The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Industrial Security Podcast
The Industrial Security Podcast artwork

Network Duct Tape [The Industrial Security Podcast]

The Industrial Security Podcast · 2025-07-11 · 1h 4m

0:00--:--

Key moments - from our scoring

Substance score

63 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality12 / 20
Guest Caliber13 / 20
Specificity & Evidence13 / 20
Conversational Craft11 / 20

Oil and gas operations - particularly upstream and midstream - depend on distributed automation across hundreds or thousands of remote well sites, tank batteries, and pipeline facilities spread across vast geographic areas with limited connectivity. Tom Siegel explains how Blastwave addresses the core security challenge: operations teams need secure access to these distant assets for monitoring and control, but traditional network security approaches create friction and require costly infrastructure overhauls. Blastwave's software-defined networking solution abstracts policy from infrastructure using overlay IP addresses, similar to NAT but applied at scale. This identity-based routing cloaks assets so they're undiscoverable to adversaries, segments networks to prevent lateral malware movement, and enables secure remote access without routing packets by source/destination IP - critical for companies managing overlapping IP address spaces after acquisitions. The solution has enabled oil and gas firms to integrate thirty-billion-dollar acquisition targets in weeks without IP reengineering, and works across firewalls and existing infrastructure. Siegel also discusses the evolution of horizontal drilling, hydraulic fracturing, and emerging AI/cloud integration challenges where human-in-the-loop validation gates control recommendations from predictive models.

Key takeaways

  • →Blastwave uses overlay IP addresses and identity-based routing to cloak remote assets from discovery while enabling policy-abstracted, firewall-independent access - useful for securing distributed oil and gas operations across hundreds of geographically dispersed sites.
  • →Software-defined networking abstracts network policy from infrastructure, allowing devices to associate with overlay addresses that route based on identity rather than source/destination IP, optimizing for performance-critical OT environments.
  • →Oil and gas companies solving the credential theft and vulnerability exploitability problem through different mechanisms - Blastwave eliminates usernames and passwords entirely for industrial MFA, and implements network cloaking to make CVEs unexploitable.
  • →Acquisitions of competing oil and gas companies no longer require costly IP address reengineering when protected by Blastwave; a thirty-billion-dollar acquisition was secured in three weeks with overlapping address spaces intact.
  • →AI and cloud systems represent the future of industrial automation, but require human-in-the-loop validation, redundant systems, and extensive testing - similar to autopilot in aviation - before closed-loop control of critical processes like tank level management.

Guests

Tom Siegel

Topics in this episode

Horizontal drillingHydraulic fracturingSoftware-defined networking (SDN)Network cloakingIdentity-based routingOverlay IP addressesOil and gas upstream operationsRemote terminal units (RTUs)Programmable logic controllers (PLCs)SCADA

Questions this episode answers

How does Blastwave secure remote oil and gas assets without requiring network infrastructure changes?

Blastwave abstracts network policy from infrastructure using software-defined networking with overlay IP addresses (similar to NAT), routing packets based on identity rather than source/destination IP. This allows assets to remain cloaked from discovery, enables identity-based access control across firewalls, and eliminates the need for IP reengineering even when companies have overlapping address spaces.

What are the three highest-threat categories that Blastwave was designed to eliminate?

Phishing and credential theft (addressed by eliminating usernames and passwords in favor of industrial MFA), CVEs and vulnerabilities (addressed through network cloaking to make exploits ineffective), and human error (reduced through simplified UI/UX that requires fewer user decisions).

Why is secure connectivity critical in upstream oil and gas operations?

Wells are highly remote and located hours apart in rural areas; operations teams cannot physically visit sites frequently for monitoring. Distributed assets like pump jacks and horizontal drilling operations require real-time automated monitoring and control through connectivity, making secure remote access essential for both operations and cybersecurity.

How do oil and gas companies handle AI model recommendations from cloud systems while maintaining security?

Leading companies use human-in-the-loop processes where AI in the cloud analyzes operational data and recommends set points or control variables, but humans manually implement those recommendations through their control HMI rather than enabling closed-loop automation directly from cloud systems.

What are upstream, midstream, and downstream in oil and gas?

Upstream is exploration and production (drilling, pump jacks, offshore platforms); midstream is transportation and storage (pipelines, tank farms, initial processing facilities); downstream is refining, processing, and distribution to consumers (refineries, gas stations, trucking).

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode contains substantial practical insights about industrial networking challenges, distributed asset protection, and software-defined networking applications in oil and gas. However, much content is devoted to lengthy industry background (drilling techniques, reservoir management) and product positioning rather than densely packed novel concepts. The core insights - network cloaking, identity-based routing, passwordless authentication, and acquisition integration challenges - are solid but interspersed with explanatory filler.

We essentially establish we abstract the policy from the network infrastructure such that you can have a group of devices or a device itself that essentially associates with an IP address that's an overlay address
if there are cvees, and I guarantee you there will be, there will also be zero day viruses, okay, which may not be on anyone's list. And so in those both of those cases as well as ancient devices that are never going to be patched. You've got a way to deal with these unpatchable systems because they're unaddressable

Originality

12 / 20

The episode presents a genuinely different approach to industrial security - moving from vulnerability patching and firewall rules to identity-based network abstraction and address-independent segmentation. However, the core concepts (network overlay, software-defined networking, passwordless MFA) are not entirely novel in the broader security industry; their application to distributed OT infrastructure is relatively fresh. The thinking is first-principles but not deeply contrarian.

it routes it based on identity. And this is something I think is very unique to us
we can essentially turn a forty eight port switch into forty eight d lands, so that each one of those is its own ENCRYPTI unit that can't see their neighbors and can't talk to their neighbors unless the policy allows that to happen

Guest Caliber

13 / 20

Tom Siegel is a CEO with relevant operational experience (chemical engineer at Caterpillar, process facility design at Eli Lilly, business development at Emerson) and has built a company addressing real industrial problems. However, his primary expertise appears to be product-market fit and business development rather than deep technical depth in security or networking. He is a practitioner-founder rather than a recognized domain authority at the level of a CISO or major infrastructure operator.

I started my career as a chemical engineer at Caterpillar. I also spent eight years at Eli Lilly, designing and building processing facilities to make medicine
our mission then is the same as it is today, which is to protect critical infrastructure from cyber threats, and we wanted to kind of come at this with a very different approach than other cybersecurity companies

Specificity & Evidence

13 / 20

The episode includes concrete customer examples (oil and gas company with 700 sites, $30B acquisition, manufacturing facility with 10 lines, airport gate ramps) and specific metrics (quadrupled revenue, tripled customer count, one person managing 22,000 devices, $250K per cell tower cost). However, many examples lack precise numbers on impact, timeline details, and financial outcomes. The technical explanations often remain abstract despite attempts at clarification.

one company, oil and gas company that acquired a thirty billion dollar acquisition target. That's a big company that you're acquiring, and they were able to protect that with blast shield in three weeks
We have one customer who has seven hundred sites that they're trying to manage

Conversational Craft

11 / 20

The hosts ask clarifying questions and occasionally push back (e.g., Nate requesting simplification of technical concepts, Andrew asking for specifics on routing and layer-two isolation). However, most follow-ups are exploratory rather than challenging. The hosts rarely press on contradictions, unsubstantiated claims, or business metrics. The conversation feels more like an extended product walkthrough than a rigorous interview.

can you Andrew just help simplify everything we're talking about
Can we come back to the technology. Can you tell us what does this stuff look like?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

address38devices37addresses27network25software22infrastructure21different21twenty20device19firewall19upstream16security15pipeline15firewalls15andrew14midstream12

Episode notes

Hundreds of subsystems with the same IP addresses? Thousands of legacy devices with no modern encryption or other security? Constant, acquisitions of facilities "all over the place" network-wise and security-wise? What most of us need is "network duct tape". Tom Sego of Blastwave shows us how their "duct tape" works.

Full transcript

1h 4m

Transcribed and scored by The B2B Podcast Index.

Let me abstract the policy from the network infrastructure such that you can have a group of devices or a device itself that essentially associates with an IP address that's an overlay address. Welcome listeners to the Industrial Security Podcast. My name is Nate Nelson. I'm here as usual with Andrew Ginter, the vice president of Industrial Security at Waterfall Security Solutions.

He is going to introduce for all of us the subject and guest of our show today. So, Andrew, how are you. I'm well, Thank you, Nate. Our guest today is Tom Siegel.

He is the CEO and co founder of Blastwave, and he's going to be talking about distributed asset protection, which is a fancy name for a very common problem in the industrial space. We have, you know, stuff devices, computers, assets, cyber assets all over the place. You know, might be distant in pumping and substations, might be local. The stuff was bought, you know, on the cheap.

It was the lowest bidder. It's old, it's ancient, and we have no budget to rip in place. So what do we do about cybersecurity? And this is something he'll be walking us through.

Then let's get right into it. Hello Tom, and thank you for joining us. Before we get started, can I ask you to say a few words of introduction, tell us a bit about your background and about the good work that you're doing at Blastwave. Sure, Andrew, thanks for having me so my background as I started my career as a chemical engineer at Caterpillar.

I also spent eight years at Eli Lilly, designing and building processing facilities to make medicine. I was also a certified safety professional during that period and managed a twenty four to seven liquid incineration operation which burned a thirty thousand gallons of liquid waste per day, so a shit ton. And then I went to Emerson did business development corporate strategy there. Then I did product management at Alta Vista.

Then I went on to do sales support at Apple, where I was at Apple for almost ten years. And then that's when I started my entrepreneurial career. I started a mobile telephony company, started a solar storage company, started a wine importing business, then played professional poker for a few years, and then eventually started this cybersecurity business called blast Wave. I co founded that in twenty seventeen, and our mission then is the same as it is today, which is to protect critical infrastructure from cyber threats, and we wanted to kind of come at this with a very different approach than other cybersecurity companies in that we kind of started from first principles thinking about what are the three highest kind of classes of threat and categories of threats and can we actually eliminate those.

The biggest categories probably no surprise to anybody here, but it's fishing, credential theft, et cetera. I'm like, well, let's just get rid of user names and passwords altogether and come up with a different model for MFA that can actually apply to industrial settings. So we did that. The second category of threats was really cvees and vulnerabilities, and could we make those unexploitable.

We came up with a concept called network cloaking, which I'm sure we'll discuss which kind of addresses that issue. And then the last one is human error, which is impossible to get rid of. But if you can make human beings make fewer decisions, they can also make fewer mistakes. So we also incorporated that into a lot of are UI and UX.

That's wow, that's a history like none other I've ever heard. Tom, you know, make like I'm thinking, makes makes my own what I thought storied background look completely mundane. You've been in lots of different industries. Now I understand that you know, a lot of what blast Wave does right now is upstream and midstream, and we've never had someone on the show explaining how that works.

I mean, I think we've had, you know, one person on talking about an offshore platform at some point. But you know, when you're looking at the industry, can we start with the industry? What's what's the physical process physically? What's this stuff look like, what's it do?

How does it work? Yeah, it's really interesting because I can talk about the physical process and it's also evolved quite a bit in the last twenty years. So, first of all, just stepping back looking at the industry, the overall oil and gas market globe generates two trillion dollars of revenue per year, and that generates one trillion in profit. So there's a lot of money in this business.

And that also means that there's a lot of gallons of oil and a lot of cubic feet of gas that are being extracted and transmitted and sent everywhere around the world. And the other thing that's interesting is that, in spite of how old this industry is, there's between fifteen and twenty thousand new oil wells created per year, and in fact half of those were done in the Permian Basin, so about eight thousand wells were created last year in the Permian Basin. I don't think people realized the magnitude of which the oil and gas companies are continuing to create wells and extract oil.

The other thing that's interesting about it is twenty years ago we had a traditional vertical drilling approach to oil and gas, and in that to last two decades we've noticed that there are capabilities to actually now drill horizontally. And what's pretty interesting is you can actually, as you start drilling a well today, you create the initial bore, which is usually a foot or more in diameter, and then you can send these kind of devices and drill bits down a relatively sloping curve that over the course of maybe one hundred or two hundred meters, you've now done a ninety degree angle, and then you can start drilling horizontally, which allows you to have higher probabilities of not hitting a dry well.

It gives you more capabilities for lower cost extraction, and so it's been a great boon for the industry. Hydraulic fracturing, which is another technique that's been exploited to get much higher yields out of these wells, also contributed to the recent boom in oil and gas. So there are many, many things that have to be considered when you start doing this process. You know, you've got to go through site selection, permitting, you've got to do all this site prep.

And one thing people may not realize is site prep means building roads. You have to build an entire infrastructure to get to and from these wells. And then once you start actually drilling the well, it's much like a CNC machine if you've been in a factory like Caterpillar or something where there's a fluid heat transfer fluid that allows you to you know, cut the metal. In this case, they use a mud that both stabilizes the well bore and it also helps you manage pressure.

And that muddud flows down through the drill pipe and then it comes out around in kind of an annulus, almost like a doughnut, that comes back up the outside of that drill pipe to be then cleaned. Having the rock kind of cuttings removed from it using a screening and operation, and then you kind of reuse the mud and so forth. So there's a lot to it. And increasingly much of this is being automated, and you're having connectivity that is absolutely essential to be your eyes and ears and these wells, because once you start producing oil and gas, these things are hours and hours away from each other.

They're very remote, very rural areas, and so that connectivity is absolutely critical. And you may have you know, we have one customer who has seven hundred sites that they're trying to manage, and so they have to have the ability to do this in an automated fashion, which requires not just connectivity but secure connectivity. Cool. I mean, you know, it's a piece of the of the the industry I never dug into.

So thank you for that. Can I ask you, you know you've said in the modern world, you know, increasingly everything is automated. I mean, that makes perfect sense. The example I often use is you buy an automobile, it's got three hundred CPUs in it.

Everything, Every every device, you know, every non trivial device you buy nowadays has a CPU in it. Can you talk about the automation in these these drilling systems, in these these upstream systems. You know, what does what's that automation look like? Is it like built into the device like an automobile.

Is it a program wile logic controller? I mean, I'm familiar with, you know, power plants vaguely, I mean monthly. I don't get out much. I'm a I'm a software guy more than a hardware guy.

But I've had a few tours. You know, I know what a PLC looks like. If I visited one of these well sites, would I recognize the automation? What's it look like?

Yeah, you would definitely recognize the automation. So what you see is your classic kind of SCATA tech stack, if you will. So you'll have remote terminal units, You're going to have PLCs. You're going to have these things mounted on a din rail in a cabinet and there can be various size cabinets.

At some well locations, you're going to have just a few number of devices. And then at some other well sites, again I go back to the horizontal drilling, You're gonna have a much bigger operation there. You're also going to have those well sites connected to what are called tank batteries, so that you can essentially manage the flow of oil and gas into these storage facilities. So there's a lot of automation that's necessary, using kind of pid control loos to maintain equilibrium within these systems.

And there can also be oftentimes challenges that happen, shocks to the system where let's say, in the case of oil and gas, the price starts dropping. Well, when the price starts dropping, the motivation of the business unit is not to just keep cranking production at maximum capacity, and so you actually want to have dynamically. You want to manage your operation dynamically based on economic conditions that can change over time. And I'll tell you something else, Andrew, about what's happening today.

There's a lot more uncertainty in the business world today than there was four months ago. And I think that is going to affect oil and gas. It's going to affect the price of oiling gas. It's going to affect the supply of oil and gas.

It's going to affect the transmission across borders. So these kinds of things can affect the automation. I'll call it like uber automation. Okay, not just between the actual plant operations and facilities, but also between different entities in the upstream, downstream, and midstream ecosystem.

So there's a lot of there's a lot of very interesting factors that affect that. And I'll tell you one other thing that's kind of interesting. That's everybody's talking about AI, and there are some of the larger oil and gas companies are trying to figure out how to apply AI to optimize their operation. And you know, everybody knows that there's there's automation that's used to help identify ways to to to deliver predictive maintenance to rotating machines, but there's also uses of AI in oil and gas to prevent things like spills.

And one of the big challenges is it's easy. If you go talk to someone at BP or Shell or Chevron and you say can I get data to the cloud, They're going to go, well, heck yeah, there's all kinds of great things that can allow you to get data out of your process. And in fact, I think you're associated with a company that does a really good job of doing that kind of one way transmission of data. And the other thing is, but once you have that data and you're using it to build AI models, then how do you get deliver those set points and control variables back to the process.

It scares the crap out of these people the idea of connecting their control network to a much less secure cloud network or corporate network, because as we all know, security is a continuum. It's not Boollyan secure or insecure. So I think there's a lot of interesting things that are happening with that, and I think just to kind of close the story on that, one company, for example, is pulling that data, they're analyzing it actually an AWS and then they are taking some of those control variables and they're using a human in the loop process so that they'll say this is the recommended set point for this process, and then the human and the loop then implements that through their control HMI.

So there's a lot of very interesting traditional ways in which automations apply to oil and gas, but there's also some very interesting evolving mechanisms that involve machine learning. So Nate, let me jump in and give sort of a bit of context here. Yeah, you know, AI and cloud based systems. In my opinion, these are the future of industrial automation and pretty much everything you know, the question is not if the question is win, because different kinds of cloud systems are going to be used in different kinds of industries at different times, you know, with different intensities.

You know, I care enormously about this topic because I am writing my fourth book. The working subtitle of the book, possibly the title of the book is CIE for a Safety Critical Cloud. You know, when you have cloud systems controlling potentially dangerous physical processes, how do you do that? There are designs that work, you know.

I I'm keen to to listen to the rest of the episode here. I'm keen to, you know, when I had Tom on, I was keen to learn from him. When I write these books, I try not to make up solutions myself. I tend to get them wrong when I do that.

I try to learn from experts like Tom and you know, gather up the best knowledge in the industry and try and package it up in a digestible format. So, yeah, you know, the cloud is the future, and I'm you know, when we recorded this, I was keen to learn from Tom about what the future looks like. And I know we're about to get right back into the interview and what I'm about to say, actually kind of has nothing to do with you just said, but before we go. A few times now it feels like you guys have mentioned the terms upstream, downstream, midstream, and I just want to make sure I'm clear on this before we continue.

Sure, this is this is standard oil and gas terminology. You know, people say, oh, oil and gas as if it were one industry. It's not. Really.

There's three industries involved, and each of these these you know sort of sub industries have a lot of different kinds of facilities. So the stream is generally considered be the pipeline. So we're talking upstream is producing stuff to feed into midstream the pipeline, and downstream is taking stuff out of the pipeline for refining and such. So, you know, sort of next level of detail.

What's involved in upstream exploration is considered part about stream. Initial drilling is part of upstream. Offshore platforms are part of upstream. The you know, onshore pump jacks are part of upstream.

You know, the whole infrastructure building roads is part of the upstream process. Midstream is pipelines and tank farms, and you know, in the natural gas space, you need to do sort of an initial separation and you know, discard waste from the product. You might even need this in liquids to take you know, if you can do an initial filter and take water out of the oil and pump it back down, you know, the dirty water back down into the well, sort of waste or carbon dioxide out of the natural gas.

There's initial processing facilities that are sort of pre sending stuff into the pipeline. There's tank farms where the pipeline store stuff. Sort of intermediate, there's liquid natural gas ports, there's oil you know, oil ports, there's oil tank This is all part of midstream, the process of moving stuff and from place to place, and you know, to a degree storing it while you're moving it. And then downstream is sort of everything you do after it comes out of the pipeline.

So there's refining, turning it into diesel fuel and jet fuel. There's the finished processing on natural gas, taking out all of the natural gas liquids, you know, making it basically pure methane with not much else. You know, there's even you know, stuff like trucking gasoline from the pipeline to the gas stations is considered part of downstream. Midstream kind of rears its head again because you might have the concept of a gasoline pipeline.

So you got the oil pipeline bringing the crude oil to the refinery. Then you've got the you know, you sort of hit midstream again taking the finished product gasoline and sending it to consumers. Then you've got the truck, you've got the gas stations. Each of these sort of upstream, midstream and downstream sub industries has sort of many components.

I've lost it now, but I saw a list once of you know, here's all the different kinds of things that can be in midstream, and it was like I countered it was twenty seven kinds of things. So it's a complicated industry, but very loosely. You know, upstream produces midstream transports and downstream consumes in a sense, refines and produces the goods that we actually consume. Human in the loop, I've heard that described as open loop.

You know, in power plants, which I'm more familiar with, you monitor the turbines the AI and the cloud comes back and sends you a text message and says, you know, you should really service you know, the turbine and generating in at number three sometime in the next four weeks, and it goes into my eyes, goes into my brain. I go and double check with my fingers. I type on things, I say, you know, I think they're right, and I schedule the service that's open loop. And yeah, it gets scary when you start doing closed loop.

And I would say that one of the key things if you look at some analogous systems where they have actually gone from open loop human and a loop, if you will to closed loop, you could. I'll give two examples. One would be autopilot on planes and another would be self driving cars. And in both of those cases, you don't just switch from open loop to closed loop.

No, you do an extensive amount of testing and validation, and you also in many cases build redundant systems that allow an additional level of supervisory control on top of your normal process control loops. And so like an example that I had heard about was a company that was looking at having tank level measurements and looking at an AI model that would actually analyze the input feeds to that tank model. So and it would pull data from third parties that would look at the truck routes for the tankers that were pulling oil from that tank, and so you could actually synthesize that data.

Now you would have to put in place a lot of i'll call it ancillary systems and ancillary testing to make that safe enough to be like an autopilot on a car, because you know, theoretically, now with all that supporting testing, autopilot on a car is supposed to be safer than humans. And with people on their phones like I see them these days, I think that's become an increasingly. Low bar fascinating stuff. The future of automation, I'm convinced.

But you know, if we could come back to the to the mundane, you talked about phishing, you talked about you know, cvees, exploiting vulnerabilities, we're talking about protecting these assets in you know, the the the upstream and midstream oil and gas. You know, can you can you bring us back to cybersecurity? How does how does this big picture fit with with what you folks do and what you're focused on cybersecurity wise? Absolutely.

So. One of the things that's interesting is, you know, I love talking to customers, and I try to spend at least fifty percent of my time actually listening more than talking to customers and understanding what their challenges are and how we can solve those. And in the case of oil and gas, there were three customers that came to us and told us the identical story, and they became our largest customers. And the story they were telling us was that they had these highly distributed assets all over these these very wide geographic areas, and they had spotty cellular and they had backup satellite to enable that connectivity that they need.

They need the eyes and the ears in the field because it would be cost prohibitive for them to get in a truck and drive out there to monitor that, you know, every few hours. So the challenge they brought to us was the security team didn't like the operations team having this insecure connectivity to these remote areas, and so the security team said, you need to do something about that. And that's where blastweed came in, and we said, you know, we can actually use our software define networking solution to cloak those assets so they're undiscoverable to adversaries, but also segment them so that if there were malware that were to get introduced in one area, it would not to others.

And then finally, you would have the ability to get secure remote access. And one of the coolest parts about this is this is not a bump in the wire kind of solution. This is a solution that allows routing and switching between groups of devices and users. So it cuts across firewalls as if they don't exist.

It doesn't route traffic based on source and destination. It routes it based on identity. And this is something I think is very unique to us, and it's something that I think customers absolutely love. And this has enabled us to address a benefit that we hadn't even thought about, which was when oil and gas companies acquire other oil and gas companies that one of the first things they face are the need to maybe reip this architecture because oftentimes the IP space there's overlapping addresses and the you know, that can be problematic.

It can take a lot of time, it can take a lot of money. And that's another solution that we've been able to deliver. Come almost by accident. We had one company, oil and gas company that acquired a thirty billion dollar acquisition target.

That's a big company that you're acquiring, and they were able to protect that with blast shield in three weeks of acquiring them, and they didn't have to re ip anything. Again, that's just because of the way we do this network overlay. So there's a lot of cool things that that use cases that have we've discovered through the process of listening and talking to customers. You know, you've said the phrase sd WAN, you know, software defined wide area network.

I have never figured out what is an sd WAN. I mean, I've worked with firewalls for twenty years. I you know, I did a lot of different kinds of networking, not not hugely. I mean I never worked for a telco.

But but can you work with me? You know, what is an sd WAN? What is your sd WIN? How does one of these things actually work?

What does it do? First of all, I said SDN, not sd WAN, So I said software to find networking, which is a principle, not sd WAN, which is an architecture. So but what I what? I guess the best way for me to think about this, And keep in mind, I'm a chemical engineer, not a software engineer, So that means I'll if it takes me, it may take me longer to understand these concepts.

But when I finally do, I can probably explain them to people. So the the way I've learned this is that we essentially establish we abstract the policy from the network infrastructure, so such that you can have a group of devices or a device itself that essentially associates with an IP address that's an overlay address, much like you get network address translation. All right, so you have an original IP address, you have a translated IP address, and the software to find network then uses the overlay address to both communicate with each other to establish the most efficient route because performance is very important in OT environments unlike IT environments, and this allows us to optimize the path for any given packet, which is also very cool.

So that's one of the elements that I think is important in software to find networking. The other thing is is that it creates this illusion that it is a point to point between two different devices or two different groups, And so that's part of the abstraction. So if you don't have to like set the path, which is what firewalls do path looking at the routing how you go from this firewall to that firewall, from this port to that port, when you just abstract that too, I want to go from this centrifuge to that control room.

It doesn't matter if the infrastructure changes. And this is a very powerful benefit of software defined networking because if you're just looking at the device you want to protect and the user who wants to connect to that protected device, as the environment evolves, and it absolutely will, you don't get put in the penalty box like you would in a firewall situation, where you could get firewall rule conflict. And if one thing to think about, Andrew, is when you think about the breaches that occur, about one hundred percent of those breaches already have firewalls, and so that means that the firewall didn't work properly, which is usually a result of a firewall rule problem, or the environment has evolved in such a way that it's no longer protected.

There's a hole. And of course we all know that adversaries just need to be right once, whereas us defenders, we've got to be right all the time, which is very tough unless you're my wife. So Nate, let me jump in here. You know, I've, as I told Tom, I've wondered about this space of software defined networking wide area networking for sometime and I'm beginning to wrap my head around it.

You know, he gave the example of, you know, you might imagine that we've got you know, the Internet, you know, local area networks. Wire networks were designed so that devices have Internet Protocol addresses and they talk to each other, and you know, routers move messages from one network to another so they get from the source to the destination. Why is any of this complicated? Why do we need any more than that?

One example that that Tom gave was you know, acquisitions. If Company A, you know, I mean there's there's Internet addresses the ten dot series, you know, two to the twenty fourth addresses our private addresses. Private businesses can assign them to their you know address to assets on their private networks, and you know, never show those those addresses to the public, to the public Internet. That's fine.

There's another set, you know, one one sixty eight is a sixteen bit address range that everyone uses. So you might say, so, so what Company A uses you know, let's say ten dot you know, zero dot one through ten do zero dot you know twenty They've got a lot of assets, they use up a bunch of the address space, and then they buy company B that's used the same addresses. Because they're private addresses, you don't have to register that you're using them in public. And now all of the equipment has the same IP addresses, and you know, for each IP address, there's two pieces of equipment in the network.

How do you route messages from from these subnetworks, from these assets to each other. This is the problem of you know, renumbering. When you acquire a business, often you have to renumber. It's a it's a pain in the butt on it networks.

It can shut you down until you're done and tested the renumbering on ot networks, and nobody wants to shut down. So you know, if there's a piece of technology, I mean the textbook technology is network address translation part of most firewalls. It lets you hide some private addresses and assign a different address to sort of that set of of private addresses. You got to you got to set up a whole bunch of firewall rules.

You can do that sort of manually painfully, but you know, it gets worse than that. I mean, I was talking to Tom after the recording. He gave me an example. You know that I didn't capture on the recording, but he said, you know, Andrew you know, they're they're working with an airport, and the airport's building a new wing.

I mean, this is common airports expand and in every you know, let's say there's twenty seven gates in the new wing. Every gate has got one of those machines, those those ramps that that sort of snuggle up to the aircraft and the door opens and people come out and step onto this device that has I forget what the name of it is, moved up to the aircraft and then they walk into the into the airport building. Every one of these devices has automation and has computers. Every one of these devices when you buy it from the manufacturer, the manufacturer assigns the same private addresses to every one of their products.

So now you've got twenty seven of these ramps in the new wing, and every you know, batch of twenty computers or devices that are built into the ramp have the same IP addresses. How do you route this stuff again? You can put firewalls in place. You can do so now you need a firewall in every ramp.

You need technology, and it gets it gets more complicated than that. For example, you know, many years ago, I worked with a bunch of pipelines. I remember one pipeline, you know, one thousand kilometers long, pumping stations, compressor stations all the way down the pipeline. Communication was important.

You have to communicate with these these stations or you have to shut down the pipeline. You know, it's illegal to operate a pipeline in that jurisdiction unless there's human supervis and so you had. You know, there was a fiber laid along the right of way for the pipeline, and from time to time some fool would run a back ode through it. So you'd need backup communications.

I could you not. This pipeline had something like seven layers of backup communication. There was satellites. There was DSL modems to the local Internet service provider.

There was cable modems. When there were a local Internet service provider, there was I don't think I think this was before the era of cell phones. There were there were analog modems that you know, we're talking fifty six kilobit you know, one hundred kilobit per second modems that you could route in an emergency Internet protocol down very slowly. But and and they had built their own by hand.

They had rolled their own what today I think would be called a software defined wide area network, where the task of that component was to say, I need you know, I need to send an Internet Protocol message from the SKATA system to you know, a device five hundred kilometers away. What infrastructure is up, what infrastructure is dead? If a piece of the infrastructure, the communications infrastructure, has failed, then you know, activate another piece of the one of the backups, and change all the routes, change all the firewall rules so that all of the messages that have to get from A to B can get from A to b.

It was, it was, It seemed to me ridiculously complicated, But in hindsight it sounds like the same kind of need that modern software defined wide area networks address. You know, they address security needs as well as just the basics of getting the messages from one place to another when the underlying infrastructure changes from moment to more. I think of wide area network, I think of routing. So there's a routing element, You've got multiple pads.

The system sort of auto heels and figures out the best pads or presumably the cheapest pads. But you've also talked about users and security. You know how does How does this routing concept work with security? How is security part of this?

You've also mentioned firewalls. Can you can you can you dig a little deep? Well? I think I think we in a way are disrupting firewalls that are used for uh industrial, lots of industrial applications.

There are great uses of firewalls. They're a fantastic tool, but it's it's kind of been used like the if you have a hammer, all the world looks like a nail, and you know, especially again, I'll talk about these remote oil and gas locations where you may only have five or ten devices, and so the idea of having a firewall to segment that is ridiculous. The expense would be prohibitive. So that's one of the other reasons why it's so cool about the way we can scale dramatically from protecting five devices at a very remote well site to two thousand devices with a single gateway.

So there's a lot of flexibility that we have that firewalls can't deliver. And when you look at a comparison of a project that involves a firewall as a solution versus blast shield, are we take one tenth of time, cost, one fourth as much. We can deliver this with half the administrative lift. It's much easier to deploy as well, and it actually works.

So there's a lot of benefits that we bring over a firewall a solution. Can we come back to the technology. Can you tell us what does this stuff look like? I mean you said it's not a bump in the wire physically.

What does it look like? Is it a dinrail box at each of these sites? Is it a dinrail box on a central tower? Is it what is it?

Something in the cloud? Can you talk about what is it that is solving these problems? Sure? So there are basically five components that we have to our platform.

The first to create the authentication handshake. One is a client that runs locally on your HMI or on your machine. And then you also typically have either a mobile application that provides the MFA without passwords, and that was patterned after Apple pay. So I spent a decade at Apple, and so the idea was, let's try to use some of that technology to provide stronger authentication.

The other thing that we have is we have a gateway, and the gateway is a software appliance and it can be deployed on X eighty six bar metal. It can be deployed on containers, it can be deployed on Kubernetes clusters, it can be deployed in the cloud awsgcp az're. It's very flexible, and it can be operated both in passive mode and active mode, so in the pat traffic path or outside the traffic path. We also have an agent that can run locally on a machine, which most people know what agents are.

And then finally there's an orchestrator that is used to drag and drop devices and people into groups and then establish policies between those groups. So that's a little bit about the way the technology is set up. And one of the things that we found is that you can have people who are i'll say less sophistic hated than many CCNA trained professionals, so they don't even need to know how to use command line to deploy our solution, so it's relatively simple. We have an example where one person is managing twenty two thousand devices, so again that provides a benefit to them in terms of op X reduction ongoing.

So that's a little bit about the way the technology works and these the way these components fit together. Because that it's your question, Andrew. That's close. I mean what you've described is sort of the pieces of the puzzle, but you know, I'm still a little weak on how they work together.

I mean, again, we've used routing a couple of times. To me, there's two ways to do routing. You can either take the message messages into one of your components, I'm not sure which one and figure out where they belong and send them on their way yourself. You can be a router or and I understand you know sometimes some software WANs can do this.

They reach out to routers like firewalls and just routers and who knows what else that can route messages and they send commands to those devices when things need to be routed differently, you know, is one of these models what you use? How how do you guys do the routing? Yeah, so let me talk about how these pieces all fit together. So the software appliance that is the gateway sits upstream of the switch and usually downstream of the firewall, and what it often will do is it will provide what we call layer two isolation.

And so what that is if you think about we can essentially turn a forty eight port switch into forty eight d lands, so that each one of those is its own ENCRYPTI unit that can't see their neighbors and can't talk to their neighbors unless the policy allows that to happen. And so that level of very granular control is something we can deliver because of the way the gateway controls and manages the routing that you're discussing. Now, there's two other components I didn't really talk that much about.

One was the authenticator and the second was the client. And the client is different than the agent, and so what the client does is essentially is a challenge response between either the sso the PHITO two compliant key or the mobile authenticator. And so what it'll do is essentially produce a QR code that the mobile application would scan and then apply your face ID, and then you would be into the system, but not authorized or permitted to see anything unless the policy had already been allowed.

So that's the way we manage both the authentication and the authorization, and that's also the way we manage routing of traffic between devices, gateways and the groups that those devices are kind of encapsulated in. So in his answer there, Tom was trying to describe things. But admittedly I was getting a little bit mixed up because there were certain things that were upstream from other things and downstream from other things, and layers two and switches, and can you Andrew just help simplify everything we're talking about.

Here In my understanding, they have a few different kinds of components. And I might have got this wrong, but you know what I got out of it was, you know, imagine, you know, firewalls can do network address translation. They can say I've got a bunch of addresses here, I'm going to show you a different address to the world. But you know, managing them in sort of scale, at scale with tens of thousands of devices can be a real challenge, especially if each firewalls only managing a handful of devices.

That's a ridiculous number of firewalls to manage. So what Thomas gott I believe is a I think you call it a gateway device is something that sort of sits between let's say a small network of five to ten devices and the infrastructure, and you can assign whatever IP address you need to to that gateway. It might in fact have two addresses, one on sort of the infrastructure side and one on the device side. So it has a device address that is compatible with whatever stupid little network of five you know, local always reused, you know, ramp IP addresses, the airport ramp addresses.

You know, it's compatible with that bit of address space. It talks to those five devices, and when those devices send it messages, it forwards those messages into the infrastructure, and it figures out the addressing, It figures out the it does encryption. If you've got sort of more conventional Windows or Linux communications, you can put his software on those devices. They that that software will do the crypto.

The software will connect sort of natively into the infrastructure and sort it all out. And then, you know, the thing of beauty is okay, those pieces kind of make sense. The thing of beauty is what I heard was they've got a management system which says, okay, you have twenty thousand devices. You know, half of them have exactly the same IP address.

That doesn't matter. This device over here in this building in this country can talk to that device over there. It's allowed, you know. But when that device wants to talk to Andrew's laptop, because I'm a maintenance technician, Andrew has to provide two factor authentication, so you can you basically you stop caring what IP addresses these devices have you don't have.

You're not configuring routing rules. You're configuring permissions in a sort of a high level user friendly permission manager, and all of the routing nonsense and the encryption nonsense is figured out for you under the hood, so you can you can think about, you know, your your big picture of devices that need to talk to each other, who should be allowed to talk to each other? Instead of how do I route this when the IP address is conflict? You don't have to ask that question anymore.

Cool, So that starts to make sense. I mean, can you talk a little bit about you've been doing this for you know, twenty seventeen, this eight years. Can you talk about can you give us some examples to help us understand, you know, how this stuff works. Having run this for almost eight years now, the journey was not a straight line we went through.

We originally started out, believe it or not, Andrew as a hardware company, and the thesis was to build an unhackable stack. So this sounds naive, and it was. We were going to start with a chip, a new chip that we had a partner developing that would have an onboard neural net. It would create seventeen key pairs, and it would encrypt the bootloader in the factory and burn a fuse so it couldn't be reset.

And that was the foundation of our product. And then we were going to write our own kernel, write our own operating system and this was from someone who helped write the OS ten kernel. We were going to write that in such a way that it used byte codes and would not be exposed to buffer overflows and other issues, so it could We were going to use formal methods to even prove the kernel, and then we'd have our networking layer, which is what our company is now, and then we'd have our own SDK to manage applications that would also use formal methods, and then finally we would have the authentication layer that we also have today.

So we went from a five very ambitious levels of tech stack to two, and then we have other people doing some of those other things. I think the market really wasn't ready for something that complex, maybe that secure from a you know, on the higher end of the security spectrum, if you will. The market just really wasn't willing to pay that, and so we simplified, we pivoted, and then, by the way, once we did come out with our hardware product in February of twenty twenty, there was another global issue that hit everyone that caused us to then pivot to a software as a service model, which then required some more development everything else.

So we didn't really launch our product until late in twenty twenty one and started getting our first customers very shortly thereafter, and since then we've grown very rapidly, to the point where this most recent year we quadrupled our revenue and tripled our customer count. So it's been an exciting ride. So let me give you an example. One customer, again an oil and gas customer, who was again trying to They were faced with a challenge where they were going to have to build their own cell towers, essentially become their own wireless isp.

And this is not unique to this oil and gas customer. There are many that are facing that and I don't know if you or your audience knows, but it's about a quarter million dollars to build a cell tower and you have to have many of them. So in a relative sense, we are not just delivering security to this customer, we're also helping save them a ton of money. So instead of ten to twenty million dollars, they're spending a fraction of that, which is also very interesting.

When they did this acquisition, there was another company that did an acquisition. They wanted to sell off certain components too, So they wanted to sell off the salt water rejuvenation or I don't know exactly what the right word is, but they wanted to offload this asset. And one of the things that they were able to do very quickly because all of our segmentation, all of our granularity and access is done in software, we can essentially just take that new entity, put their users in a group, put the devices that they control into another group, and they would have complete control of just their newly acquired saltwater assets and no visibility, no access at all to the oil and gas parent company.

So that was another great example of using this in a creative way. So you've mentioned acquisitions a few times. I mean, I live in Calgary, this is oil country. I hear about these acquisitions all the time.

You know, is this is this sort of part of the genesis of your organization is is this How often do these things happen? How complicated are these sort of mergers and acquisitions technology wise that happen all the time? Well, they happen very frequently, especially again in oil and gas in the in the case of oil and gas, because one customer or sorry, one asset owner has a certain tech stack that can only profitably make money up to a point, and then they can sell that asset to someone else who has a richer skill set that can extract more profit, more money, more revenue from that same resource.

And I would say an example that we've also seen where people are pleasantly surprised about blast shield is when there's one oil and gas customer that acquired a company and their biggest fear was they were going to have to do an IP space assessment and figure out whether they were overlapping IP addresses. And so instead of having to do that, which they didn't have to do at all, they just deployed our software overlay, and immediately we're able to segment using software each one of these devices, even regardless of whether the underlay IP address was the same.

That saved a lot of money in truck rolls that saved a lot of money and hassle and headaches in managing that that IP space, which which they were very happy about it. And the way they described it, actually they described it two ways to me. One way was, my god, this is like a Swiss army knife, and the other guy said, this is like duct tape. It's like networking duct tape.

It has it provides lots of different purposes, and it's very versatile to deliver things, to basically deliver the network they want with the network they have. So let me just sort of emphasize. Uh, Tom has said, you talked about changing IP addresses a few times. I talked about it a few times.

I've actually, you know, from time to time, had to change IP addresses on stuff, you know, not so much in an industrial setting, just just you know Internet protocol networks, just you know, business infrastructure. And here's the tricky bit. It's very hard to do that remotely. You know, imagine that you want to remote into a remote substation.

There's nobody there, but there's one hundred devices and you have to log into each device with I don't know SSH or remote desktop, and you've got to change the IP address on the device. And at some point you've got to tell the firewall that it's talking to a different network of IP addresses. And if you do that in the wrong order, if you, let's say, hit the firewall first, now you can't send messages to any of the devices because the firewall doesn't know how to route to those devices anymore.

They have different IP addresses, So you have to undo that. Now you go into the device and you give the SSH command a Linux box, you give the command line command to change the IP address, and it stops talking to you because you're connected to the old IP address. You've got to try and connect to the new IP address. Only the firewall won't connect you to the new I address because it's IP address hasn't been updated.

So now you have to sort of blindly change all these addresses. Then you change the firewall, and then you see if you can still talk to these devices, and three of them have gone missing. Why did I fumble finger the IP address? Is there some other problem?

It's just really hard to do this remotely. And so again, if you have you know, seven hundred sites, you've got to put people in trucks and drive out to these wretched sites to make these changes. If there's a way to avoid that, you can save a lot of money. So yeah, I kind of get that that it's really useful to avoid doing that.

So this is starting to come together for me. I mean, you can do the network you know, address management in your what did you call them the gateways, and that you know, gives you an enormous amount of flexibility. But and it's it's the client that does the crypto, or maybe it's the agent I've lost. Yeah, so the client is used to authenticate the agent.

The agent runs on typically a server in the cloud, those kinds of maybe a historian type of applicant use case. The gateway is the workhorse because so much of OT infrastructure cannot run an agent, and so because it can't run an agent, you need to have a gateway that can do the encryption and decryption of traffic. Now, when you think about the way a lot of these processes are controlled, they use PLCs, and the PLCs, you know, we don't encrypt the traffic below the switch, we don't interfere with that.

However, with the traffic that is upstream of the switch, all of that's encrypted wherever it may go. So I think that's that's the way it's done. One other technical question. You know, you mentioned cvees and exploits and vulnerabilities earlier.

I mean, I'm familiar with you know, let's say firewalls that say they do stuff like virtual patching, meaning if there's a vulnerability in a PLC, the firewall, you know, if it sees an exploit for that vulnerability come through, will drop the exploit and will protect the you know, prevent the exploit from reaching the device. Is is that the kind of thing you do when you talk about about protecting from exploits or are you doing something else? We're definitely doing something else.

And I think the approach that we take is we use this networking cloaking concept where you have to authenticate first before you can see anything. There's no management portal, so there are zero exposed web services. If you run a network scan on a UH factory that's protected by blashshield, you're going to come up with nothing. And what that means is if there are cvees, and I guarantee you there will be, there will also be zero day viruses, okay, which may not be on anyone's list.

And so in those both of those cases as well as ancient devices that are never going to be patched. You've got a way to deal with these unpatchable systems because they're unaddressable and so it's going to be very difficult to exploit those cool. So, you know, I understand you're you're you're heavy into oil and gas with all of the examples we've been talking about oil and gas, but I'm guessing you you are active in other industries as well. You know, given your personal background, are you active in other industries?

What can you give me some examples of what's going on there? Yeah? Absolutely, I think manufacturing is a fantastic, uh kind of industry for us. They oftentimes have our a little bit earlier adopters as it pertains to machine learning, predictive maintenance, those kinds of things, advanced analytics.

And we had one manufacturing customer, in fact, who was hacked, and many manufacturers do get hacked from time to time. They were hacked and the board asked the SISO to have an assessment to figure out what their risk posture was, and before they could complete that assessment, they were hacked again. And so this really lit a fire under the entire kind of security team, and they basically came up with a list of findings, and with those findings, they started implementing those findings and they were testing various kinds of solutions.

And in one facility, they had ten different lines, manufacturing lines, and they had deployed Blashield on one of those manufacturing lines. They got hacked a third time. Now this time though, nine of the ten lines shut down, whereas the line that was protected by Blashield continued to run. And what was really interesting about that is how quickly the organization responded.

The CFO of this company responded and elevated that to the parent private equity company. And now that's leading to us becoming the default standard for not just that one company and all of its seventeen plants, but also the parent private equity company and all the other manufacturing facilities that they're trying to manage. I mean, I've learned a lot. Thank you so much for joining us.

Before we let you go, can we ask you to sum up what are the key concepts we should be taking away from from our conversation here. So I think the company as it was founded was tried to establish protecting critical infrastructure based on first principles, and the first principle was to try to eliminate entire classes of threats if possible, and so our solution then tries to eliminate phishing, credential theft, so we have an MFA passwordless feature. We also allow you to segment using software, we cloak your network so it's undiscoverable.

Thirty five percent of all cvees discovered last year are what are called forever day vulnerabilities, and so that network cloaking capability means that they're not exploitable. And then finally, we also have a secure mode access component in there, so we're trying to deliver a lot of value to our oil and gas manufacturing customers so that they when you couple this with a continuous monitoring and visibility tool like a Nozomi Drago's Dark Trace armis Skate Offence Industrial Defender, you know, the group Clarity.

So when you combine those two, you get a ton of protection at a very low price. So that just about does it. Andrew for your interview with Tom, do you have any final words to take this episode out with? Yeah, I mean I really like Tom.

You know, the customer that gave the duct tape analogy. You know, you have lots of little networks, sometimes thousands of devices. Half of them have literally the same IP address or half of these you know, tiny little subnetworks of five devices on on airport runways or on you know, networks that you've acquired with you know, acquiring an oil field. They all have the same IP address.

They all have the same IP address range. None of it's encrypted. It's just a mess and you know this is something that lets you patch it all together. You need crypto, You need authentication.

You know, passwordless is good, use certificate instead. They're harder to fish. You know, you need to hide all of these repeated subnets with the same IP addresses. You need a permissions manager, you know, saying A can talk to BE.

You know you need infrastructure underneath the permissions manager to make the messages from A go to be. You know, you need to have some synthetic IP addresses so that when you set everything up, you know, your SCATA system can talk to an address and a port I don't know, probably on the gateway or some piece of the infrastructure, rather than the real address that's repeated you know, a hundred times in your infrastructure this. You know, this, this just makes a lot of sense.

I I. You know, it seems to me there's a bright future for this kind of of again, duct tape or you know, just patch it all together and make it work, and you know, throw some security on top of it, crypto authentication. This is all good. I'm impressed.

Well, thank you to Tom Cego for speaking with you about all of that, Andrew, and Andrew, as always, thank you for speaking with me. It's always a pleasure. Thank you, Nate. This has been the Industrial Security Podcast from Waterfall.

Thank you to everybody out there that's listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • EP 82: John Ely, The Godfather of FracEnergy Bytes · on Hydraulic fracturing88 / 100
  • Striking Oil - CrownRock by Lime Rock Capital (S3.EP.11)Private Equity Deals with Capital Allocators · on Horizontal drilling84 / 100
  • How One Mapping Tool Powers Oil Rigs, Armies, and StarbucksEnergy 101 · on Horizontal drilling53 / 100
  • Answering Your Energy QuestionsTXOGA Talks · on Hydraulic fracturing41 / 100

More from The Industrial Security Podcast

All episodes →
  • Rapid Recovery - When Security Fails [The Industrial Security Podcast]62 / 100
  • We can't - and shouldn't - fix everything [The Industrial Security Podcast]95 / 100
  • Medical Device Cybersecurity Is Tricky [The Industrial Security Podcast]85 / 100
  • Hardware Hacking - Essential OT Attack Knowledge [the industrial security podcast]95 / 100
  • Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]85 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Industrial Security Podcast episodes →