In this episode, host Aaron Crowe speaks to Dan Ricci, founder of the ICS Advisory Project, to delve into OT cybersecurity. Dan brings a wealth of experience from his time in the Navy, transitioning through various cybersecurity roles, and finally taking the leap to establish a platform that addresses the complex needs of critical infrastructure sectors.
In this conversation, they explore the genesis of the ICS Advisory Project, a tool designed to streamline vulnerability management for small to medium-sized organizations. Aaron and Dan also discuss the challenges of transitioning from military service to civilian cybersecurity roles, emphasizing the importance of mentorship, risk-taking, and continual self-improvement.
This episode offers valuable insights for anyone in the cybersecurity community and those looking to bridge the gap between IT and OT spheres. Join us as we explore strategies to enhance resilience and share lessons from the field.
Key Moments:
09:17 Building Dashboards with Google Studio
14:41 Cybersecurity: Secondary Concern for Operators
20:48 Supporting Small Supply Chain Contributors
23:23 OT Cybersecurity Impact and Mentorship
27:48 Bridging Cybersecurity and Critical Sectors
34:16 Opportunities to Share Project Insights
38:24 Adapting Skills for Career Growth
45:58 Cyber Career Evolution and Growth
56:14 Leadership vs. Management Distinction
01:00:56 Relentless Daily Self-Improvement
About the guest :
With over 28 years of Cybersecurity experience, Dan is the Senior Cybersecurity Consultant at
Ampyx Cyber, leading engagements with Rural Cooperatives and Utilities to improve their
Cybersecurity programs and protect critical infrastructure. In 2023, he founded Industrial Data Works to provide independent consulting and vulnerability intelligence API subscription services.
He is also the founder of the ICS Advisory Project, an open-source initiative to help small and medium-sized ICS asset owners across the 16 critical infrastructure sectors prioritize vulnerabilities and plan mitigation for their ICS/OT environments. He aims to provide free and accessible resources to secure critical infrastructure and protect the public.
Link to Industrial Data Works:
https://www.industrialdataworks.com/ics-advisory-project-api
Links to ICS Advisory Project:
https://www.icsadvisoryproject.com/
ICS Advisory Project Github Repository:
https://github.com/icsadvprj/ICS-Advisory-Project
Receive ICS Advisory Project Weekly Summary Slides and Other CERT & Vendor Advisory Summaries in your email every Monday:
https://docs.google.com/forms/d/e/1FAIpQLSfC490BHoCR4gHekZcMLBgbHMhUQZr7ZVYZG1OkaWdKGwH73g/viewform
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:1.574): Hey, welcome to the Protect It All podcast. I'm very excited to have my friend Dan on the call here today. Dan, why don't you introduce yourself, tell us who you are and a little bit about your background and history.
Dan Ricci (0:12.270): Sure, I'm Dan Ricci. I'm the founder of the ICS Advisory Project. I am also a senior consultant with Ampex Cyber and also I've done a lot of independent cybersecurity consulting. My background in cybersecurity really started in the Navy. I was in the Navy for 21 years, both enlisted and officer, as a warrant officer. And I learned most of my skill set in...
Dan Ricci (0:40.044): instant response, vulnerability management, threat intelligence, analysis, and offensive cyber operations during that timeframe. After I retired, I worked for one of the big four doing consulting. And then after that, I transitioned back doing defense contracting work, doing cyber risk assessments and building automation systems, meaning power distribution.
Dan Ricci (1:8.096): also some water treatment as well. I pivoted back doing a role that was more senior information security officer role, establishing a cybersecurity maturity model certification, CMMC, more tied to the NIST 800171.
Aaron Crow (1:26.378): Mm-hmm. Mm-hmm.
Dan Ricci (1:31.662): cybersecurity standards for a company called Frequentus Defense and they manufactured embedded voice gateways. So I got a lot of experience doing product security as well, understanding how that relationship between the customers and cybersecurity works. Also got my hands really deep involved in supply chain risk management because of
Aaron Crow (1:47.710): Okay.
Dan Ricci (1:58.956): Most of our customers that we were selling to were either in the DOD or US government. So really heavily involved in risk management framework as well. So that was a good experience. I transitioned from there working for short stint with SINSABER, doing the research director position until their demise. And then I transitioned into a role at the INL, Idaho National Labs.
Aaron Crow (2:26.811): Mm-hmm.
Dan Ricci (2:26.976): And during that timeframe over the year, I led the Cyber Shield program, which was focused on cybersecurity for renewables. I wrote the Malcolm Deployment Guide for Solar Power Generation with the Malcolm team while I was there. I thought that was a good contribution to the community since it hadn't existed previously to kind of show.
Aaron Crow (2:31.523): Mm-hmm.
Dan Ricci (2:55.438): where you would deploy that guide into a power generation system. And I found that it was time for me to go out on my own. I finally decided to break off, and I had opportunity to go work for Patrick Miller at Ampex. And I just went off and did that full time since this December. I transitioned.
Aaron Crow (3:0.522): Right here.
Aaron Crow (3:18.066): Mm-hmm.
Dan Ricci (3:25.292): So I'm really excited in this new role that I'm in. I feel that now in this new role, I have the capability to assist a broader group of clients in the energy sector, also in other critical infrastructure sectors. Having that flexibility again, vice, you know, the constraints of being with an organization kind of a...
Aaron Crow (3:26.290): I'm to take a few minutes to explain this. I'm take a few minutes to explain this. I'm going to take few to this. I'm going take few to explain this. I'm going to take this. I'm going to going take few minutes to going to minutes this. I'm going take I'm going few going to
Dan Ricci (3:52.578): I wouldn't say muzzles you, but it definitely limits on how you communicate a little bit.
Aaron Crow (4:1.633): 100%, you know, being prior big four, obviously, if you know me, you could probably tell you can look at my LinkedIn and say who that is. And I loved my time with the big four. There's a lot of benefits. It opens a lot of doors having that, you know, behind my, my title. You know, I'm with XYZ company. But to your point, I would never be able to have this podcast like I
Aaron Crow (4:23.408): I would have to get everything ran through legal and for obvious reasons. It's not because they're bad, it's because there's high standards and SEC requirements and all these things that go into it that have nothing to do with cybersecurity. It has everything to do with because they're an accounting firm and they do, you know, SEC audits. you know, if you don't know what we're talking about, take a look at Enron in the past.
Aaron Crow (4:48.098): And Arthur Anderson, and that's kind of the big scandal that really forced all these regulations and requirements upon these big four consultancies. And not just the big four, but any SEC auditor that's auditing the books of publicly traded companies, there are requirements for all their employees to have these continuing education hours. And they go through your finances with a fine tooth comb, which not to get political, but that's the whole thing that boggles my mind that.
Aaron Crow (5:14.596): Our Congress and senators can invest in whatever they want, but me as a cybersecurity person at a big four consulting firm, I couldn't buy individual stocks because it was against the law and they'd fire me for it and I'd be fined. So we figured out how to do it. It's just, we don't implement it for everyone. It's just the lowly people like me and you that are impacted by it. anyways, I diverged down a path. Tell us about really quick, tell us, first of all, I love Patrick Miller. He's one of my favorite people.
Aaron Crow (5:44.866): love all that you guys do. But definitely tell me a little bit about, kind of breezed over it, but tell us about the ICS advisory. Like what is that? if you haven't seen it, the link will be in the show notes, but let's talk about that a little bit. And it's more than just a pretty dashboard. So talk us through, why'd you create it? What is it? And what the kind of life cycle of.
Dan Ricci (5:52.087): You
Dan Ricci (6:9.494): Yeah, absolutely. So the ICS RISERY project was born out of my experience of doing cyber risk assessments, both during my time with Deloitte and also when I went and was doing cyber risk assessments within the DoD and realizing that the way organizations tracked vulnerabilities was inconsistent. I thought it was pretty
Dan Ricci (6:36.046): burdensome for organizations, especially small organizations where you'll have maybe like one or two people that are trying to track vulnerabilities and that exists all over the place. And I realized that, know, CISA was doing a great job, you know, documenting, you know, existing ICS specific vulnerabilities and providing a good report. But the report was done in a, it was an HTML report, obviously, I mean, your website.
Aaron Crow (6:37.223): Right here.
Dan Ricci (7:4.718): Not everyone always goes and visit websites. Also, they also had to sift through the different advisories themselves and read through them. And I thought, well, maybe we can make a way to filter this and make it really easy for them to find, I only care about these vendors. I only care about these products. And I want to understand where these products are manufactured or who are their headquarters located at. I want to understand the
Aaron Crow (7:17.310): Mm-hmm.
Aaron Crow (7:21.937): Right.
Dan Ricci (7:34.424): the CVSS score, the severity of it and start to break it down. And I was like, well, I could take that, you know, that information that was in previously an HTML format. Now it's in JSON through the C staff format that they do, but net, but provide it in a way that and visualize it so they can quickly find what they are looking for. Right. Like I mentioned with the vendors and products, then start to prioritize it visually and then create a means where they can
Aaron Crow (7:58.761): All right.
Dan Ricci (8:3.534): export it as like a CSV format because a lot of small medium-sized organizations are working with CSVs and Excel documents still. So lowest common denominator, right? Because these small companies don't have developers. They don't have a team to build tools and they don't have the time either. I thought I'd...
Aaron Crow (8:14.889): Sure. At best, right?
Aaron Crow (8:24.082): Thank
Dan Ricci (8:30.220): I have, I can make time to do this and I can create a dashboard that could start to help them. So that was really the genesis of all. And it went through iterations. mean, I was building like the earliest forms of the ICS surprise dashboard and like, know, pivot tables and slicers and, know, charts and grass and Excel, and then building them out that way. And then like sharing them with people and saying, and getting their input like on, do you think this is useful? I mean,
Aaron Crow (8:32.774): Mm-hmm.
Aaron Crow (8:58.938): All right.
Dan Ricci (8:59.916): What do you think about this? And when I was doing assessments in the DoD, I would create a lead behind document or a lead behind Excel with a dashboard pivot table of all applicable CVEs for their products and leave that behind. was going, I said, well, this is just a snapshot in time. I really need to build something that is.
Aaron Crow (9:17.894): Mm-hmm.
Aaron Crow (9:22.640): Okay.
Dan Ricci (9:28.910): update it and maintain. that's kind of where it came from on that. That's where it came from. Around 2020 and 2021, I started looking at what platform I was going to put it on, how I wanted to build it. obviously, a lot of people use Elastic and use Kibana to build dashboards. But I didn't want to pay a significant amount of money or even a monthly
Aaron Crow (9:54.387): Sure.
Dan Ricci (9:57.902): fee for something that I was going to give up for free. I discovered that Google Data Studio, is now Google Cloud Studio, was available and free. And I could build dashboards and provide them publicly. So I was like, OK, I'm going to do this. And that's why I went this direction. could someone easily have done this in Microsoft Power BI? Yeah, absolutely. I built my first dashboards that were
Aaron Crow (10:11.675): Yeah.
Aaron Crow (10:16.748): Yeah.
Dan Ricci (10:24.906): similar to the ICS Advice for Product Dashboards in Power BI for internal use within the organization. I mean, building this public platform was really meant to kind of save a small, medium-sized asset owner the pain and hassle to build and maintain this and give them a tool that they could just easily prioritize their vulnerabilities and a plan of action and milestones towards mitigations.
Dan Ricci (10:54.250): That's another really important point about the CISA ICC survivors. They make the best attempt towards providing a list of mitigations towards addressing the vulnerabilities where I think CVEs, they're great for like on here's the threat, here's the problem, but really doesn't talk about the solution unless you like dig in and like go into looking at the vendors website where at least like CISA is making a really good effort to summarize it well.
Aaron Crow (11:2.566): Mm-hmm.
Aaron Crow (11:9.947): Right, what do I do about it?
Dan Ricci (11:21.612): CISA and IDO national labs. I can't really leave IDO national labs in there because they really support and develop the advisories themselves. And then CISA turns them around and puts them out. But this is like really important for those asset owners to not sit there and... You don't want to sit there and pontificate about the vulnerability itself. You want to take action.
Aaron Crow (11:25.522): Mm-hmm.
Aaron Crow (11:32.525): Yep.
Dan Ricci (11:49.166): If you're looking at it from an OT engineer or as an respect,
Dan Ricci (11:56.504): they don't want to marvel at the problem. They want to fix the problem and move on and maintain their operational availability and integrity of their systems. That's what they want to do. don't want. So whereas like, you know, most of the tools out there that are built, they're built from a they're built by cybersecurity professionals, which, you know, we are, but they're built towards that audience. You know what I mean? And they're built towards that user. I tried to like.
Aaron Crow (11:59.302): Right. Correct. Yep.
Dan Ricci (12:25.518): the difference in my dashboards where they can also help that audience, a cybersecurity analyst, but they could also help an asset owner in starting to address their vulnerabilities. That was my thought process here. And that's where I continue to look at where I can make improvements, maybe make new dashboards that help them identify, more rapidly identify the vulnerability.
Aaron Crow (12:28.022): Sir.
Aaron Crow (12:39.545): Yeah.
Dan Ricci (12:54.606): severity, how severe it is or whether they're either going to have to patch it now, later, or never. And that's pretty much been the methodology for OT vulnerability management, right? Because you're in an environment that you can't just simply patch. There's a whole process to doing any sort of vulnerability patch management in an OT environment.
Aaron Crow (12:56.786): Right.
Dan Ricci (13:23.810): because the risk to operation availability is so much higher than your IT environment. And those were all these things that were in the back of my mind thinking about when I go and try and develop a dashboard. I think.
Aaron Crow (13:24.205): Yeah.
Aaron Crow (13:31.590): 100%. Yeah.
Aaron Crow (13:47.332): Well, you you hit on so much there, You saw need, you saw a gap, you saw something that you could provide value. I want to come back that in a minute, because I'm seeing your shadow box behind you, and I want to talk about that transition that you made as well. But you hit on something that's really important, and most tools in this OT space are built for the cyber people.
Dan Ricci (13:59.150): Sure.
Aaron Crow (14:12.914): Again, so you and I, know, I also, you know, hard hats up there. Like I came from an operational background as well, working in power plants, not just as the technology and cyber guy, but working outages, you know, I wasn't an operator, but I was directly supporting operators. So I have a better understanding than some in just the cyber background, right? So to your point, the operator and especially at small and medium size organizations,
Aaron Crow (14:39.728): A lot of times that operator is the one that has dual hats. They're wearing the operator hard hat and make me their primary responsibility is to make sure that the thing works. The process works. The plan is up and running the manufacturer. They're sending widgets, whatever they're producing or doing safe, available, reliable, et cetera. Their secondary tertiary, maybe even fourth, fifth or sixth responsibility down the list to cyber security. Right. It's a.
Aaron Crow (15:7.064): If I have time and I've done all the other things on my list, yeah, I also have to do these other things that are cyber related. So we have all these things. And when you say what you said this minute ago, we don't just always patch, right? You take a cyber person out of an IT world and give them and drop them in an OTSpace and say, Hey, I've got windows XP and I'm not going to remove it. And I'm not going to patch it. Their heads explode. But what do you mean? I know I sound like a broken record.
Aaron Crow (15:36.028): through the audience that's heard me talk about this, but I really want to beat that in. And there's other ways, like you can mitigate risk in a lot of different ways. And in OT, we mitigate things. In IT, of course, you would patch it. You'd kick off a Windows XP machine. You'd never let it on your network. There's just no reason for it. But in an OT world, that's just not the case. So there's a lot of other ways that I'm going to, in fact, many times I'm going to say, I'm not going to patch that because I'm afraid it's going to break. And I'd rather
Aaron Crow (16:4.540): put a different mitigation, turn off services, put in an additional firewall, like restrict access to physically being in person. Like there's a lot of different things that you can do in this OT space that mitigates those things. But to your point, and what I love about your dashboard is yes, it offers mitigation options, which is what CVEs do, right? They do tell you some things that, can, know, CVSS, it tells you my risk, but I'm also, there is some mitigations on if you apply this patch, you'll fix this. Or if you,
Aaron Crow (16:33.520): disable RDP, right? If it's an RDP thing and I can't patch it, just turn off RDP and then I don't have to worry about it anymore, right? But to an operator, it's more about prioritizing and really truly understanding the risks and being able to make an informed decision of, and it's not always if or when, a lot of times it's when. Can this wait until my next outage? Can this wait until...
Aaron Crow (16:58.896): the vendors on site to support this. So I had them install it on their equipment. So if it breaks, they're here to fix it. Cause a lot of times that's what happens is there, these, these small entities depend upon their vendors. And when I say vendors, I'm usually talking about the big control vendors, the Rockwells, the Emersons, the Fox boroughs, the Toshiba's, the Schneider, like all that type of stuff. They're depending on those vendors to be the subject matter experts in these spaces. And they're usually uncomfortable making changes to those environments because a lot of times they don't.
Dan Ricci (17:5.752): Yeah.
Aaron Crow (17:28.378): have the ability to change it or if they do change it, they're afraid that the vendor is no longer gonna support it and say, you changed it, you broke it, it's yours, good luck. And they're not willing to do that. So the risk to your point is far higher to patch it than it is to leave it unpatched. Because they know if they patch it and it breaks, they're post. Whereas if they leave it alone, more than likely the risk of the probability that a hacker is going to get that far in.
Aaron Crow (17:55.512): and all these other things are gonna happen in a perfect storm is lower than the almost guaranteed risk that if they break it, they bought it on the flip side.
Dan Ricci (18:5.262): Absolutely. You hit on everything. Everything that we've encountered in the real world when you're presenting the list of vulnerabilities that you identified and seeing their reaction to like, we're not doing that. And you just kind of cut it. And the part of it is you accept what they're saying and then you propose a list of compensating controls to address it. So, okay, that's fine.
Aaron Crow (18:18.962): All right.
Aaron Crow (18:21.681): Ha ha.
Dan Ricci (18:35.938): Learn to live with these risks. These are the compensating controls you're going to implement. And you're going to include a playbook for instant response when something does happen, because it's not a matter of if, it's a matter of when. So have a plan in place. I'm very much becoming a mindset. I mean, I have become have the mindset now that.
Dan Ricci (19:4.448): You just got to deal with it. You're right. Cybersecurity and risk are just part of the game and bad things happen and having a plan to address a plethora of different cybersecurity incidents is better than not having one. that way you can kind of like live, can function within your organization too.
Dan Ricci (19:34.190): Be prepared to address cybersecurity vulnerabilities and threats to your environment. I mean, that's so generic how I said that. what I'm trying to say is I think instead of the FUD, have a plan. And there's plenty of already written playbooks out there for addressing known cybersecurity.
Aaron Crow (19:53.048): Mm-hmm.
Dan Ricci (20:3.566): vulnerabilities and preparing against threats that it's not so much hard for the organization to do. What's hard is making the time to do it. your point resonated so much to me about the dual-hatted, the guy that's dual-hatted that he's got a plethora of jobs of the do already and cybersecurity is like number four on his list, right?
Aaron Crow (20:15.495): Prioritizing, right?
Aaron Crow (20:22.588): Yeah.
Dan Ricci (20:31.342): So, mean, we as a community, what can we do to kind of like help them do that and how can we make it easy for them? live in the United States, we're very much a for-profit. We're a capitalist country and everything is for profit. Not everyone is out there always has the, you know.
Aaron Crow (20:47.516): Sir.
Dan Ricci (20:59.886): word I'm looking for has the.
Dan Ricci (21:6.414): not charity, has like, is more has like, I've lost the word. Anyways, you get what I'm saying. Basically is, you
Aaron Crow (21:14.012): Yeah!
Dan Ricci (21:20.622): We really want to try and help the community out as much as possible. I think consolidating and providing those resources and pointing those smaller organizations to their resources is probably the best thing that we can ever do to improve these smaller asset owners that are critical parts of our critical infrastructure. Because a lot of times, they're the ones that are
Dan Ricci (21:48.110): main suppliers within our overall supply chain itself in the United States, especially when it comes to manufacturing. I saw this when I was working with Toyota. know they're not necessarily purely, I wouldn't consider them critical infrastructure per se, but they're a major manufacturer that could have a major impact to a large group of customers.
Dan Ricci (22:18.144): Obviously, they use local suppliers within or near their plants to provide components. It's not like their cybersecurity requirements flow down to those suppliers because we saw that when Bishuko had a ransomware attack that affected and shut down operations for Toyota themselves. And that was a few years ago.
Aaron Crow (22:40.525): Yeah.
Dan Ricci (22:46.734): So the same thing can happen from a defense supply chain perspective. And that was part of the reason why CMMC was established to hold contractors and also the subcontractors accountable to some cybersecurity standard because there are supply chain risks to the overall.
Aaron Crow (22:52.659): All right.
Dan Ricci (23:11.982): of the United States and our defense capabilities. I I think trying to help those small organizations is really critical for us to maintain larger organizations' cybersecurity that directly impacts the United States. And I think this happens around the world as well.
Aaron Crow (23:37.670): Sure. Well, you know what I love about again, it's like I told you, it's the reason I started this podcast. It's the reason that, you know, I mentor people and talk to people that are looking for jobs and how do I get into OT or how do I do this? Right. It's because to your point, I think we said this before we started recording, but, you and I only have so much time. I can only have direct impact.
Aaron Crow (24:4.312): on so many people and processes and technologies and programs and companies, right? I'm a consultant. I travel and I've had my hands on a lot of different OT programs across big and small from the largest power utility in the country to probably, you know, some of the smaller ones in the country and kind of everything in between for manufacturing, et cetera. But I can't personally design and implement OT cybersecurity across them all. They're just too vast. But
Aaron Crow (24:33.734): How can we impact and level up the playing field? Because at the end of the day, you said something that also important is I live in America. Overall, I live on Earth. I want the power to work in my country. And I want, whether it's in a small town or a big town. And same thing with our allies, whether they're on a different continent.
Aaron Crow (25:1.200): The things that we do here, what I love about Power Utility and a lot of these, you know, the 17 critical infrastructures is they don't really compete with each other, right? So they're very open to sharing lessons learned, what's working well for them, what didn't work well for them, all those types of things. So when I get two CISOs from two different Power Utilities, name whatever ones you want, they have no problem saying, hey, this is the OT program that we're doing. This is the technology that we're doing.
Aaron Crow (25:29.030): These are the attacks that we've gotten recently, like all that type of stuff, because when they share, know, rising tides raise all ships, they all get better. I've even seen a lot of the larger power utilities that are kind of helping their, you know, little brother or sister or whatever the heck you want to call them, the local municipalities, you know, because you look at a Duke Energy and they've got huge programs and teams of people and
Aaron Crow (25:55.558): you know, all this type of stuff, but you look at a regional municipality and we get back to the, you know, wearing multiple hats, they don't have an OT cyber staff. They don't have an OT SOC. They're not hiring EY or Deloitte or PWC because they can't afford it. But that doesn't mean they're not valuable. a chain's only as strong as its weakest link. So if we look at critical infrastructure across our country, yes, Toyota, like you talked about, Toyota's got a big, great program.
Dan Ricci (26:14.636): No, man.
Aaron Crow (26:24.038): But what about the smaller players? Again, Toyota is not critical infrastructure, but the analogy works. What about a smaller one that is building 10 cars a year? Or the wastewater, the water municipalities are a great example of a critical infrastructure in our country that is struggling with budget. It's struggling with knowing where to start. It's struggling with resources and technology and all the things. And we do have some great programs in our country to help, but...
Aaron Crow (26:52.196): I find a lot of times that sometimes they're just sitting and they know that there's a bunch to do and they're just overwhelmed with where do I start? We haven't done anything. I don't have an OT cybersecurity person. I can't hire an EY. I can't hire a fancy consulting company. Where can I start? Which is what I love about things like, again, this podcast, but your ICS advisory project, someone could take that and say, I have this control system. I have these devices. I have these things and narrow down.
Aaron Crow (27:21.786): the list of infinite numbers of advisories that are available to just, these are the ones that are really just us and then be able to prioritize that to say, this is my critical site, these are the systems that it has, these are the ones that are CVSS score 10, let's focus on those first.
Dan Ricci (27:40.984): Yeah, absolutely. Yeah, and while you're saying that, I remember the word, altruistic. We don't always have the altruistic motivations to help these organizations, but we should. I think a lot of us can help out a lot. And I think there's a lot of people in our community that do help, right? And there are a lot of resources. think it's just, I don't know if we always get and communicate to the right group of people.
Aaron Crow (27:48.400): Yes.
Aaron Crow (27:51.314): Correct.
Dan Ricci (28:9.298): We're really good at communicate with each other within the cybersecurity community, but going to like the same like cybersecurity conferences, great networking, great to see everyone, but we don't always touch all the other asset owners that truly need to help because one, they can't afford to go attend the conference themselves. I think the efforts that are being done through the B-Sides conferences are really great. And I think those are a great way for, you
Dan Ricci (28:36.152): those smaller organizations to have opportunity to interact with a lot of fantastic cybersecurity professionals because those are smaller and they're usually within, they're across the United States, different cities and in the world. I think those are really, really great opportunities for, for as engineers go to, also go start going to the, I think cybersecurity professionals need to start going to those conferences that are very specific to those.
Aaron Crow (28:42.332): Yeah.
Aaron Crow (28:48.434): Correct.
Dan Ricci (29:3.438): those critical infrastructure communities that they're trying to help, right? And, you know, if you want to help people in hydro, you can go to Clean Currents, you know, if you're going to go to, if you're going to go to, you know, anything in the electrical sector, you go to gridsetcon, you know, it's just, it really depends. I mean, find the sector that you're trying to help and then go to that conference as a cybersecurity professional advice, you know, going to the same cybersecurity conference that you go to annually and go talk
Aaron Crow (29:6.715): F. F.
Aaron Crow (29:19.833): Yep. Yep.
Dan Ricci (29:33.038): to these groups, submit a paper and present there, I'll guarantee you're gonna have some really good conversations that are different than the same conversations that you're gonna have at other conferences. think that's where we can be at. And maybe there are a lot more people doing this, but for me, I have found going to those other conferences way more rewarding and the conversations have been.
Aaron Crow (29:48.298): Yeah. Sure.
Dan Ricci (30:3.050): more focused on how I could apply my skill set and helping them by talking about the state of the community. State of the cybersecurity community, that's what I mean.
Aaron Crow (30:12.499): Yeah. Well, you know, right. Yeah. But but you know, there's something to that as well. Again, I want to continue to toot that horn of, you know, the advisory program. You legitimately built something because you saw that you believed that it can help the greater community. Now,
Aaron Crow (30:33.220): Not everybody has that exact idea, but I believe no matter where you are, whether you're brand new, you're a year in, I think we all have ideas and benefits that can level up depending on your level of experience and expertise. But if you're trying to break in, I've had a lot of conversations with people that are trying to get an OT cybersecurity or cybersecurity in general, like find something, build something, right? And showcase it.
Aaron Crow (30:59.824): We do this in development. Like we see this with GitLabs and GitHub and things like that, right? Is they build something and they share it and then they grow it and it turns into something. That's really where I see an opportunity for people. If you're trying to build something, you know, or you're trying to get into something, build something, find a niche that is a gap. And it doesn't have to be, you know, a full product. can just be something, again, podcasts like I'm doing. can, presentations at conferences.
Aaron Crow (31:28.174): the ICS advisory project that you've done. Like there's a number of things that we can do to give back to the community. And the really cool thing about it is, is that people know you because of it. You build a brand, you build some credibility and it helps you from a, you're not selling that thing, but that thing opens doors because, yeah, you're the guy that does the podcast. yeah, you're the guy that has the ICS advisory project. Like I know you because of that.
Aaron Crow (31:55.620): And that opens doors, just like I mentioned before, you know, working at EY opened doors because I had that name behind me. But I also, having this podcast opens doors, like having cool conversations with people like you, because the other thing about our network and this, cyber thing that you just talked about, right, is, is is a pretty small environment and small network. Most of us know each other. It's really easy to say, I would not recommend Aaron because he's a jerk or yeah.
Dan Ricci (32:17.485): Yeah.
Aaron Crow (32:24.490): I've talked to Aaron and he is who he, the person that you see on the podcast or on social media, it's the same guy you'll go have a beer with in Tampa, right? It's the same person. Like those are the types of connections and it's such a small world. Like that's how you break into this. I had a mentor tell me a long time ago, all business is the people business. And I say that a lot. But it's true. Like when you realize that, I don't care if you're the sales guy, the CEO, the technical person.
Aaron Crow (32:51.216): You have to be able to have these interpersonal connections to build trust so that way you can move beyond. Cause if we don't trust each other, then we're not going to work together. Whatever you tell me I'm going to take with a grain of salt or sand, whatever. but once I trust you and I know who you are beyond just, you know, you sent me an email and said, Hey, try out my thing. Once I see who you are and I trust that, then I'm going to, it's going to mean more to me than just, I randomly found the ICS advisory project, but I don't know what it is or what, what the value is. I don't know how much.
Aaron Crow (33:21.120): how much stock I'm going to put into it, right?
Dan Ricci (33:23.606): Absolutely. I think it takes time, right? It's not something that happens overnight. it definitely took a while for the ICS Advisor project to build up itself and become a recognized capability that's used within the community. But you know.
Dan Ricci (33:49.324): You know, that was also the thing that I thought I was like, well, I'm going to build this and I don't know if it's going to used or not, but I think it's going to be, I think it's cool. And I think I'll just build it anyways and see what happens, you know? And then, you know, over time I, you know, you figure out ways to like draw attention. mean, I built pretty much, I see as a riser project, through, through LinkedIn and building the connections there. And then, you know, it caught the attention of, of, deal.
Dan Ricci (34:17.678): Peterson and other people that are really big in our community. And it started drawing attention to it. And then over time, I've had other conversations, I think. My first webinar I ever did about the ICS surprise project was with the Nizomi.
Aaron Crow (34:36.625): Mm-hmm.
Dan Ricci (34:39.214): Daniel Jablonski was very kind to invite me on to discuss it. It wasn't my best webinar because it was the first time I ever did, but it was the opportunity to talk about it. After that, I've had other conversations with other groups on hacked planning and other podcasts. But these have been all great opportunities.
Aaron Crow (35:3.196): you
Dan Ricci (35:5.486): Uh, just like talking to you, Aaron, this is a fantastic opportunity to really kind of share the project and, discuss, uh, how it can help the community and everything like that. But also, you know, having these conversations and talking about like, you know, our experience, shared experiences, lessons learned from, uh, working with the larger consulting firms and, know, the challenges that you encounter with being able to, uh, help, help the greater community when you're kind of like.
Dan Ricci (35:34.946): you're stuck doing professional services or staff augmentation only helping that one client can fill stifling. and over time it doesn't feel like you're really developing your skillset more than just like helping this same client do the same thing over and over again. When you know there's other groups that, other clients are ad centers that you could really be helping. like your podcast and having these discussions is really helpful to.
Aaron Crow (35:37.225): Right? Yeah.
Dan Ricci (36:3.926): those ad centers that don't have the opportunity to attend the conferences. And they can sit here and listen and learn and decide whether, hey, I liked what that guest said on your show on Protect It All and understand how that person's project or website or services might be helpful to their organization.
Aaron Crow (36:6.870): Right.
Aaron Crow (36:20.594): Great.
Aaron Crow (36:29.179): Exactly. Right. It's finding that niche and finding, you know, what what do I as a person and my skill set bring to the greater community and how do I double tap on that and expand on it. Right. And showcase it so that people can find it. I can show value. And that's how you grow. Like that's my career. You know, over over the last, you know, more than two decades has been
Aaron Crow (36:54.370): growing and learning, like getting a role that I'm not quite qualified for and learning on the job, right? You know, Hey, by the way, tag, you're it. You're now this OT cyber guy before OT existed and anybody called it that it was like, you're the OT cyber guy. Like, I don't even know what that means, but okay. Right. but it was because I was a willing to say, yeah, put me in coach. and B I was willing to put my ego aside and ask questions cause I didn't know what I was doing.
Aaron Crow (37:23.058): You know, I've been in a power utility a lot of my career, but not from that perspective. You know, I was in a different role. So now I'm learning all this stuff. And a lot of people in OT are doing that now. Right. And, or, you know, maybe again, going back to your, shadow box on your wall, like maybe you're transitioning out of the military or you're changing careers from, you know, one job to another, you were a lawyer or whatever the thing is, and you're wanting to get into cyber security. This is how you do it. Right. You know, you see all these stories about.
Dan Ricci (37:32.194): Yeah.
Aaron Crow (37:52.720): all these requirements and degrees and 10 years experience for an entry level job. That's just what HR says. None of the jobs I've ever gotten, almost any of the job, I can't think of a job where I actually just went to a website, applied for a job and got the interview and then got the job. Almost every job I ever got was because I had a connection. Hey, Dan, it works for Patrick. Hey, Dan, are you guys hiring? Would you introduce me to Patrick so I can talk to him?
Aaron Crow (38:20.470): and he's got a job opening that I'd be interested in. And then you say, Patrick, I know Aaron, I was just on his podcast. I think he'd be a good fit for this role that you have. Why don't you give him a shout? That's how these things work. Going to the conferences, going to the networking things, being on stage, even if the first time you do it, you're not very good. That's okay, because...
Aaron Crow (38:43.250): It's at bats, right? It's getting up and not hitting a home run, getting up and getting thrown out, striking out, all those kinds of things until you get better at it, right? It's really easy in my career where I focused 100 % on technology and being the best firewall engineer or active directory person or exchange or whatever the role or the job that I was in. was always, I wanted to be the smartest in that role. And I got to a place in my career and
Aaron Crow (39:12.848): I read a book and it's called, you know, what got you here won't get you there. And it literally means that, you know, and you see it all the time where, where your top performer in a technology role, especially an engineer or whatever, they're their best person and you, you promote them to a manager or a leadership position and they struggle because they're, they're not, they haven't focused on honing those skills. And it is a different skillset, just like it's a different skillset to be an operator of a power plant and be an OT, savage security person.
Aaron Crow (39:41.966): at a power plant, even though you're dealing with the same technology perspectives, it's a different focus. So I can wear, some people can wear those hats and do them well, but it's all about learning and being willing to ask those questions and reach across the horn. So for you transitioning into all these things that you did in your career, all the way back from being in the Navy, coming into the civilian world, going out to international labs, like all the things that you talked about.
Aaron Crow (40:9.334): Talk about some of that, the lessons learned and maybe even some of the struggles that you had along the way in your career to get where you are today.
Dan Ricci (40:17.934): Oh yeah. mean, the whole thing that I was thinking about as you're going through that, going through, you know, talking about the transition and things like that. I think, I think a lot of people, the hardest thing to accept is like risk. Life is about risk and you have to take risk and you have to go do things that you're not comfortable doing because you'll never grow. That is the heart that, you know, I didn't get that when I was a kid.
Dan Ricci (40:47.374): because I was a very shy, emotional kid when I was growing up. had a very, I didn't have a great childhood. Wah, not everyone had a great childhood, get in line. So I'm not like, this is not a pity party here. But when I took the leap to join the Navy, because that was so far from who I was as a person.
Aaron Crow (40:59.954): Sure.
Aaron Crow (41:5.020): Right.
Dan Ricci (41:16.909): because I wanted to a, I just wanted to change. I needed a big change to get in my life and my environment. And I needed to move away from where I was at. Cause I knew I was never gonna see the world where I was heading in my life. And I needed to take that risk. Hold on one second. We need to pause for a second. Sorry. There's a, it's loud here for a second. And I'll start over.
Aaron Crow (41:36.727): Yep. Sir? Yeah.
Aaron Crow (41:43.600): No worries, I just marked it. Yeah.
Dan Ricci (41:57.673): is being taken out kind of loud.
Dan Ricci (42:1.806): Probably my microphone's pretty sensitive, so I'll start over that way, but I'll get to the point though.
Aaron Crow (42:1.978): No worries.
Aaron Crow (42:6.438): No worries. That's why we edit it for things like this. It happens. No big deal.
Dan Ricci (42:20.686): All right. All right. So yeah, as I was saying, life is about risk and we have to take risks and you can't be afraid of risk. When I decided to join the Navy, that was a great unknown and for me, that was a risk because obviously you could go to boot camp and fail. But I did as best I could to prepare. went to boot camp during boot camp.
Dan Ricci (42:49.388): I failed my first PT test. Wow. Who doesn't when you're like, I wasn't fresh out of high school. I joined the Navy three years after I graduated from high school and did the grind, working on the trucking docks in Chicago, loading trucks, not having a college education.
Aaron Crow (42:55.475): Sir.
Dan Ricci (43:11.726): worked part time at a record store, loved music at that time. So that was like the fun job, but know, working six, seven days a week was a bit of a grind. So I joined the Navy. thought, I know I was interested in the intelligence field. I had, at least I had idea what job I wanted to do in the Navy. And it ended up, actually ended up going to the intelligence community, but not as an Intel analyst. I ended up going into the communication side. But you know, all that, you know,
Aaron Crow (43:16.718): Mm-hmm.
Aaron Crow (43:30.695): Sir. Right.
Dan Ricci (43:40.846): It was just kind of like accepting those changes. Cause all of this was like a bunch of unknowns, right? You have to be comfortable with all those unknowns and then you're gonna go in and you're gonna have like all sorts of like imposter syndrome and everything like that. But all that, you know, uncomfortable feelings you learn to like live with that. So, you know, as I went through like, you know, bootcamp, you know.
Dan Ricci (44:5.922): the schooling I had to go through, because I had to go through a school called Job Oriented Basic Skills because I didn't have a fantastic ASVAB score. I hadn't been in school for three years. I wasn't a great student in high school. But I went and I learned and did the best I can. I did really good at that. Then I went to A school and I just kept on. I had really good mentors in the Navy and I embraced that. I didn't shy away.
Aaron Crow (44:12.698): Sir.
Aaron Crow (44:33.635): Right.
Dan Ricci (44:35.456): I literally grew up during those first three, four years. And had some really good mentors. But did I have ups and downs? Yes. And then I decided, hey, I had another leader. She was an air crewman. I thought, I think I would like being a naval air crewman. So I went to naval air. I decided to get myself in shape.
Aaron Crow (44:41.670): Yeah.
Dan Ricci (45:2.926): It became a really avid runner swimmer. And I went to Naval Aircrew, Minkanen School and Pensacola and I made it through. I went through Sears School. I went through Sears School. I went through all these other schools that were designed to challenge me and grow mentally and emotionally to deal with very difficult situations. all those things, all those schools and training makes me more resilient.
Aaron Crow (45:16.210): All right.
Dan Ricci (45:32.918): Right? I'm not, you know, do I, does everyone get mad and doesn't always handle things the most professionally and excellent? Yes, absolutely. The schools don't prepare you for those things. They prepare you for the certain situations. But, you know, each of those schools though, made me more disciplined and willing to like take risk. know, study is best I can because in the military, it's a very competitive environment.
Aaron Crow (45:46.578): All right.
Dan Ricci (46:2.218): and through that competition and through your peers and everything like that and your mentors, they make you stronger. They make you better at areas that you wouldn't normally be good at. like in school and in high school, if you don't grow up in a home that kind of like builds that discipline and instills it early on, you're not going to have it when you just grow out into like the regular world unless you go into the military.
Aaron Crow (46:2.343): Yeah
Aaron Crow (46:19.922): All right.
Dan Ricci (46:32.948): And you may or may not get good mentors. That is a crapshoot. That is also a risk as well, depending on your job field in the military. the military is a cross section of the United States. People from all over the United States with different backgrounds, value, ethnicities.
Aaron Crow (46:49.945): All right.
Dan Ricci (46:59.790): part of the strength of the military because, know, at the end of the day, you know, everyone's there to get the job done. But I digress. But like, but all the, all that training that I just, I don't want, even though it wasn't technical training per se, a lot of it was physical and mental. When I went to, when I crossed over from being a communications specialist, being a CTO, a communication technician operator to being a
Aaron Crow (47:6.483): Right.
Dan Ricci (47:28.088): Peter Technician Network, which is CTN, which are now cyber, they're cryptologic technician, or now they're cyber technical warfare specialists. Anyways, they changed the rating. Anyways, I digress. But anyways, when I became more of a network analysis guy and I got into cyber defense and cyber operations, I was more disciplined, more mentally prepared to go through that and get through
Aaron Crow (47:42.262): Thank you.
Dan Ricci (47:57.710): those schools and actually apply those skills and real-world operations that I didn't that I probably wouldn't have had, know early on in my career and it just kind of gradually build but like I said the mentors the people that you keep in your life that are possible Positive and uplift you, you know, those are the people that you need to to excel, you know
Aaron Crow (48:7.153): All right.
Aaron Crow (48:11.218): is that we have to be to that. And that's what we're doing. And that's what we're And that's what we're And that's what we're that's what And that's what we're And that's what what we're
Dan Ricci (48:24.588): Are you going to make mistakes? Yeah, absolutely. Did I fail? Did I like have issues with like, you know, tests? Subnetting kicked my ass, you know, when I was first learning how to subnet, I was not great at it. But once I learned it and did it over and over again, I could do, I can do subnetting very well. Reading binary, you know, that was, that took time as well, you know. All that, all that, you know, is just, you know,
Aaron Crow (48:33.168): Right. Right. Right.
Dan Ricci (48:54.286): You just.
Dan Ricci (48:57.070): practice, you work with people that are going to help you overcome those challenges. Anyways, but you get the point. The military is a great organization to get that experience, but it doesn't all have to be done through the military. You can find that within your organization or within this community itself, within the cybersecurity community to help.
Aaron Crow (49:7.797): Absolutely.
Aaron Crow (49:17.984): So.
Dan Ricci (49:26.200): you mentor you towards your goals, you know.
Aaron Crow (49:29.357): Yeah. And I think that's the piece that I love the most. And I'm a huge advocate for veterans and working with people that served. And the main reason that I love having people on my team and that come from prior military is kind of that journey you just said. Most of the time they're getting into something, they're taking a risk, they don't know what it's going to be.
Aaron Crow (49:54.950): They go through difficult schools and it's more than just mental. It's physical and mental. That brings another level of difficulty to things. It's why today I still, I rock every day, all the time, all around the world, wherever I'm at. I do physical things because it makes me show up better mentally, makes me show up better in conversations. When you do hard things, you're more used to doing hard things. So when the hard thing approaches you,
Aaron Crow (50:24.732): You've already done a hard thing. It's not a surprise. So having that and what I love about, obviously in the military, you're not always necessarily gonna get a great boss, but it's the same thing in the private sector too, right? What I love about it though is that you're expecting to work with a mentor and be mentored and be a newbie, somebody that doesn't know what's going on and have that leadership. A lot of times we lack that in the private space.
Dan Ricci (50:28.163): Yeah.
Aaron Crow (50:54.310): That doesn't mean that that's your excuse to not get a mentor. That means it's on you to go find somebody. this, or what I love about this community is there's plenty of us out here that are willing to do that mentorship for others, but you can't just raise your hand and hey, mentor me. Like it's more than that. Like you need to build relationships with people, make some connections, and you'd be surprised how many people will offer or even respond and be able to be willing to, because again, to your point, we said this earlier,
Dan Ricci (50:59.960): Yeah.
Aaron Crow (51:24.210): We want this thing to grow beyond us. I don't want to be the law of the lid. I don't want this thing to be limited to just me. I want this thing to grow beyond me. Like my kids, I've got three kids. Excuse me. I want my kids to be smarter, better, more capable, all the things better than me. I want them to far succeed me, excel me, beat me in every possible way. That's my job as their dad.
Aaron Crow (51:52.720): It's also my job as a leader, as a boss, as a mentor, as a manager, is to make my staff or the people that work for me, or even with me, better than me in all ways. If I'm the smartest person in the room, I'm in the wrong room.
Dan Ricci (52:8.113): No, I get what you're saying. know, suspending ego and listening and is really important. Listening is so important. And also, I mean, I think as I've gotten older is trying to is to continue learning and being a better listener, which makes you a better communicator, you know.
Dan Ricci (52:37.400): But like, like all the going back to like, you know, taking those risks and like, you know, and getting and making those mistakes and then being willing to take more risk again is really important in your life, right? Like I would not have ever considered going to into Naval Special Warfare and screening for that without if I didn't go through like all everything else because
Dan Ricci (53:5.760): I need to be physically prepared and technically prepared to go into that, into those, into that job. And I didn't take those previous risks. I would have not been able to do that. And, and, and although that's all that experience really prepared me for when I transitioned from the military to, you know, civilian, because I wasn't, I wasn't nearly, you know, a lot of people are really
Dan Ricci (53:32.824): coming out of the military, going into the civilian workforce are really, really... There's a lot of apprehension, you know, because it's a lot of unknowns. But my whole career was like going in and like doing unknowns, you know, especially when I went and got commissioned as a warrant officer and went to sea and learned to drive a cruiser as a conning officer.
Aaron Crow (53:41.164): Yeah.
Aaron Crow (53:56.902): Okay.
Dan Ricci (54:1.410): Was I scared shitless doing that? Absolutely. Because I mean, had like, you know, I was, you know, the OOD was probably like maybe like 24 years old and I'm like, you know, 39, almost 40 years old. And I'm like going, I know how dangerous this is. you're, you're don't, don't know if you grasp how, how dangerous this is, but you know, you know, lot of lives are, you know.
Aaron Crow (54:20.700): That's the rule.
Dan Ricci (54:28.042): at risk, doing our due diligence is super important here. really have to like, so I mean.
Dan Ricci (54:38.058): All that basically is.
Dan Ricci (54:42.594): Just think about the worst experience you had or most scary thing you had when you were in your military career and realize, think about how you addressed that situation before you're getting ready to transition into the military and realize it's nowhere near as bad as that. It's just another challenge in your life and you'll be fine. Think about how you prepared for all those other challenges you had in your military career and treat it the same way.
Aaron Crow (55:3.442): next one.
Dan Ricci (55:12.216): you'll land just fine. Talk to other veterans that have transitioned down the military and talk about like their experience. Find someone that's been out for the military for a while because most people that retire in the military usually have three to five different jobs before they find the one that's right for them because it's really different.
Aaron Crow (55:19.172): Yeah.
Aaron Crow (55:33.361): Sure.
Aaron Crow (55:37.040): Yeah. You go from everybody telling you exactly what to do, when to be, where to eat, how to dress, all the things that I was talking to a buddy the other day and he was literally talking about that. goes, I served 20 something years. I was an MP. He goes, I got out and I literally didn't know. I didn't know how to cut my hair. I didn't know what clothes I should wear. He goes, cause I just showed up and they cut my hair. Like I didn't, I didn't have a style. They just cut my hair.
Aaron Crow (56:2.778): You don't think about how little things like that are in those decisions that are just not part of your conversation because you wear a uniform and the uniform is issued to you and you have a certain haircut that you can have and there's regulations and all those things and you get in civilian world and it's just like, have fun. I don't care what haircut you have. Like I've got a beard and I've got, you know, longer hair than I would and like all those things. that's, that's okay for me. I've got earrings, like gosh, my gosh.
Dan Ricci (56:34.594): Yeah, I mean, you're now allowed to be an individual and that's okay. You're not allowed to have to, you don't have to conform anymore. And also another thing that's really important is your ranking uniform is not who you are as a person. That's sometimes hard for some people when they transition out because, know, they were Sergeant Major so and so, and that's who they were known as, or they were Command Sergeant Major, or they were
Aaron Crow (56:42.876): That's right.
Dan Ricci (57:3.916): Master Chief or Command Master Chief or a Master Sergeant, depending on the service that you're transitioning out. But that's not who you necessarily are when you get out. mean, if you're now your first name and what you can do for the organization, that's who you are.
Aaron Crow (57:23.841): Right.
Aaron Crow (57:26.544): Well, and on the civilian side, I see that a lot too, because it's one thing to have a manager title. There's a difference from my perspective between a manager and a leader, right? I can have a manager title and people that work and directly report to me. That does not mean I've earned their respect and they see me as their leader. They report to me because they have to, but you can be a leader without having the title. Like a lot of my career before I was ever an official
Dan Ricci (57:46.913): Exactly.
Dan Ricci (57:52.078): Yeah.
Aaron Crow (57:55.856): having somebody dotted line or direct line report to me, I was seen as a leader, not because they reported to me, I would be their peer, but they would look to me when the shit hit the fan, they'd be like, what should we do? Because you're acting, you're doing something, let's whatever Aaron said, let's go do it, right? Not all the time, of course, but there are scenarios like that, right? And so that's my point is you can get the manager title, but you still have to work and earn their respect and earn the right to be their leader.
Dan Ricci (58:8.579): Yeah.
Dan Ricci (58:14.883): Yeah.
Aaron Crow (58:24.784): And that's different.
Dan Ricci (58:25.038): Absolutely. Absolutely. Yeah. Like a lot of times in the military, mean, by just because of your rank, you're, you're, you're, you know, you're given certain level of respect, but that's not the same when you're transitioned out into the civilian workforce. You're, you're not that rank anymore. You know, no one gives a shit. You're what they care about is.
Dan Ricci (58:52.354): Like what are you doing for the company? What is your role and your responsibilities? And fulfill that role and responsibility. The respect will be earned over time. People appreciate what you bring to the table based off of what your results are. Your actions will really speak very clearly for that organization. Right, wrong, or indifferent?
Aaron Crow (59:4.722): Correct. Exactly.
Dan Ricci (59:19.414): I've made mistakes. I've said things I probably shouldn't have said to people and I've learned that wasn't right. But you know, at the same time though, it happens and you, you, grow up and you move on. You're always, you're always, you're always learning. Even I'm going to be 50 this year and you know, I'm learning. There's, you know.
Aaron Crow (59:39.942): Yep. Not me. I've never said anything wrong and I've never made any mistakes in my entire career. And if you believe that, I have some oceanfront property in Arizona, I'll sell you too.
Dan Ricci (59:47.016): Yeah, and you know.
Dan Ricci (59:52.558): Exactly, exactly. The thing that I to learn over time is like things, and I think this a lot, things that we said and like did early on in our life is not necessarily appropriate these days, you know, and that's, I accept that. But that doesn't define who I am going for as a person, you know. That's why I think is I am learning and
Aaron Crow (60:9.842): Correct.
Dan Ricci (60:22.474): and always trying to improve myself.
Aaron Crow (60:25.682): 100%. I'm right there behind you. I'm 47. And I continue to grow and learn every day. I'm constantly pushing myself to be better in all areas of my life, in work, in personal, my fitness, my health, my relationship with my wife, my relationship with my kids, how I show up at work, the knowledge that I have, the skill sets that I have. I'm constantly learning and growing and having conversations like this to make myself better so that tomorrow,
Aaron Crow (60:55.378): You know, there's an analogy I really love and we can wrap this up, but there's an actor named Ethan Supplee. I don't know if you know who he is, but he used to be the really big actor. He was in American History Acts, the really big overweight fat guy. And he changed himself and he lost hundreds of pounds. I think he was like 500 pounds or something at his heaviest. And now he's like 200 something. And he works out all the time and he's healthy and fit.
Aaron Crow (61:25.978): and, and he, actually had a mentor on a, on a movie, I think it was, or a TV series or something. And, and, and gave him this concept of kill your clone. And the concept is every day at midnight, there is a clone of you. And within, and you have 24 hours to improve yourself. And if you don't, cause at midnight, the next night you fight your clone. And if you haven't improved, then your clone wins, you die and the clone carries on.
Aaron Crow (61:53.724): So every day you have to improve. Now you don't have to like reinvent the wheel. You don't have to, you run a marathon every day. It's just 1 % better every day. But you should do that every single day in some way. Did you read today? Did you improve in your relationships? Did you improve in your health? Did you improve in your technical knowledge? Like you can improve in any area of your life, but you have to improve a little bit so that you have a...
Aaron Crow (62:21.106): you can beat your clone the next day. And when you think about it that way, there's no days off. Like every day I do something. Every day I'm reading, I'm listening to podcast, I'm journaling, I'm exercising, I'm having intelligent conversations to be a little bit better than I was yesterday. Because if you're not improving, you're declining. And that's where I don't really like the idea of retiring in the traditional
Aaron Crow (62:47.964): you know, work 40 years and get a watch and then go sit in front of the TV and not do anything anymore. Because I've seen too many people firsthand that, you you hit that cliff and then you go off the cliff very steeply, right? And it's because you're not using your mind. You're not improving. There's no goal. There's nothing driving you to give back. You you just talked about the ICS advisory project and how you built this thing to give back, to be value add to other people.
Dan Ricci (63:0.258): Yeah, exactly.
Aaron Crow (63:17.426): doesn't mean you have to go out and make millions of dollars, but you're doing something that is keeping you sharp and keeping you vulnerable, not vulnerable, relevant is the word I'm trying to say, right? Relevant and value add to the space beyond just you and your immediate family, which is all great, but what else can you do to continue to drive and keep yourself motivated to wake up and not just sit on the couch? We all have those days where we eat the ice cream and we don't get off the couch. That's okay.
Dan Ricci (63:26.212): It's okay, understand what you're saying. Yeah.
Dan Ricci (63:46.796): Yeah. No, exactly. You need a break. Everyone needs a break. But I mean, you can do a little bit each day that's still growing you without like, you know, exhausting yourself too much or over. You can, you can set aside time. mean, learn a language, learn a second language. Most Americans don't know a second language or find some finding another passion. Do something that brings you joy.
Aaron Crow (63:46.886): Just don't make those every day.
Dan Ricci (64:16.418): That's important because if you do that, you will grow. You might not realize it, but you are growing.
Aaron Crow (64:22.946): And, and all of those things are directly related. So it's really easy to go get us a technical certification because I want to get into OT cyber. And I'm not telling you, you know, listeners listen to me. If you're trying to get into OT cyber, you absolutely have to have the technical skillsets or you won't get hired. And you also need the softer skills. You need to be able to speak. You need to be able to have conversations. You need to be to relate to people. All those softer skills matter too. So all that to say like.
Aaron Crow (64:50.360): All these things are beneficial to you becoming a better human for yourself. And it also naturally translates to your employer and your skillset and what you, the value that you provide to the marketplace is improved in all those areas. The better you get in all these areas, the better your outcome comes on all the things that you're doing.
Dan Ricci (65:10.606): Absolutely.
Aaron Crow (65:11.900): So all that to say, my wrap up question is always, in the next five to 10 years, what's one thing that you see coming for the rise and that's maybe concerning and one thing that's maybe exciting that you see from a maybe cybersecurity, ICS, whatever lens you want to put on it.
Dan Ricci (65:28.990): I think one of the few things or one thing that I think is kind of concerning is I think the level of reliance on automation is going to become really, really heavy with leveraging AI ML within cybersecurity. And I think there's going to be mistakes made with it because we have a tendency to over rely on technology at certain times until like something bad happens.
Dan Ricci (65:57.548): I think that's just a given. I don't think that's anything earth shattering because I think that's just the way we embrace, we are very quick to embrace technology as like kind of like a quick fix, you know, because we are very much an instant gratification society. So I think that's something to be aware of. think.
Aaron Crow (66:16.081): Yeah.
Dan Ricci (66:25.250): I think a lot of analytical jobs are going to become very automated. I think cybersecurity professionals need to be very aware of that and look at areas where they can continue to make themselves valuable to the community. I think that's going to be something that we are going to have to rapidly take on board and prepare ourselves for. I think that's something we really seriously need to look at.
Aaron Crow (66:48.973): Yeah, I agree.
Dan Ricci (66:55.032): Because I think they're going to, I think.
Dan Ricci (66:58.894): I think especially with large organizations that can afford to do this, we'll do it. I think a lot of us, our professionals are going to have to look at where's their next passion and where can they bring value to other than with their current job that's probably going to be automated here very soon.
Aaron Crow (67:19.730): Yep. 100%. It goes back to that software skill that we was talking about is doing other things in addition to just the technology side. Yeah, 100%. What about the positive thing you see?
Dan Ricci (67:33.870): It's hard looking at the positive things right now. I think we're going to see some really, I think through some of the automation, think supply chain risk might really improve over the next five years. I think we might get a better handle on that. Do I think the secure by design will be embraced and adopted more so?
Aaron Crow (67:48.668): Okay? Yeah.
Dan Ricci (68:4.096): I think it depends. I think it really depends on accountability to implement it and whether companies truly, if they say that they implement, whether they keep it going and keep it sustained. I mean, we understand why.
Dan Ricci (68:31.958): why and where we got to this place, right? Because there's a, we really want to rush, you know, products to the market and we don't want to spend a lot of time investing in, you know, developing software from scratch where it was easier to just, you know, incorporate, you know, libraries and other dependencies into your software product to get it out the door. My advice, you know, designing it all from scratch. I think
Aaron Crow (68:55.616): All right.
Aaron Crow (69:0.582): Yeah. And until they can't.
Dan Ricci (69:2.294): I that's going to be a challenge. think secure bed design is great. I think it's going to be expensive and certain companies will definitely adopt it and others will just continue probably going along with it as is. I think I don't think it's going to be uniform. Yeah, until they can, until some sort of regulatory requirement and fines are hefty enough to hold them accountable, but we'll see, you know.
Aaron Crow (69:30.066): Yeah.
Dan Ricci (69:31.096): It's going to be an interesting ride over the next four years. that's all I can, I'll just leave it there.
Aaron Crow (69:34.886): Yeah. Yeah, 100%. All right, so call to action. How do people get a hold of you? Find out more about the ICS advisory project. Where are you going to be speaking, being at, all that kind of good stuff?
Dan Ricci (69:47.604): yeah. So the ICS Advisory Project has a website, www.icsevisoryproject.com, or you can just do a Google search for ICS Advisory Project. It's updated as advisors come out on Monday or on Tuesdays and Thursdays. And then you can sign up and get the weekly summary sent to you via email through our
Dan Ricci (70:17.102): through the website. I send those out early Monday morning or midnight on Sunday or Monday. And you'll get a copy of the Excel file summary of all the advisories I find outside of the CISA ICS advisory. So even if there's not a CVE associated, some vendors put out advisories anyways, and I include those along with the slide deck.
Aaron Crow (70:42.108): Sure.
Dan Ricci (70:46.298): that I do a summary of all the advisory project dashboards for that week. And then where I'm going to be, where I will be at next conference, I'll be at the CSA Level 0 Conference that's coming up here, since I'm on the board for that, for the awards board. And then I will be at the NRECA...
Dan Ricci (71:14.488): CyberTech Co-op Conference in Colorado in June. I plan to be running the packet capture challenge table there for Ampex. And that'll be a very exciting thing. We're going to have it set up where there's going be four laptops with different packet capture challenges of OTICS protocols that people can then find the...
Aaron Crow (71:18.171): Okay.
Aaron Crow (71:41.304): Awesome. Yeah.
Dan Ricci (71:42.776): find the specific flag associated with the challenge. I think that'll be a lot of fun. We thought it would be a good idea to have something hands-on because conferences don't always have hands-on things like that. The last one had a really, really awesome table for soldering and building your badge at the last conference in Crystal City. So this year, that's the one I'll be supporting.
Aaron Crow (71:49.644): Yeah.
Aaron Crow (72:3.034): All right.
Dan Ricci (72:12.759): Other than that, I'll announce whatever conference I'm going next. I won't be at S4 this year, unfortunately, but next year, hopefully.
Aaron Crow (72:15.666): Okay.
Aaron Crow (72:22.041): Well, that's this point. I always like seeing everybody at all these, at these different conferences, but now there's just so many that we can't go to them all. It's impossible. There's just too many to spread that thin. So I get it. I get it for sure. Well, hey sir, I really appreciate your time. Awesome conversation. A lot of good info. Definitely reach out folks. We'll put all the links in the show notes. So definitely check that out. Reach out to Dan. He has a lot of...
Dan Ricci (72:33.472): Absolutely.
Aaron Crow (72:48.700): A lot of information, obviously check out ICS advisory project, really cool stuff there. If you are an asset owner, you should definitely be looking at that and narrowing down the advisories that are specific to your environment to help you communicate the risk and understand and prioritize the risk for your environment based on advisories and known releases based upon that stuff. So thanks again for your time today, Sarah. I really appreciate it. Until next time, I'll see you then.
Dan Ricci (73:16.546): Likewise, thank you.
Aaron Crow (73:17.894): Yeah.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.