In Episode 10 of Protect It All, titled "Tools and Techniques for Better Network Visibility and Vulnerability Management with Kylie McClanahan," host Aaron Crow and guest Kylie McClanahan dive into the critical elements of enhancing cybersecurity through advanced tools and strategies. Kylie, CTO of a company specializing in this field, shares her insights on overcoming the challenges of consistent naming conventions, accurate vendor data, and breaking down silos for effective communication across teams.
They explore the utility of tools like Spartan and Network Perception in visualizing network vulnerabilities, mapping asset inventories, and planning effective patch management. They emphasize the importance of correlating vulnerabilities with business priorities rather than just CVSS scores and the need for a layered security approach.
The episode also discusses cybersecurity risks to non-technical stakeholders, highlighting the business implications. The duo discusses the evolving landscape in the power utility sector, the dual nature of physical and cyber threats, and the ever-present need for continuous adaptation.
Kylie shares her excitement about machine learning and graph neural networks for grid state estimation while expressing caution about AI tools' accuracy. Aaron and Kylie stress the importance of reliable data, automated processes, and vendor security advisories in maintaining effective asset management.
Key Moments:
03:47 Discussion focused on improving cybersecurity classifications and communication.
08:48 Compliance sometimes leads to minimum effort for benefit.
11:17 Vendor security advisories prioritize patch tracking.
14:46 Testing for security vulnerabilities and potential exploits.
17:20 Understanding and communicating cybersecurity risk to non-professionals.
20:50 Disagreement on consistent product naming causes confusion.
25:46 NVD website publishes overwhelming recent vulnerabilities.
27:07 Understanding the importance of asset management.
32:13 Challenges of tracking change management in organizations.
33:33 People, process, and technology are crucial investments.
37:34 Spartan takes any scan, offers change management.
39:55 Vision of the future: a dynamic ecosystem.
43:19 Vendors acknowledge changes in control systems effectiveness.
48:09 Equations useful, AI for optimization, caution with models.
49:28 Questioning truthfulness of AI in HR replacement.
53:01 Toyota and Lexus prioritize reliable, tested technology.
About the guest :
Kylie McClanahan is the Chief Technology Officer of Bastazo, Inc and a doctoral candidate in Computer Science at the University of Arkansas. She has nearly a decade of experience with cybersecurity in the electric industry, including both professional experience and frequent collaborations with industry as a graduate researcher. Her research explores the automation of vulnerability analysis and remediation using natural language processing and machine learning. She holds a GCIP certification from GIAC and speaks frequently about cybersecurity in industrial control systems.
How to connect Kylie:
https://www.linkedin.com/in/kyliemcclanahan/
https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Aaron Crow (0:1.422): Hey, Kylie, welcome to the show. I appreciate you taking the time. Um, I'm glad that you were able to carve out this time and, and I'm excited to talk about the topic. So why don't you introduce the listeners to you and the company and kind of what you guys do.
Kylie McClanahan (0:15.008): Yeah, absolutely happy to be here. My name is Kylie McClanahan. I'm the CTO of a company called Bustazo. We do vulnerability and patch management primarily for electric utilities, looking at the NERC SIP requirements to help with that compliance piece.
Aaron Crow (0:37.581): Yeah, I've got a lot of experience in that space and vulnerabilities and NERC SIP and all those different things. So, you know, we were, we were just at a conference. Well, we've been a lot of conferences together over the last while, but, but the most recent one was in Chicago. It was really smaller, smaller space. I mean, and I like those, um, I saw somebody else posting about that, right? S4 is great and all the big conferences are wonderful. I'm going to them all. I love them all, but sometimes those small conferences are really, they're intimate and you really get to, I don't know, you get more convert. I'm able.
Kylie McClanahan (0:46.496): Well.
Aaron Crow (1:6.635): a lot to really understand the talks and be able to be there and have more dialogue. Whereas some of the big ones, man, I just there's so many great things going on as for you just can't catch them all. Like same thing at Black Hat, right?
Kylie McClanahan (1:15.615): Exactly. Yeah, yeah. And like, you know what I really like about the smaller ones is you get a lot closer to the end users or the end consumers. It's really easy to get kind of caught up in the buzzwords, right? And miss what the experience is like for the person actually doing it.
Aaron Crow (1:35.177): Yeah, absolutely. Well, so let's dive in, man. Let's let's go. So vulnerabilities are a huge topic that everybody's concerned about, especially in OT, because we have all this aging architecture and, you know, we don't have staff to patch like we do in IT. And there's just all these, you know, and we're getting these passive sensors that are telling us about vulnerabilities and tell us all these things. But then what do we do about it? Right. It's such a big problem across so many verticals that have OT, which just about everything has OT nowadays.
Kylie McClanahan (1:38.750): Yeah.
Aaron Crow (2:4.809): So how are you guys approaching it and what are you guys doing to kind of help in that vast space that we need vulnerabilities in OT?
Kylie McClanahan (2:12.605): Yeah, you know, I think actually first, I'll go on a little bit of a tangent. I was at VonKahn recently. It's the first year they've done it. It was a phenomenal event. And really, going to VonKahn after primarily going to these OT conferences, one of the things that I noticed very quickly was that there's a totally different vocabulary.
Kylie McClanahan (2:40.189): There's a lot of focus, for example, in CWEs, the common weaknesses and enumerations, and associating that with CVEs, which is great, right? To be able to look historically and say, like, you know, memory safety is a huge problem, what can we do about memory safety, or, you know, whatever class of vulnerability. But, you're, you know, I'll say end user, the person charged with res -
Kylie McClanahan (3:9.404): remediating these vulnerabilities. That doesn't matter to them because that doesn't help them at all with fixing it. And I think honestly, even more so in OT, where the person tasked with that or cybersecurity in general is less likely to have any formal training or education in cybersecurity because they were brought on for their engineering expertise in many cases.
Kylie McClanahan (3:37.563): And so I actually had a lot of really good conversations there with people asking like, how do we make CVSS better? How do we make the NVD better? How do we make, you know, these classifications? And, you know, one of the conversations I had was with someone on the CVSS working group, which was how can we get better real world examples of like the difference between network and adjacent network? Like I get conceptually, but I did computer science. Like this is something that, you know, if you've never taken a networking class,
Aaron Crow (4:0.645): Mm -hmm.
Kylie McClanahan (4:7.195): or even like professional education, what are ways that like we can better communicate to you like what the difference between that is?
Aaron Crow (4:16.645): Right. Yeah. I mean, language is so important. And to your point, a lot of the people that are that are at the front lines that are that are defending and protecting these environments or remediating these environments, they don't come from a background of technology. They don't come from not that they're not capable. That's just not what they do. Right.
Kylie McClanahan (4:32.058): No, no. Yeah, and I spend most of my time in the electric sector and you see so much of that there. Now, of course, SIPP is not new at this point, but around 2015, 2016, when version five was becoming mandatory and enforceable, you saw a lot.
Kylie McClanahan (4:59.226): of people who were told all of a sudden that they were now the cybersecurity head at their plant or in their department. And I think to go kind of with the funding and staffing issues that everyone has, a lot of places are still trying to play catch up with that.
Aaron Crow (5:20.805): Yeah, absolutely. I mean, there were a number of folks that, you know, they'd been at the plant for 40 years and they're the most capable and understanding of the environment, but they're not technology people, right? They're not, they don't think in networking and vulnerabilities and IP and routing and firewalls and all that kind of stuff. It's not that they don't understand it. It's just, that's just not their primary job. So we're constantly fighting this uphill battle of...
Kylie McClanahan (5:41.434): Right.
Aaron Crow (5:45.061): trying to make it where it makes sense to them. Again, not because they're not, they're stupid or anything like that. It's just, you know, French and English, right? It's just different languages, right? And if you teach it to them, then they'll get it, but they're not going to just get it out of the box. It's not, it's not so simple that just anybody can pick it up and oh yeah, well obviously that makes sense because it's very complex.
Kylie McClanahan (5:52.282): Exactly. Exactly.
Kylie McClanahan (6:5.016): Absolutely. And that's something, honestly, that I've really tried to make something important to Bustazo as we're kind of getting started. We're still very, very new. Which is that when you go into these environments and you find out that the newbie on the team has been there for 15 years, right, one of the greatest assets there becomes the intuition. The like,
Aaron Crow (6:26.213): Yeah.
Kylie McClanahan (6:31.768): the intuition that something is wrong. And what I've seen a lot of is teams or plants, whatever, with incredible amounts of this learned experience who spend their time doing, and I want to be clear, I'm not saying useless, right? But somewhat dull or repetitive compliance evidence, whether it's taking screenshots to prove that you've tracked a vulnerability source or trying to,
Aaron Crow (6:52.325): Sure, sure.
Kylie McClanahan (7:1.079): whole documentation together in audit prep. And one of the things that's been really important to me is how can we help to automate some of these things, keep them in a database instead of a network of folders, for example, so that the intuition and the experience that they have can be better used and they're not just spending time doing these very menial tasks.
Aaron Crow (7:27.141): Yeah, you know, and I've been around NERC SIP a long time, all the way back, you know, version three and implementing five and six and all the different things. You know, I grew up in power utility and generation and transmission. So I've seen that firsthand and how difficult and how the language is. And I've seen it across multiple organizations, very large organizations. So I've seen how the same, it's kind of like religion. You read the same line in the Bible and two different people.
Aaron Crow (7:53.541): take two different complete things from the same words that are on the page, right? They're, they're the way that they interpret it and the way they implement it are vastly different. And that's where the language and the NERC SIP language is meant to be, you know, very fairly vague so that you can implement it for your organization. But you know, you can also misunderstand there's, there's, there's a lot, it's not black and white. It's very, very complex. And again, I've seen vastly different implementations of the same exact thing.
Aaron Crow (8:22.053): and they're both compliant, right? So they're both checking the box for compliance, but they're not doing the same thing from a cyber perspective.
Kylie McClanahan (8:24.535): Right. Right. No, it comes down to doing, doing what you, what you've said and set out that you're going to do. Yeah.
Aaron Crow (8:34.085): Correct. Right, right. Yeah, but sometimes I think it's a double -edged sword because sometimes I don't like compliance in that I think many people do just the bare minimum to check a box for compliance instead of using that opportunity to do the right thing, or right is not really necessarily the correct answer or the word, but the most beneficial to the organization.
Aaron Crow (9:3.013): From a not just trying to not get fined It's kind of like, you know I'm gonna go this at the speed because I don't want to get a ticket instead of I want to go this speed because it's safe and it's the right all the other factors are the right thing to do my kids are in the car and you know, There's a dog on the street and the stoplights not working and all those other factors It gets to the same answer sometimes but other times it's vastly different. Sometimes it's like hey I'm just gonna take of a different road because that road is problem. I'm gonna go the back way because it's safer. I
Aaron Crow (9:31.461): And that's probably the better way. I'm not gonna connect. I'm not gonna drive the fast car. I'm gonna drive the other car. So my analogy is breaking down a little bit, but you get what I'm trying to say here.
Kylie McClanahan (9:38.167): No, absolutely, absolutely. And sometimes, I mean, not even just sometimes, it becomes a question of funding, but requisitioning funding. If you can say, I have to be able to demonstrate this, here is a tool that will do this, it costs this amount of money. That's something that may be achievable versus I need a tool to protect my network. OK, well, what does that mean? And how far and how many people do we need? Right?
Kylie McClanahan (10:6.583): I think especially talking with cooperatives and municipalities where you're not just trying to get money from shareholders or from the, you're going back to rate payers, you're going back to like a city board. It can be difficult.
Aaron Crow (10:7.109): Yeah.
Aaron Crow (10:10.981): Yep.
Aaron Crow (10:22.853): Well, and those are even beyond just funding. So funding is a hard thing, but even beyond that, like, you know, I worked for a power utility and again, I've worked across very large power utilities and even smaller ones too, but they have teams like maybe it's a small team, but they still have somebody that has that job. When I go to municipalities and Waterview districts, they don't probably have anybody like, well, Todd knows the most about it, but that's not his job and he's not a cyber person. And
Aaron Crow (10:50.309): He doesn't even have OT in his title and he doesn't even really do it, but he can speak that language better than anybody else, which is still probably at a, you know, eighth grade level compared to the, you know, multiple PhDs that you need to have an expert level of understanding in these environments, right?
Kylie McClanahan (11:5.079): Right, right. Well, and I think, you know, to kind of go back to the beginning and the difference in language, I think this is where, you know, vendor security advisories start to become really important. And I think it's why a lot of NERC SIP, at least in practice, SIP 7 has leaned towards the patch side. You got to keep track of patches and vulnerabilities are kind of more of a, if you have time, right?
Kylie McClanahan (11:32.534): And I think part of that is this language that the advisories from vendors, or at least the notifications of patches, is something that you can do without requiring your end user, analyst, operator, whatever the term is, to have an understanding of the vulnerability and its capabilities. Whereas if you ask somebody just to scroll through the NVD, you have to figure out if it applies to you, and then also if you can even do anything about it.
Kylie McClanahan (12:2.230): And that's not easy to determine.
Aaron Crow (12:2.545): Mm -hmm.
Aaron Crow (12:5.360): Well, and again, going back to what you're saying, right, is applying a patch is black and white, it's binary. Did you apply it or not, period? I did or I didn't, or if I can't, then here's my reason why. It's a justification because I don't have that version of software or it doesn't work with this other thing that I have and the vendor gave me an exception because if I install it, it breaks something, like whatever that case may be. But to your point, like when you're looking at vulnerabilities, there's a lot of ways to mitigate. You can put in a firewall rule, you can...
Aaron Crow (12:31.792): you know, uninstall or disable RDP or whatever the thing is for the attack vector. There's a lot of different ways that you can do that. And it becomes a lot muddier to be able to to prove, especially from a compliance perspective, because that's what a lot we're talking about here is, how do I prove that I've remediated it? How do I prove that I've mitigated this vulnerability without just being able to say, is this patch number installed on this machine? Because that's a very yes or no. It either is or it isn't. And if it's not, then here's my exception.
Kylie McClanahan (12:58.165): exactly.
Aaron Crow (13:0.654): Right? But when it's, you know, when, when it's, it's all you start looking at SBOM and all these vulnerabilities that we have underlying, like, how do you know that you've, you've remediating those things? And the answer is, is you can't know. So, which means it's hard to regulate. It's hard to have a compliance program around that because compliance is always looking for this checkbox of it either is yes or no, it can't be anything else. There's no gray area. There's no purple. There's no, none of that. It's, it's yes or no.
Kylie McClanahan (13:1.302): Right.
Kylie McClanahan (13:29.271): Exactly, exactly. And you know, kind of to that point. So I'm finishing up grad school at the same time doing stuff with Bustazo. And I was part of a grant called VINT for Vulnerability Intelligence. And it's what I spoke about it as for this year. We had finished a big piece of it. So it was the University of Arkansas and the University of Arkansas at Little Rock. And then Bustazo and Network Perception. So Network Perception.
Kylie McClanahan (13:58.551): for any listeners who don't know, right? They'll take in firewall configs and give you kind of a graph model of your network they've been around for a while, particularly in the electric sector. And so the goal of the grant being, if we have this network model and we have vulnerabilities that we know apply to your devices, at the...
Kylie McClanahan (14:24.150): you know, we know that it's this vendor, this product, this version. Can we place an attacker completely, you know, theoretically, we're not doing, it's not pin testing in any sense, can we place an attacker and then see how far could an attacker get with available exploits? What if they had a high level of credentials? What if they had active directory? You know, and how far could they get? With the goal being,
Aaron Crow (14:35.021): Mm -hmm.
Aaron Crow (14:46.217): Mm -hmm.
Kylie McClanahan (14:54.454): to get kind of a binary safe or unsafe, and to be able to give you reasons for that. It's safe because this vulnerability requires RDP, and you've blocked RDP in the path to that device. To be able to say, you still can't know for sure. There's still the chance that a malicious insider is going to come wreck your system.
Kylie McClanahan (15:24.694): But to say, in this simulation, you've blocked network traffic. And then when you look at it from the graph view of the network, hopefully, you know, spur other mitigation actions. You know, you mentioned firewall rules. To look at if we have a set of assets across the network that may be vulnerable, and maybe they are unsafe vulnerabilities, is the best remediation to go patch each one of those?
Aaron Crow (15:40.905): Mm -hmm.
Kylie McClanahan (15:54.038): Or could we do something broader? Is this a time to start putting in better network segmentation? Would that help us? Could we patch an upstream node and then just one and then prevent exploitation of these further on? To be able to help you closer to the question, like, am I at risk? I know my device is theoretically susceptible, but is my system at risk?
Aaron Crow (16:18.853): And being able to calculate that like to a number or be able to understand, yes, I'm at risk. Risk is never zero or rarely ever zero unless I just don't do anything and unplug everything, turn everything off and go home, right? Then my risk is zero. But that's not what we're talking about here. But your risk is never zero. Like you never can secure your network. Like you can improve your security. You can expand your security. But we all know, given enough time and opportunity,
Kylie McClanahan (16:31.350): Yeah, right, right.
Aaron Crow (16:45.989): somebody can get in. It's just like the lock on my front door. Like I can buy the most expensive lock in the world, but I'm never going to just depend on a lock. I'm going to have a lock and a security system and cameras and a dog and a gun and like all the different layers of security because I know if somebody wants in, they're going to get in. I give enough time and opportunity. They're going to get in. They're going to drive a car through my front door. Like that doesn't help how great of a lock I have if they drove a pickup truck through it.
Kylie McClanahan (16:59.348): Exactly.
Kylie McClanahan (17:2.260): Right.
Kylie McClanahan (17:9.620): Exactly, exactly.
Aaron Crow (17:12.965): So that really, given those tools, that's a better way to understand and to, that's really a lot of the struggle that we have today is A, communicating the struggle that we have and what risks we have, right? Cause again, board level conversations, they wanna understand what is my risk, right? But they're not cybersecurity professionals, they're not necessarily technologists, et cetera. They're really looking to be able to.
Kylie McClanahan (17:32.852): Mm -hmm.
Aaron Crow (17:40.964): put it into business terms and financial terms, what is the risk? Like if here's my risk and now we're going to lower it, you know, is it a $10 ,000 cost? Is it a $100 ,000 cost? What is my risk? How much is it gonna cost me if I don't do it? Like, and a bad guy takes action. How much is it gonna cost me if I try to remediate so that the bad guy can't get in? What's the delta? And ultimately that's what we're talking about here is we're always weighing the pros and cons, the risk and the reward.
Kylie McClanahan (17:55.219): Mm -hmm.
Kylie McClanahan (18:2.739): Mm -hmm.
Aaron Crow (18:10.723): of every conversation of how do I get funding? And if I have a dollar, where am I going to spend that dollar? Is it better to patch all the systems? And OT, usually not. So what about these systems? Are these more critical? If I do that one up there, does it lower my risk enough that I'm comfortable with the risk? Because we've gone all the... And that's the conversation that today is difficult to understand, especially if you have multiple sites and...
Kylie McClanahan (18:17.715): Mm -hmm.
Aaron Crow (18:36.739): multiple types of sites. I've got power generation, I've got manufacturing, I've got gas pipeline, I've got warehouses, I've got buildings with elevators and HVAC. It's this vast problem that nobody can grasp their hands around to really understand the true business risk, because ultimately that's really what we're talking about.
Kylie McClanahan (18:53.586): Right, right. And I think you have to factor in the IT risk as well to be able to say, is that going to be the point of first compromise? Or is that going to trigger us to take steps in our OT network, even if the attackers don't ever get there?
Aaron Crow (19:1.507): Absolutely.
Aaron Crow (19:14.627): Right. So how.
Kylie McClanahan (19:14.866): And I think everyone wants a lovely equation that we plug in the eight variables and we get a number. And I think people are starting to realize that it takes an incredible amount of expertise and you're not going to end up really with a percentage. And if you are being given a percentage, please ask them exactly where that's coming from. Yeah, right, right. It's the answer to everything.
Aaron Crow (19:21.635): Bye.
Aaron Crow (19:38.723): That's right, 42.
Aaron Crow (19:43.615): That's right. Well, yeah, you know, it, it's so complex, even in, again, going back to, you know, you look at your municipalities and your wastewater and small organizations, even a small organization, it's, it's a complex problem, but you get into large organizations and multiple sites and multiple types of verticals inside of a business unit and all of that, like IT side and OT side and, and, and supply chain. And I mean, there's just so many factors that ultimately were, I know,
Aaron Crow (20:12.734): personally a lot of folks that are just throwing their hands up because they don't know what to do. They're just like, it's so complex. I don't know where to start. Like I've got a firewall. I don't know what else to do, right?
Kylie McClanahan (20:16.946): Yeah.
Kylie McClanahan (20:22.160): Right, right. And honestly, I think it feels that way for the vendors too. I was talking at VulnCon with someone from Siemens, and I'll say first, this is not me hating on Siemens, they do an incredible work. We were talking for a bit about software identification, which is of course one of the big problems, right? How do you associate that? And...
Aaron Crow (20:36.222): Sure. Yeah.
Kylie McClanahan (20:46.639): You know, he was, he was talking about in, in, internally between the product development teams, the sales teams and the security teams trying to agree on a consistent, uh, a consistent naming. You know, he'll say customers will, will come to the security team and say, am I vulnerable? I have a green box and a gray cabinet. And that could have been called eight different things by, and you know, not to hate on sales teams either. That's not my point, but in different markets, in different areas in.
Kylie McClanahan (21:16.207): you know, in different times, that same box running essentially the same software could have been called many separate things. And so, you know, I could talk for a long time about CPEs because there's all kinds of stuff there. But it's not even just a question of getting in correctly from the vendor, because within vendors, it becomes really difficult to determine consistent naming.
Aaron Crow (21:42.586): Well, and you hit something right there, especially in, in, you know, these OTSpaces, they, our OTP people look to their vendors and they, they, they look to them like they're deities and everything they say is truth from God's mouth. Right. And as we know, it's, it's not always that way. Right. They're doing the best. And again, not to hate on them. I have a lot of great relationships, a lot of these vendors, but there's no way they can know everything. So they, they do their best. They test, they do a good job of those things.
Kylie McClanahan (21:56.590): Yeah.
Kylie McClanahan (22:2.254): No, no.
Aaron Crow (22:9.882): but it doesn't always, it's not always the right answer and it's not always a hundred percent true, right? It's, it's true to the best of their knowledge. I'm not recommending or suggesting any and they're lying or doing anything malicious. It's just, they're not, they don't know everything. Yeah.
Kylie McClanahan (22:16.270): Mm -hmm.
Kylie McClanahan (22:22.158): No, no. Exactly, exactly. And you know, when you talk about especially the big international OEMs, there may be information in one area that doesn't fully get communicated to another area. You're trying to break up the silos as the buzzword goes. You know, it becomes really, really
Kylie McClanahan (22:51.597): difficult. And so I think really everyone is kind of in a lurch, hoping someone else has the answer. And we're all in this together. So.
Aaron Crow (23:3.860): That's right. So one of the things you talked about at that conference in Chicago was on this integration with network visibility and being able to get those firewall rules and the routing tables and all that kind of stuff and integrate that with vulnerability and really be able to try to understand that perspective. How have you seen that help conversations even just being able to...
Aaron Crow (23:32.147): associate and really understand where my network is, how it really lies out and where my vulnerabilities are versus just looking at a CVE score, right? Of an asset that, you know, PLC number one has this many vulnerabilities. And what does that mean to me? I don't, I don't know what to do with that, right?
Kylie McClanahan (23:41.485): Yeah.
Kylie McClanahan (23:46.764): Yeah, no, yeah, yeah, yeah. OK, so I think here's where it really starts to help. It can be very easy to get in a whack -a -mole mindset with patching. The mole pops up, you whack it with the hammer, you patch that one, congrats. And so it becomes really easy to lose track of the bigger picture, because you're handling what's right and right in front of you.
Kylie McClanahan (24:14.700): You're trying to meet the deadline. You're trying to get the audit evidence, et cetera. Especially if you are the one in charge of doing that analysis, finding the patches, getting people together to do what you need to to actually install it. It is very, very difficult just because of the grind that you're in to take a step back and look at the big picture. What has really helped in this grant, in this collaboration, is to have the visualization.
Kylie McClanahan (24:43.339): say we can show you the network model of your system and the assets. Now, we still have little pop -ups that tell you the vulnerabilities that are there, but it helps even just visually to have the piece of this is what my network looks like. I can see here, looking at the picture that there's a connection.
Kylie McClanahan (25:10.858): You know, these four devices have a vulnerability. Here's the RTU. If I better protect the RTU and they can't get down to the sensors, or I better predict whatever it looks like, it's a lot easier to see the connections between devices that are networked, right, obviously, and look for bigger remediations.
Aaron Crow (25:16.846): Mm -hmm.
Aaron Crow (25:36.749): Yeah. And what's that saying? A picture's worth a thousand words, right? So being able, it makes a big difference.
Kylie McClanahan (25:40.073): Yeah, yeah and well if you you know if If you go to the NVDs website, and it's not you know Not me hating on the NVD you put that disclaimer out there, but you go to the page That's just the most recently published vulnerabilities right I do this for a living and it is an overwhelming experience Right. It's just like you know they get published in in blocks, and so you're trying to click through
Aaron Crow (25:51.564): Heheheheh
Kylie McClanahan (26:4.873): click through a few and they all basically look the exact same because they're just slightly different and they were all published at once. It's very overwhelming and you end up with essentially an Excel spreadsheet with a ton of numbers that have limited connection to your actual network. And you're expected to make sense of that in a system that is dynamic. And really, I think, I mean,
Aaron Crow (26:30.378): Right.
Kylie McClanahan (26:35.240): visualizations, not just a dashboard, not just a graph that says here's the CVSS scores. Those have their place. But something to say, like, you know your network intuitively. Let me show you what it looks like from a cybersecurity perspective and let you superimpose those in your brain. Superimpose your knowledge of how the system works with kind of a top level view of your vulnerability exposure.
Kylie McClanahan (27:4.392): and start to see where things may be vulnerable.
Aaron Crow (27:9.930): Well, and it really even taking it a step back from that. I know again, I've been doing this a long time, both as an asset owner and as a consultant, as a CTO of a software company in the product space, right? So I've seen it from a lot of different angles and perspectives. One of the most common things I see is I walk into a place and they don't truly understand their network. They don't truly understand where their assets are, which ones are critical. Like if I had a list of a hundred assets on their environment and
Aaron Crow (27:39.944): even correlated the CVSS score to the, hey, these are the ones that are the most risky from a CVSS perspective. They don't know which ones are the most important to their business. So yeah, they could count. They could sort it by CVSS score, but that's not necessarily the right place to focus their effort because that, that the one that's at the top, maybe I say this analogy I give you can have the same PLC once controlling a turbine and once controlling the ice machine in the break room, right?
Kylie McClanahan (28:6.374): Mm -hmm. Exactly.
Aaron Crow (28:8.872): Which one should I work on? Right? Obviously I'm going to work on the turbine before I work on the ice machine. I may have some upset people, but it's not going to shut down my plant. But if you don't have that correlation and understand not just what your asset list is and what vulnerabilities and all that kind of stuff, all those things are, I believe needs not desire, not, not wants their absolute needs to be able to understand and protect your environment. But you also have to have a co some kind of translation into what do those things do and what is the risk and priority.
Aaron Crow (28:37.640): in your organization because I can't just understand because it's a Rockwell PLC that it's, I can't, there's no way I can know what it, cause I can make a Rockwell PLC do anything I want to do. Right? So I can't know by the make and model what, what the thing does.
Kylie McClanahan (28:48.422): right.
Kylie McClanahan (28:51.590): Right. You know, and I think, I mean, I think there's a lot of almost castle in the castle in the air answers. I would love just to be handed an asset inventory. I think I would weep. I would weep tears of joy. Truly. Yeah, right, right. You know, CISA has the SSVC, the Stakeholder Specific Vulnerability Categorization. Categorization? I think that's right.
Aaron Crow (29:7.655): Most people don't have it.
Kylie McClanahan (29:21.957): Um, and they have a, a calculator on their, on their web website. One of the things I really, really like about the SSBC is there's, there's two, two questions to start off with about the vulnerability itself. Is it, you know, what's the X kind of exploit level? Is it automatable? And then you get to mission and wellbeing to say, how critical is this to your mission? And we're going to give you high, medium, low.
Kylie McClanahan (29:51.684): Well, the equivalent, the actual values are a little different, but it ends up with high, medium, low. And we're going to give you some examples. And then how does this affect when you're considering critical infrastructure, the public wellbeing, if this were compromised, how much would it affect that? And then you get to a decision of track, attend or act. And what I really like about
Kylie McClanahan (30:21.124): the mission and wellbeing piece is that you don't have to be a technical person.
Kylie McClanahan (30:28.356): to or have all of the specs to be able to answer that question. Now, it's not going to get you a complete asset inventory, but you could without knowing details about uptime or rate of response, you can answer that question of how critical is it to keeping what we're doing here up and running? And if it failed, how big would the impact be to the public?
Kylie McClanahan (30:58.083): I think that's a really good step towards a workforce that is not trained in cybersecurity but is expected to perform it.
Aaron Crow (31:12.320): Yeah, and it's sad that so few organizations have an asset inventory, right? I did an assessment on a power plant earlier this year and they had an asset list, right? They gave me one. Hey, here's what we have. And I walk in and I think there were 10 assets on the list. All 10 were wrong and there were 100 assets that I found, right? So they were vastly off.
Kylie McClanahan (31:36.706): Ha ha.
Kylie McClanahan (31:39.235): Yikes. Yeah.
Aaron Crow (31:40.799): Right. And it was obvious it hadn't been updated in forever, but that was the best information that the local people had. Right. So I'm like, I'm looking at this list and I'm like, okay. And I'm sitting with the person in the room. He's not the OT guy, but he is the, the most knowledgeable person about the control system. Right. He is the guy, um, guy or gal, whatever the situation is and, and you know, wherever it is, but that is the person that is responsible for it. Right. So he, I'm asking him questions like, what is this? I don't know. Like, where is this? I don't know.
Kylie McClanahan (31:58.178): Mm -hmm. Yeah.
Kylie McClanahan (32:5.314): Mm -hmm.
Aaron Crow (32:11.006): Like, is there a router here? Yeah, it's over there. I'm like, okay, but the one you showed me is not this one. Is there a different one? He's like, no, that's the only one we have. Okay, so this list is an update. I don't know. I was just like, okay. So I'm throwing this away because it's worthless.
Kylie McClanahan (32:20.065): Right, right. Well, yeah, yeah, exactly, exactly. And it, you know, it almost comes back to it to change change management. If you don't have a system to track change management, how are you going to keep an updated asset inventory? To know if something's replaced, if something dies and you have to, you know, you have to go get a new one if a vendor comes in to do maintenance.
Kylie McClanahan (32:48.672): That's actually one piece that I've heard can be really difficult is even for organizations that really try to track, you know, some sort of change management or work tickets, whatever you want to call it, that it can actually be difficult to always grab hold of the tech who comes on site to do updates and say, hey, I need you to tell us what version are we on now? What did you update it to? Can we get, you know, the information that we want to store for audit purposes?
Kylie McClanahan (33:18.272): that's, it's hard to get that.
Aaron Crow (33:20.986): Yeah, it's a it's a hard conversation. Obviously there are products and tools. You know, I used to work for one that did some of that stuff. But again, a tool is only as good. I've said this a thousand times too, but a tool is only as good as you use it, right? I can have the best woodworking tools in my garage, but having the tools alone are not going to build me a shelf or they're not going to build me furniture, right? I have to actually get out there and use them, learn how to be good with them. And then I have to get the materials, but I have to spend time. It's really a, you know, that's why it really comes down to OT is.
Kylie McClanahan (33:40.415): Right.
Aaron Crow (33:51.129): And with anything, it's people process and technology. It's not just buying a tech, right? I can buy the best tech in the world, but it's not going to do it for me. I have to put people and resources and time and effort into these things to maintain them. Cause you know, every control system that was ever installed had an asset list when they installed it. They got, I was built documentation with gorgeous engineering diagrams, but that probably hasn't been updated. Some of these plants are 40 plus years old and that was the last time they were touched. Maybe there's red lines.
Kylie McClanahan (33:54.559): Mm -hmm. Yeah.
Aaron Crow (34:19.737): For some period of time they may have done red lines, but at some point every time it seems like they just stopped doing it like it's not enforced and they're 10 years old at best. The last time they did a major upgrade.
Kylie McClanahan (34:29.406): Yeah. Yeah. Yeah. No, no. Ab, ab, ab, ab, ab, ab, ab, ab, ab,
Kylie McClanahan (34:58.430): Spartan, we're going to help with that. We're going to help with the kind of intermediary step of even once you have a somewhat complete asset listing, we're going to help you map that to CPEs because that's how you're going to match against the NVD. And that's a complete other can of worms. But you know, because I don't, I don't.
Aaron Crow (35:10.391): Mm -hmm.
Aaron Crow (35:13.110): bright.
Kylie McClanahan (35:25.277): I don't want to sell Spartan to you if it's not going to be useful to you, if it's not going to be helpful. Um, but I, you know, I, like, I, I want to have something that's, that's useful that you don't need a whole team to manage. Um, and if, if, if, and that, you know, that, that tracks changes as you, um, use, use the tool. And if part of that is that we come on site for a week and help you set up, I'm, I'm more than happy to do that.
Aaron Crow (35:52.566): Yeah, absolutely. And it comes down to that, right? The greatest tool in the world doesn't matter unless you're using it, right? So like we just said, so that's off. So why don't you tell what is Spartan and how specifically does it work and how does it help folks map their vulnerabilities and their assets and all the things?
Kylie McClanahan (36:8.796): Yeah, yeah. So it works without, you know, we don't have a sensor, we don't have a box that plugs in, but we take an asset inventory and map that to the NVD, right, to be able to pull vulnerabilities. And then the second step to be able to associate those vulnerabilities with patches. A lot of that comes down to vendor security advisories.
Kylie McClanahan (36:38.203): that say, here's our product, here's the vulnerability, here's the patch. The CSAF standard, the Common Security Advisory Framework standard, is a machine readable way for vendors to publish these advisories. I know that BSI, the German Cybersecurity Department, has been huge in publishing that. But that becomes a really great resource to be able to associate these.
Aaron Crow (36:50.194): Mm -hmm.
Kylie McClanahan (37:8.891): And then based on features of the assets and of the vulnerabilities, we can say, you know, we have a decision tree. That's what we use to say, you know, I said, do you do it now, you know, for SIP within your 35 calendar days? Do you do it at the next maintenance cycle when you have an outage or do you apply a mitigation? And then organize those into plans based on the due date.
Aaron Crow (37:30.193): Mm -hmm.
Kylie McClanahan (37:37.530): to say these are the ones that you have to address within 35 days. These are the ones that you need to go send. Here's your mitigation plans, go send them to your SIP Senior Manager. Here's the mitigations that you have. With that comes a way to manage baseline configurations for SIP 10. You're looking at patches, ports, system services, and software assets. So to track those, track any changes.
Kylie McClanahan (38:7.002): Um, and then keep, keep that, that up, up dated. We, we do this so we don't do any active scanning. Spartan does not do any scanning with our customers. So far we'll essentially take any scan that you want us to take. We'll work with you on that. So we'll, you know, we'll take in one of our customers uses win audit. We'll take in win audit files, in map, net stat, Nessus, right? Any of these, of these file types that we can pull data from. I'm more than happy to write a.
Aaron Crow (38:17.296): Mm -hmm.
Aaron Crow (38:23.183): Sure. Okay.
Kylie McClanahan (38:36.857): write a parser and use that data. Getting the work plans out into change management. If you have an external change management tool, happy to make tickets in that. Just to be a way to manage a lot of the, I'll say banalities of this patch management piece.
Aaron Crow (39:2.349): Mm -hmm.
Kylie McClanahan (39:5.336): will give you the evidence to say, here's when we checked these vulnerability sources or these patch sources. You can print out this report when audit time comes and it's gonna have everything. One of the reports is designed, what was designed specifically for that level two evidence request. Once they've done the statistical sampling and they come back say, okay, here's the assets, here is everything we have for the audit period for step seven.
Aaron Crow (39:32.203): Mm -hmm.
Kylie McClanahan (39:36.024): And so, so really, really the idea is what, what have the, you know, what have the admin will say can be handled automatically. There's a lot. And also how can we enrich the data that you have? Um, how can we give you a view for this partnership with network perception? How can we give you a view of the, of the network? How can we give you a better understanding of how this vulnerability would affect you?
Aaron Crow (39:58.250): Mm -hmm.
Kylie McClanahan (40:5.943): and then make it available for download. Make that data available. Yeah.
Aaron Crow (40:12.265): Yeah. Yeah. That's so, so huge. It sounds like a simple, not simple thing. And, but that's the pieces. There is no silver bullet. There is no, you know, there's a lot of tools out there that do great things. Again, I used to work for one and, and, and I've implemented hundreds of others and they're all great tools, but they, they solve their own problem. And if I looked at a Venn diagram, there's all these different areas. So I,
Kylie McClanahan (40:31.254): Mm -hmm. Right.
Kylie McClanahan (40:38.038): they do.
Aaron Crow (40:41.768): what I see the vision of the future, if I were God and could just make this perfect thing, there would be this ecosystem of all these tools giving their data to something that can extrapolate and take, Hey, I need that information and I could use that information. I could use that information and I build this into a single picture and I do something with it. Right? So like taking the network map and taking the asset list and the firmware levels that are on my system.
Kylie McClanahan (41:1.621): Mm -hmm.
Aaron Crow (41:7.719): connecting that with the NVD, and when's the last time I checked on these things, and last time, all those things together, and then I can print a report that says, hey, these are the things that matter, right? So when I have that, and I have something I can look at, visualize, whether it's in a picture or even just in a spreadsheet, that I can export and say, hey, these are the things that we have in our environment, not because it's 10 years old and that's the last time we update it, but because somebody scanned it, whether it's a tool or whatever it is, that becomes a more,
Kylie McClanahan (41:12.597): Right.
Kylie McClanahan (41:17.237): Great.
Kylie McClanahan (41:23.861): Mm -hmm.
Kylie McClanahan (41:30.581): Great.
Kylie McClanahan (41:34.101): Mm -hmm.
Aaron Crow (41:36.870): dynamic and real thing that we can actually do something with, right? And then I know, hey, go do it over there. Like fix that thing first. Like fix the firewall rule or this asset over here that's controlling the turbine, let's go fix that thing. Cause it's a really known good vulnerability. Let's go fix that first.
Kylie McClanahan (41:39.157): Right.
Kylie McClanahan (41:54.069): Right, right. Well, and I think, you know, I think, I think pulling in resources like CISIS -KEV, you know, to be able to say there's, you know, there's, there's places where we can get, we can get good, good data. I don't, I, I don't need to hire 10 people just to do, you know, generation of, you know,
Kylie McClanahan (42:21.013): This this kind of of data. There's a lot of very good and well maintained data sources. You know, CISA it's the the kev is great and this is very, very upfront about the fact that there are things that may have active exploitation that aren't on the kev because they don't have a remediation. There's other lists that will main, you know, maintain things that are actively exploited regardless of remediation.
Kylie McClanahan (42:49.365): status. I think the more we can honestly communicate, not even shortcomings, but the things that we do well and the things that we don't do as well, the better the situation for the end user. If someone wants an intrusion detection tool, Spartan is not for them. I'll be upfront about that. I don't...
Kylie McClanahan (43:18.837): I don't feel the need to move into intrusion detection. But if it's something that would work in your environment, absolutely, let's figure things out.
Aaron Crow (43:32.994): What and I think more and more folks are gonna start because again, I've been I've been at this long enough that you know, it started out with oh, I've got a firewall I'm done right or I've segmented my network. I'm done right or I've disconnected I've air gapped or I've got a Data diode or whatever the thing is and I think I think we see now I think we've always known but I think the end or Business sees now there is no silver bullet. There is no I can implement this thing and I'm good. I'm done I never have to approach this thing again. I
Kylie McClanahan (43:40.213): Mm -hmm.
Aaron Crow (44:1.538): It's not that right? It's always it's always changing. My vulnerabilities are constantly changing. I'm always having to adapt. I'm always having to adjust and and honestly a lot of this is coming from the vendors themselves because the vendors have changed. You know 20 years ago the the control systems didn't have these problems. A they weren't connected to the network and B even if they were everything was proprietary like you know you couldn't talk to it unless you had one of their boxes like but now we're using IP and normal.
Kylie McClanahan (44:9.621): Mm -hmm.
Kylie McClanahan (44:20.853): Right.
Kylie McClanahan (44:26.933): Mm -hmm.
Aaron Crow (44:30.466): commercially off the shelf available equipment and software and everything else. So we've brought all these problems into OT and it's going to get, it's not going away because it's just, it's so much more efficient than it is building a custom operating system and protocol. And like, why would you do that? Like, let's just fix what we have. And I can fix, I can mitigate those problems other ways. And honestly, as we know, security by obscurity is not a good thing either, right? As you just don't know about the problems, it doesn't mean they're not there.
Kylie McClanahan (44:37.109): Mm -hmm.
Kylie McClanahan (44:47.573): Right.
Kylie McClanahan (44:57.429): Right. Well, and you know, I think some of that we can look at it from a threat perspective with an analogy to physical security. You know, there's a lot of backup data centers that are off in the middle of the woods. And, you know, I'll joke with people that I was born into the industry and it's a little bit true. My dad was at an electric utility for 40 years.
Kylie McClanahan (45:26.037): Um, and so I grew up, you know, he'd have to, he'd have to drive out. I'm in from Arkansas, drive out to the middle of nowhere, Arkansas, um, to check on, uh, you know, disaster recovery center. And I'd be like eight, be like, can I come? That sounds fun. Um, yeah. Um, and, and in that, you know, physical security, if nobody knows your data center is there, right. It's a little, it's, well, it's not a little different. It's very different with cyber security. You don't, you know, as opposed to, to.
Kylie McClanahan (45:55.893): to casing a joint where you're going to do a ton of research about a site. You don't have to do that with a cyber attack. Now you can and some do, but you can also just throw a bunch of darts and hope something sticks and things will. And so, you know, I think we're looking at a very different landscape of threats when you don't.
Aaron Crow (46:11.810): Mm -hmm.
Kylie McClanahan (46:23.829): have to have intricate knowledge of one system to be able to try and compromise it.
Aaron Crow (46:29.762): Yeah, absolutely. Yeah, that's that's funny. Obviously, we have very similar background. My dad also was 40 plus years in power utility. So it's also how I got my start.
Kylie McClanahan (46:34.421): Yeah.
Kylie McClanahan (46:36.949): Yeah, well, and actually so. I know that you also know Philip Huff. And I don't remember if I told this story at the Cybersecurity Forum in Chicago, but one of my first internships was the summer before CIPv5 became mandatory and enforceable. And I was actually working for Philip Huff. Of course, now we work together. But at the time, I was interning.
Aaron Crow (47:2.434): Right. Right.
Kylie McClanahan (47:6.741): And it was at the point where we weren't entirely sure if blocking ports meant physically or logically, there was still some wiggle room. And so I spent part of that summer in a data center with a bag of plastic port lockers and an Excel spreadsheet, putting in the serial number of the port locker and then the serial number of the device. And so I'll still give him a hard time about that. Like, you know, cause he was in the industry for a long time, incredibly capable. And so he'll...
Kylie McClanahan (47:35.157): you know, to kind of talk about his qualifications. And I'll be like, yeah, yeah, actually, Philip, do you remember that time? Do you remember that summer that I put port lockers in? Exactly, exactly. Yeah. Yep.
Aaron Crow (47:44.450): in every report and how to document them.
Aaron Crow (47:49.666): We've yeah, it's it's it's been I've done those same things that I've had teams doing stuff that you know five years later You're like man. That was a waste of time and energy But again at the time you're doing the best that you can with the knowledge you have right? So yeah, that's funny So so next five to ten years I asked everybody this question But you know what is something that maybe you see that you're excited about coming in the next five to ten years on the horizon in this space And maybe something that's concerning
Kylie McClanahan (48:1.237): Exactly. Yep.
Kylie McClanahan (48:16.597): Yeah, so this is gonna be a little bit out of left field. So I do a lot of machine learning research, particularly in my graduate work. There's some very interesting research on state estimation, state estimation of the grid using graph neural networks. So graph neural.
Kylie McClanahan (48:44.021): networks being like a graph structure, do processing a little bit different, even more than typical neural networks. And there's been some research about how to get a better and faster, a more correct, maybe we'll say sort of better, estimation of the state of the grid. Of course, a lot of these equations have been.
Kylie McClanahan (49:10.581): around and in use for a long time. I'm not saying that they're not useful. They absolutely are. And I, you know, I'm not here to say that AI is going to take your jobs. Please don't take that away from this. But I do think that's a really interesting point to allow a machine learning model to look for optimizations, perhaps, that we don't.
Kylie McClanahan (49:38.613): necessarily have the time to have someone sit down and try by hand to look for that. I'll stay on the same track for the other half of the question, which is that I'm going to be a cautionary voice about large language models. Now, again, I'm not on the doomsday train. It's not going to be Skynet. However,
Aaron Crow (50:0.130): Mm -hmm.
Aaron Crow (50:4.002): Sure.
Kylie McClanahan (50:8.821): You know, I think there's a risk in these large language models of it's called hallucination. And so it's easy to say the model makes something up. I don't love that terminology because that's putting too much agency on the machine learning model. It has no idea what it's doing. It's giving you text. And it's right now, particularly, it's difficult to find a model that will give you any indication.
Aaron Crow (50:13.890): Mm -hmm.
Aaron Crow (50:23.554): Right. Yeah. Right.
Kylie McClanahan (50:37.301): of the authenticity or the truthfulness, maybe we'll say, of what it's telling you. I see a lot of places, I mean, they're not putting it in control systems. So like that's not, but having some sort of employee chat bot or having, you know, kind of a knowledge portal. And I have a lot of hesitation towards that because how are you knowing that it's...
Aaron Crow (50:40.834): Right.
Kylie McClanahan (51:5.557): keeping its answers to what you have told it to. Now there's ways that there's a lot of research about how can you, you know, how can you get things to be more, more, um, truth, truthful. Um, I, a lot of that's very, very fascinating. Um, but I, I, I, I'm hesitant about, this is an easy way to replace HR. No, it's not. It's really not.
Aaron Crow (51:22.946): Mm -hmm.
Aaron Crow (51:30.978): Right.
Aaron Crow (51:33.698): No, it's not. Yeah, I play a lot with chat GPT and the local models and things like that too. And yeah, it doesn't know. It never says, I don't know, right? Not never, but it's gonna give you an answer. And it may not be an accurate answer, but it sounds, and especially if you're not knowledgeable enough in the first place. So like I use it and I'll have it reword things for me and I'll just do a data flow.
Kylie McClanahan (51:46.517): Exactly. Exactly. Right.
Kylie McClanahan (51:55.605): Mm -hmm.
Kylie McClanahan (51:58.997): Exactly. Mm -hmm. Right.
Aaron Crow (52:0.930): of what I want to say and instead of worrying about syntax and formatting and all that kind of stuff, then I can dump it in chat GPT and it'll give me out a thing and then I can modify it. Oh, I don't like that. I don't like that. Um, but it, it makes me be creative, but you've got to be careful because when it dumps it out, I know I'm the one that gave it the content. So I know, Hey, this is supposed to say red, not blue, right? Cause I told it what it's supposed to say as opposed to what color should it be? And it says green, like, well, I don't know any different. So green's a good color.
Kylie McClanahan (52:11.925): Right.
Kylie McClanahan (52:15.765): Yeah.
Kylie McClanahan (52:22.965): Exactly.
Kylie McClanahan (52:30.357): Yeah, yeah, right. It's a great tool for those things. You want to edit a draft, not stare at a blank page. I am all on board for that. That's so helpful. But I think you hit the nail on the head. If you're asking it about things that you are unsure of, that's where I would say, let's hands off. Let's go ask Google. Or let's go do some research. Let's go look at manuals or whatever the question is.
Aaron Crow (52:30.626): Here we go. Right? I don't.
Aaron Crow (52:38.274): Right. Sure.
Kylie McClanahan (52:59.381): It is not looking up in Wikipedia for you. It's making statistical correlations.
Aaron Crow (53:6.882): And it's guessing and it's not citing its sources.
Kylie McClanahan (53:9.173): Yeah, exactly, or it is, but it's making them up.
Aaron Crow (53:12.898): Right, it cited a source that doesn't exist. Yes.
Kylie McClanahan (53:15.061): Did you hear about, there was a legal case, okay, yeah, or it had made up a citation. Oh yeah, no, there was a case where a lawyer had cited a particular case in a briefing and the judge came back and said, we can't find this anywhere. And he said, oh yeah, oh yeah, well, CHAP GPT told me about that one actually, so, I don't want that on the court record, but congrats, my dude.
Aaron Crow (53:20.610): Go ahead and say it, go ahead and say it. What was it?
Aaron Crow (53:39.682): Oops.
Aaron Crow (53:43.491): Yeah, it's, it's inevitable to happen. And I think I'm very excited to your point. I'm very excited about the opportunity that AI and machine learning and large language models, et cetera, are going to bring to us. But we also have to be very careful. Like, you know, there's a reason why the OT world is 10 years plus behind the IT world on the technology side. You know, I drive a Toyota or a Lexus or, you know, there's a reason why they're, they're technology. If you, if you look at a brand new Toyota versus a brand new Chevy or
Kylie McClanahan (54:2.869): Right.
Aaron Crow (54:13.122): Mercedes or whatever. It's not the same tech level. And the reason behind that, if you look at it, because they never put anything into their car that they haven't tested for 10 years. So, but that's also why you look at the most reliable vehicles on the road and they're always Lexus and Toyota. Like those are the two and they're the same company, right? So there, there's a reason why, you know, you can drive, you see a 15 year old, I had a 2008 Toyota forerunner and it had 300 ,000 miles on it.
Kylie McClanahan (54:15.957): Mm -hmm.
Kylie McClanahan (54:22.101): Yeah. Yeah.
Kylie McClanahan (54:30.677): Mm -hmm. Yeah.
Kylie McClanahan (54:41.269): Mm -hmm. Yeah. Yeah.
Aaron Crow (54:42.561): And it was like a perfect vehicle, right? Nothing wrong with it. And I could, you rarely get a, another manufacturer and not to beat up on any of them individually, but you rarely are going to get a Hyundai or a BMW that has 300 ,000 miles unless you put a ton of maintenance into that thing and rebuilt motors and replace car, you know, all sorts of stuff. Whereas my Toyota, you just put oil in it and it basically just runs forever. Exactly.
Kylie McClanahan (54:51.413): No, no, right.
Kylie McClanahan (55:2.741): Right.
Kylie McClanahan (55:5.461): And it keeps, keeps going. Yeah. Yeah.
Aaron Crow (55:11.041): So we need the Toyota implementation of AI and use cases for OT.
Kylie McClanahan (55:13.845): Yeah, exactly, exactly. The move fast and break things approach to tech isn't really working in OT.
Aaron Crow (55:23.489): It doesn't work here. It doesn't work here. Well, awesome. So Hey, uh, anything kind of closing out any, any, uh, places you want to pee, anybody, you know, as far as the audience, you know, how do they get ahold of you or, or if they want more information about Spartan or anything that you guys are doing.
Kylie McClanahan (55:41.365): Yeah, well, I'll be sure there'll be links in the show notes to the Stasos website. You can find me on LinkedIn, just my first and last name has, you know, there's not a lot of people with the name Kylie McClanahan, which is really, really kind of nice. You know, I end up at conferences a lot. You can always grab me and, you know, say hi, always like I'm always happy to meet.
Kylie McClanahan (56:10.453): meet new people in the field, whether you're new in the field or you're just new to me, either one. And yeah, if you, if Spartan sounds like something that could work for you, sorry, I'm not a sales person, but like, absolutely feel like, please, please get in touch. I'd be more than happy to talk with you.
Aaron Crow (56:30.526): Awesome. Well, yeah, definitely. We'll have all those in the, in the show notes and, uh, definitely click it out, check out Kylie and, and, uh, uh, Spartan and, um, thank you for your time today. I appreciate it. Like I said, I know we could talk for hours on vulnerability and OT, so, uh, we'll, we'll leave it at this and I'm sure we'll probably do it again. So thank you very much for coming and spending your time with me today.
Kylie McClanahan (56:40.163): Yeah, thanks for having me. Absolutely. Yeah.
Kylie McClanahan (56:48.675): Thanks for having me.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.