In this episode, host Aaron Crow is joined by special guest Mike Holcomb to discuss the intricate realm of Industrial Control Systems and Operational Technology (ICS/OT) cybersecurity. The episode also spotlights the upcoming event B Sides ICS, an open and community-centric conference set to run alongside the prestigious S4 conference in Tampa.
Mike Holcomb provides insights into the much-anticipated ticket sales for the event and underscores the importance of submitting papers or presentations by the end of the year. The discussion emphasizes the significance of expertise in OT, cyber, and enterprise operations for top-level management and how events like B Sides ICS and S4 promote networking, learning, and professional development.
Listeners will gain a deeper understanding of the origins of B Sides events, the excitement surrounding B Sides ICS, and the impactful discussions and innovations poised to shape the future of ICS/OT cybersecurity. Whether the audience comprises newcomers or seasoned professionals, this episode offers valuable takeaways for everyone.
Key Moments:
00:00 Educating and supporting ICS & OT cybersecurity communities.
04:28 Passionate about learning and sharing cybersecurity knowledge.
08:59 B Sides: Global community-focused conference events.
10:43 Bringing B-Sides to Greenville increased attendance.
16:29 Promote diverse perspectives in OT cybersecurity.
19:01 Active Directory challenges in IT-OT integration.
21:07 Active Directory simplifies system management, poses risks.
28:57 Lean on IT for the correct Active Directory setup.
31:52 Availability is crucial in an OT environment.
34:14 Integrating IT and OT for enhanced cybersecurity collaboration.
36:16 IT and OT integration needs improvement.
40:54 Exploring cybersecurity in ICSOT across various sectors.
About the guest :
Mike Holcomb is the Fellow of Cybersecurity and the ICS/OT Cybersecurity Global Lead for Fluor, one of the world’s largest engineering, procurement, and construction companies. His current role provides him with the opportunity to work in securing some of the world’s largest ICS/OT environments, from power plants and commuter rail to manufacturing facilities and refineries. He has his Masters degree in ICS/OT cybersecurity from the SANS Technology Institute. Additionally, he maintains cyber security and ICS/OT certifications such as the CISSP, GRID, GICSP, GCIP, GPEN, GCIH, ISA 62443, and more.
He posts regularly on LinkedIn and YouTube to help others learn more about securing ICS/OT and critical infrastructure.
How to contact Mike:
Website : https://www.mikeholcomb.com/
Youtube : https://www.youtube.com/@utilsec
LinkedIn: https://www.linkedin.com/in/mikeholcomb/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:2.822): All right. Excited for this one, Mike, thank you for joining me. You've been on the podcast before. So, but for those that may not have heard that, that previous episode, why don't you introduce yourself, tell us who you are and, and what it is that, that you do in this OT cybersecurity world.
Mike Holcomb (0:17.571): Thanks for having me back. I appreciate it, Aaron, as always. yeah, for me, my name is Mike. In my day job, I get to work in design security for some of the world's largest industrial control environments. I get to really work with some of the world's best engineers in the control system space. So I'm very, very privileged there.
Mike Holcomb (0:46.000): and then outside of the day job, you know, a lot of it is being able to take the information I learned there and from others in the community and, being able to make that, I think a little bit more accessible to folks, whether it's through the, on YouTube with, with a free course, around how to get started in industrial control, which is really a focus for me. It really just sharing.
Mike Holcomb (1:14.186): with people and helping not only bring new folks in to the community, but also for folks that want to learn more about ICS and OT cybersecurity and why it's important, why asset and owner operators, know, they kind of get stuck, right? And a lot of them don't have a lot of resources either to build their programs and might not know where to start. So a lot of...
Mike Holcomb (1:41.802): My goals is to help, you know, not only bring, you know, new people into the community, but also to help, I guess, essentially build up or strengthen those, those environments out there that already exist where, again, especially for those that they're not like a shell or a BP with, with larger budgets, you know, it's probably small mom and pop shops or, you know, medium sized organizations that they just don't have all of those resources and don't even know where to start.
Mike Holcomb (2:10.200): That's a big part of what I share on YouTube and on LinkedIn.
Aaron Crow (2:15.932): And it's such a valuable and needed thing, right? Is not everybody is Duke, not everybody's Shale, not everybody's FedEx, not everybody's Amazon, right? There's varying levels of budgets and complexity and, you know, staff, like all those things. And you have to start somewhere like there's plenty of organizations that are in the beginning stages and they don't know where to start or they're
Aaron Crow (2:43.024): they've started and maybe they've gotten to the 10 yard line and they don't know how to get it that much further and what's that low hanging fruit and all those things are valuable. And coming from working at a big four and nothing against the big four, I loved working there. I'm glad I have that my, that feather in my cap. But at the same time, some of these smaller organizations can't pay a big four to come in and advise them.
Aaron Crow (3:7.800): They just can't, they can't even pay smaller boutique firms. They just don't have that budget or staff. So sometimes they have to do the best with what they've got. And sometimes I'm an engineer, maybe I'm the smartest engineer in the world at my controls and automation, but that's a different skillset than cybersecurity. And that's the thing that we, a lot of the times you and I are talking to those really capable, amazing engineers and trying to give them some of the knowledge they need to kind of in this realm that they're not from. didn't come, that's not.
Aaron Crow (3:36.390): They're training. They've been doing this for a long time, but the cyber thing is different. And many times it gets bolted on because they're the smartest guy or girl in the room. They're the ones that are, that are left with the, Hey, you do it. You know how to do all this stuff. Figure it out.
Mike Holcomb (3:51.210): Right. Yeah, no, it's very, very true. I used to think, you know, engineers do everything and, and no, they, don't, you know, so it's, you know, they are, they're human just like, just like the rest of us. So it's. Right.
Aaron Crow (4:4.240): Sometimes they seem superhuman and they are, but there, there is still limitations to their, their all knowingness.
Mike Holcomb (4:11.726): Very much so. And that's a big part of what I like in, in working in ICS and the OT, you know, today. I think this is not just because of me and my day job, because I get to have a lot of other conversations with, you know, engineers and other folks in automation and in OT around the world, but just getting to share with them and help them learn.
Mike Holcomb (4:37.538): from a cyber perspective, right? How to design or how to secure their environments. But then I also get to learn from them as well. So I'm always constantly learning. I learned so much every day from people, again, from all over the world that it makes it really exciting. Where, yeah, I'm an old IT cybersecurity person. I've been doing IT cyber for 30 plus years, right? And it's nothing against...
Mike Holcomb (5:5.506): You know, the folks in IT cyber, it's kind of gets old after a while though. I guess like everything, but, know, you go to most IT environments, right? They're, very similar, from environment to environment where you step into OT and, every environment is completely different. Even if you go into, you know, right. Even you go into two different power plants, right. They can be very different, internally, right. From a
Aaron Crow (5:27.996): Mm-hmm.
Mike Holcomb (5:32.494): kind of the control systems and networking perspective and the different systems and assets that they have and how those processes operate. it's very, very exciting.
Aaron Crow (5:42.048): You can even see it within a single plant between multiple units where they've done upgrades at different times. They've added third party controls differently across it because of budgets or needs or whatever. and it's crazy to see even at the same site owned by the same company ran by the same people, the same engineers, right? And there's a vast, a different between block one or unit one and block two unit two, right? And it's just that level. And usually it's not night and day. It's not going to be GE and
Mike Holcomb (5:47.382): Right? For sure.
Mike Holcomb (6:1.774): Right.
Aaron Crow (6:11.290): you know, Toshiba, but usually it's GE, but it's different levels of GE. It's, know, I've upgraded this one two years ago and this one's still waiting to be upgraded. So I'm dealing with all these different things and that sounds simple, but on the scale that we're talking about, it can be really complex to really understand the intricacies of patching and support and how it all works because that version could change the, the interconnection between PDH and UD. I mean, there's all sorts of things that can change between those things that are beyond just.
Aaron Crow (6:38.468): an operating system that we deal with and on the IT side.
Mike Holcomb (6:42.792): It can be a lot more complex and try to keep everything and when I look at ICS and OT from a cyber perspective I always try to keep it as simple as possible But but those are definitely some of the areas that that can trip people out They can get complex and they can get complicated because of you know, all those different Values and systems that that we see out there. Yeah are some of our projects, you know, they take five six seven years to
Mike Holcomb (7:9.656): to build, have an LNG facility that we just are bringing commission, bringing online right now. And we build the first two lines. It took seven years to get done. Of COVID was, was in the middle of that, which didn't help. But, and now we're about to start work on the next two lines, which is going to still take another right four or five years. So there's going to be definitely some small differences at least between, between those two that kind of like you point out, like everybody needs to be aware of from.
Mike Holcomb (7:38.510): engineering side, but also the folks that are leading the cybersecurity at the site.
Aaron Crow (7:45.768): Which, leads us to part the reason that I wanted to bring you back on this week is give you an opportunity to talk about, this, this upcoming thing that you guys are doing, which is besides ICS, it's going to correspond with, as for in, Tampa. and it's a, it's an independent, organization. Everybody's probably heard of besides, but why don't you give us a little thing of what is besides and what is besides ICS and why, why, why are you putting this together?
Mike Holcomb (8:10.584): Sure, yeah, no besides for those that aren't familiar. It's came out of the IT cybersecurity world and it was really a couple of folks that they were applying to the larger conferences out in Vegas like Black Hat and Def Con and I think it was primarily Def Con and in all, know, quality folks, right? Had great talks. Didn't get accepted for the conference and they said, hey, I'm still really, you know.
Mike Holcomb (8:38.712): passionate about sharing this information. I really still want to get it out there. So a bunch of folks just met at a bar the day before the main conference just hung out and talked about what they wanted to share. And B-Sides was born and now they have events in, you know, I think it's over a hundred, nearly a hundred countries around the world actually run the B-Sides Greenville event down in Greenville, South Carolina, where I'm at.
Mike Holcomb (9:8.092): and we get about 400 folks, every year. And it's really, I think our event, like many of the B-Sides, it's really just about bringing people together. And yeah, there's, there's talks. Most have a lockpick village. You might have some other, maybe a capture the flag that somebody is doing. but really, think B-Sides is really just focused on the community, right? Bringing the people together and just making those connections.
Mike Holcomb (9:37.058): with whether it's somebody that you just talk to for five minutes, you might talk to somebody for the next five or 50 years, right? Depending on that connection that you make. And we see a lot of that. There's even just with like B-Sides Greenville, we've seen other security groups and other conferences spin out just out of the B-Sides Greenville area where...
Mike Holcomb (10:4.492): You know, I took mine for, we started B-Size Greenville because of, I went to the B-Size Augusta conference and said, this is awesome. And to me, it's still the best cybersecurity conference on the East coast, if not in the country and personally. And, and I always was trying to get people to go to, B-Size Augusta from Greenville. Cause it's, a two hour drive. I could only get like less than a handful of people to go though. So I realized the only way to get, you know,
Mike Holcomb (10:33.016): Greenville people to B-Sides is to bring B-Sides to Greenville. And that's actually somewhat the same approach to, with B-Sides ICS OT, because we did add some OT content to B-Sides Greenville this year. And it was really well accepted. I think we had as many folks in the OT talks as we did in the IT talks, which was really exciting to see because we had some...
Mike Holcomb (10:59.118): some folks that had been in the field for a little while. then we had a lot of people that have no clue what ICS or OT is and they wanted to learn. And so that was really exciting to see. And so when we look at, well, we have S4 conference and this is, I've applied to speak at S4 and, you know, the last couple of years it's been.
Mike Holcomb (11:21.442): You know, nice try and, Dale who, know, Peterson, who runs the conference, he's actually, I'm really impressed because he gets back to everybody really quickly and he tries to work with you and say like, Hey, we can tweak this or, know, maybe, you know, it'll be a good fit or maybe next year. and, and, like, I think my topic, you know, just, you know, it wasn't going to be a good fit for, for S four. And so it kind of made me think I'm like, yeah, that's kind of how like.
Aaron Crow (11:29.296): He does. Yeah.
Mike Holcomb (11:48.718): B-side started, you it was just like you had these guys that, you know, had wanted to speak at a conference and they just wanted to get together. It's like, you know, we should do the same thing, you know, just in, you know, with S4, right? Because with S4 you have, you really do have like the expert and thought leaders of, you know, globally coming to, you know, arguably the
Mike Holcomb (12:15.662): the most important, you know, largest ICSOT cybersecurity conference that there is. And it's like, well, everybody's coming. but we also want to, you know, kind of help grow the community and bring new people in and also make it not only more accessible for new folks, but also for asset owners and operators, right? The people that own these environments or that run these plants, right? They, you can't go to S4 and get a lot of real world practical
Aaron Crow (12:20.497): Mm-hmm.
Mike Holcomb (12:45.802): information that you can take back to the plant the next day and help secure or run the environment. Right. That's just not going to happen. And I talk with a lot of owners and operators these days. And so that's really kind of this idea behind B-Size ICS is bringing in the community to kind of tapping in S4, right? Cause we have all the experts in town and then, but also
Mike Holcomb (13:13.518): bringing in new people to get them exposed to some of the, not only these experts, but just people that work in the field as well. And anybody that wants to share and then also make it very practical and approachable for asset owners and operators. And it's a $30 ticket, right? Compared to, know, over $2,000, right? For S4 right now for three days. So it makes it much more.
Mike Holcomb (13:43.596): approachable, right, think, and making it affordable and making it so people can come and learn more about ICS and OT cyber.
Aaron Crow (13:54.074): Well, it's one of those things where, you know, besides does not take away because besides that they do these at, they correspond with DEF CON and black hat and RSA and all these big conferences have these besides, and it doesn't take away from it. It's not to take away from the main conferences. Yeah. Yeah.
Mike Holcomb (14:8.442): if anything, right. Yeah. If anything, it's the opposite, because you will have people that end up going to both. you know, ideally if you were able to continue doing B-size ICS, because we actually had to get special permission from B-size to be able to do a, you know, specific conference focused on one topic. And that, cause that's not something that they've, they've done. They've done like three or four out of their entire history. And those were one-off events. And.
Mike Holcomb (14:38.498): So yeah, being able to have folks at both S4 and B-size ICS and kind of going back and forth. And you have a lot of people today that might come to the first B-size ICS and they're just starting to learn. But maybe in a couple of years, you do see them at S4 because they're ready to make that jump. And then they can come back and also get back to the community.
Aaron Crow (15:5.946): Well, it's it's you you and I have talked a lot and and we have similar aspirations like the reason I launched this podcast, the reason you do your YouTube training, the reason you do your stuff on LinkedIn, the reason I do. Obviously we have personal reasons from building our own brand, obviously, but but but that only matters if we're providing content and value, right? My my our intention is is to to grow the network, right? To have different. You know, I've been doing this a long time. You've been doing this a long time, you know.
Aaron Crow (15:35.182): At the same time, I don't think that my ideas are always the best. Believe it or not, like I've been wrong before. It doesn't happen that often, but it's happened, right? But it's not about being wrong or anything like that, right? It's about bringing more people into the industry, right? We know cybersecurity is not going anywhere. We know the importance of ICS and really having that understanding. So whether you're coming out of college, you're still in high school, you're trying to figure out what you want, or you've been in IT like both Mike and I were for many years.
Mike Holcomb (15:42.158): Right.
Aaron Crow (16:3.428): and you're wanting to bridge that gap from IT to OT and it's a hard transition, but it's not undoable, right? I've done it, you've done it. Many of us came from other worlds because there was no such thing as OT cybersecurity. So it's not like anybody has 40 years experience doing OT cybersecurity because it just wasn't called that. Now, granted we have, because we were working in this industry kind of adjacent, it just wasn't called that, right? So all of these things, the entire intention is to bring more visibility, more understanding.
Aaron Crow (16:31.824): to be open so that we're having diversity of thought and, and, and having more people's opinion. And, and to your point, Dale has to be really intentional about who gets on the S four stage. Cause everybody wants to be there. Right? So he has to really be picky on who's there and does it fit with a theme and, and do they, are they good on stage and all those types of things, because everybody expects that higher level of thing. Whereas at a B sites not to take anything away from B sites, but you can have people that have never talked on stage before get up.
Mike Holcomb (16:55.502): for sure.
Aaron Crow (17:1.294): And that's OK. Like that's the benefit and the value there is that no matter where you are in your career, you can present it besides, which is a great opportunity for you and the community. Because we get to hear your idea. Even if it's not polished enough to be main stage S4 doesn't mean that there's not good value.
Mike Holcomb (17:1.484): Yeah, for sure.
Mike Holcomb (17:18.328): Exactly. And that's, think with the schedule we're looking at putting together that we want to make sure that there is that kind of diversity across the board, right? It's not going to be, you know, the typical like old, old white guys, right? Like, like, like myself just speaking for myself, right? But, you know, also, you know, with, with a large focus on, you know, big focus for me is bringing more women.
Mike Holcomb (17:45.548): and other underrepresented groups into the community, for sure. then also with b-sides, and we have slots for new speakers, right? Someone that hasn't actually shared. That's actually one thing that we ask on the forum is have you presented this before? And like in S4, they probably are looking for somebody that has presented before. In some respects, right, we're kind of the opposite. We want those new folks that are...
Mike Holcomb (18:15.939): are really passionate about sharing their message and want to get it out there.
Aaron Crow (18:20.166): Yep. Yeah. And we know, and to dive back into some of the content, so we know the value and the vast difference between IT and OT, right? And we know, you posted something the other day that really triggered people and I think is still a valuable conversation. Active Directory, right? So we look at Active Directory. Active Directory is a good thing.
Mike Holcomb (18:37.365): Happy to do it once more.
Aaron Crow (18:43.796): I've got some, some horror stories and war stories about using Active Directory. I was an Active Directory administrator at, at AT &T and on the IT side, right? You know, supporting a hundred thousand plus users and, know, Active Directory and Exchange and all those types of things. But those capabilities have got brought into these OT spaces, right? And we don't, you know, that, that control engineer we just talked about before is not an Active Directory admin. So they're just taking whatever configuration came from the vendor.
Aaron Crow (19:10.362): and they're hoping it worked, right? And we see a lot of organizations that are trying to make trust relationships or instead of having a separate active directory, they just integrate with their IT one because I can understand at a high level how it makes sense in their mind because it's more difficult to manage multiple environments and all the, and again, that control engineer is not an active directory admin. He doesn't know how to really manage it from that level, but.
Aaron Crow (19:39.046): There's all sorts of risks that come with that. So talk to me about why, how you feel about Active Directory and OT and the whole ITOT convergence thing.
Mike Holcomb (19:48.910): Sure, sure. Yeah, this is coming from somebody like yourself. I've been doing a Active Directory since it was first a thing, right? 1998 and, you know, 1999 was when it started really picking up out of beta. And then of course, when Windows 2000 officially launched, I helped design Active Directory for the Naval Marine Corps Internet, which was not, you know, a small environment, right? We're talking the entire Navy and the entire Marine Corps.
Aaron Crow (20:13.606): Sure. Yeah.
Mike Holcomb (20:17.750): And then just carrying that, that forth. so yeah, there's this idea and I think a lot of people, if you're new to ICSOT, you don't realize something I had no clue before I stepped foot in my first plan was there's windows everywhere. Right. And the plant manager was giving me a tour and he's like, here's all of our data historians. You know, they're, they're running windows and Microsoft SQL server. And here's our active directory domain controllers.
Mike Holcomb (20:45.740): you have domain control. Well, shoot, like I know Active Directory. So, you know, was definitely something A that I could even bring more to the table to help them with and help them understand. Cause like you said, they don't, they don't have that, that, that background. But you know, when you look at Active Directory, it is a great tool, right? To be able to put user accounts and, passwords and be able to use group policies to push out security and
Mike Holcomb (21:14.698): other settings across the environment and be able to administer systems, right? Especially in the larger environment, the more benefit you get out it. The problem is when you have your IT Active Directory and then let's say you have your manufacturing facility and they also have, of course, all those window systems in the plan.
Mike Holcomb (21:44.546): And so we want to manage those as well with user accounts and passwords and group policies for all of our settings. So I think the initial instinct is, and mine would be, you know, 15 years ago would be, let's just tie them all together. Right. That's the beauty of AD. Like I can do everything from one central location. The problem that you run into is think of an attacker or something like ransomware.
Aaron Crow (22:3.194): Yeah.
Mike Holcomb (22:13.656): gets into the IT environment really, especially with ransomware today, right? It just spreads like wildfire, right? From system to system, but instantaneously, everything is compromised. If you have that connection between IT AD and the OT environment, that infection, right? That ransomware, or if it's just an attacker, right? They're just going to move from IT right into OT and take out or compromise all of the systems.
Mike Holcomb (22:43.947): And, I hear about it, it's almost like I get somebody at least on a weekly basis talking about, that happened to us. Right. And they had to learn the lesson, the hard way. So yeah, a big part of that post is that hopefully people, if we're designing a new environment, right. Hopefully you don't have to learn things the hard way. And if you have an older environment that's sharing AD and I kind of get a sense that it's probably about 20 % of the environments out there. I don't know.
Mike Holcomb (23:13.218): what you've seen, but that's kind of what I, least from my exposure, you know, lot of folks still, still have it. And I think they're just, you know, just, okay. It's just like, always I'm from California, right. And the wildfires are crazy, right. You know, so you're always worried about it. It just feels like the same type of situation where you're just sitting on massive acres and acres of just dry.
Aaron Crow (23:27.462): Mm-hmm.
Mike Holcomb (23:42.998): weeds and brush and it's just waiting for a spark for everything to ignite and go up. And that's, that's what it feels like to me. They're just waiting for that one person to click on a link or open up an attachment, infect their system. then that, that ransomware is off to the races and it takes out IT and OT and then your operations are, completely, completely down.
Aaron Crow (24:8.048): Well, you know, we've done this in business where we have, you know, a delegation of authority, right? We have, you know, we separate so that, you know, my IT administrator can't, you know, write a check. you know, my, my finance people can't see, you know, everything. Not one person has that full full rights. I've also seen a lot of operational reasons why segmentation and having separate systems. And, and it's exactly the things that you talked about, right? It's,
Aaron Crow (24:36.272): Hey, IT is rolling out this new group policy because it's better security to make sure that all the screens are locked within five minutes of inactivity, right? And this was a disconnected environment where the actual OT systems were not sharing Active Directory. But they had, what do all plants use? Pi. And usually those Pi systems are many times sitting on a corporate desktop because it's just displaying information, right? It's not control.
Aaron Crow (25:4.910): It doesn't need to be in the OT, technically OT environment. But as we all know, it's really hard for a plant to manage their environment because they put so much into Pi. It's half the dang screens in the control room is some kind of Pi manipulation, right? So the IT side implemented this new group policy that dropped these corporate machines into this thing. the screen locked after five minutes. The operators don't have a login. It's just a screen. It has no keyboard. Like there is a keyboard, but it's like hidden.
Mike Holcomb (25:19.149): Yeah, for sure.
Aaron Crow (25:34.618): somewhere else, they never log into it. They've never once logged into it. So when the screen went dark, they can't control it and they have no idea how to get to it. Right. And they, so once they finally got to it and then it happened again, then they're screaming like, is going on? I T didn't know they were doing this. They didn't know the impact, but that's the bigger problem. That's the thing that we have to understand is it's not just
Mike Holcomb (25:38.574): there.
Mike Holcomb (25:48.151): Yeah.
Aaron Crow (25:55.972): Yes, the ransomware thing is huge and yes, being able to pivot down in these environments with one login, they could then with a trust relationship or anything else, then I have access into these OTSpaces. It's also somebody can make a mistake in IT or push something they think is a good idea and it's not on paper, it is, but it doesn't work in the OT environment for many number of reasons. Like for instance, I don't want my operator to have to log into a screen ever because they need to be able to control that thing at a heartbeat, right? I control access.
Mike Holcomb (26:20.994): Right, for sure. Exactly.
Aaron Crow (26:24.944): differently in a control room than I do on a machine that's sitting out in the middle of somewhere else, right? I need that access instantly. No hesitation. I don't want them to fumble with a password, no fingerprint. It's just there. They sit in the chair, they control the thing, right?
Mike Holcomb (26:39.842): Yep. Yeah. No, it's very true. Very true. And that is one of those big differences, you know, just between IT and OT. And that's why, it's just kind of one those reasons they are very different. so, yeah, we don't need IT, AD and, and OT, AD connected together. You know, the biggest argument to that is, well, now I have to manage IT, AD and I have to manage OT and AD. Like, yes, you do, but A, you've
Mike Holcomb (27:6.422): reduce the risk that there that's there substantially. Right. And I don't know. I, I've administered AD and really large environments. It's not that hard and it doesn't take that many resources. And once you set it up in OT, right. OT is just very static. It's not like you're getting in to AD every day, you know, making changes all day. It's, know, I just, I just don't see that as a.
Mike Holcomb (27:35.936): as a valid argument. I get it as a concern completely, right? I just don't, I think it's one that is not insurmountable at all.
Aaron Crow (27:38.054): Yeah, that... Yeah.
Aaron Crow (27:45.082): No, I agree. And that's the bigger thing to always remember is yes, you have to manage all these different environments, but you're also not managing the environment very often. Like we're not getting new counts constantly. We're not installing things. Nobody's browsing the internet. there, once it's set, like most of these environments don't change for years. I mean, usually don't even have people coming in and out. Yeah. Yeah. I mean,
Mike Holcomb (28:4.364): Right. At a minimum. Yeah.
Aaron Crow (28:7.868): you're doing an annual review to make sure people change their password, like basic things, but you're not installing new things, you're not adding new devices, nobody's plugging in or unplugging, nobody's installing new applications on things, like it's very, very static, know, Sun Tzu, Auto War, things don't change and they're not updated constantly, so that's an issue, but on the inverse, then I should be able to notice when things change, right? So it's very simple. Once I set up Active Directory, and the argument I always come back with is this, it's,
Aaron Crow (28:36.032): No, I don't want you to have one environment. Yes, I think you should allow IT to advise to make sure that the Active Directory environment is set up correctly. And what that means is not to push all the IT policies down into OT. It just means they don't have a default password. They don't have the standard things that should be taken care of and secured and made sure it's configured to best practices.
Aaron Crow (29:0.604): You should lean on your IT team that does Active Directory for a living. They do this at very large organizations and very large environments. You should have them come and look at your environment just because the vendor set it up does not mean they're an Active Directory expert. I hate to tell you, but they're not. So have some outside third party review of that and make sure that they didn't leave a back door or, you know, enable something, you know, for instance, like you should never log in as domain admin ever, ever, ever to anything other than.
Mike Holcomb (29:17.815): No.
Aaron Crow (29:29.860): a domain controller. Like, and many times when I've seen when these vendors give you their service account, that service account is enterprise admin and schema admin and domain admin. And you're logging into all these machines with all those things. And we know that there's a, there's a Kerberos issue and all sorts of ways that that can be taken advantage of because you're just using it improper.
Mike Holcomb (29:38.935): Of course, right?
Mike Holcomb (29:51.462): Yeah. Yeah. Right. If you have an attacker in the environment, they're just sitting there waiting for somebody to log in with those credentials and then they take them and they they're off to the races and it doesn't have to be a state of us. You know, we see state adversaries and many of our environments, or at least they're trying to get into our environments. Right. And they're very much after, you know, floor in my day job because they don't care about our data, but they do want shells data, you know, or BP or Saudi or Ramco's, you know, it's, you know,
Mike Holcomb (30:21.240): But it's also, it's, you know, ransomware and the common attackers and the hack that this as well use all the same tactics and techniques, right? The little tricks, you know, they'll just sit there, same thing, right? They'll just sit there and wait for one of those accounts that has massive, you know, God-like privileges essentially in the environment. And yeah, it's off to the races and they just take control over everything.
Aaron Crow (30:44.828): Yep. And it happens so easily. And, and this gets back to, you know, CIE and cyber informed engineering and really looking at all these systems and really understanding what they're supposed to be and making sure you have the right team and, all that. Right. And this goes back to the whole theme of this, you know, ICS and besides is, is really making sure that people are informed and trained. There's no way that you would know why all of it, cause it's very easy to say, no, you could never do that. T.
Mike Holcomb (30:45.548): Yes.
Aaron Crow (31:13.946): without explaining, right? why the battle scars I've seen personally firsthand that active directory literally tripped a working power plant because they lost access, right? And it was done by a vendor, long story. And I've said it before, but people coming into the environment don't understand because they haven't seen those things. So having them sit down and let me explain to them why, and I'm not saying you can't ever do it. I'm just explaining the difficulties that I've experienced and why I say no.
Aaron Crow (31:43.278): and why I say segmentation is important and why I've seen I've been burned by this this way and this way and this way and this way. And these are the concerns that we have because at the end of the day and an OT environment availability, safety and availability is the most important thing. It trumps all the other CIA trade, right? It's not even a close second. It is availability 100 % of the time. So as long as I can safely operate it and continue it, if I never had active directory, like all these plant managers would throw all this crap out.
Mike Holcomb (31:58.637): Yep.
Mike Holcomb (32:5.710): For sure.
Aaron Crow (32:12.760): if they could just run their plant safely, right? Obviously we need these things because it makes it more efficient, all the things, right? But at the end of the day, many of the cyber things that we do, we struggle to find the ROI on it. And sometimes you have to look on the inverse of, if I implement this thing, I can actually make it less available. I can actually make it less reliable because of things like this. And yeah, it's a once in a lifetime thing, but I've seen it multiple times. So it's not a once in a lifetime thing. It can happen.
Aaron Crow (32:42.588): And it's not just me ask other people. There's a reason why people are so scared of scanning, you know, OT networks. It's not because vendors have told them that it's because somebody scanned and it caused a problem. Like it's, it's not, it's not a fear. It's not an unrealistic fear. Let's put it that way.
Mike Holcomb (32:42.853): for sure. Yeah.
Mike Holcomb (32:58.220): Yeah, for sure. Yeah, I actually had a, industrial CISO one time tell me, you know, in his environment, he's like, if you scan that PLC with a, with NMAP, and he very serious, dead serious. He's like, it will leave a crater in the ground three miles wide. Like, yeah, yeah, probably won't be doing active scanning in this environment. Right. But, but I can, you know, think back to.
Mike Holcomb (33:22.370): You know, me, you know, 15 years ago, you know, it's like, I'll come in and I'll run NMAP and I'll run Nessus, right? Define vulnerabilities and map out your network. And yeah, that's, that's not how it works in, in OT, but there's, that just points to, you know, how there are a lot of similarities between IT and OT cybersecurity, right? They're more similar than they're not, but when they're different, that's where we have to help folks from IT understand those, those differences.
Mike Holcomb (33:52.034): Well, also IT help, you know, is helping kind like the example with AD, right? Helping out OT folks understand, okay, well, how do we secure, you know, AD, right? How do we use it to secure the environment? Right. And that's really speaks to how we get IT and OT to work together. Right. And, and I think that's also a big, you know, going back to like B-size ICS, it's this idea of being able to bring IT and OT people together.
Mike Holcomb (34:21.742): You know, my goal is hopefully we have, you know, half of the group is, is it folks and half is, is OT folks and that we find a way to, you know, meet in the middle and work together because they have the biggest thing that always my biggest pet peeve is when people say like, I T cyber security is not OT cybersecurity. And I get the, like the idea behind it, just like we're saying, yeah, they're very different in many ways, but again, to me, they're more, they have more in common than.
Mike Holcomb (34:51.576): then they don't. it shouldn't be the IT side of the house and the OT side of the house. It's the same damn house that we're trying to protect. And we need to work together to make that happen. think awareness and education and bringing people together is the only way that we can get past all these problems that we see out there.
Aaron Crow (34:52.604): I
Aaron Crow (35:16.986): Yeah, It's, you know, the way I've said it before is like we're on the same team. We're in the same Jersey. Like yes, you're it and you have a different job than I do as an OT person, but that we're on the same team and we should be working together to secure this thing and make it more available and efficient and have the ROI and all the things. So we should use, you know, if you've got a guy in the corner, that's the best firewall guy in the business. Why aren't you using him? I'm not saying that he should
Aaron Crow (35:46.064): control your firewalls, but you should at least advise from him. You know, you should at least get his opinion because he, he is good at what he does. You still get to make the final decision, but you should at least get his opinion, right? Same thing on active directory, same thing on SQL, same thing on, you know, thin clients. We're using thin clients and all these control rooms and, you know, with the terminal server, like we have the same systems running an IT, why are we not? And we were sending that team to training.
Aaron Crow (36:12.750): and they're dedicated and all they do all day long is eat, breathe, sleep, networking, or firewalls or front end servers or whatever the thing. And the fact that we're not all using those to at least advise on our OT environments as they're being deployed. Okay, the vendor's bringing in, know, active directory and they're bringing in XYZ firewall and they're bringing in, you know, these types of switches and they're bringing in this and here's the configurations. Is there anything that we're missing? Like, as we know, sometimes those configurations will leave, you know,
Mike Holcomb (36:18.008): Right? Yeah.
Aaron Crow (36:42.524): Telnet running and you know they've got a standard password installed and you know they're not they're not encrypting the passwords on a Cisco iOS right it's just clear text on so I can look at the configuration see what the password is I mean they leave SNMP running like all the different things that on an IT side we've we've disabled 15 years ago on an OT side many times we walk in and it's still there it's running XP it's got a it's got a
Aaron Crow (37:6.996): a 3G card directly plugged into it. It's multi-home, so it's plugged into multiple networks, so it's bypassing your firewall. There's all these things that we do in OT that are just no-nos and IT, but we do them every day in OT, and we have to, we've got to get to a place where we feel comfortable to reach out to our team on the other side of the fence, because we're, like you said, we're all into the same house. Like we're all working towards the same goal.
Mike Holcomb (37:21.101): Yeah, for sure.
Aaron Crow (37:34.638): And the more that we can use that knowledge together for a shared end goal, the better off we're going to be in long run. Yeah.
Mike Holcomb (37:41.678): For sure. Yeah. Do we need people that understand both? For sure. Right. But to get to that point, it takes years. It takes decades for somebody. Like I'm working on that path and I've been doing it for a long time, but I'm still not an expert, you know, in, would never say I'm an expert in ICS or OT, anything. Right. And I'm not an engineer and I'm learning again, more than one thing, you know, every, every day.
Aaron Crow (38:3.120): Yeah. Yeah.
Mike Holcomb (38:10.818): So we have to work together until there's that time where sure you have, and I don't think it'll actually ever happen, where you just have a field of people that understand IT and OT together. And again, I think those people are going to be rare and few between. And I think that's always going to be the case.
Aaron Crow (38:34.406): Well, it's like, you you build a house, you hire, you hire a general contractor and then that general contractor gets subcontractors. gets an electrician, he gets a plumber, he gets a foundation guy, he gets a cabinet guy, he gets a, you know, paint mud guy, like, you know, all that type of stuff. Yes, he's, he's somewhat knowledgeable in all those different areas enough to say, Hey, subcontractor, that's not the quality of work that we're doing. That's not what we're trying to do. But at the same time, you don't want him.
Mike Holcomb (38:56.910): Sure. Yeah.
Aaron Crow (38:59.964): doing all the work in those areas because he's not a craftsman. He's not an expert in all of those areas, but you don't need him to be. You need him to be able to understand enough that he can say, Hey electrician, we're not using aluminum wiring in this house. Like I don't care how cheap it is. I'm not doing aluminum, right? And we're going to put it into code and here's the code and all that stuff, right? It's no different in OT and cyber and our enterprises. We need to have somebody at that top level that has the
Aaron Crow (39:28.560): the enough understanding like you and I that aren't necessarily experts in all these things, but we've been around and we've seen enough that we can say, Hey, you're missing something there or no, that's not how we're going to do this. It, we are not pushing GPOs down in these, these products and locking their screens because it's going to cause a problem. This is why, right? You know, and it's, it's the battle scars from my heart, hard hats up there that, you know, I've been there, I've, I've seen it and we've done it and pulling together and learning that, that
Aaron Crow (39:56.316): that root cause analysis, the after action, whatever you want to call it, is so valuable that that that knowledge being pushed into B sides. So what is what is what are some of the things that you guys are going to be talking on? Like what is is there is there a theme or focus on on the event other than just ICS in general?
Mike Holcomb (40:14.296): Yeah, I mean, it's one with B-Sides, and it's kind of like you build it and they will come type of, especially for the first one. But already talking with folks that want to participate to come share. We have our keynote speaker locked in. We can't announce quite yet. I'm really, really excited. Hopefully a lot of other people will be as well. I know we'll be touching on subjects like
Mike Holcomb (40:43.576): And I think there's a couple of ways to look at it because with, ICSOT, right, there's, you want to look at, there's kind of the cybersecurity, I guess, principles or practices. Like if you want to learn about like ICSOT pen testing, right? How does that work in, in an OT environment and how it's different from IT, right? That could be an example. But then at the same time, we also look at the OT world and from a perspective of different sectors as well.
Mike Holcomb (41:12.942): So you could have somebody come in and talk about like, how does the power grid work? Right? How, how does control systems and cybersecurity work in a power plant? Right. Versus you someone like we're talking about Kristen, right? You know, come in and talking about how cybersecurity impacts food and agriculture, right? Which is, I mean, it's one of those areas I didn't think about a lot because I don't, you know, I haven't worked in.
Mike Holcomb (41:41.208): food and agriculture. So it's kind of this whole, just bringing in different people that want to can't share from first time speakers to people that have probably been doing this for 30 plus years and everything in between. And they can be talking about cyber from different perspectives, from the different sectors. They can be looking at it from
Mike Holcomb (42:9.346): You know, these are the different practices in OT, how they are different in IT and just kind of a big mishmash, right? Or mashup of all that is typically what B-Sides will turn out to be.
Aaron Crow (42:22.992): Yeah, that's awesome. Yeah, I mean, definitely anybody that's out there listening, you know, maybe you've submitted something for us for you didn't get your talk heard or maybe you did and you still want to share with with more folks like definitely reach out. I'll be part of it. Definitely volunteering and helping out where I can. There's there's some cool stuff coming that when they are announced, I think everybody will be.
Mike Holcomb (42:35.214): for sure.
Aaron Crow (42:46.985): Excited to see I know you guys are still working on the venue. Hopefully that's that's found out pretty quick as well. But it'll be somewhere in that S4 area that I'm sure that that people will be if you're going to one you'll be able to get there from from the other. Is that right? Yeah.
Mike Holcomb (42:53.102): Yeah, thank you.
Mike Holcomb (43:0.024): For sure. Yeah, I think the furthest location we're looking at, and we should have it locked in hopefully by the end of the year or the end of the month, right after Thanksgiving. I'm going to go down there. But yeah, I think the furthest away is like a 10 minute drive from where S4 is. So it's, yeah, not horrible.
Aaron Crow (43:15.932): Sure. Perfect. So how do folks submit to be a talk or sponsor or volunteer? Like what's the kind of call to action for folks if they want to be involved or just participate or just attend even?
Mike Holcomb (43:31.726): Sure, no, I appreciate that. so besidesics.org is the site to go to. And then you'll see the links. There's links there for the CFP and for tickets. I would say right now we're actually probably already about 20 % sold out, is really good. Yeah, to see. So we'll have a great group. And then on the site, you'll also see the info at besidesics.org.
Aaron Crow (43:47.400): wow, awesome.
Mike Holcomb (44:0.942): So that's the best email for if you want to go through the official channels or anybody can feel free to ping me on LinkedIn or send me an email at Mike at MikeHolcomb.com. and, we'll give me a folks want to volunteer. We'll get you on the list. We've already got like yourself and, and some others from the community, which is really exciting that are coming to help out for the day. and then, try to think what else I'm probably missing something.
Mike Holcomb (44:29.570): But it should be a great event. We'll have a speaker dinner and volunteer dinner the night before. We're planning on an after party that night. We're also working with Kristen and Nejo to host a reception for women in ICS cybersecurity that night. It was something that S4 had done previously and they're not doing it this year for whatever reason. So we were going to pick that up.
Mike Holcomb (44:59.426): So I think that's definitely something also to look forward to, especially for any of the women, whether you come to S4 or B-Sides or one or the other or both, definitely love to have you at the reception that night. So, but yeah.
Aaron Crow (45:17.060): Absolutely. That's exciting. Yeah. And all this stuff, we'll share all the, all the links and content down in the show notes there, but definitely reach out. You know, if you have questions, don't hesitate to reach out to me, reach out to Mike directly happy to, do it. But I really challenge, all the listeners out there. If you haven't spoken, if you, if you've got something and you want to get in there, and submit something, maybe you've tried it as for DefCon or any of the others, or maybe you have it, maybe even sitting on the sidelines.
Aaron Crow (45:45.372): and you haven't stepped up to stage. I really challenge you to take this, right? And it's a good opportunity. It's a good skill. Mike and I talked about it a little earlier around kind of business development versus engineering. And part of my job as a consultant is to do, to sell, right? And one of my mentors a long time ago told me all business is a people business, right? You have to be able to sell your idea.
Aaron Crow (46:11.270): to people, whether you're a true salesman, people think sales and they think car salesman. But it's really, always, all of us are always selling to our wives, to our kids, to our boss, to the plant manager. You're constantly selling your idea and why it's a valuable idea and why, how you understand and how it's gonna benefit them. That's what we're doing, right? So getting on stage and honing that soft skill is valuable to all of us engineers, all of us network.
Aaron Crow (46:40.486): people, cyber people, like that's a skill set that isn't necessarily trained at a CISSP or anything like that, but it's a valuable skill to have for your career and to just better the community in general to have those dialogues and conversations. Cause you know, Mike, some people may disagree with you and I on the whole segmentation and ITOT convergence. And I'm happy to sit down and talk to them about it and just talk about my concerns, but that doesn't mean I'm against hearing their perspective as well.
Mike Holcomb (47:8.896): Sure. Yeah, most definitely.
Aaron Crow (47:10.254): Absolutely. So when's the deadline? do tickets, how often or how quickly do people need to jump before they lose the opportunity to attend?
Mike Holcomb (47:22.232): Yeah, it's hard to know since it's our first year as far as tickets selling out. I suspect we will sell out though, especially once we release our keynote speaker. But we're going to try and get as many folks in there as possible. So we'll sell tickets up to the day. But again, they probably, I would imagine, just going to sell out. And then the cutoff for the call for paper or presentations is
Aaron Crow (47:40.806): We'll sell out. Yeah. Gotcha.
Mike Holcomb (47:51.480): the of the year. So you have until New Year's to get that in. And then we'll have a really quick turnaround where the advisory board looks through those. They don't know who submits what, so it's a blind review and then take all that into consideration. And then, yeah, we'll finalize the schedule and let folks know. So that way, for those that are especially coming from out of town to Tampa this year, that they'll have time to be able to make those arrangements.
Aaron Crow (48:21.262): That's awesome. Anything else you want to share with everybody to know before we wrap it up and tell people to just sign up and let's go.
Mike Holcomb (48:29.068): Yeah, I mean, that's really, you know, that's really it, right? We want to make it as big as possible because we don't want this to be the one and only, besides ICS. We've already had folks reach out from the UK and India and a couple other places that they want to do their own version, which, is awesome. And which is what we want to have happen. We just have to make the first one a success so that the besides overall community supports us continuing with this, you know, besides ICS OT, in name.
Aaron Crow (48:37.244): Sure. Yeah.
Mike Holcomb (48:58.818): which I think a lot of people are really excited about. even though maybe they don't care about ICSOT and that's okay. Not everybody does. I think at the same time, they can see the value in the mission and support that. So there's a lot of excited people out there. And so, yeah, so I'm really excited for February to come and put on a really great show, have as many people there, again, sharing, connecting, learning, just.
Mike Holcomb (49:26.712): getting to know each other and kind of take that back out into the real world and make a difference.
Aaron Crow (49:33.742): Awesome. Yeah, that's exciting, man. Well, definitely have all those show notes. I'm excited to be there, be part of it and experience the first one and help it be as successful as possible. So thank you for your time today, Mike. I really appreciate it and I look forward to February and kicking this thing off.
Mike Holcomb (49:50.434): For sure. Yeah, it'd be great to have you there. For sure. Thanks, Aaron. Thanks, Aaron.
Aaron Crow (49:52.284): All right. Thanks, man. All right.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.