead of just monitoring one network talking to another network or just the perimeter itself of your ESP, you're looking at what is the traffic, what is going on inside this network.
And what is the timeline in terms of implementation here? So in terms of the timeline the ratification should take place in July of this year so very soon And then in terms of the implementation of when it actually goes into effect it depends on the responsible entity So in 36 months, it goes into effect for all high and medium. Control centers have to be compliant. and then in basically 60 months, so five years, then everyone else has to be compliant.
So all medium BES cyber systems have to be compliant. Can you give us some perspective on those timelines? I mean, for someone outside of this world, just dealing with regular cybersecurity things, three years, five years, sounds like an awfully long time, the pace and cadence of things that happen in the cyber world. But is this a reasonable timescale given this particular world?
This is fairly typical because in these types of environments, you don't want to be introducing a lot of change without time to do testing and preparation. So we typically like to see longer timeframes because while things are needed, if you try to force something too soon, then obviously you could be introducing too much change to an environment that really needs to stay stable. And that's what's very important about critical infrastructure is that it needs to stay stable. Right, right.
So it's a matter of setting priorities. So where do you suppose we're headed here? I mean, when you're looking towards the horizon at regulatory compliance and these entities, what does the future look like? Is it possible to look into a crystal ball and see where we're headed?
So I think we can look at where different industries are moving and then apply that to other industries. So it's not always going to be exactly one-to-one. But if you look at major themes, like with NERC SIP requiring monitoring of the perimeter of different security boundaries, and then the TSA pipeline security directive saying, okay, you have to monitor the perimeter of these different security zones and trust boundaries. And now with INSM saying, okay, it makes sense now to monitor not just those security boundaries, but also within those perimeters, what is the traffic that's flowing?
What kind of behaviors do we see? That's now going to be included inside of NERC SIP. You could look at that and say that that may be an indicator that other industries may follow suit and say, okay, it does make sense for us to start monitoring inside this perimeter. So it's kind of a natural progression.
So we don't have any, there's not many published statements saying that's the direction that everyone is going. But I would expect that to be how we see the future of regulatory compliance when it comes to network monitoring. I see. From your position at Dragos, the level of expertise that you have, I'm curious, are there common elements that you see with organizations who are being successful here, who have successful compliance programs, who have all the things in place?
Are there commonalities there? So I would say that working with different customers and I come from the product side, I'm not an expert on NERC SIP or TSA or so on, but I do work with a lot of people who are. We have a lot of experts here at Dragos. We have a lot of customers that we can talk to and compliance teams that we can work with.
So I would say that there are some general themes that we hear around the different programs and alignment And that happens because there a lot of sharing that goes on So while these different groups may be unrelated other than that they're in the same industry, they are related in the fact that they are regulated in the same way. So they form industry groups and they form these information sharing communities that allow them to talk about what are you doing to implement this specific regulation to the specific control.
And then we try to empower that as well. We have some different groups that are user groups that aren't necessarily focused on regulatory compliance, but that's often a major discussion within the group is we're trying to comply with this specific regulation. What is everyone else doing? So you see a lot of sharing and that leads to a lot more consistency.
But there's always different needs. Everyone will interpret a little bit different and that's fine. There is some flexibility that is there in the standards, and some of it will be up to interpretation. But I'd say overall, the more that folks talk and collaborate and work together, the more alignment we see.
Does the regulatory regime here tend to be collaborative? I guess I'm trying to understand if you have collaborative on one side and adversarial on the other. Imagine a needle between the two of those. Where do we stand these days?
It's highly collaborative. So there's a whole process that I'm not enough of an expert to dive into the whole review process, but it is pushed out to the general community and they're able to make comments on it before anything is ratified because these regulations do impact everyone. So it makes sense for there to be comment periods and for people to give their feedback to say, this meets my needs, this doesn't meet my need, to make sure that everything is is working the way that it should.
That's Kimberly Graham, Vice President of Product Management at Dragos. And that's Control Loop, brought to you by N2K CyberWire and powered by Dragos. A programming note for you, Control Loop is going on a temporary hiatus. Thank you for being a loyal listener.
N2K CyberWire will be back soon with more ICS, OT news, and analysis that you rely on. Please stay tuned for more updates. For links to all of today's stories, check out our show notes at thecyberwire.com.
We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.
com. We're privileged that N2K Cyber Wire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K makes it easy for companies to optimize your biggest investment, your people. We make you smarter about your teams while making your team smarter.
Learn how at n2k.com. This episode was produced by Liz Stokes. Our mixer is Trey Hester, with original music and sound design by Elliot Peltzman.
Our executive producer is Jennifer Iben. Our Dragos producers are Joanne Roche, Mark Urban, and Montserrat Thomason. Our executive editor is Brandon Karp. Simone Petrella is our president, Peter Kilpie is our publisher, and I'm Dave Bittner.
Thanks for listening. We'll see you back here next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.