Cyber Threat Intelligence Podcast

OT Risk Without The Guesswork - Episode 11 (Andrew Ginter & Pedro Kertzman)

Pedro Kertzman Season 2 Episode 11

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 38:47

A lot of cybersecurity advice falls apart the moment the “asset” is a turbine, a boiler, a rail system, or a water plant. We sit down with Andrew Ginter, VP of Industrial Security at Waterfall Security Solutions and author of multiple OT cybersecurity books, to get practical about what actually matters in operational technology security: understanding how attacks work, where they enter, and what they can do in the physical world.

We unpack why many OT programs struggle when they inherit IT-first language and assumptions. In critical infrastructure, the priorities are often safety, reliability, and efficiency not just protecting information. Andrew explains the shift from treating information as the asset to treating attack information as the threat, and why mapping “consequence boundaries” and information flows can reveal the most important attack vectors. We also talk about pivoting attacks, residual cyber risk, and how to think like an engineer when the worst credible consequence is simply unacceptable.

For CTI teams and security leaders trying to brief executives, we explore a better way to communicate risk than likelihood times impact. High-end adversaries are not random, so Andrew advocates framing board conversations around credibility and reasonableness: what is reasonable to believe about intent, capability, and opportunity, and what defenses are reasonable given legal and business obligations. We close with a hard look at the next step change AI-driven zero-days and why cyber-informed engineering and resilience, including deterministic safeguards, will matter more than ever.

Subscribe for more practical CTI and OT security conversations, share this with a teammate who briefs leadership, and leave a review to help others find the show.


https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/engineering-grade-ot-security-a-managers-guide/

Send us Fan Mail

Support the show

Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

Why Threats Must Be Understood

Andrew Ginter

We have to understand the nature of the threat.

Rachael Tyrell

Hello, and welcome to episode 11, season two of your Cyber Threat Intelligence podcast. Whether you're a seasoned CTI expert, a cybersecurity professional, or simply curious about the digital battlefield, our expert guests and host will break down complex topics into actionable insights. On this episode of season two, our host Pedro Kurtzman will chat with Andrew Ginter, who is VP of Industrial Security and Wonderful Security Solutions, where he advises the world's most secure industrial enterprises. Before Wonderful, he led the development of industrial products at HP, ITOT Middleware Products at Adolent, and the world's first industrial SM and Industrial Defender. Andrew is the author of three books on industrial or OT cybersecurity with 35,000 copies in print and contributes regularly to industrial security standards and best practice guidance. Over to you, Pedro.

Pedro Kertzman

Andrew, thank you so much for joining the show. I'm really happy to have you here. I'm delighted to be here.

Andrew Ginter

Thank you for inviting me.

Pedro Kertzman

Awesome. Andrew, uh,

Teaching Engineers To Model Attacks

Pedro Kertzman

I think it's fair to say, based on your experience, this is going to be more like an appetizer to the listeners, too. And of course, I'm gonna put all like the sources that can go and really dig into the awesome material that you have online, all your research, so many uh papers and oh my god, like so many content. But unfortunately, we don't have hours or maybe even days to go over so many content. But I'm sure we're gonna dig into some of the most interesting topics uh for people like to really start researching about so many of the uh vast knowledge you have around ICT and OT security. So if we can jump into it. So you teach uh cyber risk analysis to analysis to graduate students, right? And um, are there any like paradigms that uh around ICT and OT security that you have to help them reframe reframe a little bit uh first to in order to help them understand the cyber uh threat landscape around OT security? And and if so, what is that?

Andrew Ginter

Definitely, and you know, thank you for that flattering introduction. Um and to be fair, um I taught a course for engineering graduate students at Michigan Technical University a couple of years ago. Uh, I no longer do that, but when I did that, yeah, these were uh engineering graduate students, not IT, not cybersecurity, not you know, people who spent uh uh you know two years studying AI. These were engineers. And so um the first thing that I had to teach them in you know, if you want to if you want to design uh a security program, you have to know who's coming after you. Okay, you've got to know how much trouble you're in. And so the first half of the course or third of the course was um you know reviewing the basics. How does TCP work? How does Ethernet work? How does ARP work? What's the difference between ARP and DHCP? Um, and then leading into um how do attacks work for each of these things that we're talking about? How would you attack it? Because you can only design a defense if we understand how you know what how the bad guys are coming after us. We don't all need to become penetration testers, okay? We don't need to be able to carry out the attacks ourselves, but we have to understand the nature of the threat in order to build an effective defense. I mean, concrete example. I had a uh a colleague um attend CISSP training, you know, 10 years ago. Uh came back from training, a week-long training. I said, So what did you learn? We said, Whoa, we learned everything. It was, you know, fire hose for six and a half days. I said, Great. Um, so you know, we're defending power plants. You have a power plant to defend. How would you do that? What have you learned? And he said, Oh, well, and uh, I'd use one of each. I'd have some antivirus here and some patch program there, and some encryption here, and some VPN there. And I said, Great. And so I drew a little diagram and said, This is what you're talking about. Yeah. And I said, So here's an attack: bang, bang, bang, they're in. Um there's going, um, I guess one of each isn't good enough. And you know, the attack I described was the classic uh attack that everyone uses today. It's the pivoting attack. The bad guys get a foothold, the foothold, the rat, remote access trojan beacons out to the command and control center. You operate a bar mode control, bang, bang, bang, you're through. Um, you have to understand the attack. So I taught people the attacks and then went through the standards and defenses. I only had 40 hours. Um, but yeah, it started. The first third of the course was understand the threat. You know, these are engineers, they work with risk all day long. Okay, they they you know, they're designing safety critical systems. Um they work with risk all day long. Um, they need to under they need to be able to evaluate residual cyber risk, given the defenses I have in place. How much trouble am I still in? They have to be able to evaluate that to answer the question is that residual risk acceptable? And

OT Priorities: Safety Reliability Efficiency

Andrew Ginter

attacks are a big part of that.

Pedro Kertzman

That's that's a great point, Andrew. And I think um most of us uh in the uh when it comes to the CTI, let's say bigger industry, we are most used to whenever we're evaluating risk and communicating risk and all that, a big component of it will be uh information, right? But when it comes to T systems, information is not really the asset to protect, uh sometimes just the threat itself is the like you name it, it's just different, right? So how that how that changes, how like you you you you you make people understand that change, and how have you like been communicating this uh to help people understand that change when it comes to OT assets and and all that?

Andrew Ginter

Yeah, well uh um it's a confusing space. Um, a lot of the standards and guidance in the space still use the language of IT. Information is the asset, protect the confidentiality, integrity, blah blah blah. Or maybe in a different order, maybe AIC, not CIA. There's a lot of stuff out there that uses this language, but really that's first generation language. When bluntly, when the aircraft flew into the the World Trade Center 9-11, um the world started looking around saying that was unexpected. That was a failure of imagination. Okay, the authorities never imagined you could use a commercial aircraft as a weapon, and so they looked around and said, What else? Where else have we failed? And one of the things they settled on was industrial control systems, SCADA, they called it back then, SCADA security. Um, and so an initiative started, funding was available, but where were the world's SCADA security experts? At the time, there were less than a dozen. Okay, these were academics who'd been doing some work in the previous decade. Um, and there was a big effort, hundreds of people started getting involved. Where did they get their cybersecurity expertise from? From the IT experts, of course. You know, in in IT networks, information is the asset, CIA, AIC. Um, second generation said, Thank you. Um, that was good. Um it's been a hard fit. Um, you know, let's let's let's rethink this. And the the again, the concrete example. I was listening to uh uh the CISO of a a passenger metro, a large cities passenger metro, um speaking at a security conference, talking about sort of the big picture priorities. He did not say anything about information, he said, look, my number one priority for cybersecurity for my metro is safety. Don't kill anyone. Nobody wants to die on the way to work. Oh, that makes sense. Um, number two is reliability. I have a three-quarter million people I've got to get to work every morning and get back home every night. The trains have to run on time, I have to be able to move the people. And he said, My third priority is efficiency. It does no good to have the world's safest metro, the world's most on-time metro, if the population cannot afford to use it. These are my priorities, and these are, in a sense, physical priorities, not information. Um and you know, that that sort of second gen thinking lately, the way I've been, you know, explaining this to people is go back to the

From Likelihood To Credibility For Boards

Andrew Ginter

basics. What did you learn in school? You know, the first cybersecurity course you took in school taught you about ancient, we're talking 50-year-old, 5-0, 50-year-old cybersecurity theory, Belle Lapadullah. Um, information is the asset, protect the confidentiality of the information. What most people touched on in that same course and forgot about promptly, as soon as they had the final exam behind him, was Biba. Two years after Belle La Padula, Biba came out with a different theory. All the same concepts, all the same terminology, applied differently. Back then, you know, they were put trying to put together um uh bluntly. This was the era of the bomb, this was the era of the cold war. Um, Bell Lapadullah was concerned with if the design for the bomb is on a computer, how do I prevent the enemy from stealing the design? How do I prevent my own people from accidentally leaking the design to the enemy? Biba said, no, no. You've dealt with that. Okay, that's that's the right theory for that problem. Here's a different problem. Um, if I have a computer that is assigning targets to missiles that carry the bomb, how do I prevent the enemy from tampering with the computer and changing the targets, changing the targeting coordinates? You need a different theory. With Bell and La Padula, information is the asset. The first thing we have to do is get an inventory of all of our computers and all the information they contain, because if you don't know where the information is, you have no hope of defending it. In Biba, information is the threat. Mathematically, all cyber sabotage is information. The only way that targeting computer can change from a normal state to a compromised state is if attack information enters the computer. And so the first thing that we see very secure industrial sites that are concerned about sabotage, and most heavy industry is concerned much more about sabotage than they are about espionage. There's always exceptions. Everything I say, put it most in front of. Most heavy industry is concerned about sabotage. The first thing they do is not ask, where is my information? I need to protect information. No, no. They say, where is the attack information coming from? And in particular, where does it cross a consequence boundary? A connection between a network with acceptable worst-case consequences of compromise. I leak all of my employees' names into the internet. It's undesirable, it might be material, I might have to report it to the regulator. Um, you know, it's it's but it's not going to put me out of business. Whereas when you cross that boundary into the targeting system or into a power plant and you destroy three turbines, and the plant is down for you know two years because that's how long it takes to build and replace a turbine. Um, now you've you you've crossed into a a network whose worst credible consequences of compromise are completely unacceptable. And at that consequence boundary, the first question that I see heavy industry asking is where do I have information crossing a consequence boundary into my system? That is what I need to worry about first. That those are, you know, a complete inventory of those information flows is also a complete inventory of attack vectors. And to the greatest extent possible, I need to control those attack vectors. Eventually, I need to do an asset inventory as well. But the first thing I care about is the movement of information. Information is the threat, attack information is the threat. Understand how it moves.

Pedro Kertzman

That's that's a very good point, Andrew. And uh it brings me to uh so uh listening your um you know the tail story about like how this this moves from uh one reality to to the other, it also made me think to one of the main struggles to I think it's fair to say a lot of CTI teams and CTI analysts is how to start uh how they start creating more um start speaking the language of leadership

Tracking Breaches With Physical Consequences

Pedro Kertzman

and boards and making them understand talking about the business language, talking about business reality and all that. What you just described, for example, uh it's really hard to how can you quantify the problems if you leak employee data? Simple simple to describe the business implications if you destroy a turbine, right? Uh like two years of stopping you name it, it's way simpler to describe. So, have you seen um any examples of CTI teams working on the OT space and starting to grasp this new, more impactful reality of the implications of DOT space and threats on the OT space and real business implications on that?

Andrew Ginter

Yeah, so um a couple of things. One is I just finished reading uh the boardroom CISO. I recommend it. Uh, if you want to get the the author on the show, um it's a it's uh an extremely readable, extremely I thought, useful uh book talking about how to communicate with boards. Now, how to communicate with boards primarily about IT security. Okay, I study OT security, um, but you know, a lot of really good ideas about you got to speak the language of the board. The risk is not that we have you know 73 uh unpatched vulnerabilities, the risk is that uh you know the new uh initiative, whatever we have, fails because of oh, so you got to speak the language of the board. They don't care about vulnerabilities, they care about business risk.

Pedro Kertzman

Absolutely.

Andrew Ginter

And um more specifically on the on the OT side, um, a lot of the time, the the worst credible consequence on an OT network uh is truly unacceptable. Okay, we're talking, you know, uh high-speed trains collide, hundreds of people die, mass casualty event, completely unacceptable. Um and when I work with um with teams uh that deal with uh these these these scenarios, um, they do really good work. Okay, they you know the the universal approximation, okay. It's an approximation. The universal approximation that everyone uses for risk is risk is likelihood times consequence or impact, whatever you want to call it. Um and when I see people working on the high end of risk, they go, no, no, no, no. Okay, high-end threats are not random. Okay, um, Iran is not targeting uh, you know, uh water systems in the United States at random. Um, Russia is not targeting Poland at random. Okay, the the the high end of cyber threat to especially to critical infrastructure um is systematic. Targeting is not random. Um, there might be random elements in the attack, different people, attackers take different first steps or second steps. The defenders might take different first steps or second steps. There is human actions, uh human error in particular, can be reasonably modeled as a random process. Um, but sophisticated attacks eliminate that randomness, eliminate uh that human error um with repetition. If me, Andrew the idiot, does not click on the first phishing link that they send me, they send me another 73, and sooner or later I'm sorry, I'm gonna click on one of these because I'm just not that clever. You eliminate randomness with repetition. I mean, think about it. Um, high-end ransomware hits a shoe factory, a small shoe factory, you know, uh 30 machines, uh, 10 employees, what happens? It goes down, they have to pay through the nose to bring gurus in to clean everything out, restore from backup. If they said, Oh, this is this was really unlucky, okay, likelihood uh assumes probability, probability demands randomness. If the bad guys, if the good guys said, oh, that was that was unlucky that I got hit, how many shoe factories got hit last year?

The AI Step Change For OT Attacks

Andrew Ginter

One in the whole world that went down. So, you know, how likely is it I'm gonna get hit again next year? Extremely unlikely. How many shoe factories are there in the world? So I don't need to change my defenses at all. That was just bad luck, wasn't it? What happens? A month later, the same Ransomberg group comes in, hits the factory again. What happens? They go down exactly the same way. It's a the high end of cyber attack is deterministic more than random. And so when we, you know, when I see high-end risk analysis, they're not using the concept of likelihood, they're using the concept of intent. What is the enemy up to? Of capability, what can they do? What have they got in their pocket? What have they shown us? What do we think they have? Of opportunity, what do our defenses look like? When those capabilities hit our defenses, what is reasonable to expect coming out? Um, they they use the word in their analysis, they use the word reasonable. What is reasonable to expect? Um, and then when they present those results to business decision makers who have to you know approve budgets, they muddy the water, they stir that model the whole thing up with the concept of likelihood. And the business decision makers go, likelihood. Really? Why doesn't this make any sense? And they don't know the right question to ask. So what I've been advising people, and it's had a uh you know a reasonably good reaction, let's say 75% of people say, What a good idea, and 25% of people are saying no, absolutely not over my dead body. Experts disagree. But uh the word I've been using, I've been advising people to use when you communicate with the board is credibility. Where credibility is not defined as who is reasonable to believe, it's defined as what is reasonable to believe. What is reasonable to believe about our enemies' objectives, about our enemy's capabilities, about the strength of our defenses, about what will happen when the enemy, those enemies' capabilities meet our defenses. Um, because under, you know, in North America,

Cyber Informed Engineering And Resilience

Andrew Ginter

both Canada and the United States, most of Canada, most of the United States, put a most in front of everything I say, um, the the foundation of the legal system is British common law. And under British common law, when you or I make a decision about other people's safety, when we make decisions about other people's critical infrastructure, societal criticism, when we make decisions about large amounts of other people's money, think our shareholders, we have a legal obligation to make reasonable decisions. And so when we present the results of our very sophisticated risk assessment to the board, do not talk about likelihood, talk about what is reasonable to believe about the enemy, what is reasonable to believe about what will happen when the enemy meets our defenses and what kind of defenses are reasonable to deploy. This is different from the probabilistic return on investment calculation you can do with likelihood. If you have statistics, okay, if you have frequency data, you don't need to ask what's reasonable, you have the data. When we don't have data, I mean, how many times have passenger trains collided because of a cyber attack, killing hundreds of people? It's never happened. Is it reasonable to expect? That's the key question. And experts disagree. But, you know, I argue that that uh board members understand the word reasonable. Okay, it's very well defined in legal precedent. A reasonable decision is a decision that any other normal person skilled in the art would have made had they been sitting in your shoes at the time you made the decision. This is legal precedent. So they understand that we need to put reasonable defenses in place for credible threats. And now you can have, in a sense, a grown-up conversation with the board about what would be the impact of those threats on our business, on our legal obligations. So that's a word that uh I've seen people start to pick

Resources And How To Connect

Andrew Ginter

up is the word credibility and the word reasonable. I you know, I'm working on a uh a new book. I've written three so far. My fourth, the working title is a CISO's guide to OT security, and the subtitle is Reasonable Responses to Credible Threats.

Pedro Kertzman

Well, that was a lot of information, but that definitely goes way deeper than I thought on my on my question. Thank you. So you're uh also I read a lot of reports you helped uh put out there about all sorts of records around impact on uh OT attacks and and and all that. One thing um uh I wasn't so sure. Um you know, I'm sure you're probably the best person out there to to ask this. It felt sometimes that the number of incidents might be uh getting thinner a little bit, but maybe more impactful, like more bigger incidents, but not as many. Does it like sound about like right? And and I could be mistaken, but like by all means, uh but if so, what does that mean to like especially for CTI teams trying to make sense of the threats out there to OT space? How to proactively um help their security defense teams to protect against those threats, and if they cannot find then the how people are targeting them and all that, how to defend against those threats.

Andrew Ginter

Yeah, so um there's a lot of questions in there. Uh let me start with um um waterfall puts out a uh a report every year, free of charge. Uh, you're free free to download. And the part is unique in the in the industry in that we use a public data set, the entire data set's in the appendix of the report. Um, it wasn't quite in the appendix of the report this year because it was quite a large data set. And so we put this year's uh data set in this year's report. We put everything back to 2010 in the appendix of the previous year's report. Every few years we'll repeat the entire data set, but it's a lot of data. Um and what we do is um, unlike a lot of people who thro who follow the threat actor, what are they up to? What are their motives? What are they capable of? A lot of them follow attacks. What have we seen, you know, coming across the internet in the wild? We track breaches, and in you know, we did this deliberately. Um I talked about the high-end of risk teams doing very sophisticated analysis. They don't need this threat report. We designed this threat report for mere mortals um who, you know, have to try and squeeze a little budget for some cybersecurity. And uh they were having trouble doing this because the the threat information that was out there was just not credible to business decision makers. Um, you know, I saw one report back when we did the uh our first, and it was from a uh a large ISP uh that managed firewalls, internet facing fireballs for critical infrastructure. They said we defeated eight billion attacks on critical infrastructure last year. And I'm going, really? Eight billion? What the heck does that mean? I read the report, it didn't say what it meant. My best guess was you know, they manage firewalls, internet facing firewalls for power companies and water utilities, and they counted every dropped packet as an attack. That's my guess. Oh, yeah. I'm going, this is nobody's gonna believe this. You can't use this data to spring the money loose. And so we went to the other extreme. We said, here is irrefutable data. Um, here are all of the attacks we could find this year. You know, we do this annually, that were in the public record, no confidential disclosures. Okay, this is a public data set. Um, in the public record, uh, heavy industry and critical industrial infrastructures that caused physical consequences. Not stole some money, not could have shut the plant down, but didn't. Not we had to fail over to manual operations, the public never noticed. Caused a physical consequence. Okay, the plant flooded, and we had to bring in a cleanup crew. The the uh uh the plant burned down. Uh, you know, we had to lay off 3,000 people. These are physical consequences. So public report, physical consequence, heavy industry. Um and now we have a data set that you can look at and say, see, it's real. And again, every incident, there's a link in the appendix. You can click on the link, you can go to the front page of the New York Times, you can read the report yourself and decide whether you thought we made the right call, including it in the data set or not. It's it's it's out there now. Um, and you know, to your point, yeah, we're talking small numbers of attacks. I mean, uh beginning of the data set 2010. Uh heavy industry, physical consequence, deliberate attack, not not errors and omissions. Um, in the public record, how many incidents were there? There was one. It was Stuck Snap. Really? What about 2011? It was zero. This was the era of HavX, it was the era of Dragonfly, Dragonfly. They were stealing information from industrial OPC servers, didn't shut anything down for the whole decade. We're bouncing around between zero and five attacks. Okay, the biggest was not Petcha. Hundreds of sites went down, most of them IT, some of them physical operations. Okay, um, I think it was Hershey shut some plants down. Merck Pharma shut down four plants, uh $1.4 billion impact. Mersk um shipping, uh largest container shipping company in the world, was shut down for six days. We counted it as one attack because it was one action on the part of the adversary. They put uh a piece of wiperware in you know, disguised as a security update, in one place. So the whole decade bounced around between zero and five, and then it changed. Uh, this decade we've been bouncing around between about 50 and 80 attacks or breaches per year, most of which affect multiple sites. Okay, the biggest last year was uh Jaguar Land Rover, estimated impact of something like 800 million US dollars. Um estimated impact on the UK economy of 2.5 billion, but actual losses to Jaguar Land Rover were were closer to uh 800 million. So some very big incidents. Um, again, still small numbers, uh, but sort of two big conclusions. Um, one is when we're asking about what is credible, we have to go look at the data set. Because anything that has happened to someone like us is reasonable to expect will happen again in the future. That's what credible means, reasonable. Um, so look at the data set as part of the threat intel that you're using to make decisions about what is credible when we're dealing with you know high consequence scenarios. Um and the second thing is what we saw at the turn of the decade is a step function. We went from more or less flat up to more or less flat at a new level. Uh, and you know, most of these these attacks saying between 50 and and 80 is is a bit of uh misnomer. Most of the attacks affect multiple sites. We're talking hundreds of sites were affected uh every year. Uh, but we went a step function from you know zero to 10 up to 50 to 80. The next step, I'm convinced, the next step is upon us, and the next step is AI. Okay, mythos is finding zero days at a ridiculous rate. I mean, Firefox put out a news report saying, thank you, Mythos. You helped us find 257 zero days. Everybody should install the update. Do it now. Uh you know, finding zero days at a ridiculous rate, um, developing exploits very quickly for those zero days, automating entire attacks. Uh, this was clawed. And it's not just mythos, um, recent reports, literally in the last month, um, Chat GPT has got into the act. The uh the latest version of the Chinese AI is doing the same thing. I have not seen the data yet in the public record. I'm guessing it's gonna take 12 to 18 months before it hits OT. Um, but I'm guessing that two years out, we're not gonna be at 50 to 80 breaches per year anymore. We're gonna be at a new level, and I don't know what that level is gonna be, but I'm cautioning you know, Waterfalls customers, I'm cautioning the entire industry. The era of AI-based zero days is upon us, and uh we need to take reasonable measures to prevent unacceptable outcomes in our critical infrastructures.

Pedro Kertzman

Um I'm glad I'm not it's not only me, it's it's a big difference, and uh it's super impactful for sure. Uh so many big new incidents, the most recent one uh on the uh water plants uh in in the US. That was uh like you mentioned, not a statistical coincidence, it was just uh pure and simple uh intent. Andrew, um any final thoughts for the listeners?

Andrew Ginter

Um no, I mean you you mentioned some resources, um, a couple of things. Um the the waterfall threat report is is out there, it's free of charge. Um, I'm on LinkedIn. If you have trouble finding anything, just reach out to me. Um I I only get uh you know a couple of messages a day. I'm not swamped, I can answer you. It might take me a few days, but you know, I'll get back to you. Um and uh I write books, but you know, I work for Waterfall, and Waterfall sells technology, not books. And so if you'd like my latest, um go on the Waterfall website, you can ask for it, or just connect with me on LinkedIn and I'll I'll get you the URL. Uh, we give these books away at conferences, and you know, if uh we we can we can ship them to you as well. Uh the title of the book, if you're curious, it's all about OT security. It's Engineering Grade OT Security, which is got information in there about threats, but it's also uh the third generation, it's describing the third generation approach to OT security. I described the first gen, which is basically do it the IT way. Information is the asset. I know it's a hard fit, try harder. The second generation was no, no, no. Um information is the threat, control the movement of information. The third generation is the cyber informed engineering initiative. Uh, it's focused on resilience, which you know is talking about um a number of things. It's it's it's a it's a new way of looking at the at the problem, but let me just give you just one example. Um, you know, if if you were a technician in a power plant, uh old school, coal-fired power plant, coal dust is blown into a furnace, it ignites almost instantly, heats a massive boiler. We're talking six stories tall and almost as big as wide. The steam goes into a steam turbine, turns the turbine, turbine turns a generator, power comes out. You're the technician responsible for six of these massive turbines. You calibrate the instrumentation, you replace the instruments when they fail. You know, these turbines are your baby. You work eight hours a day within the kill radius of a worst-case boiler explosion. How would you like to be protected from a cyber attack that overheats all the furnaces under all of your boilers at the same time? Would you like a mechanical overpressure relief valve spring loaded, where if the steam pressure is too high in the boiler, it forces the valve open and against the spring, the spring deforms, the steam escapes, and there's no explosion? Or would you like a longer password on a computer controlling the furnaces? The gurus say, Andrew, you're trying to deceive us. You're asking the wrong question. They say, I want the overpressure relief valve. It has no CPU, it it's deterministic. Okay, it has a mathematically modelable mechanical failure rate. I need four of these because these things age, there's corrosion, there's metal fatigue. I need one of them on each boiler to work to save my life. And I want the larger, the longer password on the computer. And I want an absolute boatload of cybersecurity on the side because this is my life on the line. This is cyber-informed engineering. Um, the valve is resilience. It does not matter what kind of cyber attack you launch, it's gonna behave mechanically. But you know, where's the valve in ISO 27001? No hint of it. Where is it in the industrial 6243 that's used almost universally on the industrial side? No mention of it, because these are cyber security standards. The valve is an engineering tool. So cyber informed engineering is connecting these powerful engineering tools, not just mechanical ones, but also digital ones. Okay, not cyber. Cyber means it has a CPU. Digital means there's no CPU. It again is ones and zeros, but it behaves deterministically. Um, analog, digital, and cyber protections, all into one body of knowledge. Long introduction to CIE. My point is that the new book or the my current book, Engineering Grade OT Security, looks at OT security from the point of view of cyber-informed engineering. I didn't put it in the title, but it's very much that perspective on looking at the problem and what does this mean for us and what new tools do we have available to address cyber threats that we've kind of ignored or sort of been blind to for the last 20 years. Powerful tools, deterministic tools that we're gonna need in the era of zero days. So, um, like I said, if people are interested, uh drop you a note, drop me a note, and uh I'm happy to get them a copy, courtesy of waterfall.

Pedro Kertzman

Amazing. Andrew, thank you so much for so many insights and for coming to the show. And I'll hope I'll see you around. Thank you.

Andrew Ginter

Indeed, take care. Thank you so much. Bye-bye.

Rachael Tyrell

And that's a wrap. Thanks for tuning in. If you found this episode valuable, don't forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn group, Center Threat Intelligence Podcast. We'd love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure.