In this conversation, Bryson Bort discusses his background and the creation of Scythe, an offensive security platform. He also talks about the ICS Village and the Vulnerability Management Pavilion, as well as his collaboration with the Department of Energy on a vulnerability management research project. Bryson emphasizes the importance of prioritizing vulnerabilities in operational technology (OT) and understanding the risks in power plants. He also highlights the need to build trust with asset owners and gain leadership buy-in for cybersecurity initiatives. Finally, he discusses the importance of connecting technical expertise to business priorities. The conversation explores the importance of building trust and collaboration in the field of cybersecurity, particularly in the context of power utilities. It emphasizes the need for security professionals to be partners rather than adversaries, and highlights the role of organizations like the ICS Village in fostering collaboration and education. The conversation also delves into the concept of purple team exercises and the importance of starting small and growing in cybersecurity initiatives. Additionally, it discusses the significance of conversations with policymakers and the need for more cybersecurity professionals in the industry.
Hosted by: Aaron Crow
Guest: Sevak Avakians
To be a guest, or suggest a guest/episode please email us at [email protected]
—
Show notes by NMP.
Audio production by NMP. We hear you loud and clear.
Bryson ???? (NaN:00NaN) Sure, Bryson, former army officer, former intelligence community. In the intelligence community, I got the nickname Grim. Started my own offensive consultancy, which is where we.
Bryson ???? (NaN:00NaN) I started doing operational technology and industrial control systems. Actually how we got into that was smart meters into car hacking. So we were some of the first to do car hacking. Um, we just didn't go to wired magazine with it. Um, so that was called grim cause calling up Bryson's consultancy sounded kind of jerky, uh, while at grim.
Bryson ???? (NaN:00NaN) Uh, target came to me in 16 asked me to build them a special tool. I realized that was a product. So I was like, I want to do it this way. I asked to keep the intellectual property that created project crossbow, which we co-developed with them for two and a half years before I realized I learned I knew nothing about commercial software sales and development and brought in investors. Um, so core was, uh, Ron Gula from Tenable and Demetrius Perovitch from CrowdStrike. And we spun it out as Scythe in 2018.
Bryson ???? (NaN:00NaN) you to recreate any payload from scratch for the technically expert red team side and on the other side, it's basically operationalized threat intelligence. We automatically one button click, you can run all of the logic, not just doing checklist stuff. And that ties into how we were able to unify IT and OT risk assessments because it works at the beachhead level of higher level industrial control systems. I'm a senior technical advisor at the Institute for Security and Technology. They're best well known for the ransomware task force.
Bryson ???? (NaN:00NaN) co-founder with Tom van Norman of the ICS village or a 501c3 nonprofit that does education awareness for industrial control system security. We have our own policy conference that happens annually. The seventh one is coming up at Hack the Capitol in May in Washington DC. I'm a senior something at the National Security Institute. I don't know what my title is. I don't know. I'm around. I do stuff. Good to see you again, Aaron.
Bryson ???? (NaN:00NaN) cue the commercial break.
Bryson ???? (NaN:00NaN) This is where the intermission comes and it's like, go get your popcorn. Like remember that in the movies.
Bryson ???? (NaN:00NaN) My dog is sleeping quite peacefully right here on her little couch.
Bryson ???? (NaN:00NaN) Yeah, so two parts, even though this is going to come out after S4, we are debuting the vulnerability management pavilion at S4. That is with eight different vendors and the idea, and this is, this is always hard because it's that balance between the folks who want to come there and be like, we're 100% coverage. We're the best, right? And you know, that's a knock to the MITRE ATT&CK evaluations, but
Bryson ???? (NaN:00NaN) and the marketing, the way it gets taken. But where we, where Tom and I collaborated with Dale is we really wanted to not get into that marketing arms race, but more giving attendees an opportunity to see how changes in a real world infrastructure was reflected in different products. So it wasn't like, do you see everything? That's not the point of what we're trying to do. And it was, it's a really hard balance for the vendors to trust that enough and feel comfortable to do that. And for us to be able to illustrate that.
Bryson ???? (NaN:00NaN) effectively where nobody's getting egg on their face. So it's a balance. But the point is that Pavilion is going to be a running exhibit that we start to grow and do more collaboration. So whether you're an independent researcher or an independent researcher at a company with a budget who wants to participate, that's where we're going to be taking the vulnerability management Pavilion at future conferences. So please get involved with that. Back to my full-time job, because the ICS Village really is a project of passion
Bryson ???? (NaN:00NaN) the fact that I don't have hobbies.
Bryson ???? (NaN:00NaN) is my full-time job at Scythe. And so we just this week, it was publicly announced, there was the Department of Energy contracts where the prime is with EPRI and our partners are with Finite State and Southern Company. We are going to be doing a joint vulnerability management art research and development project. And so the idea there is where Finite State
Bryson ???? (NaN:00NaN) established vulnerabilities. The problem with vulnerability management is you get into the Sisyphean whack-a-mole, right? You run a scan, there's a bunch of problems and particularly in operational technology, you're not patching those problems so it's more like how do I mitigate these things and whatever you mitigate you run the scan and it's this there's more it's the same amount, right? There's constantly more vulnerabilities. It's the way code and hardware work. So our view is
Bryson ???? (NaN:00NaN) It's not about stopping those things. It's about prioritizing them. And the way I like to point that out is step one, you should get credit for the work you're already doing. You had a defensive posture of tools, hardware, and people that were there beforehand, and this is one of the things I really like about operations. Technology is
Bryson ???? (NaN:00NaN) I don't think it gets the credit that there was already an organic defense in the resilience and the architecture that was there prior, right? The cyber security is this additional layer, which is a problem that we've had to tackle and that's where we've seen the industry really work in the last 10 years, but the organic way that it was there already had some level of security. And then of course you have preventative and detective controls and architectural mitigations. I mean, you know, you have your, you have your air gaps. So.
Bryson ???? (NaN:00NaN) what do those mean for a vulnerability and what does the vulnerability mean? So getting credit for what you've already done and then understanding access and impact of a particular vulnerability helps you prioritize then what you're learning in your environment from, Hey, we've got this list. We've got the K E V's that CISA has told us about. Now let's put those in perspective so we can tackle them in a data driven security first approach as opposed to just compliance. We were supposed to run around and knock things out. So that's the idea behind the outcome of this is.
Bryson ???? (NaN:00NaN) Finite States finding these vulnerabilities. Southern Company and EPRI are providing the asset owner perspective and infrastructure so it's real world and then with Scythe the ability to provide that context and the attack logic in depth to understand context.
Bryson ???? (NaN:00NaN) That was my talk a year ago here in Tampa is why is it running Windows XP? This is the poster for it.
Bryson ???? (NaN:00NaN) Yep. And then that ties to the research that I've been doing for the last two years. And so that was a talk that Tim Schultz and I gave at SANS ICS. That was the research that went into Ian Anderson's talk last year at S4. And then I think Ian and I gave that talk somewhere else. Might've been SANS ICS another year. And it was, so the
Bryson ???? (NaN:00NaN) One of the problems I see in cybersecurity is we're so desperate for simple because it's such a complex problem. And so that's where MITRE ATT&CK gets abused because MITRE ATT&CK is a brilliant compendium of possibility in how we can all have the same vocabulary to describe things. And everybody looks at it and goes, bingo card, right? And I think in OT, you see the same problem in the Purdue model, because when I feel the Purdue model, it naturally gives me with five levels of that looks like defense in depth.
Bryson ???? (NaN:00NaN) And the reality is, I mean, I'll give a consulting engagement I did last year where they had a common actor directory domain between IT and OT. And I was like, you just realized with AD, you've made it one level. You've made your whole network flat. And they're like, what? And I'm like, because all these firewalls and everything, actor directory goes right over that. It's built to go through it. That's the point. And they're like, oh. And I was like, yes, you just, there are not five levels, you have one level.
Bryson ???? (NaN:00NaN) But even when you do properly implement five levels from the attack view, it's really three levels. First of all, most attacks still are targeting the IT network because it's the large squishy business email compromised phishing works, moving laterally, crossing over the DMZ, which is always there. There is always a connection between IT and OT. And I love when I have somebody who like is like, have you ever worked in a nuclear plant? I'm like, yeah, you know how many stories I've seen where those air gaps aren't air gaps? Nice try. Okay. I understand, right?
Bryson ???? (NaN:00NaN) And this is where we're going to go this, which it comes to assumptions. But the point is most attacks, and this is not to say, do not pay attention to exposure on OT that is directly internet accessible. And for those of you who work in it, I assure you need to be aware that your OT environment is already allowing third party vendors directly into that environment. It's in the contract. They have to have that access. Right? So no, that's there. If you didn't already know that's there, know that that's there.
Bryson ???? (NaN:00NaN) So I'm not obviating the need to manage OT direct exposure, but when we look at the most common threat factor, it's still IT, cross over to OT, and then that's the winning point is, I've taken over the beachhead. The high level industrial control systems, your SIS, your HMI, your DCS. I mean, HMIs are my favorite. I mean, it's built to do what it's supposed to do.
Bryson ???? (NaN:00NaN) I don't have to do anything special. I don't need to build in destroyer three. I just need to take over your windows XP device that can't be patched, doesn't have an EDR and I don't have to do discovery because it already connects to all of the lower level program of the logic controllers and just do this, do that, do this, do that. Done, right? I've created an impact. And so that just flattens the bottom, which is why there's like I said, there's only three levels and so.
Bryson ???? (NaN:00NaN) With our tool, we're able to, cause so much of where I see cybersecurity coming in OT starts with you have to build trust. These folks were already doing their jobs. They know their equipment. They're control engineers, automation engineers, safety engineers, plant engineers, call them what you will. They already do in their jobs.
Bryson ???? (NaN:00NaN) So thanks for showing up and telling me I had a computer. I was good before. Why are you here and get away from my stuff? Stay between the yellow lines and you look like you've never worn PPE before. Right? This is the start. You know what I'm saying? Right? This is the start of the relationship. And so what I like about how we've come up with this unified model is because IT is the biggest risk vector, you can do work and show how that work is protecting
Bryson ???? (NaN:00NaN) into their pajamas. Right? So you have this transparency and this is why we advocate purple teaming so much because purple teaming is a transparent exercise of the planning, the execution, and the fixes are all completely open book.
Bryson ???? (NaN:00NaN) And so from a building trust perspective, you're building trust with me, my process and the tooling to do it while I'm still showing you how we're getting to help you and then as we build that trust, then we can start to walk our way across into the OT environment into a safe space, right? I don't need to go directly into the program of the logic controllers that are controlling, you know, that high temperature boiler over there, which, you know, we really don't want that to go out of tolerance. You're not, you're not doing crazy stuff there, but what if we start on, you
Bryson ???? (NaN:00NaN) a jump box, bastion, or an HMI, right? And again, we're not sending commands, we're just showing that step of that attack logic and how our detective and preventative pieces can be built up. And then going to the final piece where we were talking about segmentation and air gaps.
Bryson ???? (NaN:00NaN) Validate. Prove it. Right? That's the point. You've built stuff. You've bought stuff. You've got stuff. Let's prove that it works the way you think it works because 99% of the time in my experience it doesn't. And let's find that nuance and fix it together.
Bryson ???? (NaN:00NaN) I'm sorry.
Bryson ???? (NaN:00NaN) Yeah.
Bryson ???? (NaN:00NaN) Yep. And so this is the point, right? Validate that East-West segmentation is the way it is. Your control zones are properly coordinated. And then it's so key to be able to understand monitoring on North-South because that's where they're coming, right? It's coming North-South in and out. That's command and control. That's lateral movement. And then East-West is an understanding of potential access to additional impact outside of the control zones, which were architected for that very reason to contain impact.
Bryson ???? (NaN:00NaN) Um, yeah. So I, in fact, I was, so I just flew back from Dallas and I was teaching a ransomware defense there with, uh, IANS where I'm faculty. And, um, so of course there was, there was a large percentage of OT folks that were in the class. And one of the things that I really picked on with this is.
Bryson ???? (NaN:00NaN) I get so many of these consulting calls where it's, you know, a team of one to four engineers, typically on the IT side, they're trying to figure out how to handle the OTPs in for various reasons. At some, some point in a deployment, they're thinking about deploying and they show me their technical architectures and we go through all of this. And I'm like, your problem isn't the technical architecture. Your problem is leadership buy-in. They're like, what? And.
Bryson ???? (NaN:00NaN) Here's the thing. Do not go to the senior executive. Do not go to the plant manager and be like, you know, we're here to help. Take it. Instead, go to those folks and be like, what are your priorities? What keeps you up at night? What are you trying to do? Start the conversation from just listening. I mean, this drives me nuts in our field where...
Bryson ???? (NaN:00NaN) And it's funny because I coincidentally, when I got out of the army, I took the first job I was offered because I was so terrified to be a civilian. I was broken. I had no idea what I was going to do. And so I ended up working for a multinational manufacturer and a commercial and, um, defense aerospace. And, um, I guarantee you, you have been in a plane that I did the power supplies and subcontract assemblies for. So, uh,
Bryson ???? (NaN:00NaN) but not the 737 max door that I had nothing to do with that. All the other stuff has not failed. So my stuff is still good. And it blew my mind that, I mean, I got Lean Six, so to a certified, I worked with suppliers on refining their manufacturing processes and like really got in depth on all of that stuff. And it just blew my mind how many folks didn't even know what the companies did for a living, like on the other side.
Bryson ???? (NaN:00NaN) Like they'd never, they didn't even like, not even walk the floor. They just didn't know what was even happening. And I was just like, just, just ask, stop, stop trying to be like, we're here to do our thing. These folks run the company. These folks are the revenue production. You are support, right? I think about this same thing I learned in the military, there was combat arms, which is rounds on target and is making something happen. And then there's combat support. Your job is to help those folks do that.
Bryson ???? (NaN:00NaN) You are not in charge. You are not the lead. You followed them. So start by just not leading with your stuff. How can I help you? What are your priorities? And then if you were looking for the best way to connect what you do to what they do, there's two things. First of all, there is one silver lining to colonial pipeline. Ransomware is now what I call a kitchen word. Your grandmother.
Bryson ???? (NaN:00NaN) knows what ransomware is. Your grandmother cannot explain what a decrypter is or how it works, but it doesn't matter. We now have a common vernacular that we are on the same page. That's your job as a technical expert to understand the depth of how to protect and detect ransomware, not theirs. They just need to understand that there's a business impact to this. But we now have a common word that we can understand. And that common word ties to an operational budget and a process that already exists called disaster recovery and business continuity planning.
Bryson ???? (NaN:00NaN) understanding their priorities, that is your connection to something they already understand, there's already a budget and understanding the process. And again, start with asking them what they care about. And then try to fit to that. Don't don't end up. Yeah, don't listen and then be like, Okay, well, you know, something else, right? Listen, reflect, active listening.
Bryson ???? (NaN:00NaN) Merry Poppins.
Bryson ???? (NaN:00NaN) Yeah.
Bryson ???? (NaN:00NaN) Yep. This is security becoming a partner as opposed to the culture of no or ego and arrogance.
Bryson ???? (NaN:00NaN) Well, obviously I can't share everything about that, but I can tell you by them collaborating with a few startups on a DOE grant to do R&D on these concepts, that alone speaks volumes.
Bryson ???? (NaN:00NaN) Well, security is a process, not a destination. And so that's where trust helps facilitate an optimal process of communication and execution. And again, in summary, two levels, right? There's the fact if I'm doing any, anytime you hear a talking head say, do this, do this, do this, those are, there are generally some good ideas in there. And then where it gets difficult is.
Bryson ???? (NaN:00NaN) the complexities of those ideas and putting them in place. And to this specifically recognizing this is where I was providing the setup with my background in manufacturing, how I learned it's organizational change. Organizational change is not either a piece of paper written in 1984 with an architecture or a brand new Ernst & Young developed architecture in 2024.
Bryson ???? (NaN:00NaN) It is the relationship basis for people saying these are my priorities and aligning those priorities and those resources and resources are money and people and time. Because without that, nothing's going to happen. Your pieces of paper, stay pieces of paper. And I mean, pieces of paper can feel good and you can put a piece of paper on a server or on a computer. I hate to tell you nothing happens. This is by the way, how I feel about the entire field of threat intelligence.
Bryson ???? (NaN:00NaN) So that's the organizational piece to an overall change that you're trying to do. And then this is where I was tying in the Purple Team side. Purple Team is a tactical exercise and process that you can use that naturally builds that trust and execution and communication in a safe to a way that you can then like any process, start simple, start small and grow it. The three variables to consider for a Purple Team exercise, scope. So I gave some examples of scope, right? Like starting an IT and working your way.
Bryson ???? (NaN:00NaN) the best examples I like to provide there because so many folks get the offensive response of you know the adversary doesn't consider any scope well fine that's good for the adversary we're not talking about solving everything all at once here we're not boiling the ocean we're starting with a process that requires its own maturity organizational buy-in trust execution right those that itself so you can learn something just from doing an exercise on a gold image in the lab
Bryson ???? (NaN:00NaN) You are going to learn what kinds of things are logged, what kinds of things are prevented just in your base gold image for your enterprise. From there, now do that on a computer in production in IT. What am I gonna learn from that? Well, I'm now gonna start to understand telemetry and detection and response. I'm gonna start to see the people side of my own team coming into this. And so you can start to see with a very simple scope, there are still things to be learned.
Bryson ???? (NaN:00NaN) It doesn't have to be everything, right? We don't need to boil the ocean and you can build confidence in the process and the tooling and the communication of what you're doing and then grow it from there. And like I said, start to work your way over to the OT side methodically, as opposed to just trying to bite the whole thing off at once. So scope is one variable. The second technical complexity. Cyber security is just data science. It's data science.
Bryson ???? (NaN:00NaN) And the reason that that's true is because that's our problem, right? Is we've got all of this data and we're trying to find the correlations in that data against the baseline that we don't understand because that's where the attacker is doing the attackers trying to be as close to that baseline as possible, which is why they're so hard to find. If they walked around with the evil bit set in the flag, they'd be really easy to find if it was all sending right back to.ru it'd be really easy to catch.
Bryson ???? (NaN:00NaN) It's not. They're using your computers design. They were way they were designed talking the way they were meant to talk going to a vanilla bounce node out.
Bryson ???? (NaN:00NaN) it's blending into what you've got. So complexity starts simple. My favorite tool to start simple is Red Canary created a tool called Atomic Red Team. It's literally in the name, it's what it does. It does very simple procedure level atomic tests that drive a signal. Now, that's a good starting point. You're gonna need to grow from that because that's not gonna give you a strong defensive insight, but it's a good starting point again. We're not boiling the ocean. We're starting where we're comfortable, in this case, a simple tool.
Bryson ???? (NaN:00NaN) Anybody can run the tool. It's easy to load. It's easy to run. And then the third part is frequency. How often are we doing these exercises? Most folks are already in the mindset of let's do the annual pen test. Guess what? A purple team counts as an annual pen test, right? You're doing an offensive risk assessment.
Bryson ???? (NaN:00NaN) My recommendation is you want to try to get to a quarterly cadence, recognizing there are different levels of this, right? That's a whole cross-functional group coming together to do this stuff, but maybe there's more tactical stuff where you're just able to have your own lab that's running against images on a daily basis, right? That still counts. So just those are the three variables for considering it in the two levels, right? Executive change management and then
Bryson ???? (NaN:00NaN) understanding, baselining, and learning in-depth technical insights.
Bryson ???? (NaN:00NaN) That's also why I like purple teaming versus red teaming and why I recommend do purple teams before you grow to red teams. So purple teams, you fix as you go. The outcome is not here's a report that's as you noted, everything's in red, literally, and you throw it at their head, did you already have a full-time job? Good luck with that. Poof, and I'm gone, right? I'm not there to help you fix it. I just found the problem, sub quality assurance. Good luck, right?
Bryson ???? (NaN:00NaN) And again, because the scope and the complexity is defined by the folks together. And again, that's so important in OT. OT has the veto. They decide what you do and when you do it and how you do it. You, they get that choice. Um, and also a red team is to me is a more sophisticated operation. That's where I'm taking complexity all the way to the top. I'm no longer trying to do a business focused risk exercise. I'm now going, all right. When.
Bryson ???? (NaN:00NaN) Right. Use the human imagination, which is what a red team operator can do. And that, and the point is why would you do that to start? Right. Grow to where you have enough confidence in your stack and your people to then be like, all right, we're ready. Throw China at us. See what you can do. Now we're, now we're pushing the edges, right. But I earned that I'm matured to that.
Bryson ???? (NaN:00NaN) Yeah.
Bryson ???? (NaN:00NaN) Yeah. And so fixing things at a higher level, slightly switching the topic. We mentioned at the very beginning, ICS Village has an annual policy conference called Hack the Capital. It's the 30th and 31st of May. On the 29th of May, we're going to be debuting the workforce development program that we started a pilot with a philanthropic grant from the Gula Foundation. And so we're going to be reaching out to disadvantaged students and vets to do a whole day of critical infrastructure hands-on training with
Bryson ???? (NaN:00NaN) student and teacher kits that this is the pilot so we'll be hoping to take that further but the point back to the 30 and 31st Because I'm assuming most of the listeners here are practitioners. We would love your input This is your chance to give a talk on I mean don't think about it as this isn't cutting R&D We're not looking for what's the latest and greatest you that's what Dale is looking for at s4. He's looking for the cutting edge We're looking for education
Bryson ???? (NaN:00NaN) giving a day in the life of an acid owner, giving a day in the life of a control engineer, giving them the day in the life of what it's like to run a municipal water plant, that has value for educating the policymakers because we bring members of Congress, there's a lot of government officials, directors of agencies, think tanks, those folks are all there.
Bryson ???? (NaN:00NaN) they're going to learn from you and then they're going to build a relationship with you. So when a regulation does start coming out, they will reach out to you beforehand and ask your opinion because I mean, look at it from their view. They are surrounded in the belt way with the K street lobbyists and all the folks who can afford to actually talk to them. They want to break out of that. They're looking to build these relationships with folks like this. They're looking to understand what's real life like down on the line, down in the trenches. Please submit the CFP, go to the icsfields.com. You'll see our events page for hack the cat.
Bryson ???? (NaN:00NaN) We want your talk, share your experience because that's how we're going to make all of this better together at a country level as opposed to you know, where we're here talking at individual asset owners.
Bryson ???? (NaN:00NaN) Best way I can to illustrate this, I was a lead expert witness in a federal district court in 2021. And I was talking to the judge and he was like, yeah, the case I had last week was around lobster farming. I'm not gonna tell the detail, but what I was working on clearly was nothing to do with lobster farming and it was much more in our space. Just to give you an idea, I mean, of the scope of here, I mean, this is the judicial branch that these folks have to just day to day, it is everything in our lives that they're a part of. We are this much of a fraction.
Bryson ???? (NaN:00NaN) back on cybersecurity experts who are like, why don't people take what we do more seriously? I'm like, well, just think about your day. On your average day, where does cybersecurity rank? I mean, step one is waking up on time, finding coffee, feeding yourself, getting clean, good clothes on, getting to work, right? You start listing all the things that are bigger priority on your day. And cybersecurity is maybe what?
Bryson ???? (NaN:00NaN) 20 to 30 for most of us, the only reason we're this in it is because it's what we do for a living. So when you start putting in the pantheon of what life involves and you know, another example is you can see this in the, um, SEC filings of public companies. Now the good news is cybersecurity has finally crept up to be a top five on average, but it's still just top five. It's not number one. It's not number two. It's somewhere usually three to five, five on average in how public companies have to disclose risk.
Bryson ???? (NaN:00NaN) even bigger risks that they have to consider.
Bryson ???? (NaN:00NaN) Yep. Tools don't solve problems. Automation just gets you there faster, whichever direction you're going.
Bryson ???? (NaN:00NaN) not going to make the table that way.
Bryson ???? (NaN:00NaN) Oh, you do not want that list, it's too long. I mean, I'll be teaching a handful of times. I'll be in Chicago in April. I don't remember all my other classes. I will be at the, at JSAC, which is a military cyber conference up at West Point. I used to be on the board of the Army Cyber Institute for a number of years. Actually, I also got a medal for my critical infrastructure work with the Army Cyber Institute.
Bryson ???? (NaN:00NaN) Check out the Jack Voltaic project if you want more. I'll be at RSA of course, the ICS Village will be at RSA. We are, since 2015 we've been a perennial part of the sandbox, not the Innovation Sandbox, the other sandbox, so come and say hi there. Hack the Capitol in May. Black Cat and Def Con in August. So pretty much wherever the ICS Village is for the most part, you can come and find me. My name makes me really easy to find online. If you want dad jokes and...
Bryson ???? (NaN:00NaN) the risk of spitting milk through your nose every day. That's my Twitter account. LinkedIn is a little bit more professional and usually just where I'll be.
Bryson ???? (NaN:00NaN) Thank you, appreciate it. And again, appreciate your support because you do work with us on the volunteer side.
Bryson ???? (NaN:00NaN) Thanks for having me, man.
Aaron Crow (NaN:00NaN) Hey, welcome to the show. Excited to have Mr. Bryson on the podcast again. So Bryson, why don't you, uh, for those that don't know you, which I don't know they must be living under a rock, but why don't you introduce yourself? Tell us who you are and, uh, and all about you.
Aaron Crow (NaN:00NaN) You too, man. Yeah. I mean, for those of you, I talk about all the time, but for those of you that are not part of ICS village, there's, there's a lot of opportunities for seeing us at conferences. I say us, cause I love being part of, of that organization, right. Um, and volunteering and being there and spreading the knowledge around of all the things that you've done and I've done and Tom's done and all these amazing people that are part of this organization and get to spread that knowledge and, and help people get into the industry and understand. And it's a, it's a great,
Aaron Crow (NaN:00NaN) teaching and learning and opportunity for folks to dive in no matter what your skill set is. So if you're interested, definitely pick it. Hang on a second.
Aaron Crow (NaN:00NaN) Go ahead.
Aaron Crow (NaN:00NaN) Let me mark that clip because for whatever reason my dog decided to come in the room so I'll cut that out.
Aaron Crow (NaN:00NaN) Yeah, I don't know. She must be scared because the neighbor is mowing. The neighbor is mowing and it's loud. So it's a lab and she's a big wuss. So. So with that, obviously, definitely check out ICS Village and all that we do. I know that there's a big pavilion at S4 if you're going to be there.
Aaron Crow (NaN:00NaN) that may have already been passed by the time this is released, but there's, there's so many opportunities, DEF CON and road shows that we do and all these opportunities to get involved in and learn and, and bring your, you know, leaders, et cetera there. So, um, man dive, dive into, I know you and I talked off, off before this around some stuff you guys are doing with DOE and, and vulnerabilities, obviously the vulnerability pavilion, but why don't you dive in and tell us a little bit about that stuff. That's, that's super exciting.
Aaron Crow (NaN:00NaN) But, and that's so powerful. Like, you know, so I've, I've worked as a consultant. Um, you know, I'm, I'm a consultant now again, um, and, and working for big four and others, even small firms, right? Is, is, it's really easy to walk into a power plant and, and have a list. I just did an assessment last week of a power plant, right? And, and it, there's this lot, there's windows XP and, and I had a, a non experienced person, uh, not, not non-experienced. Yeah, exactly. Right. And non-experienced. Yeah.
Aaron Crow (NaN:00NaN) Exactly right and I had a guy that was that was assisting me on this assessment and he's an ot guy but He's not really a power guy, right? So he didn't he's not power utility Experience so we're walking in and he's like, oh my gosh and like his eyes are popping out of his head And i'm like, that's fine. And he's like wait what and i'm like, yeah, but it's disconnected. It's in the water lab It's not connected to anything else. There's no control with it Like there's no like worst case scenario a hacker gets a hold of the water the chemistry xp machine
Aaron Crow (NaN:00NaN) So what it doesn't impact it, right? It, they, they can't do their water lab and they do it manually, right? It's not impacting that, right? And so it's really easy to walk in with a red pen and just mark up everything that that's, you know, 30 years old and not patchable, but you really need to understand the attack vectors and the other things that they've got segmentation and they're not, the networks are not connected to everything. And you to really understand the risks of these environments and the vulnerabilities, because I can dump a finite state S-bomb on top of it.
Aaron Crow (NaN:00NaN) But it can explode and I don't know what the hell to do with that. Being able to contextualize what that means to me, like all of these things. And okay, so what? Tell me the story why these things matter and what I should do about it. That's the next step that asset owners are looking for.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Nope. Yep.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Mm.
Aaron Crow (NaN:00NaN) All right.
Aaron Crow (NaN:00NaN) Yep. Yeah.
Aaron Crow (NaN:00NaN) Yeah, I mean.
Aaron Crow (NaN:00NaN) I'm laughing because again, I just did an assessment like two weeks ago, I'm at a power plant wearing PPE and they give me the network architecture drawing. It looks like it was drawn in 1984. I'm asking the local plant person who is the only person, what is this, what is that, where is this box, where is this box? And he doesn't know. And where's this firewall? I don't know, it's listed as a Cisco, whatever it was, like Cisco old AF firewall.
Aaron Crow (NaN:00NaN) And there is no Cisco OAF firewall in this room. So where is that box? I don't know. It's still in the drawing though. And that's the latest drawing they have, right? So when they tell me they don't have remote access, or when they tell me there's no connection to the corporate network, how do you know? Obviously you don't, because you don't even know where a firewall is that's on the drawing that you gave me.
Aaron Crow (NaN:00NaN) So how are you, so you talked about that trust and that is so big and that's something that most, they skip over, right? They focus on the technology and it doesn't matter how great your technology is. If you can't win over the plant manager, it doesn't matter how great it is, he's never gonna let you in the door. Like if you laughed about the PPE, which is why I was laughing about it, right? If I show up in penny loafers and slacks to a power plant, they're not gonna let me in the door, right? They're not gonna trust me. It doesn't matter how great my stuff is, they know that I don't belong here.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) It's what you just said is so powerful, right? And I've seen it a thousand times. I've seen again, working as a big four firm and all the different places. And we try to, hey, I'm smarter than you. Just take what I know and let me cram it down your throat because this is the medicine you need, take it, right? And it's the old, what's the song? A spoonful of sugar helps the medicine go down, right? You can't just force, exactly. You can't just force down.
Aaron Crow (NaN:00NaN) these architect, even if they're right, right? Even if I'm the smartest guy in the world in my architecture, I've proved it a hundred times. It doesn't matter, right? If that's not a problem, they understand. If they don't know about ransomware, or they, you know, I can't tell you how many plant managers have told me, well, I've been doing, I've been running this plant for 40 years. This is the same technology we've had for 40 years. It's never been a problem until y'all connected to the internet, just disconnect it, we're all good. Just go away, right? And I have to explain to them, yes, that's one attack vector, but it's not the only. The nuclear.
Aaron Crow (NaN:00NaN) power plant environment where you bring it into, I've got a whole story around that, that doesn't stop it, right? But what I'm trying to get back to is what you just said is so powerful, right? It's IT thinking they're the dog and they're the tail wagging the dog when the operational, the plants, all those things are really the guys shooting the guns down, the bullets down range, they're the ones that matter. And the IT is a support of them. So you can't force your architecture, you can't, you know,
Aaron Crow (NaN:00NaN) try to patch everything in a power plant or rip out the XP box because it's XP. Oh, the sky's falling. We have to put windows 11 on it. No, that's not the answer. Find different ways to have these solutions and it really all starts with building trust and having conversations, not telling them your architectures better or their babies ugly, asking them what they need help with and how can you help them? And then you start inching your way into when they trust you, then they'll look,
Aaron Crow (NaN:00NaN) maybe listen to you or look to you as, hey, we're gonna deploy this new thing. Why don't you come over and give us some advice on this stuff?
Aaron Crow (NaN:00NaN) Exactly. So, so with the, with the, the DOE thing with, with Southern Company and Finite State, how, how is Southern Company? And I've worked with Southern, they're, they're awesome. Right? How are they using that same mindset and how are they being the, the bleeding edge and the, the razor's edge on this thing? And how are they going to do this and be successful? How are you going to do this? Sure.
Aaron Crow (NaN:00NaN) Absolutely. So when you, when you're approaching these scenarios like this, like you're going into greenfield, you're doing these new things, you're in, in a power utility. Um, again, just theoretical, not even necessarily this, but how do you bridge those conversations? How do you, obviously you've got to build that trust. You've got to do it in a safe way, but you have to have that understanding. Um, and then what is the outcome, the ultimate goal of, you know, at the end of this, what is the, what is the, where's the finish line? Like, how do you get there?
Aaron Crow (NaN:00NaN) from where you are to then.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Sure.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) There's so much there too. I mean, if you, if you look at the IT and OT, just from a procedural perspective, right, the teams are different, the experiences are different. I can't just take an, an instant response plan from my IT org and cram it on the OT side and expect it to work. Or the same thing with red teaming. I'm not going to, I'm not going to purple team, red team, anything in an OT environment, the same way that I'm going to do it in an, in an IT environment. Um, just from the people involved, like if you bring.
Aaron Crow (NaN:00NaN) Again, as an asset owner, but in the past, you know, I had one of the big four firms come in and they were doing a red team on the, um, pen test on the IT side and, and the CSA, they convinced the CSA. Hey, we should do this in the OT side too. Sure. So that came over and I'm like, okay, so I'm going to go, I'm going to use my laptop. You're not going to touch anything. You can tell me what commands you want me to do. And I may do them depending on the environment that we're in and the system that we were wanting to run them against. Right. Um, it was completely different, right.
Aaron Crow (NaN:00NaN) I still got the, I checked the box. We went through the exercise. We learned a lot, but still on the IT side, they just had carte blanche, right? They were, they were doing their thing and they were running their scripts. They were doing what they need to do. They had this real big, long list. And the first version of their, their report on the OT side, they had all of these gaps and they had them all as negative. And again, this was 2011, you know, it was a long time ago, right? Before there were really any OT products that existed. Or...
Aaron Crow (NaN:00NaN) even the OT market was, was fairly new from that term, but they had, everything is a negative and I had to walk through them with it and say, look, to your point, all the things that we had architected from an operational perspective were an actual benefit. So all the things that you had on here as negatives, I was countering, not all of them, but some of them as maybe they weren't good things, but they definitely weren't, you know, rated 10, you know, blinking light, horrible things. And this is the reason why. So
Aaron Crow (NaN:00NaN) I added that caveat. So it changed it from a glaringly red document to a, you know, there are some things that we learned from this, but it's not all the sky's falling chicken little.
Aaron Crow (NaN:00NaN) Go do something about it.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) Yeah, it's like bringing the SWAT team to break into your house. Like I don't need a SWAT team to break into my house when I didn't even lock my door, right? I literally didn't lock my door. Like my neighbor can break into my house. I don't, I don't need to go get a SWAT team with a, with a battering Ram and, and MP5s and any of that, like just open the door you're here. And that's where a lot of our environments on the IT and OT side, uh, many of them are, so why would you start with bringing the SWAT team when you can start with.
Aaron Crow (NaN:00NaN) something that's a lot more feasible and, and they can say, Hey, we're going to go ahead and put a lock on the front door. Um, that way this won't happen again. And then let's check the next problem that we found. Okay. Maybe you should lock your windows and maybe she put in a security system. Maybe she put in some cameras, like let's fix some of those things before we release the SWAT team.
Aaron Crow (NaN:00NaN) Absolutely. And that's, I'm super excited about that. Tom and I've been talking about that quite a bit and I've been given my, you know, input sometimes on asked, but, um, you know, just so excited. There's so many people that are reaching out to me through the podcast and, and they're, Hey, I want to get into OT. I want to get into cybersecurity. How do I do that? Where do I go to train? And, and yeah, there are some things out there. SANS does some great things and there are some things out there, but more is better.
Aaron Crow (NaN:00NaN) Right. We need more. We need different perspectives. We need different options. We need more options. We need more people fighting this fight. Um, this is not, to your point, this is a, this is a country level. This is, this is a bigger problem than I can solve than you can solve individually as a, as a consultant or as an asset owner. Like we need, we need help. We need more people in this fight. And from having the conversations on the Hill, you know, you know, you've had as many of them, probably more than I have, guarantee you more than I have.
Aaron Crow (NaN:00NaN) Um, but you know, going to talk into the, our congressmen and our senators, they, they have, they're talking everything from farming to, you know, cybersecurity and, and they're not cybersecurity experts. They're not even close. They barely know as much as my grandmother does to use your analogy earlier. They're expecting their staff and others to, to have an idea. And then they want to build relationships with people that they can reach out to. If there's something that comes up, like they're not, you don't want, they're not going to be an expert in all these things.
Aaron Crow (NaN:00NaN) But they have to make a decision and have an opinion on these things when legislation is coming out or when, you know, regulations need to come out. Right. So we need to build those conversations. It takes time. It takes doing more than your daytime job and going out and talking and doing those things, uh, in addition.
Aaron Crow (NaN:00NaN) Yep. Sure.
Aaron Crow (NaN:00NaN) Yeah. And it's, it's w you see NERC SIP and you see the regulation that's come out around power utility. And I have this conversation all the time. And why is, why is NERC SIP so much or why are the power utilities so much further advanced, even though you and I know they're, they're still in their infancy stages. But it's because they've had these conversations for 15 years and they've been pushing this narrative and they've been pushing. This is the things that you can do. And the industry has been part of that.
Aaron Crow (NaN:00NaN) right? They've been having these conversations with regulators. So they've gotten the spotlight and these other industries haven't gotten as much spotlight, right? So, so we need to have these conversations, things like hack the capital or great opportunity to get in front of people, have those conversations. And to your point, it's, it's not, Hey, my, my widget is the best widget. It's about, Hey, these are the problems that I'm seeing. This is a day in the life of a consultant. These are the types of things that I'm seeing as an asset owner. These are the types of problems that I'm having from an operational perspective.
Aaron Crow (NaN:00NaN) not even just a cyber thing, but hey, I have all these things that I'm trying to solve. How do I do that in this space? Like these are, these are problems that we need to solve as a, as a bigger entity, uh, as a, as a country, as, as a, as a, as a cyber security and stop just trying to sell our crap.
Aaron Crow (NaN:00NaN) They don't.
Aaron Crow (NaN:00NaN) Yep. Well, you know, I know we say it all the time, but it's people process and technology. Like you can have the best technology in the world, but it doesn't matter. The analogy I always give is I can, I can buy the best woodworking tools in the world. If they sit in my garage and I don't do anything with them, what good are they? Right? I still have to pick them up and do something with them.
Aaron Crow (NaN:00NaN) So what do you have coming up? How do people get a hold of you? What is coming up on, obviously S4, this will be out after S4, so what are the next six months or so that you've got coming up?
Aaron Crow (NaN:00NaN) Very cool.
Aaron Crow (NaN:00NaN) That's awesome. Most of those I'll be at as well, supporting the ICS Village. I always look forward to doing that work. Definitely, I think our ask is pretty clear here for people to get involved, like get your organization involved. If you're a vendor and you support this space, consider sponsoring the ICS Village, coming out and throwing your hat in. And again, it's a nonprofit. And the reason for that is because we're providing value to the greater organization. All of this...
Aaron Crow (NaN:00NaN) the infrastructure and all of this OT space, it's a great mechanism to build and for a greater cause than just, you know, go into a conference. So it's a lot of fun and there's a lot of good value and awesome conversations that we have there.
Aaron Crow (NaN:00NaN) Absolutely. Well, hey, Brison, thank you. I'll put all those details in the show notes, but thank you again for your time and joining me on the podcast.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.