In this episode, host Aaron Crow shines a light on the collaborative spirit that unites these professionals as they confront contemporary cybersecurity challenges. It features a roundtable discussion with industry veterans: Pascal Ackermann, Senior Threat Protection and Response Engineer; Brett Seals, expert in incident response and threat detection; and Gabriel Sanchez, head of the Advanced Threat Protection Center
The discussion takes listeners on a journey through both nostalgic tech, with mentions of the Tandy TRS-80, and the pressing issues of today, such as ransomware threats. The guests delve into the delicate balance between old and new technologies, the intricacies of integrating IT and OT security, and the evolving skill sets needed in the field. From power plant vulnerabilities to global geopolitical ramifications, the episode underscores the critical importance of securing essential infrastructure.
Listeners will hear shared histories, stories of past crises, and these experts' proactive solutions. Topics range from cloud and artificial intelligence trends to the crucial need for workforce development. This episode provides a detailed, engaging, and educational experience for anyone interested in cybersecurity.
Key Moments:
10:43 Incident detection parallels between the control room, SOC.
13:58 Integrating safety programs into utility sector operations.
19:24 Balancing risk vs. cost of device replacement.
24:10 Immediate support is needed for 24/7 operations critical.
32:21 OT and IT share the same protection goals.
34:59 Focus: Enhancing asset management and system visibility.
39:42 Early hacking: dialing, shared networks, pranking neighbors.
44:32 Shift towards active technology use in OT.
50:58 If it ain't broke, don't fix it.
55:37 Defending infrastructure and impacting global mission together.
59:52 Issues transcend borders; global cooperation is needed.
Guest Profiles:
Brett Seals is an expert in instant response and threat detection engineering, currently working at the firm 1898. Before joining 1898, Brett garnered a decade of invaluable experience in the United States Navy, where he supported both expeditionary and cybersecurity operations. During his Navy tenure, he served at the Navy Cyber Defensive Operation Command, the Navy’s equivalent of a Security Operations Center (SOC), managing a fleet of sensors. Brett also spent considerable time around the Fort Meade area. As the COVID-19 pandemic began, he transitioned from his military role to his current position, continuing his commitment to cybersecurity in the private sector.
Gabriel Sanchez embarked on his professional journey in the early 2000s, transitioning from college into what we now recognize as a burgeoning career in cybersecurity. Initially, Gabriel found himself working as a contractor for the Department of Defense, focused on missile simulations and charged with the responsibility of protecting their network—an early, hands-on introduction to cybersecurity before it even had a formal name. Following this formative experience, Gabriel spent the next decade in the electric utility sector, stepping into a groundbreaking role to establish an entirely new cybersecurity program from scratch. His trailblazing efforts in this novel position underscored his capability and foresight in an evolving digital landscape.
Pascal Ackermann is a seasoned professional with over two decades of experience in controls engineering and operational technology (OT), having entered the field in 1999. Throughout his career, he has focused on building resilient and secure OT networks. For the past year, Ackermann has specialized in helping customers make sense of security events within their environments. He assists clients in discovering and interpreting security incidents, providing insights into their relevance and impact. Additionally, Ackermann and his team are equipped to respond to security breaches, offering on-site services to recover, remediate, and ensure systems are back up and running efficiently. His deep expertise makes him a trusted resource in cybersecurity for OT environments.
Connect Brett at https://www.linkedin.com/in/iambrettseals/
Connect Gabriel at https://www.linkedin.com/in/gabrielsanchez-1898andco/
Connect Pascal at https://www.linkedin.com/in/pascal-ackerman-036a867b/
Company Website at https://1898andco.burnsmcd.com/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Aaron Crow (0:1.350): Awesome. Hey guys, thank you so much for joining me. This has been a long time coming. I'm excited. Normally I have one, maybe two guests this time. There's a whole bunch of us, right? It's a good round table. So I'm going to kick it off with just, you know, kind of pitching it over to you, Pascal. Pascal and I worked together at EY. We've known each other for a long time. This industry is so small. I love how much, you know, even though we, you know, I worked for Morgan Franklin, you guys worked for 1898.
Aaron Crow (0:28.953): I don't see us as competitors. see us as so much. There's so much that we can do to lift up the needs in this space. And there's more work than any one of us can do or any one company can do. And I really feel that the more we work together, the work comes on the back end of this, right? So yes, there's gonna be times where we're gonna be competing in a...
Aaron Crow (0:49.454): RFP or anything like that, but there's more times that we can go together and help each other and help the community. So I appreciate you guys taking time and being on my podcast today. So Pascal, why don't you introduce yourself, tell us who you are and, and what's kind of go around the whole.
Pascal Ackerman (1898 & Co.) (1:2.808): Yeah, thanks for that. And yeah, by the way, you're absolutely right, right? So today we're working for 1898 or for Morgan Franklin, but next week or next year, that could be different again. being friends, having those connections in the community is what's key to me, right? It doesn't really matter who's paying for your t-shirts. But yeah, Pascal Ackermann, I'm the Senior Threat Protection and Response Engineer with 1898. That's a long title to basically say that I help.
Pascal Ackerman (1898 & Co.) (1:31.808): our customers make sense of security events. But first of all, we'll try to help them discover security events in their environment and then also try to make sense of it in a means that when there's something comes up, we have the staff to go out and say, hey, this is what this really means. This is really not really relevant to your environment or this. And then we have the team that can go on site and help recover.
Pascal Ackerman (1898 & Co.) (1:58.456): Remediate or another way shape or form get the customer back up and running again So I've been doing that for about a year now But before this I've been I've been in controls and engineering and OT and ICS or whatever you want to call it these days since 1999 so if you if you followed my Career path I started off as a controls engineer then I started building resilient and secure network OT networks
Pascal Ackerman (1898 & Co.) (2:23.950): And then I started attacking them and now I'm basically combining all of those knowledges into the new role where we have a security operations center specifically designed for OT space. So with that, I brought two colleagues of mine on this call that are trying to keep me in charge, trying to keep me in order, I should say. And I'll start with Brett, man, introduce yourself.
Brett Seals (2:49.628): Hi, yeah, I'm Brett Seals and I do incident response and threat detection engineering in 1898. I work for Gabe and yeah, I came here after 10 years in the United States Navy where I supported expeditionary and cybersecurity operations to include working at the Navy Cyber Defensive Operation Command, which is kind of like the sock of the Navy and their freedom sensors out there. And yeah, I I spent some time
Brett Seals (3:19.844): out around the Fort Meade area. And as the pandemic was hitting, I was transitioning out and, you know, the social engineering campaigns that I ran on various industrial cybersecurity consultancies started to yield some fruit. And I got my white whale, Burns and McDonald, 125 year old architectural engineering and consulting firm that was right down the road from the rust belt that I grew up in. Right.
Brett Seals (3:47.942): So was a name in the household. And I can't tell you how pleased I was to earlier this year, find out that the guy who wrote what I consider to be one of the most direct and actionable tomes on industrial cyber that was modern and relevant was being picked up by Mr. Gabriel Sanchez here to come and work with us. So I, when he came on board, I told him that
Brett Seals (4:18.420): He'd been working here a lot longer than he realized because the way that the words went on the page made sense to me and it was a resounding truth is resounding to all so that's the kind of philosophy mindset and shape of The way that I've approached being actionable in industrial cyber, but gay brought us together. So over to you bud
Pascal Ackerman (1898 & Co.) (4:40.963): Hahaha.
Aaron Crow (4:41.172): Good job, Gabe.
Gabriel Sanchez (4:42.256): Yes, yes. So Gabriel Sanchez, been doing cybersecurity for, man, the 90s. For anyone that gets glimpses at the video, you'll be able to see some antiques in the background. Early 2000s, I was actually getting out of college and actually getting paid to do what we call cybersecurity today, but was basically doing DoD type contracting. Didn't really realize I was doing cybersecurity at the time. It was basically, you
Gabriel Sanchez (5:11.538): organization that was doing different type of missile simulations and they say, need to protect our network, right? And so that was kind of cybersecurity for me, learning on the job. And then after that, I went into electric utility space for about a decade. And that's really where it was very new. I basically went into a position that hadn't existed before. They said, the entire cybersecurity program. What I thought was gonna be two years turned into about a decade.
Gabriel Sanchez (5:41.304): After that went into the banking industry kind of at a global scale supporting about 80,000 employees doing cybersecurity there for operations centers. And now I sit today leading the Advanced Start Protection Center, trying to make sure I keep Brett and Pascal happy as much as possible. So although sometimes they say that they work for me, it's kind of really the other way around. I basically work for them to make them happy.
Gabriel Sanchez (6:8.231): Based out of Houston, we run an advanced start protection center and it's kind of like Pascal said, a security operation center with an OT focus.
Aaron Crow (6:18.068): Very cool. Yeah, I mean, that Mac on your desk looks similar to mine over there in the corner. So that was my very first Mac computer back in the day. had a, first computer was a Tandy TRS 80 that, yep. There you go.
Brett Seals (6:31.514): I got a Trash 80 that controls the lights in my underground bunker here.
Gabriel Sanchez (6:35.450): No, geez.
Pascal Ackerman (1898 & Co.) (6:36.795): Let's hope it keeps running.
Brett Seals (6:40.291): It's the most dependable computer I have
Aaron Crow (6:42.822): Yeah, exactly. Exactly. Well, awesome. So, you know, that's what I love about this industry is I think most of us really got this and we came through it like we didn't go get a degree in OT cyber security because we were around before it existed. Like we were, we were in the marketplace before OT cyber was a thing. We didn't even call it OT. Like very similar. I worked in power utility and I've worked in critical manufacturing and some of those places, but a lot of my career was spent in
Pascal Ackerman (1898 & Co.) (6:42.923): Ha ha ha ha.
Aaron Crow (7:9.168): in power generation and transmission distribution. And I got kind of shoehorned in because I worked in IT, I did networking, I did systems administration and active directory and exchange and all that kind of stuff in corporate America. And I brought those skill sets to this place and like, hey, we have to design a secure network and NERC SIP and all these things. Nobody knew what to do. They were control engineers and they were doing the best they could, but that's not their skill set, right?
Aaron Crow (7:38.740): A lot of the people like us that are out there, most of us have that type of story. Like we started out here and we transitioned and all of a sudden now we're doing this OT cyber stuff. And that's a good thing because with that, we bring the experience of being a controls engineer first, right? So when Pascal's looking at a problem, he's not coming from some cybersecurity textbook he read and he's bringing that thing down. He's like, I was a control engineer. We're not doing that here.
Aaron Crow (8:7.853): This is why and we can do it. We just have to do it differently, right? So that's the conversation I have all the time and I love the experiences that we bring from from that perspective from the plant side, right?
Pascal Ackerman (1898 & Co.) (8:19.066): And that can be a very difficult conversation too, right? You go into a site and there's ransomware everywhere and they'll be like, what do we do? Do we pull the plug on stuff? I'm like, no, well, what happens if we do, right? If you lose your HMI, if you take this switch down, what's it gonna affect the rest of the process? And people be like, okay, maybe if I take this HMI off, now I can't control my steam engine, my steam turbine. Maybe we shouldn't do that. So it makes for a really tough situation, a tough conversations once you're.
Pascal Ackerman (1898 & Co.) (8:47.288): once you get into those scenarios.
Aaron Crow (8:50.804): Absolutely. It's a different, know, OT, we have the same problems that they have in IT. We have a lot of the same tech stack nowadays that they have in IT. It just, how we deal with resolutions are different. Like what I do, you know, right of boom and even left of boom, but specifically right of boom is going to be different, right? In an IT world, I may kick something off the network, force things off, reboot, you know, a lot of things. In OT,
Aaron Crow (9:18.676): from my experience a lot of time that's picking up the phone and calling the control room. Hey, something's going on. What can you do? Do you know what's going on? And do you see this exactly?
Pascal Ackerman (1898 & Co.) (9:25.609): What am I allowed to do? What am I allowed to touch right now?
Gabriel Sanchez (9:27.896): Alright, alright.
Brett Seals (9:28.624): You know, my time in Southeast Asia, there's a saying there actually have a shirt I wore the other day on the front says same, same, but different on the back, right? You know, because there are so many things that are same, same, but different. Cause I just earlier today, I was having a conversation with somebody talking about the way that I've customized the NIST IR 8428. I'm not sure if you're, you're savvy, but I think it's a fantastic framework to be able to, to custom tailor, right?
Gabriel Sanchez (9:32.626): you
Aaron Crow (9:36.006): Right.
Pascal Ackerman (1898 & Co.) (9:37.252): Haha.
Aaron Crow (9:53.438): so talk about a little bit what explain what it is for sure
Brett Seals (9:55.694): Yeah, sure. So it is an OTD for framework that NIST put out two, three years ago now. And it has some very, it's a framework, right? So it's a way for you to be able to generalize and abstract the specifics of your process environment. And I tune it to make it a specific thing that we can fit our playbooks, runbooks, whatever we want to call them based off of the magic words of our clients, industry or culture, right?
Brett Seals (10:25.498): Because, you know, being able to look at that first initial phase where we're doing incident alert detection, there's analogs between what happens in the control room and what happens in the SOC, right? I'm doing, each event has attributes to use the object oriented programming terminology, right? The criteria of those attributes are what constitutes our priority and our communication, our response playbooks in relationship to it.
Brett Seals (10:54.894): And the same thing is true in OT except for the most urgent criteria is the plant manager having to put his hard hat on, right? And if he has to go down onto the floor, then we've got that's an urgent problem. We've have enough downtime to where Bob had to get his hard hat and nobody wants Bob's feet on that floor, right? Whereas on the other side of things, we're being able to make the urgent assessment of
Brett Seals (11:22.810): whether or not it's a legitimate root level intrusion of a perimeter DMZ asset. Right. But the correlation between those two data sources, sources is how we still conduct root cause analysis the same way. And we share the findings from one another and all throughout the incident life cycle. It's, it's like that. I'm getting data sources the same way from OT that I am from IT because
Brett Seals (11:50.096): A lot of the IT systems that now overlap with that OT environment and the detection sources are from a mature process environment detection system that came from the need, the legitimate need of asset inventory or discovery to be more accurate.
Aaron Crow (12:6.152): Yeah, and that's the thing. There's a lot of frameworks out there, but I think you hit on a good point there, right? That framework is really a common language that we know how to talk about things, right? It's whether, choose one, right? I've implemented lots of different frameworks and you can argue NIST 853 is better or NIST 872 or any of the frameworks that are out there, which is better. I don't think it matters as much which one you choose. I think there are some that are more,
Aaron Crow (12:35.216): applicable to your industry, maybe. But even anyone that you choose, it's fine. Pick one. And that's the language that you use to write the policies and procedures to implement the capabilities and the controls. It's just a language. It's a dictionary that you go, Hey, what is an incident? What is a response? What is threat detection? Like, what are those words? So we know we're talking about the same thing at the same time.
Brett Seals (12:37.436): Mm-hmm.
Pascal Ackerman (1898 & Co.) (12:41.334): Just choosing.
Brett Seals (13:0.732): Yeah, an authoritative reference to stand on, right?
Pascal Ackerman (1898 & Co.) (13:1.240): And you'll find that you'll pick one, right? Hopefully you pick one because well, imperfect security right now is better than perfect security never, right? Just pick a direction. And you'll find that after a couple of years, you'll be like, this is nice. I did the NIST cybersecurity framework or whatever the NIST DFIR. And it fits my needs about 90%. What else is out there? But now you got the terminology. Now you got the know-how. Now you got your environmental awareness to see, okay.
Pascal Ackerman (1898 & Co.) (13:28.920): maybe something from the ISA portfolio is better suited for me. But you have the ability to ask those questions and to have that knowledge.
Gabriel Sanchez (13:33.808): Yeah.
Gabriel Sanchez (13:37.946): Yeah, and real quick, and Aaron, you might have run into this like in the utility space, but one of the key thing for us is, for example, for me in the utility space, safety, and we can argue OT overall, safety is a huge thing, but what programs does that specific sector have? And then how can you implement, and Brett uses the words like tuning, or we can even get frameworks, how do we kind of implement those pieces into what they have already, what they've been doing?
Aaron Crow (13:37.950): So what are, what, go ahead.
Gabriel Sanchez (14:4.708): as part of their safety program and kind of risk analysis for decades, right? And that's a bridge, talking the common language and then also getting it to still kind of feel the same with the same outcomes, which is basically making sure you can operationalize whatever it is that that critical sector is doing while keeping safety in mind has been kind of a key piece.
Aaron Crow (14:30.578): Yeah, absolutely. All of these places, again, we all came from more of an operational role. Many of us in OT have, and it's very common to see safety is important, safety and availability. know, the CIA triad, don't care about confidentiality. I care about availability, and I usually associate availability and safety. Those are kind of, you know, parallels, right? And availability and safety trumps everything else. It's not that I don't care about confidentiality. It's just not the priority.
Gabriel Sanchez (14:37.040): Yeah.
Aaron Crow (14:59.666): The most important thing is to control and be it safe and make it safe, right?
Brett Seals (14:59.825): The web?
Brett Seals (15:3.590): The way that I saw it is that the idea of CIA and IT and OT, we have safety, reliability and productivity. And that's the paramount. That's the triad that governs our OT cybersecurity programs because another quick and easy analogy that is attached to this, in IT we have zero days and OT we have forever days.
Pascal Ackerman (1898 & Co.) (15:3.641): I would
Brett Seals (15:29.176): It's a completely different foundational philosophy. And as the IT guy who went OT, right, it made me want to my skin off. It was terrible, right? It's an awful thing, but it's just a reality of these high availability environments that are also easily to measure whether or not they're actually stable because they're so consistent.
Aaron Crow (15:51.016): Yeah. They don't change, right? Sun Tzu, Art of War. I'm not patching every day. I'm not updating every year. I'm not replacing all my hardware. There's as we've all been in places where equipment's been there for 40 years and it is reliable and consistent and capable. so, you know, and I see a lot of OT cybersecurity pundits, you know, well, you can't scan the network. Then it's not safe. You shouldn't rip it out. You shouldn't be dependent upon something that I can't scan. I like, that's just asinine, right?
Pascal Ackerman (1898 & Co.) (16:20.110): No, that's wrong. Even the stuff that's not reliable, if it's an integral part of your process, it's gonna have to run, right? I've been in environments where they had a 386 and every day it would overheat, but it would run like the most core part of the process, the standardization of the milk, standardization process. I think I went around, but anyway. But they couldn't replace it, so every day they would...
Pascal Ackerman (1898 & Co.) (16:49.594): pull out the plug, put it back in, reboot it and start the process. So, and after about 20 years of that, they finally decided to move it all to a PLC. And it was a million dollar project to get it off that 386 onto like a standardization PLC. So I know why they didn't do it, but in the meantime, they need to keep running.
Brett Seals (17:4.792): Okay.
Brett Seals (17:8.956): This 386 reminds me of a realization. Sometimes you learn things that you learned as a kid, but you remember them as an adult and they have a whole new context. When I was a kid, my mom and I had a Tandy 386 with a floppy drive. We got an extra SCSI drive. I didn't understand why it is for the longest time because I was on the peak amount stupid through my cybersecurity journey for so long and continue to be in so many other ways.
Brett Seals (17:38.618): why it was that I had to like, typed before I could actually read because there was a book, a compiled book. But now I understand that it's because the system binaries for the shared objects on that operating system at the time was not universal enough for all the drivers that were being required. So you had to compile the binaries on the 386 because Lord knows what kind of weird drivers that were required to run your sound blasters by creative labs, you know,
Aaron Crow (17:57.150): Right.
Brett Seals (18:6.236): And that's really an analog as well to the reason that that million dollar project happened on something that somebody bought in 1985 for $1,000 maybe if even that, right?
Aaron Crow (18:15.688): Yep. Why? mean, we, know, Gabriel, you, came from power utility and, every turbo control, every turbo control cabinet you walk up to has do not key Mike when this cabinet is open. Right.
Gabriel Sanchez (18:22.226): Yeah.
Gabriel Sanchez (18:27.822): Yep, exactly. Yes, absolutely. It absolutely did.
Aaron Crow (18:33.676): And there's a reason for that. they get equipment? So could you just say, well, that equipment's not good because you can't key a Michael. That's a risk. And yes, and that's the conversation I think we have so often. And the biggest struggle I see from IT practitioners and cybersecurity folks that come into the O.T. space, that it's hard to wrap their head around sometimes that that three 86 that's running in the corner. Don't touch it. Leave it alone. And it may cost five million dollars now to replace that thing.
Aaron Crow (19:2.162): this site only makes a million dollars a year. So I would lose money if I replace that thing, but if it doesn't work, then the whole place shuts down. So it's that risk reward conversation of when is it risky enough that I need to replace it or mitigate versus just leave it alone except the risk of I know I have to reboot it every day, but as long as it works, that's a lower risk than replacing the PLC that isn't guaranteed to work in a short period of time.
Aaron Crow (19:30.024): The cost, may take me 10 years to recoup that cost because the margins are so small, right? And that's a different conversation in OT that the IT folks, they just throw capital dollars at it and replace with brand new MacBooks or whatever and put it to the cloud. And that's just not the same in OT.
Brett Seals (19:49.066): No.
Pascal Ackerman (1898 & Co.) (19:50.234): if you can even refine the replacement, For stuff like that is just like, yeah, on the IT side, you go to the next greatest and latest database server, you upgrade that stuff. And there's a situation where you can, but in most situations, if you throw enough money at it, you can fix it. And on the OT side, I've been in situations where you can have all the money you want, but if a vendor doesn't exist anymore and you're running that Windows NT blow molding machine and you need to have a replacement for that NT.
Aaron Crow (19:58.110): Right.
Pascal Ackerman (1898 & Co.) (20:18.766): Better hope that you get a backup with at least the software that you need installed because...
Aaron Crow (20:23.294): Well, and it goes back to that availability and reliability, Is we've all had Windows machines, newer technology, and yes, it's way more capable. We've got GPUs and all the stuff that can do is incredible. But what I want to depend my life on, like if this was a life-saving device and I was scuba diving and this computer was controlling my oxygen and I was a mile below the surface of the water and I was depending on a Macintosh
Aaron Crow (20:52.084): or a Windows 11 machine, am I going to put my life and expect it and then allow people to patch it while I'm under the water?
Pascal Ackerman (1898 & Co.) (20:59.902): While you're under.
Gabriel Sanchez (21:2.458): Well, a lot higher consequences, right? And that kind of brings us to, and this is probably a bad word, right? It brings us to a lot of that IT convergence, right? And I know a lot of people don't like that, that, yeah, I know, we got a drink already, that buzzword of the convergence. But I do think there's convergence with responsibility, with convergence with people, but it's not necessarily always a convergence in the approach, right? Like to your point, the approach is different, the culture is different. And I think sometimes, at least I know,
Aaron Crow (21:4.606): Right.
Aaron Crow (21:10.206): right.
Pascal Ackerman (1898 & Co.) (21:11.127): drink.
Gabriel Sanchez (21:31.960): I sometimes will take it for granted because I've been through the IT, I've been through the whole OT experience and kind of back and forth. But there's a lot of organizations that it just becomes, it seems natural to say, well, I have an operation center that's with IT. Well, now I'm just going to extend that into the OT because there are similarities with software and there are similarities with they need to protect their networks and firewalls and so forth. But...
Gabriel Sanchez (21:59.110): But the approach is just a very, very, very different thing. And the risks are much higher. And then how do you have operators have enough confidence that someone that is maybe a tier one that does your initial triaging as a typical operations center knows to make the right call to say, hey, I think you should do this when you got the operator has been, you know, boots on the ground for 15, 20 years and saying, what does this person know about OT?
Aaron Crow (22:27.838): Right, Well.
Gabriel Sanchez (22:28.816): Right, so I know I just opened up a can of worms, so I apologize.
Brett Seals (22:30.880): So hold on a second. Hold on. Hold on. Gabe. Are you, are you talking? Are you saying that I shouldn't send it in an in map tack T four just cause I learned it at a sans class? Is that a bad idea? sorry. I got all the way.
Pascal Ackerman (1898 & Co.) (22:32.743): Everybody's ready to jump in, I see. Let me, let me.
Aaron Crow (22:35.736): Yes!
Pascal Ackerman (1898 & Co.) (22:43.342): No, T4 is fine, that's not a T5.
Aaron Crow (22:43.763): or
Gabriel Sanchez (22:46.298): T5, right?
Brett Seals (22:51.612): Is that right?
Pascal Ackerman (1898 & Co.) (22:51.896): Well, yeah, T5 is insane, insane speed as T5.
Aaron Crow (22:57.052): Yeah. Right, right. Yeah. Well, but you know, it's, it's, it's, it's funny because again, ito T convergence. And I, I agree that there are things that we can, for instance, let's, let's pick an easy one. We both have firewalls. We have firewalls and OT. We have firewalls and it there's a prime example of how you can use and leverage your it organization who probably has a firewall organization. And that's all these people do is firewall, firewall, firewall, firewall.
Brett Seals (22:57.234): I was trying to be conservative, okay?
Pascal Ackerman (1898 & Co.) (22:59.158): yeah, fair enough.
Aaron Crow (23:27.716): And you can use their knowledge to help you make sure your policies are good and that, you know, your firewall rules are good and you don't have any any any's and things like that that we see all the time in OT, right? But the prime example that I also that I also see is telecom. And a lot of folks use telecom or their networking organization because again, we're using Cisco switches or whatever switches in these O.T. spaces. Well, why wouldn't I just have telecom support them?
Gabriel Sanchez (23:39.408): Yes.
Aaron Crow (23:53.404): In the prime example, I always ask, and I'm not saying that they can't, and a lot of organizations have been successful, but when that plant that runs 24 seven, when that switch fails at three o'clock in the morning on a Saturday, they don't want to put in a ticket and wait three weeks to get a replacement. They need it now. So what happens is, is if you, if you put in it with a dependency upon an IT organization that does not have the SLAs to support,
Gabriel Sanchez (24:13.392): Yes.
Aaron Crow (24:21.180): the needs of the facility, then what do they do? They go to Walmart and they replace it with a D-Link off the shelf because they need the plant to work. And then they kick IT out and say, you are not supporting me anymore because obviously you're not supporting me anyways. So I'm not going to let you in my facility anymore. And we're going to do it on our own. And we're going to leverage our vendors and our in-saf, our controls engineers that are smarter than you anyways about our process. And we're going to do it our way. And it may not be your secure way, but it works.
Aaron Crow (24:49.958): and your way left me in the dirt and it wasn't working. And I've seen that at every kind of facility you can imagine. Why is that dealing there? We had to go through IT, they didn't support us. So we went to Best Buy and got a switch and it works and we're not touching it. Don't even look at it.
Pascal Ackerman (1898 & Co.) (25:4.314): I haven't just seen that, I've done that in my previous life, right? Control engineer, middle of the night, okay, who do we call? Well, IT. Beep, beep, beep, we'll be there between 1 a.m., between 1 p.m. and 2 p.m., bye bye. So what do you do? You go to something that's open 24-7. Thank God we sell at fries at that time. And then you do what you need, right? Because production.
Pascal Ackerman (1898 & Co.) (25:28.174): It's not going to be the IT folks who have to go to the plan manager and say, well, we are downtime because we couldn't get our ass out of bed. But it's going to be us having to say that. But yeah.
Aaron Crow (25:40.296): Well, and that goes back to another example of why it's different, right? And it's not just the technology stack is very similar. So if you look at it on paper, it's really easy to see, well, I can use, can leverage my IT organization, but it's that people process and technology and Pascal, you just hit on something. Your bonus was probably tied to the availability of that plant. IT's organization is not. So when it goes down, your bonus, your paycheck, your job is literally on the line.
Gabriel Sanchez (25:55.536): Right.
Aaron Crow (26:9.598): Theirs is not.
Gabriel Sanchez (26:9.968): Yeah.
Pascal Ackerman (1898 & Co.) (26:11.628): And then you're trying to get a hold of them, so that could be...
Aaron Crow (26:14.388): And their best case is, again, power plants. They're in the middle of nowhere. I worked at TXU or Luminator, Vistar, or whatever the heck you wanna call it. were at headquarters in Dallas. Well, my power plant is six hours away. All the IT people are there. They don't have IT staff in the middle of nowhere at my power plant because it's too expensive. It makes sense. But I have to have a way to get this thing back up and running. So I lean on a Pascal type person
Aaron Crow (26:43.356): and he's going to go to fries or Best Buy or he's going to go pull a switch out of his house. Whatever he has to do to get it up and running and we've all seen it.
Pascal Ackerman (1898 & Co.) (26:51.438): I'll send it to the cloud if I have to. Talk about opening up again.
Aaron Crow (26:53.500): Right. Whatever. Bypass. Yeah.
Brett Seals (26:54.260): 100%. Getting out of the military, one of the things that I didn't expect was all the fun cultural measurements that you had to do as a consultant. It's considerably different because it's a much more stable culture in the military. But I quickly come to understand it and make the joke that we are kind of like marriage counselors for OT and IT.
Gabriel Sanchez (26:54.482): Hmm.
Brett Seals (27:21.062): Like everybody, everybody has different requirements out there in the dynamic of what makes an organization and reminding and having an objective third party kind of help connect the dots between, guys, your requirements actually aligned to the same business objectives. So this is how you support each other. And it's a natural check in balance that you have between the, these two parties to be able to, to maintain safety, reliability and productivity. Right.
Brett Seals (27:50.574): And, you know, like the, the stories that I've heard or some version of, you know, 20 or so years ago, we had the IT guys come in here at the site. They gave us these Cisco switches, didn't have the, the real time, packet requirements of our protocols. so we ended up getting burnt, didn't get the good maintenance contracts that we expected had to get swapped out, kicked them out. Now we have corporate IT. Right. And.
Aaron Crow (28:15.966): Mm-hmm.
Brett Seals (28:18.168): the analogs are still there locally at the site. That's typically the configuration that it's gone into, but now our OT engineers and the process control guys, maintenance guys, they have been, their positions have expanded to include all this cyber stuff and they're ready to see some help, but they have to learn how to love again, Aaron. There's not trust, you know? So that's where we talk about advocacy training and, you know, not being too aggressive in communication.
Aaron Crow (28:38.877): Yep. That's right.
Brett Seals (28:47.632): But that's the job.
Pascal Ackerman (1898 & Co.) (28:47.946): Here's the kicker though. here's the kicker from all of those companies, organizations I've been with. The ones who do OT and OT cybersecurity, the best are the ones who have figured out how to have IT and OT work together that might have like an IT-centric, a business-centric acquisition program where they get their equipment. But then they have an OT person who does the maintenance, who does the uptime, who does the patches and stuff so that they...
Aaron Crow (29:2.899): Mm-hmm.
Pascal Ackerman (1898 & Co.) (29:16.206): they know what the schedule is about. They don't reboot a switch in the middle of the night. No, they actually communicate it with the OT team. Hey, we need to do this update. I need to get some available time. And then they work with them to get that implemented. the companies who do that IT OT liaison the best, and it could be a one person, it could be a team, but the ones that do that are typically the best at doing cybersecurity for the entire organization as well. And I've seen a lot of that, a lot of progress when I wrote my first book, what, 10 years ago now.
Pascal Ackerman (1898 & Co.) (29:45.828): That wasn't there. was really, it was like IT, OT. They didn't like each other. They actually were in each other's way for a lot of things, but it has come a long, long way. Where I'm starting to see the difference now is more into the response of things. So they're really good at segmentation. A lot of customers or lot of organizations really started to push for architecture that's defendable. They've installed.
Pascal Ackerman (1898 & Co.) (30:12.814): network security monitoring tools and asset management systems or as a discovery systems. But now they're being overwhelmed with all of this extra data they're getting. So what to do with these events? What does it mean to have frosty group going around it? Is that really relevant for my system? Right? And that's honestly the reason I joined the 1898 team because I've had those conversations with so many asset owners that I'm like,
Pascal Ackerman (1898 & Co.) (30:41.678): we need to come up with something that we can support them. And I think the MSSP that we built is a fantastic way to go out there and help customers say, no, don't worry about Frosty Goop because you're an Ethernet IP shop, right? It's not going to affect your environment.
Aaron Crow (30:57.586): Yeah. And people don't know what they don't know, right? They see what's in the news. We see these nation state attackers going after all these things. You know, there's more and more, you know, fear and, you the sky's falling, you know, do everything. And again, the OT market hasn't helped the vendor market of, you know, pushing that fear to sell fear cells. You know, we know that, but as an asset owner and as a
Aaron Crow (31:23.506): you know, provider and a service provider, consultant, know, MSSP, all those things, you know, at the end of the day, the good ones like us want to help. And I don't want to just sell you something to sell you something. That's not what I want. I want we all want to help because at the end of the day, I'm dependent upon this electricity to work and
Aaron Crow (31:43.652): and you know the the gas to get there and and you know my Amazon order to arrive and and all the things that we like right it's Christmas and Pascal's got his hat on right you know it's it's the tis the season to order stuff and we want that stuff to work so it's dependent upon you know all of these things working and and to your point Pascal like I see the biggest challenge and I'm excited to see a change and I've seen it in my career as well is is OT and IT
Pascal Ackerman (1898 & Co.) (31:52.228): Hahaha!
Aaron Crow (32:12.510): We're on the same team, right? We're literally on the same team with the same goals. And yes, maybe you're on the offense and I'm on the defense or we're on special teams or whatever analogy you want to give, but we have the same Jersey. Like remember that we're not enemies. We're not opposing forces. We're literally protecting the site. We want the same protection for these assets. We may do it a different way or come at it from a different perspective.
Aaron Crow (32:39.710): But we all have the same goal of protecting these assets and making sure that it's available and safe and reliable and capable and all of those things that aligns with the business organization, right? And it's just a matter of making sure those teams talk and they network and they have relationships. And I know, hey, I need to do this and this is a concern I have. And I reach out to Pascal and say, hey,
Aaron Crow (33:2.014): this thing came up and we're doing these things in IT. Is that something we need to worry about in the OT space? And he gets like, yeah, it's not really a problem here for this, this, and this reason. like, okay, we'll note that, right?
Aaron Crow (33:16.136): You're on mute, Brett.
Pascal Ackerman (1898 & Co.) (33:16.767): You're muted. That's kind of nice that he's muted. I don't get that very often. It's nice and quiet.
Brett Seals (33:19.392): Yeah, that's unusual, right? man. No, finding the ways to be able to connect and not just, you know, find common ground between those integration points between IT and OT, but also be able to do support functions, right? To be able to use automation capabilities and data analytics to be able to gain observations about
Brett Seals (33:45.296): how to improve the production process, the safety. Like there's a lot of money that is left on the ground that could be weaponized from some of the data that comes off of security tools in these environments too. Because that's again, where it all started off from, monitoring process states. But drawing those two together and it's, glad I got here when I did. I also feel like I lucked out.
Brett Seals (34:13.456): because I'm on the tipping point that kind of people were at with OSHA in the seventies that I've heard from a lot of my family members about how everybody was real frustrated about having to pay to implement all these controls. But once they got in place and they actually had more uptime from less loss of life and injury, right? So like we're on the other side of that one now. People appreciate the risks enough to know it's not fairy tales.
Brett Seals (34:41.200): But we still have some work to do on what I heard here is how we started the call, workforce development, that culture aspect, Hearts and minds, yeah.
Aaron Crow (34:47.912): Yep. Yep.
Aaron Crow (34:51.444): Well, I mean, when I started this at Vistra, you know, doing this, was really because of NercSIP is why the company had allocated budgets towards this, but I didn't have budget. So when I was rolling out, going to these, we were literally doing control system upgrades at all these plants and they were having to implement NercSIP. So they were medium sites. We were segmenting units. So they were, you know, they wouldn't hit that 1500 minute and 15.
Aaron Crow (35:18.548): 1500 megawatt and 15 minute timeline. So they'd be a low impact, which had different requirements than medium. All that to say, when I went to these sites, I wasn't saying, hey, I want to do cyber security stuff. I was going in saying, hey, I can get you better availability, better visibility and understanding of your assets. Is that something that would be valuable to you? Yeah, absolutely. Awesome. Now on the back end, I was getting all the cyber stuff that I wanted, but they don't care, especially 12 years ago.
Aaron Crow (35:47.358): They didn't care about it. Nobody cared about it. the answer anytime anybody came in with about cyber security, the plant manager would say the same thing. Unplug it from the network. I don't care about cyber security.
Pascal Ackerman (1898 & Co.) (35:57.370): You
Gabriel Sanchez (35:58.630): Yeah, but you've, you know, like to your example, you've tied that into metrics that they now care about. So I think that was super important because they've been living with metrics for a long time. How long have the lights been on? How long have we been, you know, doing our production? The assembly, you know, lines not, is not broken, right? And so tying that into metrics without necessarily just, you know, rushing at them with the cybersecurity pieces is a really, it's a really good approach.
Aaron Crow (36:2.900): Correct. Correct.
Pascal Ackerman (1898 & Co.) (36:25.367): And it's knowing it's knowing your audience too, because I'm pretty sure the people you told that story to or you told those advantages to of the solution we're implementing were probably engineers, maybe management of a plant. So those are typically they love that asset management, maybe some sessions seeing in there what kind of traffic, what anomalies, what's this new system. But the higher up you go, the more they're distant, the more they go to like an Excel sheet type. Okay, if I install this,
Pascal Ackerman (1898 & Co.) (36:53.082): Yeah, it's going to cost me a little bit extra, but in the long run, I'm preventing a cyber breach, which if you look like a competitor is going to save you a million dollars for every occurrence or 10 million, whatever it is nowadays. So it's really about finding the audience.
Gabriel Sanchez (37:4.346): Yeah. Or one of my favorites is about the visibility of just vendors that are even authorized to be on their network, but it's only at certain times. Now they're getting visibility into, wait a minute, why did they log in at this time? We're over the weekend, right? So it's not always the big bad hacker. Sometimes it's just a matter of just what's going on. Who's coming in and out of my house. Now I see that and I know it. Better lock things down.
Brett Seals (37:31.228): Turns out the integrator that you hired had a layer VPN, a layer 2 VPN connection into your process environment and it's auto start on his computer.
Gabriel Sanchez (37:40.223): Oops. Yeah. Oops. Yeah. Could be accidental for sure. Yeah.
Brett Seals (37:43.099): Oops.
Aaron Crow (37:44.480): I literally did an assessment at a power plant in October in West Texas and there were 3G modems sitting on the outside of the pack. And I asked the engineer what that was for and he said, the vibration monitor vendor has remote access through that system. So it completely bypassed everything and it went straight in. Now the vibration monitoring system didn't have control, so they say. I said, but what happens if it trips because it detects vibration?
Brett Seals (37:47.616): huh.
Gabriel Sanchez (37:55.249): wow.
Gabriel Sanchez (38:5.094): Wow. Yeah.
Aaron Crow (38:15.014): I don't know. I'm like, I'm pretty sure it's probably gonna have a trip, you think? If that turbine is out of alignment, you don't think they're gonna trip the unit? Yeah, I'm like, maybe we should look at that.
Gabriel Sanchez (38:21.365): Absolutely.
Brett Seals (38:25.820): Would you call it BCSI? Is there any kind of stuff about the Bulk Electric system in there?
Gabriel Sanchez (38:26.064): Absolutely.
Pascal Ackerman (1898 & Co.) (38:31.762): Even if it's just a jump point, right? Even if it's not properly secured and it's just a jump point directly from the internet to your internal network with the rest of your control system, eventually, if it's not doing control right now, but you're wide exposed, wide open to the internet, eventually that's going to be a control point because somebody's going to find that hole and it's going to get on your network and either deliberately or by accident knock something over.
Brett Seals (38:56.162): Yeah. The old story of how the casino got hacked from a fish tank thermometer. Yeah. You know, I mean, it's out there in the streets kids be careful. Yeah.
Pascal Ackerman (1898 & Co.) (39:2.138): Ha ha ha.
Aaron Crow (39:4.724): Well, it's the same thing, same thing with Target, right? When Target got attacked, it wasn't, they didn't come in the front door. They went in through a subcontractor and came in the back door, right? That's the way these things happen. They're going to, a hacker is going to go the path of least resistance. And the other thing that I always hear is, well, we're too small. Why would anybody want to attack us? Like, I think we know now they look at show Dan, they, they, they find if they can see you, they're going to, yeah, it's there. I saw you like we all, we all saw. Yeah.
Gabriel Sanchez (39:7.472): Yes, yes.
Gabriel Sanchez (39:11.292): Correct. Absolutely.
Gabriel Sanchez (39:26.126): Opportunity. Yeah, the opportunity. Or training ground. Or training ground, right?
Pascal Ackerman (1898 & Co.) (39:28.653): Opportunity, yeah.
Aaron Crow (39:33.140): We all saw war games back in the day where he was just dialing trying to get a video game and ended up in the wrong computer, which obviously that was a video or as a movie. But still, it's the same thing. Like they're just playing around. I remember when when again, this is dating my technology, but I remember when I first got the very first cable modem at high speed Internet and cable modem at that time was shared network. So when they plug in, you're on a shared network with all of your other neighbors and it's on a, you know, slash 24 network.
Brett Seals (39:33.157): Yeah
Brett Seals (39:56.314): Yep.
Pascal Ackerman (1898 & Co.) (39:56.558): Ha ha ha ha.
Aaron Crow (40:2.708): So I just started pinging around and finding other computers and then I found a printer shirt. So then I printed something to one of my neighbors, like I see you or something annoying like that. Exactly.
Brett Seals (40:10.140): Did you try and connect to him on Microsoft net meetings too? There's a deep cut from that era. I remember that stuff, dude. Yeah, that was bad. It was bad availability.
Gabriel Sanchez (40:12.112): Ha ha ha ha!
Pascal Ackerman (1898 & Co.) (40:15.268): Security nobody knew.
Aaron Crow (40:19.491): But that's the way it was, right? yeah, it's because I could. I wasn't malicious. I didn't break anything. I wasn't trying to steal anything. I was just being stupid because it was fun.
Brett Seals (40:30.204): One of the things that's the coolest about working where we do is that I have the ability to like, I was going to go talk to a client about trains. So I went and talked to a guy that has worked on trains and nothing but trains as an engineer for the last 30 years. Right. And when I was asking him about these automated braking systems and how they're set up, and I was kind of describing the type of attack profile that I was like workshopping with him and he didn't realize I was weaponizing him. Right. But when I was like, so could that work? And he was like,
Brett Seals (40:59.356): Well, yeah, but why, why would you do that? And I was like, yeah, exactly. That's why I was like, yeah, it is that easy sometimes. Yeah. You know, because they just want it to work. It's, it's form over function. And that's why security always falls off by design unless it is such a requirement that it makes it, just, appreciated instantly by the people who are building it. And it stays through the development of the thing.
Pascal Ackerman (1898 & Co.) (41:3.929): Because we can.
Brett Seals (41:26.812): It has to be there from the beginning and stay in there, otherwise you'll be bolting it on forever.
Aaron Crow (41:31.304): So.
Gabriel Sanchez (41:32.323): Some interesting use cases that I see, just real quick Aaron, interesting use cases that I see sometimes is where IT getting impact, ransomware, doesn't matter what it is, right? And where they'll just all of sudden go into just let's shut down all of OT or completely close it off. Yeah, air gap, let's do something, because we don't know if OT's impacts are not, or we don't know what the root cause is, or we don't know how far the hackers got in. And so I'm hoping that's a trend.
Aaron Crow (41:34.899): Yeah.
Aaron Crow (41:48.221): Air Gap it.
Gabriel Sanchez (42:0.252): you know, that we start seeing that we get away from where you don't even have the visibility to know whether your OT has been impacted or not or how far that threat actor got from your business network into your OT, right? And we see, you know, countless examples. A lot of it hit the news where, well, OT has not been impacted and OT has not been breached, but we're doing it just to be on the safe side because we know IT did. And it's like, well, you kind of have the same outcome, right? You know.
Pascal Ackerman (1898 & Co.) (42:25.274): Yeah, still OD is impacted. You got to stop your production, OD is impacted.
Gabriel Sanchez (42:27.142): Right, well, technically it was impacted because, you have no signs of breach, but you still ended up causing the same effect, right? And so that's hopefully a trend that I'd like to see us get away from as well, but an interesting use case.
Aaron Crow (42:38.784): So we talked about the people problem, not the problem, but one of the bigger value adds is that workforce development and training and camaraderie and coming together as a team. From a technology perspective, what do you guys see as one of the bigger hurdles that we're still facing? I know some of the ones that we've already talked about in the past, but what are some of the ones that are coming up in the next?
Aaron Crow (43:6.545): bit that could be an issue to implement and do it in the right way without impacting OT.
Pascal Ackerman (1898 & Co.) (43:14.490): I actually see something that's got both of those tied in to it, and that's cloud and AI. because we see a big shortage in the workspace, right? And it's on the OT side, the cybersecurity side, but it's also on the OT controls engineering side, right? It's really hard to get dedicated people for your controls environment. So I can foresee within the next five to 10 years, most of those control systems going to the cloud. And I'm not saying that's good or bad at this point, but...
Pascal Ackerman (1898 & Co.) (43:44.078): I can see them moving to the cloud where you have like your PLC and your HMI and your whole process environment in the cloud. And you'll have your remote IO sitting in your process space, of course, because you can't get around that. But just so that organized companies like big companies, like the big engineering companies can support that remotely without having to have dedicated remote access into your plans. So that's the one reason I see that coming.
Pascal Ackerman (1898 & Co.) (44:11.767): I'm not looking forward to that because now you're putting a lot of eggs in at one cloud basket. If anything goes wrong, it can have devastating impact on your environment.
Gabriel Sanchez (44:14.086): Hahaha.
Gabriel Sanchez (44:21.596): But yeah, but I do see a big, agree with you, Pascal, but I also see with a lot of the tool sets, whether we're doing it on cloud, whether we're doing on-prem, I see a big hurdle when it comes to certain technology or tool from the whole passive versus active. I, a lot of critical infrastructure still want to do just to be on the safe side, everything passive, everything passive, everything passive. And I think...
Gabriel Sanchez (44:47.026): And I'm hoping, and we're starting to see the trend move away from that where there's been more confidence built up into, okay, maybe a tad bit more risk to do something active or to ping in this way or scan in this way, but doing it in a responsible way. We're getting a lot more out of knowing exactly what did this PLC actually do as opposed to let's just rely on everything as far as network monitoring or whatever comes up for the wire. It's now kind of a little bit more of an intentional kind of let's do.
Gabriel Sanchez (45:15.154): a bit deeper than just a passive type scan and do something that's more. And so I see that as a hurdle that OT still kind of struggles with.
Aaron Crow (45:29.108): Yeah, it's funny, I'm working with one of your teammates, you know who I'm talking about, at that power utility. This was back in 2012, I think it was. It was before any of these passive tools existed. So we took commercially off the shelf IT stuff, know, Mac, and we were scanning OT environments in critical power generation sites using IT off the shelf stuff. And we did it without incident. But it's not like we were
Brett Seals (45:29.274): Yeah
Gabriel Sanchez (45:43.377): Yes.
Gabriel Sanchez (45:47.504): Mm-hmm.
Gabriel Sanchez (45:56.754): It could be dumb, Right, right.
Aaron Crow (45:57.830): in-map scanning randomly and just going after the stuff. We were doing it intentionally and we were very cautious in how we did it, but we rolled out active capabilities again, back in 2012. Luckily it was probably because nobody had had all the war stories and heard that you can't do active and now everybody believes that you can't do active and there was no passive option that didn't exist.
Pascal Ackerman (1898 & Co.) (45:59.674): .
Gabriel Sanchez (46:5.820): Right?
Gabriel Sanchez (46:16.530): Correct, correct, right.
Brett Seals (46:19.334): Yeah.
Aaron Crow (46:22.504): So we had to bring in, again, we did, you know, Mac and Splunk and WhatsApp Gold and IT tools in a power plant running VMware. Yeah.
Gabriel Sanchez (46:22.674): Correct.
Gabriel Sanchez (46:26.418): Yeah
Gabriel Sanchez (46:33.488): Yes, could be done, absolutely.
Brett Seals (46:35.804): Yeah. No, you know, when I, when I came here and met, our, our mutual friend and the team that, he was hired onto, was the first time in a long time that I had seen magic on a computer screen, right. With, with Terraform, being able to use open tofu, I think is what they're going to call it now to automatically instantiate environments, writing code based off of describing a thing instead of making it do a thing. Right.
Aaron Crow (46:50.056): Right. Yep.
Brett Seals (47:5.820): and knowing how that could be weaponized with adversary attack platform, C2 infrastructure, malleable profiles for callbacks that can be handed over seamlessly between something that didn't exist before the attack and won't exist after. Right. That same technology though, can be weaponized to create highly available environments that are cross cloud domain and are shared distributed workloads between data centers and cloud resources as well.
Aaron Crow (47:14.398): Yeah. Yeah.
Brett Seals (47:34.342): So there's flips of that. can build those protection domains from Comp Sci 101, right, inside of how we integrate these new technologies, but it is something that is going to require a scalpel.
Aaron Crow (47:48.542): Correct.
Pascal Ackerman (1898 & Co.) (47:50.169): Yeah.
Gabriel Sanchez (47:50.514): 100%.
Aaron Crow (47:51.644): And it's like, you know, just like the human body, all of our, all of us are a little bit different, right? We're different sizes and we have different whatever, like I can go to a power company, Duke energy, Vistra, next era, you name it. And I can go to two of their plants that are right next door to each other. And they will not be the same. They'll have different controls. I have different integrations. They'll have different HMIs. They'll have different processes. All of those things are going to be different. Even, even beyond that.
Brett Seals (47:57.820): Cheers.
Gabriel Sanchez (48:12.856): Right. Yep.
Aaron Crow (48:20.668): I can go to two units in the same plant and those two units will be different. And that's, that blows people's mind. Obviously it doesn't ask cause we see it all the time, but it's to that level of, of, of difference. And it's because they're on different upgrade schedules and you know, upgrade unit one this year and unit two next year and unit three and six years. Cause the budget got pushed out or whatever that reason is. a prime example of that is we bought, we bought a power plant, again, years ago and it was, there were three plants that this, this,
Aaron Crow (48:50.118): And it may have been Burns & Mack that built it. I don't remember. whatever company, engineering company that designed it, Floor, whomever it was, when they designed it, they built three plants and they took that one plant design and they built three different locations. So exact same schematics. The hardware was the same. The turbines were the same. The bowlers were the same. Like everything about it was the same. Two of them were owned by a power company and one was bought by a financial company. The whole reason and point of my story is
Aaron Crow (49:18.736): After 20 years, the power company did control system upgrades and all the different things. And the financial company, that was their only power plant. They didn't do anything to it. It was exactly the same as the day that it was built. It still ran. It still was reliable. It still produced generation and electricity. But when you walked in, it was sun micro stations and all of the things that were implemented 20 years ago and never upgraded. And it just shows the difference in the two different sites because of
Aaron Crow (49:47.314): When it started out, they were all in the same level playing field, but every outage over 20 years, they just grew apart from where they started to where they are today.
Brett Seals (49:56.908): That's a wild evolution literally driven by environmental variables. Right? It's almost like twin study cases of the rich twin, the poor twin, you know, like how that went down. That's fascinating.
Gabriel Sanchez (50:13.478): Makes it interesting because every decision you make along from year to year can actually just completely changes the makeup of how you either might protect it or what it looks like and everything else to it, right? it kind of like, you know, the example we were talking about earlier, if you had to go to Best Buy just to make it work and that was your best option, that solution actually will probably survive for years and years because it's now just working. And like you said, you better not look at it, you don't touch it. Everything's good now.
Gabriel Sanchez (50:41.776): You might have a deal link there that lasts eight years because of just that moment in time where that decision had to be made. So that's really interesting.
Aaron Crow (50:49.456): And again, if you look at it, and this is where we've got to as an industry, stop looking at, well, you have a D-Link there or it's not a managed switch or it's a out of support switch or it's a Windows XP machine or whatever that is. And we really need to get back to, it providing it? Is it doing its job? Is it reliable? why would I replace it? My dad worked in the power utility industry for 40 years.
Gabriel Sanchez (51:9.648): Right.
Aaron Crow (51:18.608): And they used to have a saying that he still says today, he's 75, 76 years old. If it ain't broke, don't fix it. They don't just replace things because there's a new version. Like you don't, you know, it's, like today's generation, you know, you need new tires on your car. So you go buy a new car. No, replace the damn tires. Like you don't need a new car. Your car works. It's reliable. It gets you from point A to point B.
Pascal Ackerman (1898 & Co.) (51:26.430): I know that thing.
Gabriel Sanchez (51:26.514): Yeah.
Gabriel Sanchez (51:38.150): Hahaha!
Aaron Crow (51:45.608): You know, you can upgrade the radio. You don't have to buy a new car. I'm not telling you not to. I'm not telling you shouldn't. Just saying you don't have to.
Pascal Ackerman (1898 & Co.) (51:54.392): Yeah, it's a different mentality, for sure.
Aaron Crow (51:56.901): It is right, but IT is I'm going to replace it every two years. I'm going to give you a new laptop like my my monitor. Right? Yeah.
Pascal Ackerman (1898 & Co.) (52:2.806): I'm leasing it, right? We're leasing our equipment. I wish we could do that on the OD. every two years Rockwell is going to give me new PLCs and they're going to take their old stuff back. But yeah, if you could do that, it's probably not very feasible because between those revisions, you have to redo your whole PLC program, your I.O. modules, your communications, the downtime behind it. So wishful thinking.
Brett Seals (52:8.284): Yeah.
Aaron Crow (52:25.842): Well, and you do a control system upgrade at a power plant and it could be, let's use Emerson or Foxboro or whatever vendor you want to talk to. When you do that upgrade in three years, you may have to change your field IO terminations. Like it's not just replacing a computer, right? Sometimes you're having to rewire things, physical things, and that takes time. And if it doesn't work and maybe a wire's wrong, then you got to rerun a wire. Like it's bigger than just, I'm going to give you new laptop.
Brett Seals (52:25.978): You know...
Aaron Crow (52:54.611): It's not that simple.
Brett Seals (52:56.696): Aaron, I think the first time that I heard somebody tell me that they have had an active infection of Conficker in their process environment and they were just living with it like bed bugs. it was shocking and a little disappointing, but I mean, it's still kind of like surprising when it happens, but it still happens, Aaron, right? And it's okay.
Brett Seals (53:23.716): Right? It sounds counterintuitive, but if it doesn't affect the stability of the system and it can't go down because it's so available, then I guess it's okay.
Pascal Ackerman (1898 & Co.) (53:23.908): I've been.
Pascal Ackerman (1898 & Co.) (53:33.700): I've been in situations where they let WannaCry run and you know what I'm talking about, which one I'm talking about, Aaron, but they had WannaCry all over the place. We installed a cybersecurity monitoring, OT cybersecurity monitoring solution and it started popping up like 10, 20, 30, 40 stations with WannaCry. And they're like, well, we're still running production and once we get to it, we'll get to it. But until then, we're just gonna let this run. I'm like, yeah, I'm not gonna connect any of my personal stuff on your network for a while.
Aaron Crow (54:0.948): You
Aaron Crow (54:4.486): Again, that's the different mentality and that right there is so hard for people to grasp that haven't worked in this industry. And you're going to let, if it's not broke, don't fix it. Like it really comes down to that thing is, and that doesn't mean you just let want to cry, run forever. I've actually seen environments where Stuxnet is running. but you know, there was no applicable system that Stuxnet could impact. Right. So yeah.
Pascal Ackerman (1898 & Co.) (54:23.834): Well, see you later. Drink.
Brett Seals (54:27.440): It was the most prolific for the time, right? mean, and to again, go back to the beginning of the call, because this is all coming full circle. know, the Navy, learned at a C &P conference when I was a junior sailor, like all public information on this, right? It's just me being an analyst being like, that's weird. I know what those words mean. I found out that the payments system for the United States Navy, the thing that cut my check.
Brett Seals (54:53.716): It was based off of the same language that amazing grace hopper wrote. that's right. The lady who coined the term computer buck, cobalt. So whenever it would break, they had to bring somebody out of retirement because they haven't taught cobalt that I'm aware of in colleges probably since the late nineties. I know some guys that were in some of those last classes around here in these parts. so yeah, no, it's just, if it ain't broke, don't fix it though. But when it breaks,
Aaron Crow (55:14.270): Mm-hmm.
Aaron Crow (55:17.029): Mm-hmm.
Brett Seals (55:23.216): Boy, boy, does it break. And yeah, no, and making sure that we're doing what we can in our part to be able to defend the global mission and protect critical infrastructure for humanity. I think three days of a widespread utility outage would cause some pretty severe chaos that maybe genies that don't go back in bottles and doing everything that I can, getting out of the military.
Aaron Crow (55:27.132): Absolutely.
Brett Seals (55:51.566): was very strategic coming here to be able to have a greater impact on how I could help out with that. And I found nothing but brothers and sisters with the same intent since I've gotten out. I've found more of a tribe, leaving a tribe that people typically have a hard time translating from, but I'm happy. I'm happy to be here with these two guys. We take good care of each other and I'm, I'm thankful to be able to hang out with you today, man. This was fun.
Aaron Crow (56:19.912): Yeah, I mean, that goes to, you know, always ask that wrap up question. We already kind of answered it with the technology stack and what you just answered there is probably the negative side or the scary side. But I mean, we can look back to Katrina and New Orleans and see what happens when you lose power to an area for any period of time. And it was within a day and it was martial law. It was scary.
Brett Seals (56:42.192): Yep. Doesn't take much.
Aaron Crow (56:43.408): everything stops working, right? And same thing in North Carolina when they took the substation out and that entire county was without a power for a week and you can't pump gas, the refrigeration doesn't work, your water doesn't work. Like everything is dependent upon electricity, everything, right? And that goes down and we are a third world country like that. Very quick.
Brett Seals (57:6.694): People, people forget now. Now my, my kids are worried about the internet when it goes out, right? It was the electricity for me when I was a kid. Yeah. As long as the wifi, as long as that's battery backup works, then we're good. Right. But, you know, and then everybody forgets about, they're typically having some of the bigger challenges water. Right. Like that, that really, you forget how much of a caveman you really are until somebody shuts off the water to your house.
Pascal Ackerman (1898 & Co.) (57:14.274): What happened to the wifi?
Aaron Crow (57:35.956): Correct.
Brett Seals (57:36.154): Right? You get a clogged sink, you have to, main that pops, and then all of a sudden you're thinking about the holiday in. Right.
Aaron Crow (57:43.667): Mm-hmm.
Pascal Ackerman (1898 & Co.) (57:46.066): I got enough snow on the ground to have water for a while.
Aaron Crow (57:51.456): I've got the air conditioner on in Texas. It's like 70 degrees today. It's, it's, it's nice and hot. I'm actually taking a side note. I'm taking my family. So again, I live in Texas. My kids have grown up in Texas. So we're going after Christmas. We're taking a vacation. A friend of mine lives, has a house in Minnesota. So I'm taking the kids to Minnesota so they can experience like what actual weather and winter, what it actually feels like no ice fishing and do all those fun, you know, real cold weather type stuff.
Pascal Ackerman (1898 & Co.) (57:55.246): my god.
Brett Seals (57:58.172): There you go.
Brett Seals (58:10.603): nice.
Gabriel Sanchez (58:14.758): The real cold. man.
Pascal Ackerman (1898 & Co.) (58:21.924): That's a good idea, because you won't get that.
Aaron Crow (58:23.218): Yeah. So no, not here. So what, what's called the action guys, like how, how do people find out more about you guys, what you guys do, where you're going to be conferences, speaking events, like all that type of stuff, like late on us.
Pascal Ackerman (1898 & Co.) (58:36.172): I'm very active on LinkedIn. anybody who pings me there and a lot of people do for like advice on where to go next with their studies, where to look for jobs and stuff like that. I'm very active. I always share stuff on there. You can ping me up on there. You can go to our 1898 and co website and contact us through there. in terms of speaking, Dave, what we got on the plan.
Gabriel Sanchez (58:59.334): Yeah. I mean, S4, we will be at S4 as well coming up in February. So, you know, feel free. And Tampa this year. So feel free to meet up with us there as well. That's the conference I know that's the one coming up as far as I think we'll be at the, you know, huge second, I think OT second and Houston area will be there as well. Yeah.
Aaron Crow (59:4.052): Yep. In Tampa this year. Yep.
Aaron Crow (59:22.376): Yep. Awesome.
Brett Seals (59:23.258): Yeah, Gabe gave been Pascal. Don't let me out of this bunker very often.
Gabriel Sanchez (59:26.949): Hahaha
Pascal Ackerman (1898 & Co.) (59:27.630): No, actually we do. We're taking you to Belgium, remember? We're going to do the ISA conference. So the European ISA conference.
Brett Seals (59:34.214): That's right. I met my targets this year. I get to leave.
Gabriel Sanchez (59:36.850): So ISA conference, I think that's in June. Yeah, sometime in June will be ISA conference.
Aaron Crow (59:37.172): Hahaha
Brett Seals (59:43.196): Yeah.
Aaron Crow (59:43.200): That's the funny thing is these problems are not just, you know, America focused. are nationwide. are countrywide. They're, they're, they're border. They don't depend on borders or the bad actors don't really care where the thing is. Right. And they're just going to see, like we said earlier, like open for opportunity. So it takes a village for us to protect this nationwide. And we see what's going on in the Ukraine and, Israel and Gaza and all, and again, not to get political, but
Gabriel Sanchez (59:54.066): Very true.
Aaron Crow (60:9.490): just from an impact and availability and all of the downstream things that can happen from power not being available, water not being available. We depend on electricity and clean water to live the way that we do and the way that we've got accustomed to. And to your point, like my power goes out and I've got everything on battery backup and my wife's in there still surfing a phone and there's no electricity. I'm like, don't you wonder how this still works when we have no electricity? And she's like, you know, I never really thought about it.
Gabriel Sanchez (60:35.578): No!
Pascal Ackerman (1898 & Co.) (60:35.770): You
Pascal Ackerman (1898 & Co.) (60:40.396): You're welcome.
Aaron Crow (60:41.691): Exactly.
Brett Seals (60:43.340): For sure.
Aaron Crow (60:45.288): That's awesome. Well, gentlemen, I really appreciate y'all taking the time today. As always, it was a great conversation. I look forward to seeing you guys in person at S four and other times as well. thank you again so much for, for being here and fighting the good fight. really appreciate it.
Pascal Ackerman (1898 & Co.) (61:1.368): Our pleasure. Thank you.
Gabriel Sanchez (61:1.372): Thank you, Aaron. Thanks for having us.
Brett Seals (61:2.300): Yeah, I appreciate it. Thanks, Aaron.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.