In this episode, host Aaron Crow converses with Lesley Carhart, Technical Director at Dragos, who brings over 15 years of experience in incident response and forensics within critical infrastructure sectors.
The episode dives deep into the standard practices in industrial settings, such as operators shutting down power plants for safety and the lack of forensic investigation into equipment failures. Lesley emphasizes the importance of integrating cybersecurity into these environments, pointing out that many failures are due to maintenance or human error, though a notable portion does involve cyber threats.
Listeners will learn about the challenges and necessary collaborations between operational technology (OT) and information technology (IT) teams. The discussion addresses cultural and trust barriers that hinder effective cybersecurity measures and advises on how organizations can improve their defenses regardless of size and resources.
Lesley also highlights the evolving landscape of cyber threats, including the increasing sophistication of adversaries and the vulnerabilities caused by standardizations in industrial systems. Real-world examples underscore the complexity of securing these environments, emphasizing the need for proactive and informed cybersecurity practices, such as "cyber-informed engineering."
Tune in to better understand the critical intersections of cybersecurity and industrial operations, and learn practical strategies to safeguard essential services.
Key Moments:
05:00 IT-OT miscommunication leads to cybersecurity risks.
09:23 IT processes are too slow; bypassing is required for solutions.
11:36 Leaving an outdated system may pose less risk.
15:09 Slow changes in OT due to unforeseen impacts.
19:17 Include cybersecurity in root cause analysis discussions.
20:31 Nation-states analyze and bypass industrial control systems.
25:40 Cybersecurity is essential to combat potential system threats.
29:27 Communication, champions, and leadership crucial for cybersecurity.
31:37 Cybersecurity struggle due to resources community helps.
35:03 OT vs. IT language differences affect incident classification.
38:08 Empowered safety culture prevents accidents and retribution.
40:22 Few people have diverse cybersecurity skills and experience.
45:05 Experience across all 17 critical infrastructure verticals.
48:29 Evading detection in the nuclear enrichment process.
51:25 Identify industrial devices, build security program.
About the guest :
Lesley Carhart is a renowned cybersecurity expert specializing in industrial control systems (ICS) security. With a keen understanding of the convergence between traditional IT and operational technology (OT), Lesley has been at the forefront of safeguarding critical infrastructures. Her work emphasizes the vulnerabilities of human-machine interfaces (HMIs) and programming devices, which are increasingly resembling typical computers and thus becoming prime targets for malware and ransomware attacks. Lesley's insights highlight the significant risks posed by these hybrid systems, underscoring the importance of robust cybersecurity measures in protecting essential processes. Lesley is honored to be retired from the United States Air Force Reserves, and to have received recognition such as “DEF CON Hacker of the Year”, “SANS Difference Maker”, and “Power Player” from SC Magazine.
How to connect Lesley:
Instagram : https://www.instagram.com/hacks4pancakes/
Blog: https://tisiphone.ne
Mastodon : https://infosec.exchange/@hacks4pancakes
Linkedin : https://www.linkedin.com/in/lcarhart/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:1.828): Hey everybody. Welcome to a protected all podcast. I'm very excited about today's episode. I've had the privilege of meeting Leslie in person and having some awesome conversations at beer Isaac and, and other conferences where she spoke or, or a DEF CON, all these kinds of things. So Leslie, why don't you introduce yourself, tell us who you are. and kind of what brings you here and how you got into this crazy thing called critical infrastructure and OT and cyber security.
Lesley Carhart (0:24.770): Hey, all. It's nice to meet you. If I haven't met you before, my name is Leslie Carhart. I am a technical director at a company called Dragos that does industrial cybersecurity. And personally, I've been doing incident response and forensics in the industrial and industrial tangential sector for over 15 years. That's what I do. I investigate power plants, trains, manufacturing facilities that get hacked and how it happened and how to prevent it in the future.
Aaron Crow (0:52.334): And it's a lot of fun stuff, right? So, you know, lot of my history and my career has been, you know, the hard hats behind me have been in critical infrastructure and power plants. So, you know, I was an asset owner. I supported 40 something plus power plants and nuclear power plants and fossil fuel ones and solar and wind and all of that. So the problems and I've also worked for consulting firms and seen stuff, you know, across manufacturing and wastewater and, you know, other industries as well. But
Aaron Crow (1:20.580): You know, those critical infrastructures are so, they're so important to our country, to, you know, just our normal way of life that we turn on lights and we expect it to work. But so many times the systems are old and we don't have enough people and resources and money and time and experience where we need to lean on people like you and Dragos that have the experience of, yeah, I know how to run a power plant, but
Aaron Crow (1:47.182): I don't know what to look for for bad people coming in and doing things like talk about a little bit about that and some of the things that you guys experience or see and it doesn't matter if it's a big company or a small company, a wastewater. It's really the same across all of those types of things in this critical infrastructure.
Lesley Carhart (2:4.238): So I want people to take a few things away from this. First of all, I do this as a full-time job. I know that when you look at the news, you only see the really big cases that get reported. They get regulatory reporting, or they somehow make it to the news, and you see them happening in industrial. Industrial systems are getting attacked all the time. I do this, and my team does this as a full-time job.
Lesley Carhart (2:25.838): I divide our caseload into three general categories. The first one is commodity stuff. Now, if you're looking at the industrial systems, if you aren't familiar with them, if you don't work in that space, they're kind of a layer cake. call it the Purdue model. university made a model. It's a model. It's not a framework. It's just a general description of kind of how these things are laid out. The top level, the computers look like computers for the most part. There's been a lot of convergence between technology
Lesley Carhart (2:55.754): You see Cisco stuff, see Windows stuff, doing important control stuff. Not the actual controllers, but the machines that show people the status, the HMIs of what's going on in the process, the things that are used to program the lower level devices. All those are starting to look like typical computers and they're vulnerable to malware. They're vulnerable to ransomware. And it's a big deal to lose those. It's not necessarily going to make something catch on fire or explode, but it means you can't see what's going on in your systems anymore.
Lesley Carhart (3:25.600): you might have to shut them down because it's not safe to run things that can kill somebody when you can't see if they're running safely. So there's the commodity stuff that's going on. Ransomware is hitting those environments more and more because, like Erin said, older stuff for a reason because they have long life cycles and they require rigorous testing to put into production with life and safety implications. And they tend to be less secure from a security design and security tooling
Lesley Carhart (3:55.456): perspective as well. You don't see much EDR for reasons, again, rigorous testing, long life cycles, not modern antivirus, not modern firewalls in a lot of cases. So they're very vulnerable and they're doing important stuff. So those getting ransom, getting hit by other commodity malware, worms, happens all the time and it's a really big deal. Now at the lower levels of that Purdue model, you've got industrial controllers, PLCs, RTUs, things like that that aren't running familiar operating systems or protocols.
Lesley Carhart (4:26.093): And those aren't necessarily getting hit in those attacks. Most of the malware doesn't need to touch that stuff. They don't need to go to the effort, expend the resources yet in a lot of these cases. But again, losing those higher level Windows systems, big deal, really big deal showstopper for lot of industrial environments. And the second category that we see is insider stuff.
Aaron Crow (4:50.191): Mm-hmm.
Lesley Carhart (4:50.476): There's a bad relationship overall in a lot of environments between the IT people and the OT people because of years of miscommunications and poor cybersecurity practices because we have to adapt to.
Lesley Carhart (5:3.374): critical life and safety process environments and we haven't been doing that. So there's a ton of shadow IT and evading security controls going on in these environments. A lot of times they haven't been touched by security in a long time. So people will do things like connect modems, connect dual home systems, connect things to Wi-Fi, add in remote access because they want to access things from home or they needed to during the pandemic. And there's not a lot of awareness in a lot of cybersecurity teams of all of these potential vectors.
Lesley Carhart (5:33.330): for things to get into the environment or be tampered with. So that's a big deal too. Most of those are unintentional insiders, but we respond to horrible intentional insider cases too, where somebody did something physically to somebody, hurt something, hurt somebody, and we have to investigate who did it and what they did.
Lesley Carhart (5:53.708): And the final category, state adversaries or state sponsored, state style adversaries. And what we're talking about there is mostly sabotage preparation and espionage. So in terms of espionage and manufacturing, it's a lot of stealing corporate secrets, manufacturing secrets, things like that.
Lesley Carhart (6:11.360): In terms of sabotage, it's mostly pre-positioning for future sabotage. It's stealing enough data about these complicated, safety-controlled industrial environments over years that if there is a geopolitical cause in the future...
Lesley Carhart (6:25.944): there is the potential to do something malicious. Industrial environments are complicated. Again, that layer cake, there's a lot of stuff going on. And adversaries need to build these databases and access into these environments if they want to do something quickly in the future. And they are absolutely doing that.
Aaron Crow (6:43.640): Yeah. Yeah. And I see that so often is, is you hit on the insider, right? And that's one that really hits to me. These engineers are doing what they think is right and what they have to do to support their environment. So whether that's secure mode access or, know, they, they got a, a net gear switch because it was three o'clock in the morning on a Saturday and their network switch failed and they can't get ahold of IT because they're not supported during the weekend. So they go and they make it happen. and they're not intentionally
Aaron Crow (7:11.982): doing malicious activities, but they also don't know, I just bypass the firewall and put my OT environment directly on the internet. They didn't mean to, but they did. And that brings in all these other cascading dominoing effect of issues that now some attackers, it shows up on Chamoon and now I've got people impacting and I'm behind the curtain now, unbeknownst to me until somebody finds it or there's a negative impact or there's an assessment or somebody says,
Lesley Carhart (7:11.992): Mm-hmm.
Lesley Carhart (7:21.091): Yeah.
Aaron Crow (7:40.686): Why is that plugged in over there? That wasn't like, that's new. That changed.
Lesley Carhart (7:45.486): Shadow IT doesn't come out of nowhere. Shadow IT, especially in industrial, is a byproduct usually of poor cybersecurity. Bottom line, end of story, if you have industrial stuff in your organization, and you probably do, even if it's just building automation and control stuff, like your heating, cooling, data center backups for your power, things like that, if you've got industrial stuff, you've probably been doing cybersecurity. They're wrong for a long time. Everybody has been. People are just over the last five or so years starting to rectify that.
Lesley Carhart (8:15.614): And people did shadow IT because cybersecurity told them to do things they could not do.
Lesley Carhart (8:21.842): They couldn't upgrade systems because their vendor would put their system out of warranty or it would kill somebody. And they needed remote access for a variety of reasons, especially during the pandemic. So shadow IT happens 90 % of the time, probably, because people don't have a good dialogue with cybersecurity. They don't have good communication. They don't trust cybersecurity. And there is something that is preventing them from doing their work in a
Lesley Carhart (8:48.392): logical way. That's where that comes from, especially from O.T. So when I'm talking about insiders, again, the vast majority of those are unintentional insiders doing something that majorly impacts cybersecurity with all these new threats, but they did it for a reason, and they probably did it because we don't have a good relationship with them.
Aaron Crow (9:5.978): Yeah. And my experience both on, um, as a vendor, as a consultant, but also as an asset owner, that that was the problem I was having as an OT, you know, owner, um, reaching across the, the, the, the desk to my it brethren. And they'll be like, well, you have to do this and you have to go through my process and it takes six weeks. And I'm just like, I don't have that time and I can't do that. And I, can't use that model of switch or that model of server. doesn't fit in my use case.
Aaron Crow (9:32.676): I'm like, well, that's the only way we can do it. I'm like, okay, so I'm going to go around you because you won't let me go through you.
Lesley Carhart (9:38.220): Yeah, once more for the people in the back again who are just on this, the beginning of this journey. Yes, we need to do cybersecurity in these environments. We have to do it differently because again, let's talk about these systems. Oftentimes they're bought for very long life cycles and they are tested to function in a certain way that layer cake of technologies. You're buying them all together from an OEM and they have been tested for years usually to work safely together. The high level systems, the window systems, the protocols, the lower level devices, they were
Lesley Carhart (10:8.164): sat in a lab for years typically with the OEM with them rigorously testing it in all different conditions to make sure it wouldn't fail when somebody would die.
Lesley Carhart (10:16.940): That's what's going on, or the process equipment wouldn't catch on fire, get damaged, et cetera. You can't just swap out a part of that. You can't. There are maintenance windows. There are upgrades available from vendors, but those come in life cycles. They are not regular. They are not routine. They are out of band from your normal patching. You have to do updates differently in those environments. You have to schedule around maintenance outages. You have to work with the OEMs and with the operators and the safety personnel. All of that is possible, but you have to do it
Lesley Carhart (10:46.894): very, very differently. And if you try to force it in an IT way, things are going to go catastrophically wrong.
Aaron Crow (10:54.138): Yeah, and you you talked about that, you know, testing out and it's beyond just in an IT world. You have an old laptop and well you call IT and they just ship you a new laptop because the image is the same and most of your stuff is stored in the cloud and it's really simple. You swap one for the other. It doesn't really matter. Is it Adele? Is it an HP? Is it an IBM? Is it a Mac? It doesn't really matter, but in these OTSpaces that's not the case and I may have Windows XP running and there's a reason it's running because it's.
Lesley Carhart (11:19.243): Mm-hmm.
Aaron Crow (11:23.042): Whatever the application or the process that's running on it is not applicable with any other operating system. So if I try to put in Windows 11, yes, the server is new and it can be patched, but it doesn't serve the function and the whole system will shut down. So is it more important? And that's where this this risk reward thing with with OT comes in is there is a risk to to a vulnerability or an attack or malware or all these types of things. But there's also a vulnerable a risk to life.
Aaron Crow (11:51.926): safety availability of my system and sometimes having patching the system or updating with the latest OS or latest hardware is more risky to my business than leaving it alone and mitigating it in other ways.
Lesley Carhart (12:6.264): Yeah, I get called in on six-year-old, 10-year-old infections in networks. They've known that they were infected with config or sality or something for 10 years. And they finally have the outage to clean it up. And it's in everything. So it's a massive cleanup effort. But we get called in for that kind of stuff. Like, how do we even approach this? How do we even clean 500 industrial computers that have been infected for 10 years or get an embedded adversary out? Somebody did risk modeling there. Oftentimes, they talk to us or they talk to another cyber
Lesley Carhart (12:36.280): security vendor about who was in their network, what the potential was. They talked to the OEM about potential impact to their systems and they made a risk decision that shutting down their systems for two weeks would cost so much it would put them out of business as opposed to leaving it infected.
Lesley Carhart (12:52.470): Now there's better things that we can do there, things like partial containment, sometimes some segmentation, isolation of systems, restriction of protocols at firewalls, things like that to slow the spread and maybe clean parts of the network. So we can make plans for that. We have to do it very strategically with the subject matter experts. Again, you can't just install EDR on everything. You can't just upgrade everything. You can't just dump.
Lesley Carhart (13:16.598): other security tools run them on these systems if they aren't vetted by the OEM and by the safety and the engineering personnel. So you have to make a really good plan there. It's doable, but you have to be cognizant of those actual consequences. Real life things, people dying, things getting damaged, products being damaged, the environment being contaminated.
Aaron Crow (13:37.016): Yeah, they're huge implications and that's one of the bigger differences and especially for folks that aren't in OT and I know we're talking to a lot of that right now is you may not understand or grasp the real difference. And the analogy I like to give sometimes is like, you're in a plane, a commercial plane, and you're flying and the aviation system needs a patch. You're in the air. Do you want them patching that aviation system when you're in the air or had you rather wait until the plane lands for them to try?
Lesley Carhart (14:6.304): Ironically, that was my first life. My first life out of high school was as an avionics technician, and that's where I learned a lot about industrial computers.
Aaron Crow (14:14.424): Yep. And it's an easy when you put it that way and people like, yeah, I don't want to update that as I'm flying in the air.
Lesley Carhart (14:21.230): How about your car? Do you like your car patching, updating while you're on the highway? Does that feel good? Do you like that when your computer system in your car, your media display shuts off and says, I'm patching?
Lesley Carhart (14:33.250): when you're using your map? No, of course not. And just that on a larger scale where you're talking about water going to houses or trains running or the complicated, incredibly complicated just-in-time logistics and manufacturing systems we use today. No, you can do it, but you've got to be cognizant of all of those risk factors.
Aaron Crow (14:51.576): Yeah. Well, and you know, we've seen even this year that weren't, necessarily cyber. They weren't cyber issues, but we saw train derailments and things from sensors on, on wheels. And there's all of these, these dominoing impacts of things that you don't necessarily, yeah, you're doing one thing because you think it's good, but you don't realize necessarily the downstream impacts of those things and all. And that's why things happen slower in OT. It's just like, you know,
Aaron Crow (15:19.276): One of the things I did when I was at the power company, when I first started there is we had a bad weather event in Texas and we had to roll out weather stations and emergency satellite communications at all of the facilities. So I rolled out working with vendors to put satellite dishes and satellite communications and these independent weather stations that are reading temperature and air pressure and all that kind of stuff at every facility.
Aaron Crow (15:46.648): I did that across 48 sites in two months because we had a deadline with the Texas legislation and we had to do it within a few months, right? So I got it done at all 40 something sites in that timeframe and the nuclear facility, I had to install it in the parking lot. And why is that? Because I had to make a penetration into the control room. And anytime there's a penetration in the control room, you have to have all of these studies. Why? Because they're tested very much around keeping radiation out. So the people inside that bubble,
Aaron Crow (16:15.994): can survive if there's a nuclear reaction or something happens and they have to be in there to control it. So it took me a year to get the one at the nuclear facility actually installed. And it wasn't surprising to me because there was six levels of documentation and engineering studies and all this different kind of stuff. But it was just a cat five cable to one one cat five cable penetration into the control room took a year, a little over a year, year and a half to get it done.
Lesley Carhart (16:42.146): Yeah, absolutely.
Aaron Crow (16:42.683): And people just, it blows people's minds when they think about that and how long it takes to do a relatively simple thing like running a cat five cable.
Lesley Carhart (16:50.006): It requires infinite patience and a lot of diplomacy to do this job.
Aaron Crow (16:53.518): That's right.
Lesley Carhart (16:54.354): I want to turn it around for a second, based on what you just said for the engineers and the operators out there. Now, the thing that I want to express on that side of things is cybersecurity is a real and growing thing. Again, I said, I do this as a full-time job. What we're struggling with still is those operators and engineers who have thought about all these maintenance errors and human errors and safety implications of those. So there's tons of safety controls in these industrial processes to keep bad things from happening.
Lesley Carhart (17:23.042): There's digital systems like safety instrumentation systems, and there's physical controls, and there's human controls. Because maintenance issues, equipment failures, human failures happen. And the implications, like we've talked about, things failing in industrial processes is really, really bad. So there's layers of safety controls to keep catastrophic things happening.
Lesley Carhart (17:44.500): And a lot of industrial operators are in the mindset that those safety controls are pretty infallible and that they aren't, you know, they don't think about cyber as a potential impact that can cause something to get past those safety controls.
Lesley Carhart (18:0.076): The cyber incidents are happening. They're going to continue to get worse because people have figured out that this is a target. The media is a wonderful sphere for amplifying things to adversaries. And adversaries who learn about an environment, they are engineers too. They are process engineers. Usually they're specialists on the systems and state-style adversaries and well-resourced criminal groups.
Lesley Carhart (18:21.880): who can sit there and figure out how to evade safety controls. And that's not in a lot of engineers or operators threat modeling right now. They aren't thinking about somebody tampering with their safety instrumentation systems, then also giving them a bad reading on an HMI on purpose, and then tampering with a lower level industrial device to cause a bad impact.
Lesley Carhart (18:43.314): So we need the operators and engineers to start thinking about cyber too, as a potential root cause of things. That is a very big hurdle as well. We've got the cyber people who are thinking cyber, cyber, cyber. That's all they think. And you can't do that in OT. And you need have the OT people who might be cognizant that there's hackers out there and they're doing bad things. But when they think about their low level process, they are not thinking about a malicious hacker causing the failures they see. So on that side of things,
Lesley Carhart (19:13.170): what we really need is the engineers and the operators to start involving cyber in difficult root cause analysis. When things don't make sense or things repeatedly fail in their environment, when they can't identify a cause for a system doing something potentially nefarious or bad, it's really important to start getting the cybersecurity personnel involved in that to identify if there is something else going on from that perspective because they've modeled for every type of human error and equipment, devices,
Lesley Carhart (19:43.066): failure out there to keep people safe, which is great. That's awesome. But they haven't thought about a determined adversary of purposely evading those controls. You know, like some of the physical ones, that's hard to evade, but a good engineer, ask the engineers how they break things if they were a bad guy. There's always a way. So they've got to start thinking about calling in cybersecurity to be part of those investigations to make sure that's not what's going on.
Aaron Crow (20:12.792): Yeah, I mean, especially when you're talking about these nation states, they have potentially unlimited or very large budgets at least. There's no reason to expect that they don't have representations of this equipment sitting in a lab that they're sitting there beating up and saying, hey, I put it in this scenario. How can I break this safety thing? How can I get, how can I bypass? How can I avoid, how can I get around all of the things that, because it's not surprising. Emerson,
Aaron Crow (20:42.494): Siemens, they all have these standard architectures and it's done the same, whether it's a nuclear facility or it's a manufacturing facility, their control systems are usually deployed around the same way using same subnet IPs, same architectures, all that kind of stuff. So it's really easy to understand if they've got Siemens and it's pretty easy to figure out Seem and I'm not trying to beat on Siemens Siemens or GE or Emerson or whomever, right? They're all the same. And there's a reason for that because they have to be able to support
Lesley Carhart (20:54.700): Yeah.
Lesley Carhart (21:4.110): Yeah, no, everybody, everybody knows. I need them to think that way. For more reasons. Yeah.
Aaron Crow (21:12.423): a dot an architecture that that because they're so big and they have so many customers, it makes sense why they have a very, you know, standardized architecture that they spread across their environments. But for an adversary that makes it really easy to understand what that looks like, recreate it and find ways around.
Lesley Carhart (21:31.052): Y'all, the barrier to entry is lowering. It requires system knowledge too. To break a process, you have to understand the consequences that can occur in that process and all the safety controls and how it's set up. But Erin just described these big vendors. There used to be some layer of security by obscurity because every environment was a little bit homebrew, it was a little bit custom. But we're seeing a lot more standardization. We're seeing a lot more IT technologies like Windows and Cisco, et cetera, in these environments. The barrier to entry to launching attacks
Lesley Carhart (22:0.928): against these process environments is lowering. And the vendors are aware of that. Vendors are putting in more security controls. They're doing some application whitelisting in a lot of the big vendors now. They're doing good stuff. But again, when you're talking about determined, well-resourced, not just state, but also criminal, it's a trillion dollar industry now, ransomware, criminal adversaries are starting to have automated tools, knowledge of the systems. They're able to buy expertise on those systems. We have LLMs now that will write you in
Lesley Carhart (22:30.902): They will write you ladder logic for industrial processes and tell you how to break it. Barrier to entry to launching industrial attacks has been rapidly lowering. That's why I do the job that I do. And again, we've got to try to get ahead of this on both sides. We've got to fix all the problems with IT cybersecurity coming into these spaces, and we've got to fix the culture of it can't possibly be cyber on the OT side of things.
Aaron Crow (22:57.666): Yeah. And you know, I've, I've talked about it. I talked about it at DEF CON last year. and, and continue to, but you know, cyber informed engineering is, know, something that comes out of, out of the Idaho national labs, right. And it's not a concept really that in my opinion started there, but they've really branded that. And I love it. Right. And it really goes to, me, what it means is cyber is just another risk thing that needs to be part of the conversation when they are designing that power plan or that manufacturing environment.
Aaron Crow (23:25.870): they need to consider cyber in their design. Like what happens if a bad actor gets in here and turns that one to a zero gives you a bad reading, right? And they're in the operator is going to be, and I've been in a power plant where the plant was running fine, but the operator screen smurfed. So what did they do? They punched the unit out because they couldn't control it. They didn't know what was going on. So their training says to be safe, to make sure I save equipment and life, I'm going to shut the unit down safely. So then we'll figure out what's going on.
Lesley Carhart (23:28.428): And I don't.
Lesley Carhart (23:52.524): Yep. Yeah.
Lesley Carhart (23:56.326): I mean, that's it's very significant there. A lot of swapping goes on. You know, like it's something breaks. It's again, the root cause analysis is we don't assume that it's cyber. We just swap out a box. We call in the OEM to replace a part. And there's never any forensic analysis done on a lot of those devices to figure out what went wrong. So yeah, I mean, this is going to continue to get worse. And I'm not trying to be fear mongering. You know, it's just like, it's not I'm not trying to sell people widgets here. Yeah, I work for a company that does this stuff.
Lesley Carhart (24:26.132): it.
Lesley Carhart (24:26.798): Like it's just logical. Like these systems do life critical things. They do things that are very noticeable in society and they make a good target for extortion. They make a good target for geopolitical objectives and people are learning how to attack them better. And we have to take that seriously. Are 97, 98, 99 % of failures industrial devices in these countries that were concerned about security
Lesley Carhart (24:57.312): are 99 % of them still going to be maintenance failures, human error, things like that. Yeah. I get sick all the time of getting pinged on the internet whenever there's some kind of industrial accident out there. Was it cyber? And everybody's assuming it was cyber. Probably not. 99 % of the time, it's still going to be just a part failed or an operator made a mistake. Yeah. Yeah.
Aaron Crow (25:12.634): Yeah. Yeah.
Aaron Crow (25:18.852): human error.
Lesley Carhart (25:21.538): But there is that small percentile, significant percentile where it is. There are all these groups who are interested in tampering with these systems for a variety of reasons, whether it's making money or making a statement, whether it's terrorist groups or states.
Lesley Carhart (25:39.060): And that is actually happening. And the only way we get a good idea of what they're doing, what their capabilities are, and where they are living in environments, mean, look at the phone networks right now, that whole quagmire of unwinding intrusion and persistence and footholds in our phone systems in the United States.
Lesley Carhart (26:1.738): The only way to catch that stuff is to do cybersecurity. We have to do cybersecurity in these industrial environments. And we have to take the stand that in some small percentile of cases, there is a cyber cause or some kind of element to what's going on in that environment when something fails.
Aaron Crow (26:24.634): Yeah, and it's almost like in a perfect world, you would have a cyber person embedded in the operations team or whatever. And anytime there's something that goes on, that person is investigating the cyber aspect. Could it be a bad actor? Could it be malware? Could it be ransomware? Could it be et cetera, et cetera, et cetera? Instead of, and I'm going to throw out a Hail Mary and assume that this is probably what you guys get most of the time.
Lesley Carhart (26:34.030): Hmm.
Aaron Crow (26:52.824): You guys are getting it in the 11th hour after they've tried everything else and they've rebooted it and they've replaced stuff and it just keeps persisting and they don't know why. And they call you when they have no other options and they've tried everything else they know.
Lesley Carhart (26:59.554): Yes.
Lesley Carhart (27:5.026): We get called in late.
Lesley Carhart (27:10.412): We get called in so late. We have a lot of retainer customers at Dragos. So a lot of organizations with industrial networks keep us on retainer so that if they have an industrial incident for insurance reasons and for practical reasons, if they have an industrial incident in their OT environment, they can call us in. And a lot of organizations are still scared to call us for a multitude of reasons. Like there's political reasons and regulatory reasons, like not wanting a big eye incident.
Lesley Carhart (27:40.336): So just that not doing any investigation to know to call us. And then they wait again like you just described until they've exhausted everything else or maybe somebody sees something weird and we get called in maybe months later when all the evidence has been destroyed.
Lesley Carhart (27:56.982): we need to get this, we need to change this culture. And that means both teams need to work together better in all organizations that have OT stuff. The cybersecurity people need to start really being cognizant of these environments and of industrial consequences and processes. And we've got to build a better culture of involving cybersecurity in root cause analysis and OT as well.
Aaron Crow (28:19.364): So without dropping names or specific customers, et cetera, who's somebody that's doing it well? Like who's somebody that's kind of embodying that, you know, the thing that it's going to take to win in this space like this.
Lesley Carhart (28:33.368): Yeah, I mean, it's really interesting. I see every vertical around the world, different size organizations, and some of the very well-resourced verticals and companies, like think about the big oil and gas companies. They have big cybersecurity teams, and they can afford nice security operations centers with the best tools. But none can buy everything. In some other cases, I see even small organizations where there's just that one cybersecurity champion for OTE who's really rocking.
Lesley Carhart (29:0.792): who's really motivated and has educated themselves and is building good relationships between the teams. And that's really effective too.
Lesley Carhart (29:7.958): I've definitely seen Fortune 100 companies where the relationships between teams is a disaster and they have incidents because nobody's talking to one another and everybody's siloed. So it's a mix. I don't think there's one thing that solves everything, but having a good champion for OT cybersecurity who seeks out the right expertise inside and outside and then having leadership executive buy-in for that is a really big element. Yeah, resources help.
Lesley Carhart (29:37.872): If you ask us what industry keeps us up at night, it's water and sewage. People in the United States are not familiar with what it would be like to lose sewage systems for a month, two months. That is not something we are accustomed to thinking about, how bad that would be, or losing clean drinking water for an extended period of time. People in the United States, most of Europe, UK, Australia are not accustomed to that idea.
Aaron Crow (29:50.073): Mm-hmm.
Lesley Carhart (30:7.898): So yeah, it's a big shift in thinking there, you know, about the potential implications.
Aaron Crow (30:15.534): Yeah, for sure. And, it's promising to, to hear and for the audience listening, you don't have to have a huge budget to make an impact. You can be that champion that is somebody needs to own and kind of plant that flag and say, I'm going to be that champion and get that, that ownership and build those relationships. Cause it all comes down to building trust between OT and IT because, you hit it in the beginning, right? Is
Lesley Carhart (30:24.876): No.
Lesley Carhart (30:40.206): trust and vocabulary.
Aaron Crow (30:42.840): A lot of the reasons why we don't have that communication is because in the past they were untrustworthy and they tried to push something down or they failed to come through or whatever. That doesn't make it okay. We've got to rebuild those trust. We're on the same team. We need to be fighting in the same direction.
Lesley Carhart (30:48.110): Okay?
Lesley Carhart (30:57.558): It's only going to get worse. have to function as an individual unit of doing this defense for these industrial systems.
Lesley Carhart (31:5.402): And I didn't articulate well enough, water utilities, if you don't know, are incredibly under-resourced. Water and sewage are utilities that are usually municipal. They usually have one IT person. They have nothing to do cybersecurity with. And that's very, very, very challenging for them. They have no money for tools, for resources, for planning, for personnel to do cybersecurity. So really scary situation in a lot of the developed world right now. And the other thing there is, yeah, we've got
Lesley Carhart (31:36.277): low resources, but we also see some really good community efforts there, like Water ISAC in the United States that are doing good community efforts to try to get them the resources they need. So again, motivated people who are doing good stuff to try to fix these problems and build better relationships can make a huge dent, which gives us some hope because again, water sewage are the ones that keep us up because they have nothing. They have no money and they're doing this vital thing for society.
Aaron Crow (32:2.574): Well, and again, you know, coming from critical infrastructure and you know, I've worked at the largest power utilities in the country and I've worked for small ones too. I mean, and everywhere in between and you hit on something really important earlier is it doesn't matter that you're the largest and you have a big budget. That does not necessarily mean you're, winning. And sometimes it can add more, more difficulties because of layers of management or whatever red tape that makes it more difficult than some of the smaller municipalities with one guy. Well, he's the guy or gal.
Lesley Carhart (32:19.798): It helps.
Lesley Carhart (32:22.926): but.
Lesley Carhart (32:26.882): Red tape.
Aaron Crow (32:32.024): He that they are the one that can can make a big impact instead of having to have a committee of people to sign off.
Lesley Carhart (32:38.914): But it does help to have money for like antivirus and things. It does help to have a detection tool or something, to have somebody who can monitor your systems full time. Those things cost money. So it's a mix. It's a mix. Again, there's not a single answer, but caring about this problem and thinking about it strategically with an involvement from both sides of this issue is a huge element. And that's somewhere to start for a lot of organizations.
Aaron Crow (32:41.719): Exactly.
Aaron Crow (33:6.788): So speak to that person, speak to that person that is the OT person, or maybe they want to be, and they're trying to make a difference and they don't know where to start, and maybe they don't have a budget, maybe they don't even have authority, but they're interested and they know they have problems and they wanna help. Like how can they best start moving that rock uphill?
Lesley Carhart (33:28.696): So from an organizational perspective, it's important to have an OT cybersecurity champion. Maybe they're one person in your SOC. Maybe there's somebody you hired to be in that role part-time, full-time, something like that. Maybe it's part of their job and that's half their job or something. But it's important to have somebody who owns that relationship. And then that person needs to do a lot of shadowing of the OT team. They need to understand the process, not as an engineer, chemical engineer, electrical engineer, but understand it well at a high level, understand what can go wrong, the consequences, how the
Lesley Carhart (33:58.640): systems laid out, how people do their jobs. And then they also need to be a cybersecurity person. They also need to be able to associate with and get expertise from other cybersecurity people and call in vendors when they need to, whether that's industrial vendors or cybersecurity companies like us, to figure out what's going on in their environment and how to best secure it and respond if there's an incident. So having that champion is really good for a facility or for a holistic organization. It depends on
Lesley Carhart (34:28.532): how you lay out your environments and how different they are. But it's something somebody should own and they should really care about and they should learn both sides of this problem as much as they can at a high level so that they can pull in the right expertise to solve these problems.
Aaron Crow (34:44.417): Yeah, that is so, so true. And the other thing that comes up for me in that is, the language difference between OT and IT. And even though we're, talking firewalls we're talking, the tech is very similar, especially now in many of these spaces. You said big I incident, right? And there's a reason why a power company is hesitant to call something an official incident because that means certain things.
Lesley Carhart (35:9.068): Mm-hmm.
Aaron Crow (35:11.374): And there's a timer that starts and there's all of these requirements that go into when they're there when they know it's an incident. And so when I've done tabletops with people that are non OT or yeah and they're like, well, you should just call the incident response team and declare it an incident like, yeah, time out. I don't want to call an incident yet because I don't know that it's an incident. As soon as I've declared an incident, then there's all of these things that happen from a regulatory perspective. And those can be big impacts, especially if it's not true. So
Aaron Crow (35:40.910): Those are big things around language and understanding and trust and all that kind of stuff too.
Lesley Carhart (35:45.486): I have very nuanced view on.
Lesley Carhart (35:47.872): industrial cybersecurity regulation around the world for a couple of reasons. First of all, sometimes it deters investigations and monitoring because nobody wants to detect anything. And they will do the bare minimum required in monitoring so that they don't have a big eye incident they have to report to either shareholders or the government. And, you know, the other thing is requiring people to do things that they don't have resources for. I talked about like those municipal utilities like water and sewage, the ones that have no resources.
Lesley Carhart (36:17.948): If you regulate, they have to do more cyber stuff and you don't give them any more resources or tools, that's going to take away from something else they're doing. It's probably not going to be processed stuff. It's probably going to be like patching. It's going to be like some IT thing they're going to stop doing to do your cybersecurity mumbo jumbo regulatory stuff. Regulation has a place. Yes, we really want people to report incidents to the government so we know what state actors are doing to our critical infrastructure so we don't get into the situation we are.
Lesley Carhart (36:47.096): with the United States phone systems right now. That's a big deal. We don't want to end up there 10 years down the line. We need to know what these adversaries are doing and where they have footholds. So we really need to be cautious, though. We want to get that reporting. We want to make sure we incentivize people to do cybersecurity, but we have to balance that with scaring them away from even doing detection.
Aaron Crow (36:49.188): Mm-hmm.
Lesley Carhart (37:11.738): and taking away the resources they use for other critical things to cybersecurity, like updating their systems and building new architecture. That means regulation needs to come with resources, both educational resources and money, money, money, and people to help these organizations get where they are and where they need to be. And they need to be written really well so that reporting is still possible, detection is incentivized, and people are not
Lesley Carhart (37:40.834): disincentivized from doing basic cybersecurity because they're scared to have an incident. That's a hard problem.
Aaron Crow (37:47.130): Correct. It is. And I saw it, you know, and just to do an analogy or an aside, I saw it in the safety culture and in critical manufacturing and critical infrastructure, right? Is once we had this safety zero and we in the organizations that I'm with empowered their people, whether you're an intern or you're a 40 year person to stop on unsure.
Lesley Carhart (37:59.192): Yep.
Lesley Carhart (38:12.974): Yeah.
Aaron Crow (38:13.654): and to be able to challenge anyone. Hey, that's not the same. Like, don't stand on the chair. Go get a go get a ladder and put on a harness and, you know, make sure you're locking out and tagging out. It's amazing how when we started doing that and they empowered and there wasn't any retribution for doing these things that people turn things in. And they said, hey, we had a near miss today because Bob was in his chair. I safely got Bob down. I told Bob that he shouldn't stand in his chair. We should go get a ladder. That was a near miss. And Bob didn't get fired for it. Bob didn't get in trouble for it. In fact, it was a
Lesley Carhart (38:20.750): Thanks
Aaron Crow (38:43.756): Okay, Bob, now you know not to do that. If you do it again, yeah, there's probably going to be some retribution, but there shouldn't be this negative beating over the head or fines or anything like that all the time. Because then to your point, it's going to stop people from wanting to raise their hand or look for as long as I don't know it's there, then I don't have to report it. So I'd rather just not know.
Lesley Carhart (39:4.236): And also that culture of Bob, why were you standing on the chair? Can you not get to a ladder? Do we not have enough? Is there not one in your workspace you can get to quickly when you have a problem? Do we need to buy another ladder? That stuff happens in cybersecurity too. If we detect something late, if we don't detect something until there's a root cause analysis done, what were we missing? This isn't somebody's fault. We're not firing the CISO of the organization. Like we're all building OT cybersecurity together as a planet right now. Like this is...
Lesley Carhart (39:33.004): This is a fast growing problem that's been growing for a while and it hasn't been attended to for a while. We're all doing this together. There's not a lot. I know like all the people who do my job, there's a limited number of people around the planet right now who do what I do. So we have to change that culture. We have to incentivize people to detect and report. And people who are in legislation in various countries really need to be cognizant of that being a really big problem right now.
Aaron Crow (40:3.204): So you hit on something really important in there as well, and it's the resource thing. There definitely is not very many people that have the skill sets and experience in OT and IT and cyber and have the diversity of experiences from, again, I came from working in power plants and all that kind of stuff. And I also worked in Fortune 100 IT enterprise organizations. So I bring both of those things to the conversation.
Aaron Crow (40:32.346): So when I'm looking at those problems, have those experiences, but there aren't many people like me and like you and like others that we know. How do we, how do we grow that and get more people involved in more diversity of thoughts and ideas and experiences? Because when you look at the resume or the job requirements on some of these things, it's like, well, you need 20 years experience and a CISSP and blah, blah, blah. And like, there's like 12 of us that have those requirements and we all are currently employed. So what are you going to do when none of us want that job?
Lesley Carhart (40:59.406): Yeah, I mean, that's a really interesting problem. I do a lot of mentorship. I've actually got a Calendly on my social media where I let people sign up for mentorship sessions with me. And I get asked regularly, like, how do you get into OT security? And it's tough because we all have these really strange backgrounds. Like, you were in electric power. I was an aircraft mechanic.
Lesley Carhart (41:18.112): You need to combine those two sets of knowledge. And let me describe the two sets of knowledge for you. One of them is cybersecurity, whatever your niche of cybersecurity is, whether it's monitoring, detection, incident response.
Lesley Carhart (41:31.606): whatever, architecture, network security, engineering, things like that, you need to combine some level of skill with that. It could be entry level skill and some knowledge of industrial processes. The mistake I see a lot of people do is they focus on like industrial protocols. Like they go by a bunch of PLCs and they like exploit the PLCs. Y'all, let me tell you something about PLCs.
Lesley Carhart (41:56.140): You're going to exploit the PLCs. Yes, send them a stop command. They stop. They are very simple computers. They are very vulnerable. I describe these industrial environments usually as a The model is a crispy candy outside and a gooey candy center. You can exploit those unencrypted industrial protocols. That's fine. But the reality of it is what can you do to the process? We talked about this earlier. Processes are complicated.
Lesley Carhart (42:26.072): They're getting less so because there's a lot more standardization. But really what matters there is what causes somebody to get hurt or to the equipment to get damaged or the environment to get contaminated. Whatever those consequences that come from those processes that are really, really bad, that's what you're worried about. And from a cybersecurity perspective, you're not worried about exploiting a single PLC. They're usually redundant.
Lesley Carhart (42:50.446): There's usually three layers of physical and digital safety controls keeping them from doing something really bad or shutting down the processes if they do. A good red teamer, and red team's another niche of cybersecurity who's learning how to exploit these systems, is thinking about how do I make the place catch on fire? Not really, I mean, just from a test perspective, but like how would an adversary do that? How would they evade all these safety controls and the redundancy in the system and the logic in the system
Lesley Carhart (43:19.650): to make this consequence happen. It's not exploiting a single PLC. Do you need to know how to do that? Yeah, but every system's got different code, different ladder logic, different protocols, and you can learn those pretty fast. Really, what you need to focus on is that second set of knowledge is, how does process work? I don't care what process. It could be canning tuna. It could be getting an airplane off the ground. It could be electric power generation, distribution, transmission, et cetera. It could be how cars work.
Lesley Carhart (43:48.812): you need to understand how a process works, how safety controls work, what the stuff in a general process is. It's the same. They're different vendors. There's different layouts in like tuna canning and airplanes flying. But process environments are still kind of in the Purdue model. They still have that layer cake. A lot of the protocols are similar. Once you understand how a process works, you can usually understand how other processes work.
Lesley Carhart (44:16.302): You don't need to be a chemical engineer. You don't need to be an electrical engineer. Focus on that. Focus on learning that. If you're a cybersecurity person who wants to get in this space, go find a process you can learn about. Whatever's cool to you. Go learn how trains work. Go find a friend who works in a manufacturing facility and see if you can shadow them for a while. Find some way to learn how stuff works and you'll be able to figure out how things can be broken. That's what my advice is there.
Aaron Crow (44:45.326): No, that's great. And to your point, is, you know, I came from critical infrastructure and power generation and transmission distribution, all that kind of stuff. But over my career, I've worked in all the 17 critical infrastructure verticals, right? And I can walk into, even though most of my experience is from a power plant, I can walk into a critical manufacturing and I understand it because I understand how the process is worked.
Lesley Carhart (45:6.904): Heel cease, heel cease.
Lesley Carhart (45:9.378): You send them a stop command, they stop. When you the big red dot on the wall, that's gotta work. There's no encryption on these protocols. Yeah, the protocols can be, you might have DNP3 in your power environment in the US. You might have Modbus somewhere else. Yeah, whatever. There's simple industrial protocols that you can look at in a packet analysis tool. They all have HMIs that share the status of the system. They're oftentimes Windows systems. They all have engineering workstations to program stuff. They all have some PLCs, RTUs at the lower level.
Aaron Crow (45:11.448): Right. Yeah.
Lesley Carhart (45:39.312): sensors, actuators. Process is a process. Learn how a process works.
Lesley Carhart (45:44.950): Listen to us, listen to me and Erin. You can go learn this stuff, but don't focus like, my God, I'm going to hack a PLC. Like, I found a PLC or an HMI or something exposed on Shodan. Yeah, you can, you can hack it. But like hitting the buttons on the HMI, there should be levels of safety controls that if you try to, yeah, you found a water HMI on Shodan. Okay, yeah, there's a lot that exposed and that sucks. And that's a bad thing for cybersecurity, but most of them have layers of controls that keep you
Aaron Crow (45:58.937): Yeah.
Lesley Carhart (46:14.864): from changing the chlorine levels too drastically. There's other stuff there. It's a whole thing. It's not just that one system that you have access to. So that's an element of understanding how to do cybersecurity there.
Aaron Crow (46:17.839): Right.
Aaron Crow (46:29.422): Yeah, yeah. And if you're going to set up that lab and you know, there's nothing wrong with having some fun and hacking a PLC, but more understand how to make it work the way that it should work in a proper way and how it can control things. Yeah.
Lesley Carhart (46:40.460): It does not exist in a vacuum. Your PLC, yeah, take one apart, sure, I got some PLCs on my desk, they're fun to play with. Build yourself something at home with ladder logic, know, make something, brew your coffee or something. Sure, that's great, but that's really, you need to understand how you brew the coffee. How does a coffee maker fit into this? Not just the PLC, it does not exist in a pile on your desk and that's it, it's connected to things.
Aaron Crow (46:56.152): Right.
Aaron Crow (46:58.606): Right. Correct.
Aaron Crow (47:5.700): Well, especially in these critical places, right, as we have, you know, backup and tertiary systems. I mean, you again, I support a nuclear power plant and that we had analog things like there was analog and then there was digital and then there was a tertiary digital like so even if I hit one, there were two other systems that protected it. And if it got out and there were thresholds, even if I could say.
Lesley Carhart (47:16.394): Talk about backups.
Aaron Crow (47:28.426): ramp up chemicals are down, it could only do it to this amount. And then the other ones would say, yeah, you can't do it that fast. You're out of here. Or there's something outside of normal. I'm failing to analog and I'm going to send an operator out to move physically, move a valve for instance.
Lesley Carhart (47:42.666): And I'm going to use the word. I haven't used the word in like 10 years in one of these podcasts. I'm going to go back to Stuxnet. I can't believe I'm going to do it, but we're talking about nuclear stuff, uranium enrichment there. Look how much went into figuring out how to break a nuclear process there.
Lesley Carhart (48:2.560): uranium enrichment, like people had to figure out a very out-of-the-box solution to screw that up. It involved changing the spinning of centrifuges in the enrichment process. The holistic process of like creating nuclear power and creating nuclear weapons involves enrichment. That's one aspect and that is its own process. And somebody had to have the engineering expertise to look at that segment of a process and then say, hey, with all these safety controls in place,
Lesley Carhart (48:32.544): with all these human controls, these incredible levels of redundancy that you're talking about, what can we do that nobody's going to notice and evade detection using these analog controls and these physical controls and these human controls in an air-gapped environment? That's an extreme example. Nuclear is incredibly secure for a reason because really bad things happen if it goes wrong. process is a process. They are complicated. They have layers of safety controls. And these adversaries who are thinking about attacking them
Lesley Carhart (49:3.222): they're looking for low barriers to entry but then they have to think about the process and that's the hard thing.
Aaron Crow (49:10.734): Yeah, yeah, absolutely. Man, this has been eye opening to people again. So I've actually seen Stuxnet running in the wild in a power plant, but it wasn't. It didn't have Siemens S7, so it really wasn't dangerous, right?
Lesley Carhart (49:25.477): And it's not the right centrifuges, it's not urine enrichment. Yeah, Yeah. No. It's very tardy. Yeah.
Aaron Crow (49:28.044): Exactly. So it's there. It's like, my God, we have stuck snap. Yeah, but it doesn't really do anything. So yes, we'll clean it, but it's not. I'm not going to shut the plant down because of it.
Lesley Carhart (49:38.122): amusing that they got that in there. I mean, that's awesome. No, it's not awesome, but it's wild. Yeah, but yeah, that's a very old case. We don't talk about it a lot anymore because it is so long ago, almost 20 years ago now. But that's like the extreme example. Like again, I do this every day and people are attacking this stuff. Normally doesn't take that level of effort. Like most environments are not that secure. They have Windows XP systems that are exposed to the internet. They are not hard to get
Aaron Crow (49:39.940): Correct. Yeah.
Lesley Carhart (50:8.197): you're still dealing with those fundamentals in most environments that aren't defense or nuclear. much lower barrier to entry, much lower barrier to doing bad things to the process.
Aaron Crow (50:19.502): Yeah. And that's going to be kind of my theme here is, is, you know, there's usually when I come in and do an assessment or whatever, you know, it's not fancy many times like, Hey, where would I start the foundations? Do the basics go look. And do you have an asset inventory? Do you understand where all your assets are? Do you have a network diagram? Do know where, you know, look at your firewall rules, look at your routing, make sure you don't have something directly connected to the internet. These basic things are not super expensive. I don't have to hire.
Aaron Crow (50:47.192): you EY or, or big four consulting to do some of these things. These are things that I can do, you know, in my downtime and to make sure and, and, and get a, and raise the level of my cyber security in my environments exponentially without having to buy a single product.
Lesley Carhart (50:55.128): for something else.
Lesley Carhart (51:5.312): If I would challenge everybody who's listening to this, and thank you for listening, especially if you've gotten through an hour with us, I really appreciate it. I hope you've learned something. If you are cybersecurity professional, try to identify where industrial devices exist in your workspace, in your facilities, even if you're not a manufacturing company. You probably have data center industrial controls that do very important stuff for your operations. Identify where those industrial systems are and if anybody's doing security on them.
Lesley Carhart (51:35.216): start finding a champion, building some kind of fundamental program, figure out what's there. Like Erin just described, an asset inventory. Don't scan things intrusively, like, you know, passive discovery. Try to figure out what's out there, try to find resources and help to understand what's going on in that process environment. And just start from the fundamentals. Anything's better than nothing. I implore you all, like, again, I see people on their worst day ever all the time. Start somewhere.
Lesley Carhart (52:5.417): Start with the basics. There's low tier adversaries that you can catch just by doing the fundamentals in these environments.
Aaron Crow (52:10.884): Yep. And it's amazing how many, you know, of these vulnerabilities or these, these, these risks kind of go away when you do those basics, that don't, that don't take much. when you, when you start thinking about them, when you're looking at these issues. Yeah.
Lesley Carhart (52:24.654): Deterrence is a real thing.
Lesley Carhart (52:26.210): You know, lot of these criminal actors, like if you are too hard of a target and it's not worth the monetary effort to break into you, they'll move on to another target. This is not a be all end all. I hear that crap like, the adversary only has to succeed once and defenders have to succeed all the time. No, it's a layer of defense in depth. Like you are deterring more adversaries the more you do. The more you do, the more stuff you'll catch and the more people will find you too, too time consuming and money consuming to intrude into and they'll move on.
Aaron Crow (52:35.085): easier target.
Aaron Crow (52:47.834): Yep.
Lesley Carhart (52:56.194): to somebody else. This is the doable thing, but you have to start somewhere in your industrial space and you have to do it a little bit differently.
Aaron Crow (53:5.006): Yeah. Awesome. So, so with all of that, I'm going to give you the final wrap up question that I always give everybody. What in the next five to 10 years, what's one thing that you see coming up over the horizon and cyber that's maybe concerning and one thing that's exciting that from your perspective.
Lesley Carhart (53:21.518): So concerning, these attacks are only going to continue to get worse because people who are doing bad stuff see them in the news and see that they're successful. Like you want to cause an impact, want to extort people, bringing down critical infrastructure and manufacturing logistics is a great way to do that. And it's an incredibly powerful tool for states as part of larger geopolitical and conventional warfare campaigns.
Lesley Carhart (53:43.712): when it's the most cost effective thing to do, which sometimes it is, sometimes it isn't. So that's only going to continue to get worse. These problems of convergence of technologies, standardization of systems, we're starting to see commodity toolkits and malware that has the capability to hit malware systems. That definitely happens. People are starting to build automated toolkits to attack standardized industrial configurations, and that's really bad. But on the positive side, I'm
Lesley Carhart (54:13.568): I'm getting a lot more retainer customers. I'm getting a lot more people calling us for architectural advisory services, fundamental incident response plan construction, things like that. And I'm sure that our competitors out there who are in the industrial space are too. That's good. People are starting to care. We're getting called in a little bit earlier in some organizations to be part of root cause analysis. That's good. People are starting to have us take a look at long-term infections that have been there for 10 years. That's good.
Lesley Carhart (54:43.472): So, defense is growing, attacks are growing, they're both happening, it's two sides of the same coin unfortunately, but I mean, I'm glad that OEMs and industrial operators and owners are starting to care a little bit more about cybersecurity while the adversaries are also ramping up targeting of those systems.
Aaron Crow (55:2.776): Yeah, I think that the same canary in the in the coal mine that's that's that's making it, you know, getting more budget and more people from a from a defensive side from these companies. Obviously, the adversaries see the same thing, so they see that it's working. So they're going to do more. And then the more it's just this, you know, tail, you know, snake eating its own tail. Yeah. Exactly.
Lesley Carhart (55:24.426): We're both going to be employed for the rest of our careers. I'd like to go become a bartender or teach karate for the rest of my life, but that's not going to happen. We're both going to be very, very busy for a long time, but things can get better.
Aaron Crow (55:33.252): That's right, that's right.
Aaron Crow (55:37.432): That's right. So yeah, it can. And you know, I've seen in my career, I've seen a drastic improvement in this in all spaces. Does that mean there's not a lot of work to do? To your point, there's a ton of work to do. and we're way behind the eight ball and it's not where I want it to be, but we're here and I've seen a lot of really great people and a lot of really great conversations and a real, a lot of great work that's being done in this space. And I, and I want to empower
Aaron Crow (56:5.082): by using this platform, by putting people like you on this and having these conversations that people don't get frustrated. They don't just feel like I can't do anything. It's too big of a problem. Cause it's not, it is a big problem, but you can, you know, you can be the ripple that makes it makes an impact in your organization.
Lesley Carhart (56:21.005): Agreed.
Aaron Crow (56:22.456): So what's called the action for you? Where are you going to be? know you've got all sorts of things going on in your world. So what do want people to know or reach out to you with? You already mentioned your Calendly link. So that that's really cool for people to take advantage of.
Lesley Carhart (56:34.092): Yeah, I'm hacks for pancakes on all social media minus X. So master Don boost, I'm on LinkedIn, I'm on Instagram, all that stuff. So feel our threads, feel free to reach out to me through any of those. also have my calendar link if you want to get mentorship from me. I do mentorship clinics around the US conference circuit currently. But the big news for me is I am moving to Australia within the next five, six months. I'm going to be based in Melbourne and
Lesley Carhart (57:4.066): I'm excited to be part of the conference scene and mentorship scene there when I arrive.
Aaron Crow (57:8.504): That's awesome. Hopefully I'll get to come down there and see you at one of those conferences instead of just the US US based ones that that we've spent so much time on on this shore. So well, thank you for your time today. I really appreciate it was an awesome conversation. I think it was super valuable for folks, so definitely reach out.
Lesley Carhart (57:18.029): Give me.
Aaron Crow (57:27.834): can't recommend it enough to reach out and ask questions. And, you know, if you're looking for mentorship, you know, Leslie would be a great one to reach out to as, as you heard from in this conversation, there's, there's a lot of valuable knowledge there and, and insight that, that, happy to share as all of my guests seem to be, which is why I love doing this. It's, it's not hard when it's
Lesley Carhart (57:49.442): Thank you so much for having me. was so much fun.
Aaron Crow (57:51.660): Absolutely, thank you for your time.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.