Welcome to Episode 25 of the Protect It All podcast, titled "Funding OT Cybersecurity: Priority Setting and Practical Approaches." In this episode, host Aaron Crow tackles the pressing issue of securing Operational Technology (OT) systems in critical sectors like energy, manufacturing, and transportation. Although often overshadowed by IT security, the increasing number of OT system attacks makes it clear that underfunding is no longer an option.
Aaron explores the unique challenges of OT cybersecurity, such as legacy thinking and budget constraints. He offers strategies to align cybersecurity with business goals, prioritize investments effectively, and implement risk-based funding approaches. The episode emphasizes the importance of understanding asset inventories and making incremental improvements to strengthen security.
Listeners will also learn how to bridge the communication gap between OT teams and business executives and translate technical risks into business impacts. With real-world examples and actionable insights, this episode is essential for anyone tasked with protecting OT environments.
Tune in to gain valuable knowledge and start effectively prioritizing and funding your OT cybersecurity initiatives.
Key Moments :
00:10 Cybersecurity requires comprehensive, risk-aware approach beyond basic safety.
05:18 Understanding OT risks is crucial for prioritization.
09:11 We do business at the speed of trust.
12:13 Communicate cybersecurity's financial impact to business leaders.
13:58 Cost-benefit analysis of asset inventory in OT.
18:15 Establish security basics before advanced AI implementation.
23:21 Easier board conversations amid constant news events.
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Aaron Crow (0:2.082): Hey y 'all, welcome to another episode of Protect It All podcast. I'm your host, Aaron Crowe. Today we're gonna dive into a topic I think it's critical for everyone involved in OT specifically. We have this problem everywhere and it's around funding. Specifically in OT cybersecurity, especially around critical infrastructure.
Aaron Crow (0:26.798): sectors like energy, manufacturing, transportation, all of those 17 critical infrastructures. It's often an afterthought compared to IT, the cybersecurity side of things. But with the increasing risk of attacks targeting OT systems, we're seeing more and more of that in the news lately. Organizations that can no longer underfund in this area. In this episode, we're going to cover
Aaron Crow (0:54.208): why securing OT cybersecurity is challenging, how you can align cybersecurity efforts with your organization's business goals, how to prioritize investments and get the most out of the dollars that you're spending. And then obviously real world examples of how myself and others in the industry have navigated this challenge. But let's dig in first with why is funding for OT cybersecurity challenging?
Aaron Crow (1:21.770): legacy thinking in OT and I've heard this so many times is, you know, it's isolated, it's air gapped, it's, you know, the vendor designed it securely, etc, etc, etc. You have a vendor designing a system and maybe they bring in security for that system, but they don't always and rarely do they ever integrate the other systems like again, in a power plant and you may have a balance of plant, you know, main control system, but then you also have a
Aaron Crow (1:50.422): a turbo control system that is separate many times. And then you've got these third party controls. You've got, you know, all these other things that are PLCs or et cetera, but they're not included. know, vendor A brings in a security platform, vendor B brings in a security platform, but they only care about themselves because they just can't know all the different things that are there. But someone within the organization needs to understand that umbrella of cyber. So,
Aaron Crow (2:19.323): In IT, we know that as we bring in commercially off -the -shelf products, as we're integrating into the cloud, as we're installing applications, we're always looking at it from a, do we make sure this is secure? How do I make sure that this isn't going to add risk or that I at least understand that risk? And then how do I mitigate that risk? A lot of the times in the OT space, unfortunately, the folks that are making the decisions are looking at it from a
Aaron Crow (2:46.072): from a operations perspective, making sure that the car drives. My goals are that it can get there, it can get there safely, and I get a certain mile per gallon as an example with a car. But from a safety perspective, they don't always necessarily think, especially if you look at the newer cars today, they're not looking at, well, can I hack this? Like, can I get shut down from a
Aaron Crow (3:13.752): from a bad actor using the cyber and the technology side. So we really have to start thinking about these things differently in OT. And that tide has started changing, but the cost has not been really looked at. The understanding the risk of the environments. Again, disconnecting your environment is not enough. Air gap is not enough. Installing a firewall is not enough.
Aaron Crow (3:39.086): The other big one that we've seen over the past five to 10 years is, I've got an asset inventory or I've got a network monitoring. I've got passive monitoring in my environment. That's great. All these things are good things to do. Firewalls are great. Air gapping is great. Secure mode access, like all of the things, but it's not a silver bullet. We have to really start understanding. INL has come out with, and I've talked about it many times, even talked about it at a talk at DEF CON, the ICS Village with Cyber Informed Engineering.
Aaron Crow (4:10.162): as we design these systems, cybersecurity and, just availability, reliability has to be looked at and making sure that we have the right folks at the table. with that, one of the reasons with budgets is, is competing priorities. all the way back to when I started doing this in, I don't know, 2010, what I think was the first OT cybersecurity quote unquote project that I did. I was going to these locations and I didn't have a budget.
Aaron Crow (4:37.870): So when I was going in saying, I have $300 ,000 of scope that I need to get added to this upcoming outage and I don't have any money, but you have to do it. It's not optional. So that meant that they were de -prioritizing. They were not doing boiler maintenance or XYZ. They weren't building this new thing. They were having to choose where to get that money because it's not like they just came up with new money. So really prioritization.
Aaron Crow (5:4.506): And really the only way you can prioritize those things is if you truly understand the risks to the organization. And unfortunately, a lot of times in OT, we don't really understand those because they just don't understand the assets and how they can impact and how one system can take down. Many organizations, especially in critical infrastructure sectors have limited budgets. And when it comes to investing in new production capabilities versus cybersecurity, OT is often going to lose out.
Aaron Crow (5:33.504): OT is not a efficiency. It's not going to add capabilities necessarily. If you just look at the cyber perspective. The other piece to this is when I was deploying this and going to those plants, I was not selling it as cybersecurity. Now, yes, there was a compliance thing. It's NERC, it's regulated, it's critical infrastructure. But also I was deploying this as this is operational availability. Like what can we give
Aaron Crow (6:3.074): that would make the plant run more efficiently, then have more visibility into their environments. Cybersecurity is going to get part of that. But when you start looking at logging and monitoring on those systems, there's a lot of things that you can provide that can give the plant, the environment, the OT systems, more reliability. And that helps with justifying those costs beyond just a cost center of OT cybersecurity.
Aaron Crow (6:32.908): Misalignment between cyber and business teams. We see this a lot, especially in OT and IT. The business comes on site and says, hey, have to do this thing. You've got a Windows XP machine in your environment and we've got to patch it or you can't patch that so we've got to replace it. And they just don't understand. That's not the answer. Yes, but on the flip side, the plant doesn't, can't just say, no, we're not going to do that and not do anything.
Aaron Crow (7:1.262): It's gotta be a healthy balance of, I can't replace the Windows XP machine because it's the only way this thing works and replacing it would be super expensive, et cetera, et cetera. How else can we mitigate this? I can't put in Windows 11, I can't put in Windows 10, we can't patch it. What else can we do? Right, and then sit down at the table, understanding the ultimate goal is reducing the risk. The ultimate goal is not replacing the XP machine. The goal is to get rid of the risk or at least reduce the risk to a place that we're acceptable.
Aaron Crow (7:29.336): So really understanding and looking at those OT risks in a different light and making sure you have, know, the OT teams should be working with closely the IT teams. They have firewall teams, they have network guys, they have all of those capabilities that are not necessarily held at the OT sites, right? They don't necessarily have those skill sets in -house, but unfortunately I see it a lot is the OT and IT, they just don't talk and they don't trust each other.
Aaron Crow (7:57.110): IT tribes to cram things down the OT folks throat and vice versa. And then they're against each other, right? They're adversaries. Instead of, we're on the same team, we need to find a solution to this problem, right? That there's often a communication gap between OT cybersecurity teams and business execs, or even just OT teams in general and IT cybersecurity teams, right? Cybersecurity leaders are speaking in terms of threats and risks while the...
Aaron Crow (8:24.738): the business are focused on revenue and operations availability. So, you know, it's critical to learn how to translate and make sure that you're speaking the same language, especially again, coming from corporate into these production spaces, these critical infrastructure environments. You're using different vernacular and different languages to be able to get across the message and be able to, again, communicate that you're
Aaron Crow (8:53.932): focused on reducing risk. One of the things I say, I say it a lot, but it's, it's, we, do business at the speed of trust, building those relationships with between those it, those OT, the, the, business, the, the corporate, like all of those things, we have to build that trust because then when I walk in the plant and I say, Hey, we have this problem, this is the concern I have. This is a new, a new vulnerability ball, whatever it is.
Aaron Crow (9:19.874): then we can sit down together and I'm not dictating how the plant needs to run their operation. At the same time, they understand it. I wouldn't come to them unless it was a really big deal. And I'm willing to work with them to figure out a solution that doesn't break their environment and will fix the problem that we're looking at, right?
Aaron Crow (9:38.848): Next is how to align OT cybersecurity with business goals.
Aaron Crow (9:45.644): Risk -based approach to funding. Again, looking at this, there is no silver bullet. I can't put in product A or product B. I love firewalls. love all these things. They're great products, but it needs to be a bigger picture understanding of what's going on in the environment, right? So I need to have that risk -based approach. That way I could prioritize, and I'm not gonna necessarily do the same thing at all locations. I'm a site that's low impact to my environment or to my business.
Aaron Crow (10:13.474): I'm not going to spend the same amount on technology and people and resources, people process the technology as I am my crown jewel. The nuclear power plant is going to have a lot bigger budget and different requirements than the mine or the coffee house. It's just going to be different. So one of the key ways to secure funding is to take that risk -based approach instead of just talking about the technical vulnerabilities.
Aaron Crow (10:41.154): focus on the operational and financial impacts of a breach or downtime. Another common example is, you know, I've got two PLCs. They're the exact same model, make same firmware, everything about them. One controls a turbine and one controls the ice machine in the break room. They have the same vulnerability. So if I just focus on the technical vulnerability, they're both the same risk. But when I look at the downstream of what they do, it's a complete different use case, right? Yes.
Aaron Crow (11:10.656): somebody will be upset if the ice machine goes down in the break room, but it's not going to impact the business, not to the same level, right? So I'm going to spend and take different effort. may say, yeah, I'm not worried about this one. We're gonna isolate it. I'm gonna mitigate it in different ways, or I'm gonna accept that risk. Whereas the one that's controlling the turbine or the manufacturing line or whatever the thing is, maybe I need to do a different mitigation for, right? Imagine a ransomware attack that shuts down production and a manufacturing plant for two days.
Aaron Crow (11:38.722): The loss revenue for those two days could be far higher than the cost of cybersecurity measures. So it's really just being able to translate those costs and understanding the risk to the business. Colonial pipeline is a great example of that as well. It wasn't even an OT device or attack, but it impacted OT. There's too many times we're fighting and arguing on whether or not it was an OT attack or not. At the end of the day, did it impact OT? Did it impact the business? Did it impact your ability to sell your product?
Aaron Crow (12:7.842): whether it's electrons or gas or widgets or whatever the thing is. And that really gets back to being able to speak in dollars and downtime. Business leaders respond to financial impacts. If I'm going to communicate to a business leader, I can't say, there's X number of vulnerabilities. What does that mean? I don't know what to do with that. When pitching cybersecurity investments, explain how much a downtime event could cost the organization and how cybersecurity could help
Aaron Crow (12:37.322): reduce that risk or reduce the likelihood of that, right? Obviously, it's not an exact science, but being able to understand, if these things go down, this one site is X number of dollars per hour per day. And this one critical update or lack thereof, this vulnerability could bring down the entire environment. I did an assessment at a manufacturing facility not too long ago, and they had multiple lines.
Aaron Crow (13:6.734): network switches that supported multiple lines and they had no redundancy. Now this isn't a cyber issue, but again, looking at this from a risk understanding, if one of those switches goes down, loses power, just fails for whatever reason, then multiple lines are down and they're not producing product, right? So that lack of redundancy or even a cyber attack, if somebody updates firmware, whatever, something goes bad, then those things go down, right?
Aaron Crow (13:36.022): you can lose millions of dollars per hour if those production systems are taken offline. So articulating those costs of downtime helps you to under, well, we just installed those switches. Well, okay. But if it goes down, it's going to be a million dollars a day and it's going to a hundred thousand dollars to fix this. So it doesn't do it. Is it worth it to you? Right. And what's the likelihood that that could happen? You know, and then, you know, being able to show the math.
Aaron Crow (14:4.730): and not, you know, fear selling, but realistically, what is the likelihood of those things happening? And then, you know, there's a common problem in OT with asset inventory or lack thereof. Not really understanding what assets I have in my environments, which there's a lot of products out there. We talked about passive monitoring and even active to be able to help with that asset inventory and understanding the assets that are in your environment.
Aaron Crow (14:31.928): But once I have an asset inventory, let's say I've got the best products in the world and I know all of my assets and I have a complete list of every asset that's on my network, that's in my OT environment, that's not enough. And I use the analogy a minute ago, two PLCs, right? Not every system is equal. I need to understand the asset inventory is the first step. The second step is understanding what each of those assets are and what they do, what their function is.
Aaron Crow (14:59.554): and then being able to tie that back to the risk, right? So again, those two PLCs I explained, right? One is in the break room and one is controlling the turbine. What is the risk to the business? They're gonna be vastly different. So being able to understand that and classify that, right? And utility company protecting the SCADA system that controls water flow or electricity distribution should take precedence over securing a non -essential OT device like the ice machine in the break room. Or again.
Aaron Crow (15:28.354): you're probably not controlling my ice machine in the break room, it's just an explanation of drastic differences between two devices that could be the same type of device, right? How do you prioritize cybersecurity investments? Many times I see, again, I came from the vendor space, I sold product, I was CTO, and a lot of times vendors are focused on
Aaron Crow (15:56.940): you know, we're the best of this and that and whatever, right? But at the end of the day, when you're looking, when I walk into a place looking at their OT cyber, many times it's not the super fancy, sexy tools and technology or even people that you need. It's starting with basic. What are the fundamental things that you have to do? So focus on those things. Like if I had a dollar to spend, what is the most efficient place to put it that would get me the most return on investment?
Aaron Crow (16:24.256): as far as reducing risk and securing my environment. Many times that's starting out with an asset inventory. Many times that's a walk down. Many times that's, you know, putting in a firewall or locking down a firewall because many times firewalls are already there, but maybe they're really porous and they're more like a router than they are a firewall. So focusing on those fundamental cybersecurity measures that can give you the most protection for that dollar network segmentation, access controls, secure mode access, monitoring, logging, you know, again, firewalls, basic
Aaron Crow (16:54.050): basic type things, even training and people. Do you have people that are looking at this stuff? Do they understand what they're looking for? Like do they do they do you have people, know, processes and procedures that know, hey, if I see these types of events, what happens, right? So all of those types of things are foundational, that many don't even have those. And those are not always necessarily expensive. Those are things that you can do with a fairly, you know,
Aaron Crow (17:21.002): small budget, but gets huge, huge value on the backside. Choosing solutions with a high ROI. There's a lot of products out there that are OT specific and there's good reason for them. Again, with monitoring, especially packets, when you're looking at the network, a lot of these OT devices, the IT products just don't speak those industrial protocols and all that, right?
Aaron Crow (17:46.296): But at the end of the day, you need to be looking at products that'll give you the biggest bang for the buck. So if I look at a firewall, right? A firewall does more than just block packets. It can do a lot of different things from, especially these next generation. They're reading packets and they're looking at the protocols and all that. Same thing with secure mode access. I'm doing secure mode access, but I'm also stopping people pivoting. I'm stopping people from being able to copy files, data loss prevention.
Aaron Crow (18:12.346): I'm stopping the attack vector of being able to bring in a USB drive because nobody ever actually plugs in. Antivirus, like those are, again, looking at those simple things. They're not always the most complex or the most sexy. Before I start worrying about AI, I wanna make sure that I've got network segmentation, that I've got asset inventory, that I'm monitoring my network. Adding AI or any of these newer awesome capabilities, great things to have.
Aaron Crow (18:41.826): But before I ever start talking about those, I better have a really advanced and mature OT environment that I've got automation and I've got everybody trained and it's already doing those basic foundational things. An asset management system can help a power plant track aging equipment, reducing the risk of failure, lowering maintenance costs while improving cybersecurity, right? There's an example.
Aaron Crow (19:4.096): asset, asset, asset, I need to understand what my environment is. And it's not just from a vulnerability and being able to patch it. It's also just where are these things? What are they doing? Do they need to be updated? They need to be replaced? What is my maintenance schedule on them? Incremental improvements versus huge capital investments. You don't have to solve everything day one. Again, this recent assessment I did, newer company,
Aaron Crow (19:33.590): manufacturing environment, they have very little done yet. And that's okay, because they're willing to start. willing to, you know, they know they can't, how do you eat an elephant? One bite at a time, right? Focus on incremental improvements, a little bit at a time, like start adding team. You don't day one hire a hundred people, you hire two and you train them, you get them really good, and then you onboard more and more and more. Because if you hire a hundred, most of them are just gonna be standing around because you don't know what to tell them to do.
Aaron Crow (20:1.142): It's the same thing with technology. You don't have to go out and buy all these things because who's going to run them? Who's going to support them? What value are you going to get out of them? If I bought every tool available and had all of the holes plugged, NIST CSF, and had a solution or a mitigation for absolutely everything in there, who's going to run it? How do I get it done? how do I, when do I start getting value from those systems? It's beyond just having the tools. The other analogy I usually say is I can have the nicest woodworking tools in the world and they can sit in my garage, but they're not going to build me any furniture.
Aaron Crow (20:31.438): I have to be trained and understand how to use them and then go actually use them. I have to get materials and then I have to get the value out of the tools. The tools themselves are not going to solve my problem. So instead of asking for a full overhaul, like all of the problems, the sky's falling, I need $10 million or $100 million or $300 million to fix all the problems, start small, right? That doesn't mean if there's big problems that you shouldn't ask for more, but it's okay to start.
Aaron Crow (20:58.498): with small projects and fix one thing at a time. Multi -factor authentications, QR remote access, make sure your backup and recovery is good. Network segmentation, like these basic things, again, they don't necessarily sound sexy. They're not the ones that they're necessarily gonna be talking about at Black Hat on the main stage a lot of the time. And especially in the vendor pavilion, they're not the ones that have all the marketing behind them, but they're the ones that real world are probably gonna be
Aaron Crow (21:27.138): the most value add in the short term for your organization. The kind of conclusion and call to action there is there is no single solution. There is no silver bullet. There is no one size fits all solution. You can have, even within an organization, you can have multiple sites of the same type. And I'm gonna...
Aaron Crow (21:54.648): handle things differently. So really look at those and understand there is uniqueness to what you're doing. And it's okay to have, you know, the expectation is not to be, you know, perfectly mature, a five on everything as far as maturity goes in an SCSF assessment, right? You're not, you don't need to be perfect. The goal is not to be, you know, you're not platinum coating. It's not gold, you know, it's not gold plated. It's doing what is needed and,
Aaron Crow (22:24.470): your business will be different than your competitor. It'll be different than people in other critical infrastructures. So know that. That doesn't mean you can't learn from others, but you also need to adjust based upon your needs. Emphasize those critical incremental investments that you can help improve security without overwhelming your budget. And then, again, start small.
Aaron Crow (22:49.730): like build your case for larger initiatives, show value, build something, do something, come in with an assessment, and then go into doing, deploying a product, and then show value from that and expand it. Hey, if we had this, we could do these other things and just continue to build on that and show that extra value. And then, you you'll be amazed how quickly it can grow and justify those funding. As more and more events are happening in the news, I think it's gonna be easier, at least to be...
Aaron Crow (23:17.656): having conversations with the board, with executives around this because it's something that they're hearing constantly. So thank you today for tuning in. Hope you found these insights valuable. Whether you're struggling to secure funding for your OT environment, get it started, you don't know where to start, or you face the same thing and you've your head against the wall because you know the problems, you've tried to.
Aaron Crow (23:45.582): pitch it up and it keeps getting kicked down. So let me know any funding strategies you guys have had, anything that's worked for you, maybe something that hasn't worked for you. Love to hear about them. Definitely reach out any way that I can connect with you folks. Just let me know. Stay safe and secure out there. Thanks for your time today.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.