The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The PrOTect OT Cybersecurity Podcast
The PrOTect OT Cybersecurity Podcast artwork

Todd Beebe: Beyond IT vs. OT, The Common Ground for Securing Any Environment

The PrOTect OT Cybersecurity Podcast · 2023-12-28 · 1h 4m

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence9 / 20
Conversational Craft7 / 20

Todd Beebe brings three decades of cybersecurity experience to challenge the persistent IT vs. OT divide that hampers security operations. His career trajectory - from building Ernst & Young's attack and penetration testing program to serving as an information security officer - has given him unique perspective across industries including oil and gas, finance, and power utilities. The core argument is straightforward: whether defending IT or OT environments, attackers exploit the same attack paths: IP addresses, open ports, Windows devices, and Active Directory credentials. Beebe emphasizes that modern OT networks are structurally identical to IT networks except for domain-specific devices like HMIs, PLCs, and engineering workstations hanging off them. He traces how the security landscape shifted in 2017 with the NSA vulnerability releases and the rise of ransomware targeting Windows infrastructure rather than specialized OT systems. This conversation highlights the resource disparity - OT teams often support distributed, geographically distant assets with skeleton crews while IT counterparts enjoy specialized teams focused on narrow domains like firewalls or virtualization. The episode challenges listeners to think like attackers and administrators performing enumeration, not as IT or OT professionals, but as security practitioners securing TCP/IP infrastructure with business and operational technology layers above it.

Key takeaways

  • →Threat actors exploit the same IP-based attack paths in both IT and OT environments - IP addresses, open ports, Windows credentials, and Active Directory - making the traditional IT vs. OT security separation counterproductive.
  • →Modern ransomware targets Windows infrastructure first, not PLCs or specialized OT devices, meaning compromised core Windows systems can still cascade operational failure even without touching proprietary OT technology.
  • →OT teams typically lack the specialized expertise and resources of IT teams despite maintaining crown jewels like power plants; unified IT-OT teams need shared ownership of network segmentation, patching, and Windows security practices.
  • →Security practitioners should think like attackers performing enumeration on TCP/IP networks rather than adopting defensive IT or OT-specific mindsets; enumeration, credential discovery, and lateral movement work identically across domains.
  • →Cloud and hosted infrastructure represent rebranded hosting solutions with identical IP exposure risks that organizations learned in the 2000s with Code Red and Nimda attacks, requiring the same network segmentation controls.

Guests

Todd Beebe

Topics in this episode

Network segmentationRansomware attacksHMI (Human-Machine Interface)TCP/IP networksWindows Active DirectoryThreat enumerationUnauthenticated remote code execution vulnerabilitiesPLC (Programmable Logic Controller)Engineering workstationsErnst & Young penetration testing

Questions this episode answers

What's the fundamental difference between securing IT and OT networks?

According to Beebe, the core security mechanics are identical - both rely on IP addresses, open ports, Windows systems, and Active Directory - with OT environments simply having additional specialized devices (HMIs, PLCs, engineering workstations) layered on top of the same TCP/IP infrastructure that attackers exploit.

Why did ransomware attacks increase significantly starting in 2017?

The 2017 NSA vulnerability releases introduced multiple unauthenticated remote code execution flaws that threat actors could exploit on default listening ports without credentials, making Windows systems across all environments attractive ransomware targets compared to earlier exploitation methods like MS08-067.

Why can't OT teams just operate independently from IT teams?

Threat actors don't distinguish between IT and OT networks - they move laterally across unsegmented infrastructure from IT to OT because there's no network segmentation, allowing them to target the core Windows systems that control everything, making unified expertise and shared security practices essential.

What should OT and IT teams focus on together to improve security?

Both teams should collaborate on securing the shared TCP/IP core infrastructure through network segmentation, Windows patching, credential management, and firewall configuration - the true attack surface attackers exploit - while specialists handle domain-specific systems like SAP, HMIs, and PLCs.

How does thinking like an attacker differ from thinking about IT vs. OT security?

Instead of thinking in terms of IT or OT domains, defenders should think like threat actors performing enumeration: discovering IP addresses, identifying open ports, finding credentials, becoming an administrator, and determining lateral movement paths - a process identical across all network environments.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

There are a handful of usable operational observations - using Windows Firewall as a compensating control to reduce patch pressure, the 2017 NSA exploit release as a ransomware inflection point, and bringing IT teams in as vendor-accountability advisors rather than territory owners - but the episode is padded with lengthy career origin stories, repeated teamwork platitudes, and mutual affirmation that dilutes the useful content-per-minute ratio significantly.

if you put Windows firewall on those engineering workstations, whatever you want, and you block these certain ports from the machines that don't need to talk to them...I won't bug you about patches again because me as a threat actor, if I can't hit a port, I can't take advantage of a port
the biggest fear is this decision by the SEC to hold CISOs accountable for breaches

Originality

7 / 20

The IT/OT convergence and 'we're all on the same team' framing is extremely well-worn territory; the episode rarely escapes it. The observation that threat actors have shifted from parasitic long-term data siphoning to short-term ransomware destruction, and the 2017 NSA exploit release as the inflection point, shows some genuine pattern recognition, but most of the episode recycles standard industry talking points.

2017 to me is, is when the game changed as far as how no matter what environment you're on, if you got Windows on it, then the threat actors, this is what they're going to go after
the threat actors now eventually they want to be, they want to be known so they can get the ransom

Guest Caliber

11 / 20

Todd Beebe is a genuine 30-year practitioner with hands-on pen testing history at Ernst & Young, cross-industry CISO experience in oil and gas, finance, and chemical, and real OT exposure - not a career thought leader. His credibility is docked slightly because his current employer is deliberately withheld and he acknowledges limited time as an OT-side employee, keeping him more IT-adjacent than a deep OT operator.

got a job with Ernst and Young. They brought me down to Houston where I now live for a role to build their attack and pin UM program. And from there did two startups
been in oil and gas, I've been in finance, I've been in chemical

Specificity & Evidence

9 / 20

The episode has scattered historical specifics - MS08-067, the 2017 NSA exploit releases, Banyan Vines, Novell, Code Red/Nimda - and the host's concrete example of 42 power plants supported by a team of six is the strongest grounding moment, but there are virtually no current named companies, breach case studies, dollar figures for ROI, or measurable security outcomes to anchor the operational claims.

42 something power plants that I was responsible for and my team of six had to support all of those
Ms. 08067. That was the only one I remember because as a pen tester that was the bread and butter

Conversational Craft

7 / 20

The host functions more as a co-narrator than an interviewer, frequently redirecting to his own lengthy anecdotes and consistently agreeing with the guest rather than probing or challenging; there is no productive pushback, no attempts to stress-test claims, and the only substantive question toward the end ('what's coming over the horizon') is a podcast cliché that the guest himself admits he wasn't ready for.

I spent you know, five years as a senior manager there at ey and, and same thing like I never saw myself as an, as a consultant or an advisor
Yeah, 100%

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A67%
  • Speaker B33%

Most-used words

team34trying26didn26figure24vendor23environment22technology21different20threat20windows20somebody19almost19back18cyber17together17organization17

Episode notes

About Todd Beebe: Todd Beebe, a cybersecurity veteran since the early 90s, commenced his journey by thwarting attempts to hack his BBS. His expertise led to pivotal roles with an international organization, securing remote access, fortifying websites, and pioneering firewall deployment. Later, at Ernst & Young, he spearheaded the Attack & Penetration practice in Houston, penetrating Fortune 500 clients and contributing to the precursor of the Hacking Exposed book series. Todd's entrepreneurial spirit thrived as he founded cybersecurity companies, notably inventing the telecom firewall 'TeleWall' and the web application firewall 'eServer Secure,' holding nine US patents. His career includes fortifying the White House and Pentagon against cyber threats and building cybersecurity programs for multiple Fortune 500 organizations.

Full transcript

1h 4m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Cybersecurity concerns are ever evolving. OT cybersecurity is even more complex, and it's so much more than just software and hardware. How do you stay on top of it all? Aaron Crowe has over 25 years experience with cybersecurity. Fifteen of those years focused on operational technology across multiple industries, and he wants to help you. Welcome to the Protect OT Cybersecurity Podcast, brought to you by Industrial Defender. Now, here's your host, Aaron Crow.

Speaker B: All right, thank you for joining me, Todd. Uh, why don't you introduce yourself, Tell us who you are a little bit about yourself and your background.

Speaker A: Uh, yeah. Todd Beebe, information security officer, my current employer. Try, um, to keep that secret. Um, been doing cyber, uh, as well as I can. Been doing cyber for a little over 30 years. Got, uh, into it. One thing led to another. Wasn't my plan to do anything in computers. I was planning on going into law enforcement, but, you know, just how life goes. So, uh, luckily it stuck with me and had, uh, a pretty good career.

Speaker B: That's awesome. So what was that, that path like? So, so you were actually, like, going to school and learning for that, and you. You had a. You had an alternate path that approached yourself?

Speaker A: Um, yes. Ah, so here's how the story goes. It's like I was. I was in, you know, kind of the math classes and other things, advanced math classes when I was a kid. I was. I was trying to do everything I could to stay away from the geekdom, and, uh, didn't take a computer class in school, was planning on going into law enforcement, maybe go back, go to law school. And, uh, when I graduated, uh, shortly after I graduated college, one of my friends bought a computer to play, like, Duke Nukem or some game like that. And I thought, okay, that's. That's cool enough, right? It's, uh, that's. That's not nerdy. That's kind of fun. So I bought a computer. Uh, next thing I know, I was taking it apart, putting it together, helping other people kind of set up their computers, um, set up a bbs. And, uh, again then after just a few short years, uh, a company in Lincoln where I was, uh, born and raised, um, decided they needed somebody that handled their remote access. And since I had the BBS experience, it was kind of a natural progression. And then after that, they said, hey, Todd, we're planning on getting, uh, this 56k line. Can you go set up this Internet thing? And so that's what I did. And it's like, hey, Todd, you know, there's this firewall. Can you go figure that out? So it was kind of like I was one of the guys on the team was. You just go figure it out. So whatever it was, um, and I did that for a number of years where I was really kind of the security guy for the organization doing kind of. I wouldn't even call pen test back then. It was just more vulnerability assessments and that kind of thing. But did enough, I guess, got uh, enough experience that I got a job with Ernst and Young. They brought me down to Houston where I now live for a role to build their attack and pin UM program. And from there did two startups. And it's just, it's just. But again it was not in my plans. My plans. My plans was to go to law enforcement and to get into law school. So uh, but uh, it's, it's been a great career and I love it. I, I try to do whatever I can to get other people into it and uh, teach and uh, it's, it's that's just again one thing led to another.

Speaker B: Yeah. You know, it's really amazing how careers happen that way. Right. Similar path. Right. I went to school for engineering and, and ended up in this path. I was really good at this technology thing and it was just, you know, like something natural to me. And it started out as a part time thing and then it turned into this whole, you know, long career that I've had. And a lot of the time I was the guy that, you know, raised my hand. Does anybody know how to do this or does anybody want to volunteer to try? And I was usually the one either that was either fallen told or I raised my hand and you know, signed uh up for it because I was like, oh, that sounds interesting. Let me try that. Right. So, so a lot of my career was, was that in figuring things out. And you know, I got into OT cyber before that was a term. Right. We didn't call it ot. There was no ot. But um, it was the same thing like it was before. It was pen testing, you know, and even the path at ey, you know, I spent you know, five years as a senior manager there at ey and, and same thing like I never saw myself as an, as a consultant or an advisor, especially in like the capacity and you know, PowerPoints and uh, you know all of the stuff that comes with being an EY consultant, um, was not my forte but you know, mine either. Yeah. And, but, but you know I learned so much during that and I was able to see and it Helped me, you know, get into the role that I'm in now, right, as a cto, because I was able to see not just the technical stuff, but the business stuff and all those other pieces that tied in together that I wouldn't have probably been able to see, uh, without being in ey and being in those different, you know, being asked to do different things beyond just my, My technical prowess that I was. That got me to, you know, that one position. It's, it's, uh, I don't remember the name of the book, but, you know, what got you here won't get you there, right? You need to be able to do the other things, the soft skills, the, the presentation that public speaking things, things like that I use on this podcast all the time. That my technical skills didn't necessarily help me now. Without those skills, I wouldn't be able confident to have these conversations with really smart people. But. But I also need these other skills as well.

Speaker A: So it's one of those things when you look back, the steps kind of, you know, kind of the little, you know, pebbles or rocks that are kind of building and built your career, you can kind of see, hey, that now makes sense. It's right when it, look, when you look back, it makes sense because right now, uh, you know, when I was, when I. Even when I look at it says it doesn't make sense to me that, that I was. Because it wasn't even on my mind. It wasn't a plan. I mean, one of the guys I work with that was early in technology, he was formerly a welder, but he was one of those guys that had that mindset of, hey, he's the guy, he'll figure it out. Right? And I think that's what really started, uh, cybersecurity. And a lot of people that I know in cybersecurity that are, you know, from that generation were the hey, you go figure it out kind of thing. Um, because there wasn't. There wasn't a. There wasn't really training for it. There was. There was no kind, uh, of discipline for it. It was just a part of it. But it wasn't. It wasn't the typical idea of keep everything up and operational. It was almost try to figure out how could this get broken and try to prevent this, you know, prevent things, um, but also detect them. It was, um. But, yeah, looking back, it makes sense. But when I did it, it was like, this doesn't make any sense. But like you said, now I'm more comfortable because I had to go up in front of CIO's Fortune 500 companies. Barely. Pretty, pretty early in my career. It gives the confidence for that public speaking that eventually is starting to even show up even more now today than it showed in my previous and uh, my previous year. So uh, yeah, that seemed to be a common theme.

Speaker B: Yeah. And you know, you couldn't go to the guidance counselor in high school and him map out the path that you know, a lot of times your career takes like there is no path like it was left and up and down and sideways and, and ah, two steps back and four steps forward. And sometimes you just have to be willing to take a risk and jump off and, and learn some new skill. And you know, it's just like with anything, whether it's, you know, jiu jitsu or learning a language or whatever. The thing is you have to be willing to suck at first before you can get good at something. Right.

Speaker A: I think that that's the thing is you just can't be afraid of failure.

Speaker B: Right.

Speaker A: Right. It's like I'll keep failing until I finally figure this out. I don't even think of this failing. It's just another attempt.

Speaker B: Right.

Speaker A: So I think when, when people get um, you know, bothered by the failure, they'll stop before that next step would have got them moving forward. And I think it's just that mindset of that's why they threw stuff at us is like they'll just go figure it out. They won't stop until they figure it out. That even though, you know, there's no, there is no expectation of success because they've never done it before. Who brought in a 56 day line, who set up firewalls before is like nobody on the team. Okay, we'll just go figure it out.

Speaker B: Right. So uh, and a lot of the stuff we do, nobody's done this stuff before. Right. We're, we're charting new territory. So it's not like you can find a, a perfect example or even hiring an eye. A lot of the things that we do sometimes is, is, is a one off. It's, it's something that nobody's seen before exactly the way that we're doing it. So it's not like you can go find a perfect example of somebody that's done this 12 times and bring them in. So somebody's gonna have to figure it out. Why not you?

Speaker A: Yeah. There's no 200 page manual that's going to walk you through it. It's like somebody else is building the steps on some notepad somewhere. You know, that probably Excel spreadsheet is like, they're tracking it down in case they have to do it again. It's like, let me try to remember this stuff. But then the next time they do it, they don't have the list. So they do it a little bit better the next time because they're, they're not hampered by. I just got to find a, uh, routine and stick to it. It's no how can I improve it. It's that that mental challenge of continual improvement I think is really very, is key to being a good cybersecurity person.

Speaker B: So what are some of the common uh, or bigger things that stand out for you as far as maybe issues that you've seen maybe in your current role or even a previous role that we're, we're still faced with today? A lot of times in ot, we face the same thing over and over and over again. What are some of those things that maybe come to mind for you?

Speaker A: Um, so this one might be a little challenging with the OT that OT stint, uh, on or our um, view of this, of this podcast. But the ot I see a little bit of what I seen very early in my career where it was the IT guys and the telecom guy, there was like two closets. And then all of a sudden, you know, Cisco or whoever was coming out with voiceover IP and it was kind of the writing was on the wall that these things were going to merge because that's just, that's just, that's Mother Nature. She likes things efficient and she doesn't like repetition. And I see uh, the same thing with OT environments where there is this hesitation of hey, it is going to come in and want to do it their way. And what I tried, what I've tried to find in my career when I've uh, been in um, environments and I currently in with OT environments or OT crew is, is trying to find that commonalities because to me I tend to not focus as an IT person. I'm a cyber person no matter what the environment. I mean I've been in oil and gas, I've been in finance, I've been in chemical. And to me I think uh, like because early my career as a threat actor, not, not a criminal one, even though we won't talk about what I did when I was under 18, but that I was paid to focus on where's the gap? And I think I still think like an attacker. And to me I don't look at OT and it. I look at. There's IP addresses There's ports, there's probably windows, there's probably active directory. It's like that, you know, whatever else hangs off it, I'll get to that later. But if I can master those four things, just get an IP address, get a port open, figure out what's listening, it, uh, doesn't matter to me what the environment is. If, uh, you can't stop me as a threat actor from figuring those parts out, I'll eventually get to the things that are most important, like SAP or, uh, hmi. Ah m. Or an engineering workstation. I'll get to those. If I can get an ip, get a port, get access to that, get some credentials. I mean, all those are just common denominators. So I tended to try to focus on common denominators of. Hey, guys, I know we, you know, we're not, I'm not an expert on this certain, um, protocol that you guys are using, but does that machine have an IP address? Do you know if it has open ports that I can get to without credentials? Or do I need credentials? And are those default credentials? I mean, it's, those are the things I focused on as a threat actor. I mean, usually when we did a pen test at Ernst and Young, of course that was early days. Within 30 minutes we'd have credentials and open ports and IP address. So beyond that, it was pretty much starting to write the report of what can we get to that's most important on it. But we were already kind of, you know, we were already settled in as, uh, an administrator pretty quickly. And so when I talk to individuals, whether it's the individuals on my team that are, you know, on the IT or OT side, trying to harden the environment, I'll say this is how you need to think. Like, I don't really. I try to stay away from, think like an attacker, but think like a, think like an admin. Nowadays, like you're very, your very first admin or your new hire admin, they're going to try to enumerate the environment because they got to figure it out. They're going to try, you know, they're going to be doing the same things as an attacker that lands on a box is. Now I got to figure out what's going on. So they have to, they have to do enumeration, they have to find some credentials, but it's, it's not. And you know, I'm trying to stay away from it OT Telcom, you know, because all the networks are eventually going to merge, you know, IP when IPs came out, or, uh, TCP IP came out. Banyan Vines and all those other things, Novell, you know what I mean? As soon as Microsoft decided to, I think it was TCP IP or something bundle and get an IP address on those Windows boxes, it was kind of the beginning of the end of all the other just networking solutions that were trying to put a different network. We'll call it OS or network, you know, what's the word? There's a word I'm looking for. But, um, the, you know, the TCPIP is really what's driving it all. Whether it's driving the Internet, driving companies internally, driving OT networks. And anything that hangs off it will be able to be accessed by threat actor if there's not the right controls in place. So that's, that's where I focus to try to secure something is what are my attack paths, right? What's available to me to get from point A to point. Very important. Right?

Speaker B: Sure.

Speaker A: Uh, so, you know, you know, that, that, that's how I think of things. So stay away from IT versus ot.

Speaker B: Yeah, well, the thing about that though, right, is, is definitely I've been on both sides of that, that table, right? I've been in the IT seat, I've been, you know, hesitant to let me in, and I've been in the OT seat where I, I didn't trust the IT people, right? But to your point, uh, it's the same technology. Uh, and, and as an asset owner, when I was working at a power utility and I was the OT person, right? And, and it was my responsibility for all the power plants and all the OT technology. It was. The insane thing was that I had 42 something power plants that I was responsible for and my team of six had to support all of those. And in my invite tech stack, I had firewalls and VMware and Windows and a patching solution and antivirus. And I had that times six at every location. And I had six people to support all those physically geographically distant locations. And I had a team of six to do everything. And they had to be an expert, not an expert, but they had to be good enough in all of those capabilities where when I looked across the aisle at my IT counterparts, they had an entire networking firewall team and they had a VMware team and they had a, uh, switching team and they had a application team and they had hundreds of people that were supporting each of those things. And all they had to dedicate was on Active directory or Palo alto firewalls or VMware. Yeah, they were specialists on those things. My guys had to be good enough at all of those things. While they weren't experts in any, nor could they do, there, uh, was not enough time in a day for my small team to do all of the. What I would want a normal admin to do on normal preventative maintenance in these environments just because of outage windows and I can't patch and they're in different locations and I have to send them in a car to go out there because we don't want to do it remotely and like all of these reasons. So we're constantly fighting, you know, whack a mole, you know, we're supporting things, we've got cyber issues, we've got patching all these things in a small team where the IT team has more funding, more resources, more training, more people like uh, everything about it. But OT is really where the crown jewels were, especially in a power utility.

Speaker A: That's where the money's made, right?

Speaker B: If the plant goes down, the IT stuff doesn't matter.

Speaker A: Right. Everybody can send each other an email and we can check into SAP to say we're not making money right now because ot.

Speaker B: Right, exactly.

Speaker A: I agree. What's funny is I've thought that same thing that kind of the newer organizations and as OT environments get mature, they look identical except for some of the devices that hang often to an OT network, whether it's Cisco gear, VMs, virtual, you know what I mean, IP addresses, Active Directory. And that's what, that's the attacker's bread and butter, right? When you think of a threat, that's what they know it. They're not going to like MO in most cases. I haven't heard of too many organizations where they have an SAP environment that, that's getting hit. As soon as somebody gets in, you know, they're just going after the Windows devices. Especially now since it seems like what really changed to me is 2017 when those new, all those new vulnerabilities that, you know, certain rsa, not, uh, rsa, NSA had got released from then I think it was around that almost that exact same time that ransomware became a thing is because now they, they figured out, hey, if we go after these devices on just some ports, they're listening on by default, boom. Because before that it was like MSO, Ms. 08067. That was the only one I remember because as a pen tester that was the bread and butter. There was no other really major, like if you had this and you could get to a machine that was listening On a port. That was it. You were on it, right?

Speaker B: Yeah.

Speaker A: And since, since those releases, it's like got the threat actors thinking, uh, of like, if we can find more of these. And now there's a lot more of those vulnerabilities where it's just unauthenticated. If you can talk to the device, you can get on the device as a system. So it's just that thought process of 2017 to me is, is when the game changed as far as how no matter what environment you're on, if you got Windows on it, then the threat actors, this is what they're going to go after. They don't ransomware SAP, they don't ransomware. Well, engineering workstation, they run on Windows. Yes, but they don't ransomware PLCs. They ransomware the core and then you can't. Then everything else stop. Right? It's, that's, you know, to me, if we get more people thinking like that, they'll think, okay, we really have to bind together IT and ot, uh, bringing together the expertise of how to secure that core infrastructure that everything that's custom for that environment, whether it's some business that doesn't us SAP, but they, they have other applications or tools that they use that, that are unique to that organization. They still have Windows, they still have virtual, they still have, you know, core TCP IP networks, all the devices that hang off, uh, you know what I mean? It's, it's getting that mindset of, hey guys, we need to work together. Because the threat actor doesn't care what network they get on, whether it's IT or ot. It's where can they make money, right? They can move from IT to OT because there's no segmentation. They'll take that out too. You know, they're not, they're not picky. They're like, we need to get in, figure this out. Like I said, become an admin and figure out what the lay of the land is and what credentials do I need to get to where. And then boom, late, the booby trap and leave. And then, you know, the ransomware hits. So you know that that's why I think the teams really need to work together and, and just think of different. It's an ip, it's not IT or ot, it's ip. Plus there's technology systems that are business oriented as far as SAP and all those other applications. And then there's, there's HMIs, you know, engineering workstations, PLCs, etcetera, that are hanging off that. But the rest of it, whatever, those are just the custom things hanging off of it. The rest of it's all the same. So they almost should have this. They should be, you know, tied at the hip of their specialists for SAP. In the IT world, there should be specialists for, for, for PLCs or engineering workstation or how to configure those. But still those two, uh, the other teams and network, kind of the network core, kind of Windows networking team should just be tied at the hip as far as, hey, who's got the most experience with this? Educate us on how we can do that too and feel comfortable putting in that patch or putting in Windows firewall or putting in some segmentation because you guys have already done it over here. So, uh, because really that's what it's going to get down to is. I mean that's what we did back in 30 years ago. It was we connected all these web servers to the Internet, figured out people are eventually going to be mean, M oops. Just want to come to our website, just visit our stuff. They're going to try to attack it. It's like, shit, now we got a segment. And so that segmentation is just kind of whittling down to now to almost to the device level. And then of course then we decided, let's do cloud. Let's put them all out back on the Internet where anybody in the world can hit my OWA server or anybody can hit my Azure server or my AWS server. It's like, hold on, didn't we learn this 30 years ago that just leaving it out to hang isn't going to end well if we don't put in some kind of controls? I mean, uh, I just think a deja vu. I've talked about this for previously. This, you know, the cloud slash hosted is just deja vu. It's all an IP network. Right?

Speaker B: It's a, it's a new term for the same crap we've done before.

Speaker A: Right, that's what I meant. Let's just, let's just rebrand it Cloud. That sounds sexier and doesn't sound like it's hosted because we've been doing hosting for 20 years. Years. People didn't really want to do it because security had enough gumption to say, hey guys, we already did that. We already had our web servers hanging out to dry and guess what Code Red Nim Day hit. Yeah, that wasn't a fun day. So let's, let's try not to do that again. Um, but again, I don't mind. It's the new challenge of trying to figure out how to, uh, keep this secure and keep it running. But to me, I've seen this before and it's like, let's try to use some of the known controls to control IP networks and ports and applications and I think then we can get down to, uh, we'd all be on the same page versus us versus them or these are different worlds because I don't think that's going to solve it.

Speaker B: Yeah. And you hit something really, really important there. And I agree 100%. Right. We have to do this together. Right?

Speaker A: Yeah.

Speaker B: There's definitely differences in IT and ot. Um, there's, there's no doubt, there's intricacies and, and I've seen it again because I've lived in both worlds. But there's definitely value in the knowledge that we have in the technology and the IT side and we need to be working. So, so I know like Idaho National Laboratory is working on the cyber informed engineering. Right. So, so they're looking at that. And how do we tie our control system engineers with, with an understanding of cyber? You know, I, uh, uh, spoke with Andrew Ginter a little bit earlier and he said the way he described is like it's two sides of the same coin. It's, it's the cyber side and the engineering side. Like we know how to design systems, but we also need to bring in the technology, the IT side. Right. And part of that is, you know, it goes back to what we talked about before. It's those soft skills. I've been there and had to win over an OT person and went over a plant manager. And I didn't do it because I convinced them how smart I was. I didn't do it by convincing them they were stupid and I knew more than they did. Uh, on this technology thing. I did it because I made them trust me. And how did I make them trust me? I built a relationship with them. I understood their perspective, I understood why they were concerned. I asked questions on where their issues were, what, you know, touched the doll and where, where somebody hurt you in the past. Right. Because most of these, these experiences came from an IT person came in, they said they had a plan, whatever they did broke my stuff and now I don't trust them anymore. Right. So, so we can't just do that again. We can't just take IT processes and cram them into OT and hope it works again. Because just like you just said with Cloud, we've done this before and they've done this before and they're not going to do that again. They've been burned. They're not going to do it again. So we have to approach it differently. That doesn't mean we don't. We can say no and just ignore it and continue to keep OT and IT separate because we think that makes us better. Because it's not like it's not a long term solution. We've got to get to a place where we're on the same team. We're, you're offense, I'm defense, or we're both, you know, uh, you're right guard and I'm left guard. But we're both on the same team fighting the same goal. Like we're defending the power plant or the manufacturing facility or the train or whatever it is that we're protecting. But we're not enemies. We're on the same team fighting the bad guys. And they're over there, they're in a different uniform. We have the same uniform on and we've got to be able to have those conversations.

Speaker A: Yeah, yeah. So what I visualize when you say that is, is, you know, I'm always trying to come up with analogies but there's, you know, the, the Iot things. But if, if to me it's. If we made a new slogan, I, um. Ito, there's information in a business, whether it be SAP, the financial information, the documents, the email, uh, ah, all the stuff that's really on an IT network, right? It's really information focused. And then the, the on the OT side, the operational, that's, that's all the PLCs, engineering workstations. But what they both have in common is that technology, technology is the common. So that it's almost like they're, they're, they don't realize. It's almost like they're Siamese twins and they want to be a little bit different. But it's like guys, you, you have so much in common. Just look in the mirror, right? It's like if you guys would just tie it together and realize that you both have that underlying technology that they both are living off of, right? Is okay, let's figure out how can we make those both. Both. You know, what can we, what lessons can we learn in both environments to be able to secure. Uh, like what, what I've told OT guys my, almost my entire career is, hey guys, if you put Windows firewall on those engineering workstations, whatever you want, and you block these certain ports from the machines that don't need to talk to them. Um, so they're not your patch management system. Whatever you need to talk to them. I won't bug you about patches again because me as a threat actor, if I can't hit a port, I can't take advantage of a port I can't take advantage of. If that's Windows XP or Windows me, I can't take advantage of it. Or if it's Windows 2022. Right. I uh, can't take. If we can put some of those controls like I said, that I've been doing for 30 years, the Internet, if that, that if we can get to that level where we can get some comfort of just getting some visibility into your environment so you can see what is what talks to what and what really needs to talk to what, then we can kind of lower all these, this pressure of you got a patch, you got a patch, you got a patch, got a patch.

Speaker B: Right?

Speaker A: It's, let's, let's patch the things that make ah, an operational impact. Like, like the reason you're putting in this patch is because the system will go blue screen if somebody logs in this way.

Speaker B: Right?

Speaker A: That, that, that makes sense to me. You won't have to put it in because Blue keep or the next, the next name vulnerability Blue Keep or turn a blue or whatever comes out and then, then it's like, okay, what do we do? What do we do? You know what I mean? It's like how quickly can we get them out now? Even though we don't have the cadence of putting them out quickly. So it's, it's just being able to tie at the hip and say hey, we're, we're Siamese twins. We, we have common ground. We have common um, objectives. We do have differences. Uh, but we also have a lot in common. So, so let's figure that out so we can leverage each other versus um, like you said, have just have some bad memories of somebody who didn't know what they were doing coming in and trying to force something. And then it blew up and now we just can't kind of get past that because, because that, that, that made a big impact in our world. Right?

Speaker B: Yeah.

Speaker A: Um, so I'm thinking, you know, that that's what I try to talk about more when I, when I'm called to make speak, uh, speak is let's find that common ground because that there is that underlying, I mean there was a guy that just showed a slide at the last seminar. Uh, I was not seminar but a conference and he showed, okay, here's level one through level five. That most people think of. And he says, this is it and this is OT. He goes, Nope, level two and above, that's pretty much IT technology, right? Uh, it's Windows and VMware and Cisco and you know, all those different, you know, IP based solutions. That's level two and above. Level one is kind of the unique stuff to ot. And you know, once we all realize that, we got to work together on those parts because, because even IT as specialists for SAP and, and the home, you know, the built in or the company built applications, all those have specialists. So we can still have specialists over here, but we need the, the team that's doing the core to all be on the same page and working together to share that knowledge and share that experience. So we can, we can do it right, and we can make sure, you know, cybersecurity has a seat at that table that says, okay, now let me validate what you guys did to make sure that the, the controls you want in place are actually blocking what we want IT to block. Um, you guys will confirm it's allowing what you needed to allow. So I think we're going to get there. I think it's just, it just felt like, like I said back in the day when there was the telecom guys and the, the IT guys and they kind of knew eventually there's only going to be one wiring closet. So eventually we're going to be in there together. And so let's find some, let's find some common ground.

Speaker B: So the, the irony is I've been in, I've been in those rooms where, you know, there's, there's the IT rack next to the OT rack and they're the same rack and you open up the cabinets and they're almost the exact same gear inside of each of them. But the IT guide can't open. He doesn't have the key to the one on the OT side. It's just like, come on guys. Like, okay, uh, again, we're on the same team and, and part of it I get, I keep that signal, right?

Speaker A: Like they almost look identical. Like you could put a mirror up and like, which one's yours?

Speaker B: Exactly. Let me blindfold you. I'm gonna take the labels off and you tell me which is yours versus the other one.

Speaker A: And it's like, hold on, I didn't have mine in that order. That's the only reason. It's same as same ass gear for everything. So, yeah, that I think, like I said once, I think once that becomes more apparent that there's more common than not common. Um, that I think the pressure will go down that it's not a takeover, it's just a merger. Right. Um, that's what it was with it and the telecom guys. It was a merger. You guys are still the specialists in your area. We, we have, we're the specialists in the core network and we have specialists for the applications. You know, everybody can. Then folk, like I said, then people can focus instead of becoming a jack of all trades and saying, okay, hold on, I got to work on the engineering workstation today and try to figure that out. No, no, no. Uh, this database over here that I'm not really an expert on, I got to figure out what it's like. You know what I mean? It's that, I mean that's, that, that's got, that's got to be a high stress situation. Right?

Speaker B: Uh, well, and I can see why.

Speaker A: Hesitant.

Speaker B: Yeah. And up until now, a lot of the ot, you know, you're, you, you lean on your vendors up until now, so you're leaning on your control vendors and you're hoping that they have the expertise. And up until now, like 20 years ago, they did have the expertise because it was all proprietary and it was one off and, and custom. But now when they started bringing in commercially off the shelf equipment, when they started bringing Cisco and Microsoft and all that type of stuff, these control vendors aren't experts either. Like, they started bringing in things they didn't know the impacts of.

Speaker A: Yeah, that wasn't. Nobody on their team wrote it. Nobody on their team is patching it. No one, no one's figuring out the next features. You're right. Nobody's testing it and installing it back

Speaker B: and over to the level that it needs to be, at least. Right?

Speaker A: Yeah, well, I didn't even think about that till you just said that. But you're right. Now they're, they're kind of, hey, they decide, okay, that's not our thing anymore. We'll let, we'll let the uh, you know, mother nature take over. She says the strongest wins. And IP1, the network battle, Windows bun Windows pretty much won in most cases, a majority of servers. I mean, there's Unix out there too, but. And you know, then there's virtual. That's coming up. It's almost like that's just the wave and it's trying to stay ahead of the wave. And I didn't think about that. That, yeah, even the vendors don't have, you know, do they have 20 year windows veterans or 20 year, you know, Cisco or whatever the uh, IP on their team that's coming to you or is it, you know, that application. Right.

Speaker B: And most of the time when they're deploying it, the vendors will show up and the, their field engineer that's deploying it is the, is the control system guy. So he's the OT guy, but he's rolling out active directory and firewalls and all this other stuff that he's clicking a box and he's following a script.

Speaker A: Uh, oh yeah.

Speaker B: When it doesn't work the way he expects it to, he doesn't know how to respond. He or she doesn't know how to respond. And I've seen it backfire in real time in person and seen the implication of that not going well and what that can do. So it's, it's all the way up

Speaker A: the chain made me nervous as an asset owner. That, yeah, like it happens. Yeah. Because that's who's, who's, you know, got, got their, you know, 24, 7, 365 contracts to maintain the entire environment. Uh, then they're like, the guy coming in is like, but I just know this application because this is what we built. But yeah, give me, give me, give me the booklet so I can run through the config. What's the default password? Okay, I'm going to enter that so I don't have to worry about if I, if you guys call me in the middle of the night, I'll know what it is. I won't have to ask or nobody else stays it. So it's, it's kind of, um. Yeah, yeah, you shouldn't have told me that. It really makes sense. Oh yeah.

Speaker B: It gets to the root of the problem. High level. We need to have a conglomerate within the organization in each organization that you have a big picture understanding of what's going on in my environment. Like having an OT specialist is great and that's, you should maintain that, but you need to have somebody you know when you're, when the vendor is bringing an active directory. There's no way you can expect that, that OT guy, uh, to be an expert in it. So why don't you consult with your IT brethren that have an active directory expert and bring him in. Not to design it, not to tell them everything they're doing is wrong, but to say, hey, have you thought about this? Have you looked at that? Oh, we've seen that problem. This is why you don't do it that way. We should implement it this and make suggestions. Same thing on firewalls, same thing on Networking. Same thing on VMware. Like you have these entire teams of it people and if we start training and having this dialog where they're brought to the table as advisors and not hey, you own this and now you're responsible for it and you're going to, you're going to cram this configuration down the OT guys throat. That's never going to work. But if you, if you bring them in as advisors and say, hey, why we were bringing this vendor and they're bringing an active directory in VMware and Cisco and Palo Alto and XYZ, I want all, somebody from my representation on the IT side to sit in these meetings and ask questions, ask the vendor how are they configuring it? Make sure that you're doing best practice. Make sure they're doing, you know, they're, they're checking the boxes and doing the configuration correct. They're not leaving default passwords, they're not, you know, leaving vulnerabilities open that we know, you know, you should be doing in normal baseline. You should lock down, turn this off on this device, disable this thing. Yeah, just a normal basic stuff we do on the IT side many times are missed on the OT side because nobody asks the question.

Speaker A: Yeah, that's a yeah. What you're saying just rings true to me is like just looking at them as advisors because it isn't that they're holding and hopefully the ot, if they're listening to this, bring them in as advisors so they can hold the vendor accountable. They're not there to point fingers at you guys. They're there to hold the vendor that's deploying this, that's selling you this and deploying in your environment, holding them to, to hey, you know, asking them the right questions to see are they giving me a base install that's left with a bunch of default passwords or default accounts that the uh, threat actors already know what the hash is. You know, who knows. But you know, always bring in somebody that's been there, done that. They can say, okay, here's, here's the five things or here's the top 10. I would recommend you almost as a consultant, an in house consultant, right? So bring them in and say, hey, they're talking active directory or they're talking VMware, they're talking Fortinet or they're talking, they're talking these different tools. Do we have anybody in the organization, not just our team, anybody in the organization that's been there, done that with that so they can come in and Say, okay, you know, you might not be able to tell us all the things we need to know, but at least tell us what should we not do? Like, what are the mistakes that have already been made? Let's not make those, let's not make those again. I mean, we do it all the time with Cloud and all that, but let's not do that in our own organization. Let's let the world do it, but let's try to, try to leverage somebody else who skinned their toes or skinned their knees and so we don't have to do it again. They're not trying to take over territory, they're just trying to share their knowledge. Uh, you know, IT builds, builds bonds between teams. When the shit hits the fan, then you know, you can trust the other person because they were there to support you, you know, not hold you accountable, hold your vendor to a higher standard of uh, hey, deploy this. Right? So we have a stable environment. Because that's the ultimate goal of an OT environment, is uptime. So, so let's do it right, right. Let's, let's hold them accountable. Even more so than in the IT network where there's a little bit more give on things, you know, kind of coming and going or going offline for, uh, you know, a little bit of time. So, you know, I like that idea of trying to figure out how we can look at other teams in the organization as advisors versus they're going to take over our territory. Right. And they're trying to hold the vendor accountable. Not, not, not our own team.

Speaker B: Yeah, yeah. And one way I've seen that be successful and in a few organizations, really advanced ones that I've been fortunate enough to be part of and help kind of advise is, you know, almost like a service catalog. So the IT organization almost has a service catalog of options. Hey, these, you know, we're really good at active directory and firewalls and networking, blah, blah, all that kind of stuff. Right, right. And they almost, they budget. So usually the IT organizations have a bigger budget for technology. The T that we just talked about being the same on. I know, but the OT side rarely has enough budget on that technology side. They're really good at operating the plants or manufacturing or whatever, but they don't ever have enough. In my experience, have enough. The O and M capital budget, all of it is lack. Um, so maybe the uh, IT organization can start putting line items from, from staff. Like, hey, we want you to spend 10% of your time. We want somebody from this team to spend 10% of their time advising on, on that side. So I want somebody from active directory and networking and firewall and you know, kind of go down the list and offer that as a service to, to your customer who is the operational side, which is the reason the business is existing in most scenarios. And then, then you also are, you're not just coming with, hey, we're better than you, we're smarter than you. Hey, I'm coming with resources and, and maybe even some funding that can help you fund some. Hey, we, we were, you know, uh, we chose to go with the insecure option because, you know, we had $100,000 and that bolt on those other things, it was 150. Well, what if we brought that extra 50 so we could do it the right way the first time as well as bringing advisory. So we'll help you have those conversations, hold these vendor vendors accountable and do it right now as opposed to waiting. You're still going to own it. It's still going to be your baby. We're still going to just advise you. You have the ultimate say, but at least we're helping you because again, it's all one team. We're, we're going towards the same goal here. Then you're coming with more than you know. Here is my T shirt that says I'm from IT and I'm here to help. You're actually coming to help. And you have budget and you have resources and, and that's something that people can get on board with.

Speaker A: Yeah, I agree. It's like I'm here to share whatever I have resources, time, energy, knowledge. I'm here to share. Because you're part, uh, because we all report to the same CEO. So, so we're all on the same team. Whether we're on the offense, defense of some team, it's, it's like we're not trying to take over your territory. We are trying to make the organization leverage all the knowledge the organization has to make the organization better and make it m. And more stable. I mean, that's, you know, keep it running. I mean, no matter if it's it or ot, we're trying to keep everything going forward productively. You know, it's. Production is what we need to do as, as, as an organization. But so, so let us, you know, leverage us as just, uh, you know, a free resource that you guys can use, you know, you know, in the organization I'm in, we try to go down there and at least monthly have team meetings and then go down whenever they want, uh, you know, any kind of consultation so I've seen that in practice and trying to build those teams and build the team, you know, go to lunch together to build that camaraderie outside of just, you know, inside conference room.

Speaker B: Right.

Speaker A: But I think that that also mentally, subconsciously helps build that team of. We're all trying to do the same thing. It's just some people have more expertise in other areas, and let's leverage that because, you know, I don't know if one day we install something that you guys have on your network, but I would be like, I have no idea. You know, the first person I'm going to call is you guys. Right. I mean, I mean, one of our vendors gave us training vendors gave us a plc. And I'm like, guys, I have no idea what to do with this now. You get it on the network, I'll try to hack the hell out of it.

Speaker B: Right.

Speaker A: I have no clue. And I'm not going to, you know, that, that, that's, that's above my pay grade or above my knowledge. So I want to leverage you guys. Can you guys tell me what I need to do? I think we just got to figure out how to get that word out that, that we're all on the same team. And what, what ties us together is the technology right now. Because it started whenever whoever started the Internet, but a TCP ip, they didn't know that it would eventually roll to all businesses across the world. Right. It was really meant for organization like government and educational, so they could interact. And then it just took off and it took out, you know, countless. I wouldn't say countless, but multiple. Big, big organizations. Novell, Banyan Vines that tried to build their own network and no TCP IP wins. But also means the threat actors know your environment. So. Yeah. So be aware of that, that if they can get an IP on your network, get to an IP on your network. You know, that's the, that's the challenge of, uh, security is trying to, Trying to solve.

Speaker B: Yeah, you're bringing back memories now from, from Nova M. My novel Netware days. So, so there I remember having to upgrade a system that had been running for, I want to say, three years without ever rebooting. And it was a terrifying thing to upgrade to TCP IP and reboot that machine and bring it offline and bring it back up. So that was a, that was a long week. That thing back up and running because it had never shut down in three years.

Speaker A: A lot of long weekends when we were trying to move over to TCP ip.

Speaker B: Yep.

Speaker A: From bank we had Banyan Vines at the first, you know, corporate job that I had. And that, I mean it was head above. It was very mature. But it wasn't what was on the Internet. Right. It wasn't going to connect us. And then it was, it was almost like trying to manage two different environments. It just, it's not efficient. Eventually one will win and uh, it looks like IP1. So let's work together. Right?

Speaker B: Uh, yeah. One way that I've seen, ah. And I know not everybody has this ability, but that I've seen be really successful in this space and being able to bring these two organizations together is building out a lab. So in a couple of organizations I've built very large labs. And think about it like I've got my control system and my. All of the OT stuff, the OT stack, the firewalls, the VMware, like all of that. And it does a lot of things like a. Obviously I can test stuff and I built like a deployment factory. So before we deployed technology in the power plant, we tested it in this space first. So everybody was comfortable with it. That's one of the concerns that a lot of the uh, you know, OT, plant managers, etc. Have. I don't know what this is going to do in my environment. Like I want to make sure it's not going to break. Okay, let's. If I had a representation of your environment and we test it there with your configuration, would you be comfortable? Yeah, absolutely. That make me feel better. Right. So, so with that. But it also does a lot to bridge the gap between IT and OT and help the IT people. Yes, the technology is the same, but why is it different and explain it in real time. Well, you can't do that here. And this is why, this is how we have to do it. Because of X, Y, Z, whatever those things are.

Speaker A: Right.

Speaker B: But also be a safe space to challenge. Well, why can't you do this? Like could you. Why don't we try this? Because I'm not going to try that in production on a power plant or on a, on a manufacturing facility or whatever that thing is while it's running. And I uh. Usually an outage in an outage window, I'm not going to have time to do it. There's very limited time to do that and I don't have time to play around. So if I have this safe space that I can try new things and I could test it without impacting production, without doing, you know, and it's a real world example. It's not virtual. That where this thing is physical, this is virtual. It's not, you know, it's almost a like for like.

Speaker A: Right.

Speaker B: Problem is, is it takes some money to set up, somebody has to maintain it, etc. But it's, it's taken a program that's taken years to get up and going where, uh, you start getting instant credibility when, when that plant manager walks in and he sees the same cabinets that he has in his environment, he sees the same gear, he seems, the same screens that his operator screens are running, like the same graphics, everything about it, it's a duplication of what he has and bringing in the IT people, bringing in the OT people. And it's really a training environment that you can play in in a safe space. And it's, it's, it's done amazing things as far as building, uh, trust, training both sides, training the OT people on the IT stuff and the IT people on the OT stuff. And it's just a place that they can really mesh together, that it's hard to do on paper and just in a conversation, but seeing is believing.

Speaker A: Well, I think it also helps them, you know, you know, even though everybody's talking the same language, native language, it gets them to really, okay, now I see what you meant when you said this, because now they, the either the IT guys or the OT guys get to experience. It's like, okay, now this is why you're saying this is not as disruptive as you said. Now I understand exactly what device you're talking about and now I know why you're concerned about it. So, um, I can't say too much on the thing, but there is a lab that I probably need to take more advantage of, get both more teams involved with. And maybe this was another one of those just weird kind of things in my life path that said, here's a nudge. So I'll take this as a to do item that definitely is something to take advantage of. Um, because it does not only it helps build knowledge in people's heads, it builds that camaraderie because you're actually working through problems together versus, hey, you're just going to advise me and I got to go solve the problem. Right, Right. And now the chances are I didn't ask the right questions and I still, you know, somehow there was an outage. So it's like, no, now we have a safe place where you can ask all those questions and you can actually put it in place. So then those things that might have happened that, you know, you didn't take notes for Or I didn't communicate well, then. Then they got it, uh, got a chance that you could ask that question. I could communicate better and you could take better notes so you felt more comfortable, or you could do enough repetitions after, you know, you know, I left to go do my day job in it and somebody could then do some repetitions to say, okay, let me see if I really got this down. And I really feel comfortable with this. Um, so, yeah, I agree with you that a lab is, Is, uh, while expensive, it's, it's, it's a really great tool to kind of not only build the experience, but build those teams to make them mesh more as one is. We have specialist, but we have common ground. Right. You know, you know, these are the things that are also in our IT environment. So.

Speaker B: Well, it's like you said, it's breaking bread, right? It's, you know, one of my mentors told me a long time ago, all businesses, the people business, so the more that you can build relationships and you can build those connections, I don't care if you're the janitor or the CEO, it's the people business. So it's dealing with the person sitting across the table. Not, not your differences, not that he's it. You're ot whatever those things are. You have to talk to the person on the person's level and build connections. What, what, what do we have in common? What is the common language? Like, what do we. What can we agree on? And then figure out where we differ, how we can come to a resolution or a solution that we can both agree on. Right? And it really comes down to that. And this is a space again, just like going and grabbing a beer, going to lunch or grabbing a coffee. This is a place I can do that while I'm doing. Hey, you can't do that now. Ot well, why not? Well, let's try it. Let's see what happens. Okay, Try. And then he'll say, yes. See, that's why you can't do that. Oh, okay. Now I understand why I can't do that.

Speaker A: Yeah. I'm thinking, what can Ping do, right? Let it walk. Ping this IP address in the lab and watch the lights and that thing go out.

Speaker B: Exactly.

Speaker A: I got it now. Ping is not so safe. It's like, now I, now I have experience with it. So it isn't just this hypothetical that I heard of I can actually remember. You, uh, know, because experience is something that comes back and, you know, you'll, you'll bring it back up and it's like, yeah, yeah, I got it guys. I won't even mention ping again or whatever it was. Right, right. It's like, um, it's the best way to kind of build that experience without blowing anything up or, you know, causing any kind of option.

Speaker B: So, uh, nobody wants to get the black star on their hard hat when they're at the power plant and they had to trip the unit. Like, I don't want that.

Speaker A: Yeah, I agree. And I didn't think this podcast was going to make me want to have to do list right here, the things I got to do now as action items out of a podcast. But thank you for making me have yet another to do list. Um, I appreciate it. Um, I mean, I love the ideas. I love the thought of the advisor coming in as, more as an advisor of like, hey, we're here to help you hold the vendor to a higher standard. Right? Because the vendor reports to the. Is providing things to the company. So, uh, we're on your side. We're all on the same team to make sure that vendor is going to produce and leave what we, what we really need in the condition that is really most advantageous for the company. You know what I mean? In the best condition it can be in. And we can ask the right questions because we've already had this vendor in, not this vendor, but like somebody deploying the same technology, it might have been a different reseller, but these are the, these are the things we held that reseller accountable for. Because right now the vendor, we'll call it the, the solution provider that's providing the majority of the solution isn't provide it isn't Microsoft walking in the door to give you active directory. And it means probably a Cisco sale. And well, it might be a Cisco sales guy, but you know, it's most likely that vendor, uh, vendor A, that vendor A has, is also deploying that technology because it's needed and they might not have the expertise of the, um, the original vendor. So, so I like that idea of coming in as the, as the advisor or that recommendation of, uh, hey, we just want, we just want to keep, uh, the vendor honest and make sure they make it the most stable and secure that they can leave it and it's operational so we don't have to worry about trying to figure it out six months later when we figured out, hey, they didn't deploy these patches and they left all these settings in Active Directory to default. And now we're already in production, so now what do we do? Right?

Speaker B: And now we don't feel comfortable making changes because we don't know what impact it may have. So we're just going to leave it running.

Speaker A: Right, Right. Because apparently that vendor had, uh, never put in those settings, so they have no clue what will happen. So they'll say if you make changes, it's. It's no longer under warranty.

Speaker B: Exactly.

Speaker A: So. So it's like, no, we don't want them to say that. We want to hold them during the warranty period to deploy correctly so we don't have to bring you in again to reconfigure it.

Speaker B: Well, and that's what my team was successful in doing. Like, so we do that in the factor acceptance test with the vendor. And I'd make them, um, hey, we're going to do it this way and you're going to sign off on it before we leave this fat. Yes, I'm signing off on the things that you're delivering, but you're also going to deliver these other things that I want. And we're doing it this way because I have to support this thing. Eventually you're going to deliver it and I have to support it after you leave. Right. And I want you to sign on the dotted line that this configuration worked in your factory before you shipped it to my site. So you can't come back later and say, oh, well, we don't agree with that configuration. Like, no, you're going to do it and we're all going to agree to it before we leave here.

Speaker A: Yeah, that seems like, uh, again, I've not been on the OT side as an actual employee, but it seems like that's part of the challenge is it seems like the vendors are very much, hey, you know, we'll cut you off at the knees if you try to hold us accountable to something that we didn't control where they're not working. You know, the, you know, this sounds more like a vendor problem of the vendors not working. Like they're a partner or an advisor to the customer. They're like, this is what we know. This is how we deploy it. This is what you're getting. And if you, if you do anything else differently, then it's on you. And it's like, it's like I'm, you know, I'm assuming that most of those environments are damn expensive. It's like, hey, if I'm paying you this money and this much money to deploy this stuff, you guys should be having rockstars on your team. You guys should have, you know, ip, Cisco, uh, Windows and all those experts that show up alongside your application, uh, expert who, who's ratifying it. Right. Yeah. And instead of. It's just the guy doing, doing this other stuff that he's not an expert, so he'll just leave it at default

Speaker B: and it comes back to holding him, um, accountable. Because most of the vendors do have that, but if you don't ask for it, they don't send them. So they'll just send the field guy, they don't send the Cisco guy, they don't send the active directory guy, they don't send the OT guy, they just send the control guy. But if you ask them, oh, yeah, we've got those guys, there's an extra charge and that's where that, uh. Okay, well, I'd rather pay the 150 instead of 100 if I get that, because I want that, because that's what's going to help me long term. Yes, it's a more upfront, more cost, but long term, it's going to save me, uh, if I, if I look at it that way.

Speaker A: Right, right, right. Yeah, I did. Yeah. The. An ounce of prevention is worth powder cure kind of thing.

Speaker B: Absolutely.

Speaker A: Get it done right early because otherwise trying to retrofit it and something that, you know, uptime is, is the king. Um, I wouldn't, I wouldn't want that responsibility. I mean, right now all I got to deal with is criminals. So. So, I mean, at least they're not knocking at my door 24. What they might be, but they're not getting in 24. 7. So, uh, yeah, that would be a very high pressure situation. Knowing that the vendor kind of left me with that and then not now. I'm. I'm kind of trying to balance of, uh, what do I need to do to get this more secure and stable? Um, not stable. More secure without disrupting stability. Um, what's the balance now? Well, we're already in production, so. Right, production, um, is king.

Speaker B: Yeah, exactly. Absolutely. Well, so we've talked a lot about today. Ah, a lot of different things, but, you know, in the next five to 10 years, what's. What's one thing maybe coming up over the horizon that you're, you're excited about that you see? And maybe what's one thing that's concerning that you may see coming up over the horizon?

Speaker A: Good question. So, so exciting. Sheesh. Uh, I wasn't ready for that. I mean, I know I, I should have been ready for that question. I'm. I'm just excited at, at the, the opportunity. For me personally, I'm Excited at the opportunity of there's a lot more people of all different backgrounds that are student, you know, focusing on getting into cyber. Um, and personally I've been, you know, doing uh, side education for free to get people into cyber. I think that's good for, good for the um, good, good for all. Um, the biggest challenge is the biggest fear is this decision by the SEC to hold CISOs accountable for breaches. I mean I was um, I didn't, we didn't really get into too much my background besides cyber. But I was a volunteer firefighter for 12 years. Like I said I was going to go into law enforcement, almost switched my career to go into medicine. So, so, so. But with all of those, I think of uh, who are the first responders and I can't imagine. And just the name that we say, we don't say first preventer. Right, right. They're like, how, where did this expectation come that were going in? And I think I get a little bit of where it might have come from. There was this, um, it seemed like a lot more people that were not technical, moved into CISO roles than the technology people or the hands on people. And they were thinking that hey, we'll just treat cyber like another risk, like a hurricane or a flood. And it's like, no, no. Uh, well, my background as a threat actor, paid pen tester is these are criminal.

Speaker B: Yeah.

Speaker A: You know, you know you got to look at it a lot differently that there's an active threat. This isn't risk, this is a threat. This is like the analogy I like to give is, I know everybody thinks that at any point in the time, um, my house could be robbed, but it's, it's a whole different thing. That's a risk. Right. So what do I do? I put an alarm system, I have guard dog, whatever. I mean, you know, I mean that I, I think that that risk is manageable, but it's whole, it's a whole different thing than the police knock on your door and say, um, Mr. Beebe, we just uh, we have an insider to one of the organized crime rings in the area and they have your address on their target. That's a whole different. I'm going to be checking my windows a lot more. I'm going to be going to sleep a lot. I'll be a, I'll uh, probably not sleep during the night when there's an active criminal who wants to. It's like the fact that you think that, hey, like nobody holds fire chiefs responsible because there's fires in their Neighborhood. Right. Their goal as a first responder is to minimize the damage. They already accept police officers. There's. To minimize, you know, try to catch the criminal before they do more crime. Um, doctors. Doctors aren't, aren't set up. Okay, Doctor, if I don't live to be a hundred, it's on you. Right.

Speaker B: Right.

Speaker A: It's like you did that doctors don't become aware until there's other symptoms. So so does cyber and cyber. For some reason this is my biggest concern in cyber and I was part of it, so I'll take responsibility because I grew up through it. Is when did we decide to make the most junior person on cyber as the first responder? They're the ones that are supposed to analyze one alert kind of in a vacuum and decide which one to throw over the fence to the more senior people. Where the senior people are more likely to say, oh, that one looks a little off. And they do it because of experience. And there's no, there's no real checks and balances for analytics. If they flag it as malicious or suspicious, it goes away. Like a help desk ticket. But the help desk tickets, the end user knows, hey, my computer still has an issue, I'll report it. The threat actor is not going to say, whoa, whoa, whoa, you didn't catch me. You should have. I saw the ticket. Like there's, you know what I mean? It's, it's. There's. With that kind of environment that the SEC doesn't seem to be, uh, aware of is that it's very hard how we have it designed right now deployed with, with junior analysts looking at the first are the first ones to get a whiff of a potential threat. And they haven't had, they've never successfully hunted by most of them, have probably never been involved with an actual incident. So how are they going to know what it looks like when they see it? I mean at least doctors, they stand behind and shadow the other doctors for years of like, okay, here's all the symptoms for this patient. What's your recommendation? We don't, we don't really shadow first responders in our or, you know, in most organizations, I tried to do in my organization. But in most organizations they're not shadow where everything they look at, every time they get an alert that they look at, somebody else takes a look at that alert and says m, you probably should escalate to this one. So they start to see it. So I think that's my biggest concern is, is, uh, you know, everybody's hoping that, you know, Artificial intelligence and all these other things will take, take the load off, but I just see more alerts right nowadays because we have more visibility. When I was doing pen testing, um, 30 years ago, there were no alert. So I mean when we got in networks, we were on everything. Yeah, um, I probably shouldn't say this, but the, you know, statute of limitations that we probably did once or twice run an exploit on a box and it killed it.

Speaker B: Right, right.

Speaker A: Because, because we didn't have anything to test on. We were getting exploits or building exploits kind of on the fly. There wasn't GitHub, uh, there wasn't all these, these places where you can just find these tools. There wasn't metasploit, but nobody saw anything. Nowadays we have so much more visibility, but it's a lot. Because of living off the land, there's a lot more false positives. So again, I, I think that's the biggest challenge going forward is how can we, how can we educate the, those that look at alerts. Um, until we get some other tool that looks at alerts and can really kind of sift through. Okay, this is odd for this environment. Um, and that's, that's, that's, that's what's most challenging. Because the threat actors now, they're not, they're not um, what I consider to be parasitic. Where in the old days they, they live, they, they kind of linger for months or years because they were sifting off data and then they were just parasitic. They didn't want to be disruptive, they didn't want to be caught. And the threat actors now eventually they want to be, they want to be known so they can get the ransom. So, so that, that shrunk that time window significantly and they're um, they're criminal. I mean the other ones were had, were almost like paid employees that had a long term mission. These guys are just in it for the short term money. So they're almost like organized crime to where you know, if, if they have to shoot everybody in the house to get out alive, they'll do it. And these guys, if they have to burn down every window system in the environment, they'll do it. So it's a different threat level. And then we, so we got this much shorter window and we still have junior analysts that are the first ones to try to say there's that smoke is actually, that's white smoke or that's black smoke. That's actually this, it's not really that.

Speaker B: Right.

Speaker A: You uh, know, they just see smoke. Go look at it. They look at it 15 times. Well, smoke means this. It's always false positive. So every time I see smoke, it's like, no, no, you gotta, as a firefighter, you got to look at the different, what, what direction is it? What, what's the density, you know, what's the color? It's like, who's teaching them that? And it's just, um, I think that's the biggest challenge is, is keeping up with the threat actors that are, are just, um, more. More, um, criminal than, than opportunistic as far as sifting off data so they can go build their own plant cheaper. Right. In another one country. So, um, hopefully that answers your question. I was a little long winded, but, uh, absolutely.

Speaker B: No, man, this is a great conversation. I think there was a lot of lessons learned here. I think there was. Obviously you took away some things to, to go do some action items.

Speaker A: I got it right here. There's my to do list. But so I'm ready, uh, to continue learning. I think that's the most important part of anybody in cyber is if they have that mindset of it's not failure, it's I'm learning. Right.

Speaker B: Yep.

Speaker A: And if we can get that into the mindsets of the, of the next generation, I think then we did what we needed to do.

Speaker B: Yeah, 100%. And I mean that, that's the focus of this podcast, is to get information out. Have. You know, if somebody learns one thing every time they hear this podcast or others like it. Right. It's going to improve everybody. Like, uh, you know, rising tides raise all ships. Like, learn. Be willing to change your perspective and listen to new information and, and look at it. And be willing to suck at first as you're trying this thing.

Speaker A: Exactly. Like anybody that's a professional football player probably sucked at it for a while. They probably got knocked on their tail and like, okay, this isn't for me. The other guy's bigger. Well, eventually you might grow too, so. That's right, Just stick with it.

Speaker B: That's right. Well, hey, Todd. I really appreciate you, sir. I really enjoyed the conversation and, uh, uh, thanks again for joining me.

Speaker A: Well, thanks for the invite and thanks for the to do list.

Speaker B: Absolutely. All right, Have a good one, sir.

Speaker A: All right. Thanks for listening to the Protect OT Cybersecurity podcast. If you got some valuable information from today's show, please subscribe, rate and review the show on Apple Podcast, Spotify or wherever you get your podcasts to learn more about Aaron and to get your free copy of the OT Cybersecurity Solution Buyer's Guide go to industrialdefender.com that's industrialdefender.com or you can click the link in the show Notes.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mythos And The Disappearing Patch WindowAI Proving Ground Podcast · on Network segmentation96 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Network segmentation87 / 100
  • It's not you, it's your printer: State-sponsored and phishing threats in 2025Talos Takes · on Network segmentation86 / 100
  • Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]The Industrial Security Podcast · on Network segmentation85 / 100
  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Network segmentation85 / 100
  • Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew GaultSecure & Simple · on Network segmentation83 / 100

More from The PrOTect OT Cybersecurity Podcast

All episodes →
  • Ron Fabela: Secure Access That Makes Sense for Operations
  • Dan Gunter: Lessons Learned from Real-World Attack on Ukraine’s Critical Infrastructure
  • Thomas VanNorman: ICS Security Takes a Village - Building an OT Security Community
  • Don C. Weber: The Gray Area Between OT and IT
  • Ron Brash: Understanding the Small Details to Define Risk
Explore the best B2B Ops podcasts →
All The PrOTect OT Cybersecurity Podcast episodes →