Ep 47: The Intersection of AI, OT, and Cybersecurity with Sulaiman Alhasawi | PrOTect IT All
HomeEpisodes › Episode 47
Episode 47
Episode 47 Interview

The Intersection of AI, OT, and Cybersecurity with Sulaiman Alhasawi

Mar 3, 2025 00:48:48 with Sulaiman Alhasawi
OT SecurityCritical InfrastructureAIRisk ManagementRansomware

Watch This Episode

In this episode, host Aaron Crow is joined by Sulaiman Alhasawi, a cybersecurity expert based in Kuwait. Sulaiman shares his journey into OT security, beginning with his PhD research in Liverpool and leading to his creation of ICSrank.com, a search engine for OT devices. 

 

The discussion gets into individuals' unique cybersecurity paths, emphasizing the importance of learning from diverse experiences. They explore the challenges asset owners face in understanding vulnerabilities, the role of AI in cybersecurity, and the international perspective on OT security. 

 

Throughout the episode, Aaron and Sulaiman highlight the significance of community, knowledge sharing, and taking actionable steps to improve cybersecurity posture in critical infrastructure. Whether you’re an industry veteran or a newcomer, this episode is packed with insights and practical advice to help you protect it all.

 

Key Moments: 

01:10 Sharing Diverse Experiences

05:44 Simplifying Asset Management Challenges

08:15 Action Transforms Ideas to Value

11:44 Unexpected Targets in Cyber Attacks

13:20 "Obscurity Isn't Security"

16:50 Simplifying Cybersecurity Communication

21:12 Unintended Internet Exposure Risks

24:49 Podcasting for Community Impact

28:53 OT's Vital Role in Hospitals

32:26 Diverse Experiences in Power Plants

35:54 OT Data Integration Priorities

36:55 Prioritizing Safety Over Immediate Updates

42:10 Global Business Resource Allocation Challenges

46:08 Finding Our Podcast & Resources

47:25 Global Unity in Shared Struggles

 

About The Guest : 

 

Sulaiman Alhasawi is an active researcher  in ICS/OT cybersecurity, with a PhD specializing in securing critical infrastructure. He is the founder of ICSrank.com, a platform dedicated to discovering and assessing security risks in Industrial Control Systems (ICS), Operational Technology (OT), and Industrial IoT.

As the host of the ICS Arabia Podcast, Sulaiman brings together global experts to discuss cutting-edge topics in OT security, bridging the gap between research, industry, and real-world cyber threats.

His latest research, "How to Find Water Systems on the Internet", was featured in SecurityWeek magazine, shedding light on OSINT techniques used to uncover vulnerable water infrastructure. (Read it here: https://zerontek.com/zt/2024/09/30/how-to-find-water-systems-on-the-internet-a-guide-to-ics-ot-osint/)

Follow Sulaiman for insights on ICS/OT security, threat intelligence, and ethical hacking:

 

 

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]



Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

 

Chapters

01:10Sharing Diverse Experiences
05:44Simplifying Asset Management Challenges
08:15Action Transforms Ideas to Value
11:44Unexpected Targets in Cyber Attacks
13:20Obscurity Isn't Security
16:50Simplifying Cybersecurity Communication
21:12Unintended Internet Exposure Risks
24:49Podcasting for Community Impact
28:53OT's Vital Role in Hospitals
32:26Diverse Experiences in Power Plants
35:54OT Data Integration Priorities
36:55Prioritizing Safety Over Immediate Updates
42:10Global Business Resource Allocation Challenges
46:08Finding Our Podcast & Resources
47:25Global Unity in Shared Struggles
Read the full transcript

Aaron Crow (0:0.962): Hey, welcome to the show. this is the protected all podcast. I'm really excited about this episode. I think you may be as far as distance away from me, the furthest away guests that I've ever had on my podcast. So thank you very much. Why don't you introduce yourself? Tell us where you that you're sitting today. and, and a little bit about your background in OT and cyber security.

Sulaiman Alhasawi (0:21.574): Thank you, Aaron, for having me. My name is Sulaiman Al-Hasawi. I'm from Kuwait. I started my journey in OT security in 2012 when I did my PhD in Liverpool, UK. And since then, I'm still doing this, mainly research. I also have a product called the website, icsrank.com. It's a search engine for OT devices.

Sulaiman Alhasawi (0:51.078): I'm also the founder of ICS Arabia podcast. We're interviewing all the professional people like Aaron. Hopefully, you'll be my guest one day. So that's it in a nutshell.

Aaron Crow (1:3.884): Of

Aaron Crow (1:7.564): Awesome. So you got started in this and always love this. We all have these different ways that we get into this space. Like, so I came from a IT and technology background and got thrown into OT because I was working in power plants and critical infrastructure. So I came at it from that lens. I didn't cut, you know, I had electrical engineering background, right? So I didn't really come at it from a, know, collegiate.

Aaron Crow (1:32.798): or book side of things or research side. So I always love the perspective of how you come into it in these different ways. And it just goes to show there's, we talked about it before we started recording, we can always learn from each other. Like we all have different perspectives and different experiences and different ways that we got into this. And all of those values and experiences are so valuable to

Aaron Crow (1:55.832): to the greater community and being able to learn from each other. Cause again, you're going to have experienced and seen things that I haven't and vice versa. And if we can sit down and put our egos aside and you know, I don't have a PhD. Like I don't have any of those things, but I know that I can provide value because of my experiences and you have all a lot of experiences that you can provide value to. So that's what I love about this community and this space. Cybersecurity seems to be a unique place that,

Aaron Crow (2:22.712): people, practitioners and experts from different backgrounds are willing to put their differences aside and really work towards the goals of improving the cyber posture of whatever thing they're trying to protect.

Sulaiman Alhasawi (2:38.195): Sure, Absolutely. I totally agree with you. We all learn from each other. We share knowledge together. And I like the community. Really, I love it. It's very different than the other cybersecurity communities.

Aaron Crow (2:46.370): Yeah. Yeah. So, so what, what made you start with the ICS rank? So I love the idea. So why don't you tell us a little bit about a more listeners may or may not know what it is. Why don't you dive into a little bit about what that is and what the purpose and kind of goal of why you started it what it's turned into.

Sulaiman Alhasawi (3:7.058): Okay, so ICS rank idea, but it goes back to my research, my study during my PhD. It was deeper than that during the research. The idea was to develop a framework to assess the OT devices on the internet. I remember in 2014, I looked at Chodan, I think it just came out maybe, and I saw PLCs and SCADA and Echema, you name it. And I said, wow, that's interesting.

Sulaiman Alhasawi (3:37.276): So I had a question, how to rank those devices? mean, how secure are they? How to assess them? So I developed a methodology like using open source intelligence data. So the more data about a device, maybe it could show you the posture or the security or the criticality of this device. And that's the risk of this device that can happen. So.

Sulaiman Alhasawi (4:5.638): times it goes on and then I finish the framework, my study. Then I said, why don't I make it real? So I developed a tool, a simple tool. Now it's still small, it still not has all the functions that I mentioned in my research. But the idea of it was to find the devices.

Sulaiman Alhasawi (4:30.864): like HMI, Scaria, whatever, using major search engines like Shodan, Synthesis, ZoomEye, and other search engines, of course, that I could have my hand on. So the idea or the motivation was to make it easier for asset owners to filter out devices by their vendor names and product names. Because many asset owners, don't know how to find the ICS devices and they don't know

Sulaiman Alhasawi (5:0.602): if they are exposed or not. that was the idea. I know Shodan has done this very well, but still Shodan don't give you the categories listed like I do in my tool. And the tool is still small. The next version will be out maybe this month. It will have more features, more capabilities, of course. So that's the idea.

Aaron Crow (5:25.590): So, thinking so first that that's amazing. And you're so right. Like these asset owners, they have so many devices that they don't exactly always even know which versions they have. and sometimes just narrowing it down to Rockwell or GE or Schneider, Yokogawa or whatever the thing is really helps them to say, cause you look at show dances or, or, or a lot of these alerts that come out and it's just like all of these things, the sky's falling. I don't even know where to start.

Aaron Crow (5:53.090): But if I can at least narrow that down just a little bit, hey, I only have Rockwell or I only have, you know, Emerson Delta V or whatever that thing is. If I can start narrowing those things down. And we also know that site to site, even within the same company, they're going to have different, you know, vendors and hardware that's in their space. So understanding those risks and what the real.

Aaron Crow (6:14.350): what the real risk and understanding the vulnerabilities in those spaces helps them to make decisions on how do I configure things? Do I need to update things? Like all that type of stuff is invaluable to them because they have just so much over. It can be overwhelming to look at all the things that I have to do in an environment.

Sulaiman Alhasawi (6:30.640): Yeah, the idea of ICS rank in my research was to cover all the information about the device, like you said, CVEs, web interfaces if they exist, default credentials, any news about the device. So once you filter the device, then it will give you everything available on the internet about this device, whether they are exploits, whether they are...

Sulaiman Alhasawi (6:55.194): You name it, anything that could jeopardize the device. But still, the current one is simpler than the set. Because it's still one man job. I'm still doing it alone. That's why it's slow. And as you know, I'm a family guy, so it's taking time. Yeah.

Aaron Crow (7:6.350): Yeah.

Aaron Crow (7:13.499): Absolutely. Yep. But, but ultimately what I love about that story is all it takes is an idea and we all have, I believe that everybody has those ideas and has great, you know, great things to offer and value to bring to the, the organization that they're in, the larger community. And ultimately, I know it kind of sounds woo woo, but even the world, right? As we can make a change.

Aaron Crow (7:41.528): You know, even a small pebble thrown into a big lake makes a ripple. And that ripple can start out small, but if you throw enough small ones in and you time them in the right place, those ripples can get really big and they literally go across the ocean. And it just goes to show that we can make an impact, right? And little things make a difference. So yes, you're a small thing and it started out with an idea in your head, but how many people have that idea in their head and don't actually...

Aaron Crow (8:8.578): take that action and take it and make it to be something like it. You could have stopped at your research and said, that's a cool idea and put it on a shelf and it could have been a book on a shelf in the back and nobody but you ever got the value of it. Right. But instead you took it that next level. And that's where I challenge people. So I get a lot of folks that are reaching out, you know, how do I get into the industry? How do I, you know, I don't have experience. I didn't come from, you know, that background. came from IT or I came from the military or I came from whatever.

Aaron Crow (8:37.388): That doesn't mean that they don't have value to bring. So think about those types of things. Make, come up with an idea and make something, right? With chat GPT and AI and all these things, the ability to take your ideas and turn them into reality are that much easier, right? It doesn't make it easy. It just means some of those barriers, you don't have to be a perfect coder to be able to build a website to do certain things or build a database. Like there's so many tools out there that can help us and do it so quickly and fast.

Sulaiman Alhasawi (9:5.136): Yeah, totally agree. I I was lucky also that AI came along. it did help me with my research and developing the website. And I mean, the current version is coming and it has more features with the help of AI, of course, because I don't have to search now those websites or read a lot of documents. just give it the idea and it will show you the code. You just have to be familiar a little bit with the programming.

Sulaiman Alhasawi (9:34.278): But I have a computer science background, so it wasn't true.

Aaron Crow (9:36.994): Right. So what's one of the most interesting things, if you could think of, that you found in this process of building this ICS rank and maybe it's one of the vulnerabilities or one of the assets or something that you found along the way that was interesting or scary or funny or I'm sure something comes to mind.

Sulaiman Alhasawi (9:58.610): Yeah, yeah, I mean, because I've been using and digging Shodan and Google, of course, since 2012 or 14, I discovered many things. Now it's not as it used to. Now there are less devices that are exposed when I started. When I started, I used to find the Windows XP that's running ICS. I took snapshots of those devices just for memory.

Sulaiman Alhasawi (10:28.930): I found default credentials, many of them I managed to enter to. I'm exposing now myself. yeah, I also managed to find devices that shows who are the asset owners. That gives hints because they have some domains and you could tell this is water utility. I was amazed and I wrote an article about that because I also write articles.

Aaron Crow (10:36.536): Sure. Yeah.

Sulaiman Alhasawi (10:58.546): blogs. So I wrote an article and that article went boom because it's not easy to attribute devices to who's the owner. because it always show you the ISPs that those devices are running. So but that those devices, they had the clues that who was the owner. so yeah, like I told you.

Aaron Crow (11:27.490): Yeah. Yeah. Well, you know, that that's the funny thing. Again, I get this a lot. And many times it comes from the smaller waste utility, wastewater or, you know, water utilities or, or even small, you know, manufacturing or whatever. And these owners or these plant managers are like, why would somebody want to come after me? We're a small paper mill or we're all small water utility. And you just hit the nail on the head, right? Is a lot of times it's just because they found it. It's because it showed up on showdown or they ran across something or somehow it came in their sphere.

Sulaiman Alhasawi (11:28.281): in.

Aaron Crow (11:56.780): and they're just attacking it because it's there. They're attacking it because they can. They don't necessarily even know what it is or what it does. They're just, it's opportunity. It's there, it's available. I'm going to see what I can do with it. And then sometimes they get lucky and it happens to be at a wastewater or water utility or something like that. they're like, okay, I hit a jackpot here because I'm in something that's really valuable instead of a vending machine that's, or the break room ice machine, right? You just never know.

Aaron Crow (12:26.188): what the device is because the PLC could be controlling a turbine or it could be controlling an ice machine in a break room. And you really have no idea just by a PLC. You can't tell the difference between them unless they actually say, know, turbine at power plant A. And sometimes they do.

Sulaiman Alhasawi (12:43.689): Yeah, exactly. Yeah. Yeah. I also saw a joke, you know, from Twitter when I posted that article. I don't know, maybe he was an asset owner. He said, Oh, oh, man, you put this tool, ICS, right now I cannot play hide and seek. He said, because he was trying. He thought that he was hidden, but he wasn't.

Aaron Crow (12:53.517): Haha.

Aaron Crow (13:3.478): Right. No, he wasn't like the ignorance is not, is not security, right? Obscurity by security, you know, that, that, that, that, that whole mindset of it is, is long gone because again, with tools on the flip side, bad actors are able to use these same tools, AI, et cetera, that we're talking about. Showed in, you know, they can be used for good or they could be, you know, the hammer is, is not good or bad. Just like a gun isn't good or bad.

Aaron Crow (13:29.550): A knife isn't good or bad. Any of those, they're just, just inanimate objects. It's what I do with it. I can build a house or I can hit somebody over the head with it, right? Either those are two different outcomes with the same tool. It's not the tools fault. It's what I do with it. Same thing with showdown. Showdown in and of itself is not bad, but in used in the wrong way, it can be used for malicious activities.

Sulaiman Alhasawi (13:47.410): Yeah, I also had this criticism sometimes from some people. They say, why are you right about these art exposing devices? Why you develop these tools? And sometimes, you you go and ask yourself, do I really want to share this knowledge? But you're right. mean, in cybersecurity, you have to share this kind of knowledge because whether you get it or not, the attackers are doing it. and the number of devices now has decreased, which means that

Aaron Crow (14:8.920): Correct.

Sulaiman Alhasawi (14:16.697): I said, know about this, so this kind of knowledge is good, this kind of information is good. Yeah.

Aaron Crow (14:22.030): Absolutely. Ignorance is not going to help you. Not knowing that you're exposed does not make you more secure than knowing you're exposed and actually doing something about it, right?

Aaron Crow (14:36.363): Yeah, absolutely. so what you, you spend a lot of time. obviously ICS rank and this, but you also spend a lot of time doing, you know, OT hunt and researching into those findings. So, so how do those things align and how do you, how do you, you know, kind of dive into finding those vulnerabilities in these OTSpaces and really going after that type of stuff.

Sulaiman Alhasawi (14:58.350): Yeah, what I do, you know, my job, I play different roles in not the security. Sometimes I'm the researcher, sometimes I'm the coder, sometimes I'm a podcaster, whatever. But when I'm, when I have a researcher hat, you know, I just go and find the new filters that shoulder hasn't covered or nobody has covered. And I managed to do that by reading the manuals of famous, you know, vendors. Sometimes by

Aaron Crow (15:7.224): Sure. Yep.

Aaron Crow (15:17.166): Okay, sure.

Sulaiman Alhasawi (15:25.788): crafting keywords from each vendor and test them out, you eventually end up finding a device. And sometimes it's not classified as ICS in Shogun. So when I find a finding, sometimes I ask myself whether I want to include it in ICS rank only or just share it and write about it. So I decided to do both, if I have the time.

Sulaiman Alhasawi (15:55.665): So my writing, if I write, I go more details. I just do the style that I did in my research during study. So I just, I show how I found this device, what are the filters and if there are any CVEs related to this one, what's the impact and et cetera, know, just to make the article valuable for and a simple language for.

Sulaiman Alhasawi (16:24.388): even for the asset owners to understand. So this is relation between my blog and my tool. They complement each other.

Aaron Crow (16:35.982): Sure. Well, and that's powerful. And again, you hit something there I want to double click on and that's, it's really easy in the cyber world. I talk with a lot of folks that are super intelligent. They're super capable, but it doesn't matter how smart you are or I am if we can't make the asset owner understand, right? If we talk over their head or we talk down to them,

Aaron Crow (17:2.218): It's not going to help them improve their cyber posture. So we have to take these really complex, you know, cause not everybody has a, has a, you know, computer science, engineering background or even electrical engineering background or whatever their background is, but we have to make it where anybody can take that information. And okay, what is the, what, what do I do with this? Like what all of this stuff is awesome. I'm glad that all that's there at the end of the day, what I really need to know is, okay, I have this device.

Aaron Crow (17:28.044): Yes, mine is, it is applicable to my device. What can I do about it? Is there a CV? Can I patch it? Can I turn off a notification? Can I monitor? Like what is the mitigation that I can do for this risk in my environment if I have that risk, right?

Sulaiman Alhasawi (17:41.266): Yeah, exactly. And I write various articles for various search engines sometimes. Sometimes I show them how to find these devices in Jordan, sometimes in Zoom. I know it's Chinese. And sometimes using Census. And not just the operator, sometimes I show them if there are issues with the web interfaces, if they are exposed for this product, and if there are default credentials. try my best to...

Sulaiman Alhasawi (18:10.278): to show it and also if they are open for other ports like could also jeopardize the device like telnet or FTP because some of them have telnet and or many of them have telnet unfortunately until now

Aaron Crow (18:30.286): Intel net and default credentials and, you know, HTTP, not HTPS like, and, you know, insecure protocols. Like it's just like a laundry list of all the vulnerabilities there, potential vulnerabilities in these spaces. And, and, you know, that's the other piece in this world that we live in, in OT. We can't just go replace it. You know, in IT, you would never put a windows XP machine on, the enterprise network, right? They just kick it off. They give you a new laptop here, take a brand new windows 11 or

Sulaiman Alhasawi (18:33.266): Yeah.

Aaron Crow (18:59.338): or a MacBook or whatever it is, but they would never allow Windows XP machine in their environment. But we know, and you said it earlier, sometimes Windows XP is running a critical system in production, not sometimes, many times a Windows XP machine is running in these spaces and you can't just rip it out. And I've talked about this multiple times, but we have to know that. it doesn't, it doesn't mean that it can't be secure. just means I have to know those vulnerabilities and how do I protect against those things, right? Not everything is, you know,

Aaron Crow (19:29.326): It has perfect security and and you know, it doesn't even matter if if Windows 11 if I've patched it 100%, there could be a zero day that nobody knows about. There's a vulnerability on my Windows 11 machine. So yes, Windows XP or or know what Vistra and a lot of those different older older operating systems have a laundry list of vulnerabilities that are known. I guess the argument can say, you know, Sun Tzu art of war use your weaknesses and strengths as weaknesses as weaknesses.

Aaron Crow (19:59.210): I know the vulnerabilities of Windows XP. There's a bolt load of them and I can mitigate against them. I may not be able to patch for them, but I can isolate, can make sure it's not on the internet, I can put air gaps in between things, I can monitor those devices for.

Aaron Crow (20:14.134): those vulnerabilities, hey, I know it has a telnet, I know it has this, I know it has that, I can't disable it, so let's monitor it. I only wanna allow telnet from this one IP to this thing. Nothing else should be using telnet on this network, and if it is, boom, I wanna notify on those things. Like those are things that we can do that when we can't just replace a Windows XP machine or patch it because there's not a patch to fix the vulnerability, right?

Sulaiman Alhasawi (20:36.306): Exactly, totally agree. the defense of depth, like you mentioned, and walking around the device is a way to protect these devices and zoom and segmenting the networks and not exposing it to the internet, of course, which is still happening.

Aaron Crow (20:57.007): It's amazing how not too long ago we were putting these devices, I think many times even by accident, we were putting these devices directly on the internet, right? Directly available for access. And these are devices that are controlling physical processes sometimes in really important environments like power plants. And if you could actually kill someone or spin a turbine or break damaged equipment at least,

Aaron Crow (21:21.258): And we had no idea that we were doing these things or the people that were doing them, they weren't doing it maliciously. They were just trying to get their job done. Like ultimately, every time I've come across a problem or any of these things, it almost never has it been a malicious act. It's always been, well, we were trying to get our job done. was three o'clock in the morning on a Friday and we had to get this done. The plant was down. We had to get it back up and running. It was critical. So we did what we could. We didn't realize that we also connected it to the internet when we did this. We were just trying to make it work.

Sulaiman Alhasawi (21:50.918): Yeah, sad, that's sad.

Aaron Crow (21:56.248): But it happens a lot. And part of this is because we don't really, we don't always have a computer engineer or a cyber security person at the plants making these decisions, right? These, these are very capable people. And you mentioned it before you wear multiple hats. You've got your journalism hat and you've got your ICS rank hat and you've got your researcher hat and you've got your practitioner hat. We're all wearing multiple hats. You go into these OTSpaces and these people are, they're not just.

Aaron Crow (22:23.992): They're not just a cybersecurity person in OT that's sitting on the corner just doing OT cybersecurity stuff. They're running the plant. They're going out and they've got a hard hat and steel toe boots and they're in the plan and they're engaging with the equipment. They're physically running stuff and they're returning valves and they're doing all of this stuff. And also they have to also be the person that's responsible for that OT cybersecurity stuff. It may not be their experience. They may just be the most technically capable person at the site. And somebody said,

Aaron Crow (22:53.260): you're it. But it's a a it's a priority of time. It's also a lack of knowledge, just because they haven't experienced it or had that background. They haven't been able to devote time to do it. It's not they're not capable. It's just they haven't spent that much time like I've never done, you know, vulnerability research. You would not. Could I do it? I'm sure I've done a lot of stuff that's similar, but that's never been something I've done. So you wouldn't want me doing those things. I'd rather come to you and say, Hey, why don't you research this thing for me because I'm

Sulaiman Alhasawi (23:10.834): Hmm.

Aaron Crow (23:22.070): not going to do it as well as you. Maybe I want to learn from you, but you don't want me doing that by myself because that's just not my experience and my specialty, right?

Sulaiman Alhasawi (23:29.978): Yeah, I totally agree. I and you don't blame them sometimes because they don't have the resources. I mean, they have to get the job done. So who to blame and maybe how do you educate them to outsource this or train the guys in-house? Well, that's what we're trying to do. I mean, if you cannot afford it, because I heard you once in one of your podcasts.

Sulaiman Alhasawi (24:0.202): The podcasts are for the asset owners who cannot afford to just come and tune in to Aron and ICS Arabia and listen and learn for free.

Aaron Crow (24:10.990): Correct, yeah, 100%. And that's why I do this. I'm sure that's why you do it as well as, obviously it helps me and my brand and all that kind of stuff. But ultimately the reason I do this, this is a lot of work. This comes out of my pocket. I pay for this editing, I pay for the software, pay for the, this is time out of my day that I'm not doing other things. And it's not free. And I do this because I want to make an impact. I wanna make a difference and I want people to learn.

Aaron Crow (24:40.020): It's way that I learned. I do this as much for me. So I'm constantly growing and learning from awesome people like you. But also we're getting to share that with the greater community that we can come back and look and listen to this and watch it and learn for themselves. Like, hey, how can I use ICS rank in my space, in my environment to better understand the vulnerabilities that I have in my environment so that I can better protect them? So if one person

Aaron Crow (25:7.882): listens to this podcast, goes to your website, finds one device that was vulnerable that you didn't know was vulnerable and makes a change to their architecture to make their environment more secure, then this podcast was worth the time that you and I dedicated in my opinion, because one person made a difference in one device and that small pebble in the big pond, it makes a ripple all the way across it, even though it seems

Aaron Crow (25:32.906): insignificant at the surface level, it could have had a big impact that we don't even know about, which is awesome. And I love doing this. And so I get so passionate and I'm smiling about it. I love doing these episodes and just want to continue doing them.

Sulaiman Alhasawi (25:42.413): Yeah.

Sulaiman Alhasawi (25:47.248): Yeah, never underestimate what he do. Like you said, even one person is enough to impact.

Aaron Crow (25:54.222): 100%, 100%. And your environment and your community and your peers and your company, but also in a bigger perspective, we're literally across the world from each other. I'm in the US and Texas and you're in a different climate, a different time zone, like in a different continent, like all of the things. Yet we're able to have this conversation and talk about things that we...

Sulaiman Alhasawi (26:14.737): Yeah.

Aaron Crow (26:19.862): We have a lot in common. I'm a father. I have kids that do this because I want a future where my kids can grow up and they can depend on power and water and have clean water and all those things. Ultimately, I want that for all of my listeners. I want everybody to have that ability to protect their environment and make sure that they can run water systems and run power plants and all those kind of things without it getting turned off or having the vulnerabilities because they didn't have the resources to hire.

Aaron Crow (26:48.812): you know somebody to do it that doesn't mean you can't make a difference right.

Sulaiman Alhasawi (26:53.394): Of course, mean, this is a social responsibility. mean, what we do now, we want to protect the critical infrastructure, which is important for everybody. And this is like very, very critical. know, I've been asked a lot during, I was in television, I was on radio also, they asked me, what's the impact? What if something goes wrong? I always ask them back, can you afford not to have electricity or light, dead water? They said, no, this is what we do. And this is so much.

Sulaiman Alhasawi (27:24.587): serious work, it's very critical. And I think asset owners should look at it this way, that cyber security isn't a luxury or an expense, it's your responsibility to protect it. As long as you have it, you have to learn how to protect anything. If you drive a car or go on a plane, they teach you safety and what to do, what not to do.

Sulaiman Alhasawi (27:49.318): This should be also the mentality or the mindset of asset owners. You have an asset, so how are you going to protect it? As simple as that.

Aaron Crow (27:59.118): 100%. Yeah. It's, I believe it's asset owners obligation to, to make sure that it's safe, reliable and effective. and, and cyber has become part of that conversation. It's one of the risks to the business. It's not just cyber security for cyber security sake. It is literally, you know, it is a risk to the business process and understanding the safe, reliable and effective running of an environment, whether it's a manufacturing facility, but especially in critical infrastructure where people's lives depend on it. Like,

Aaron Crow (28:29.070): If you lose electricity, you lose water, people can die from that, right? Directly, indirectly, having no running water, you can get sick. Having no electricity and hospitals, that's a big, big impact. Backup power only lasts so long and it's a big deal. And that's why I've done IT and OT. I do both of those conversations. I spend most of my time focused in OT.

Sulaiman Alhasawi (28:29.468): Yeah.

Aaron Crow (28:58.348): And that's mainly the reason I'm super passionate about it because, you know, in IT, your email server goes down or your web server goes down and you can't sell a widget. Yes, it's going to hurt you financially, but people's lives are not directly impacted. And when I say that, I don't mean they're not impacted. Obviously, if you lose your job, you know, if you can't make you can't buy food, there's obvious impact, but it's a different impact than, you know, people are directly killed or lives are lost because there's no electricity, there's no running water.

Aaron Crow (29:27.202): You know, I can't do surgeries. There's all these different direct, very one level of separation with O.T. cybersecurity that is, that is very impactful and very huge and as a big risk to the world, to your point, like to the global people on this planet, we're all humans. Like we look different. We have a different background and experience. We have different thoughts and opinions. But again, I'm a father. I have kids. I have a wife. I have a mother. I have a sister. Like I'm a human.

Aaron Crow (29:55.468): I'm on this planet and I want to help other humans to be safe. And I think if we, you know, I don't want to sound Pollyanna or whatever or anything, but you know, it's, really just, if we can weed back all the other stuff that you and I may not agree on or understand or align on, if we can focus on the things that we do, it's easy to have a conversation like this and not get into the weeds of the other things, right?

Sulaiman Alhasawi (30:15.292): Yeah, exactly. I mean, I'm also thankful to discover OT security or ICA security because I didn't know it. I was an IT guy since the 90s, maybe like you. Maybe we share the same page, maybe. And in 2012, when I visited this university in Liverpool, I asked to do a PhD, then the supervisor told me, go read this.

Aaron Crow (30:29.752): Yep. Yep.

Sulaiman Alhasawi (30:45.154): he gave me some papers and I look at the papers it says SCADA security back then. What's SCADA security? So I took it home and I read it and it was something I fell in love you know I couldn't understand most of it but I loved it so I said okay I'm in I told him I'm in so it took me maybe one year or more just to learn the OT stuff you know because I'm not an engineer so

Sulaiman Alhasawi (31:13.394): I had to read, you know, the learning curve was a bit high, you know. I cannot proceed in cybersecurity if I don't understand the theory of OT. So that's what I did, you know, theoretical. But later on, back at end of the study, I started to visit, you know, factories and stuff like that to compare my studies and stuff like that. But yeah, I'm thankful I discovered it. And since 2012, I'm here and I feel I'm happy, you know, with the community like you guys.

Aaron Crow (31:43.846): Yeah. Yeah, it's, different, you know, and, and again, very similar background in that I came from IT and it was about 2010. I think when I, when I really kind of transitioned, I'd spent time in OT, but it wasn't called OT when I, when I started in OT, it wasn't called OT. Um, it was, you know, cybersecurity or compliance or whatever, just technology. Um, and I just happened to be the guy that understood the networking and the technology side of things. And they said, Hey, we need help over there. Go do it over there.

Aaron Crow (32:11.355): So I'm just showing up at power plants like, okay, what do I do here?

Sulaiman Alhasawi (32:18.076): Yeah, exactly.

Aaron Crow (32:19.438): but I've had an awesome fun time doing it and learned so much from doing that and working outages and power plants and doing control system upgrades and segmentations and all the things and manufacturing facilities. over my career, I've been fortunate to go from everything from a nuclear power plant to solar and wind, critical manufacturing, auto manufacturing.

Aaron Crow (32:45.666): you know, pharmaceuticals, like you name it. I've kind of seen a little bit of it all. and it's been really awesome to see at the end of the day, it's just OT. It's just PLC. It's just doing the same thing. Like it's sending a signal and says, somebody wants it to do something. It has a threshold. And if it sees this, then it does this action. It just happens. Is it moving an arm? Is it, you know, adding fuel to a turbine? Is it spinning things differently? Like it's just the same process in a different business.

Aaron Crow (33:13.676): Right? It's really no different. OT is OT is now granted. I need to understand the business side of it too, but as far as just the technology side of OT, it doesn't really matter what vertical you're in. They're very, very, very similar.

Sulaiman Alhasawi (33:26.748): Totally agree. I notice that OTs is very simple. They use a similar language in all kinds of OTs industries because I've spoken in my podcast to medical industries, you name it, oil, gas, water. They always think the same. I think the OT is very simple, simpler than IT. It's not as complicated, it's not as diverse.

Sulaiman Alhasawi (33:51.152): So even I know there are many vendors, but they still speak the same language. And it may have a cybersecurity symbol. And like you said, that routine.

Sulaiman Alhasawi (34:3.458): It affected our mentality, we are people, you know, I don't know somehow so don't you agree?

Aaron Crow (34:11.640): So what do you see coming like the future trends of things? Obviously OT is, I agree, it's simpler, it's different. And part of the reason that those different vendors, they speak the same language is because they're gonna be intermingled, right? That you've got vendor A and vendor B and vendor C all in the same space doing different things on own different assets, but they all have to be able to talk together because it's one ultimate process. It's one planner, it's one manufacturing facility, and they have to work together.

Aaron Crow (34:40.226): because at the end of the day, they're doing this process and then the other one does this next step, but they still have to send, okay, I'm done, it's your turn now, right? It could be as simple as that.

Sulaiman Alhasawi (34:50.044): Yeah, I mean, I've read a lot that those vendors, want to unify the communication, for example, developing OPC and that. And I think there is a setup called Neom. I can't remember the name, but the idea behind it was to make it standardized, you know, like

Sulaiman Alhasawi (35:21.763): like a language, uniform language between the OT, but I'm not sure how far it went. yeah, I mean, like you said, you know, even the protocols are different, but they meet in one, they meet somewhere, they meet somewhere, Yeah.

Aaron Crow (35:38.360): Yeah, I mean, on the business world, would look at that like as an integration, whether it be an API call or something like that, right? It's a way that I can get data from, SAP into my ERP system or data from my network switches in the Splunk. We use Syslog and there's a lot of ways that we send that data, SNMP, et cetera, on the cyber side. We need to do that in the OT space, which is why...

Aaron Crow (36:5.454): The other piece to that in the OT side is we care more about availability and speed than we do. That's why we don't normally encrypt our protocols at that space. I'd rather protect the whole network and not let you see the network traffic at all than encrypt the network and add complexity and overhead to that environment because that impacts the ability for it to do what it's supposed to do. Again, I usually go to the extreme to tell my story, but when I'm in a nuclear power plant,

Aaron Crow (36:34.732): I care more about that they could control that reaction than I do anything else. That's the only thing I care about, right? I wanna make sure that that reaction is kept in control. And it's the same thing I always say when we talk about patching. I said, okay, you're on a 747, you're in the air, and the control system in the plane needs a patch update. Do you want them to patch it while you're at 30,000 feet? Or do you wanna wait till they land and do it in maintenance mode?

Aaron Crow (37:3.330): I mean, for me, I want them to land. I don't want them to do it while I'm in the air. Not if I'm in the plane or my loved ones, right? I'd rather them wait. And that's why we don't pass the same way in OT that we do in IT, because you patch an IT and your laptop reboots and you're in the middle of a zoom call. Nobody dies, right? It's frustrating. It's annoying, but nobody dies. You reboot your laptop and you're all good. Worst case scenario, crashes your laptop. They send you a new laptop. You're up and running. You don't lose data. All your data is in the cloud anyways. That happens in an OT space. People could literally die.

Aaron Crow (37:33.474): Right? We've seen planes that have crashed here recently, the helicopter that hit in the United States, they say that may had a control system issue that they couldn't control it. Like there's all sorts of little things like that. And I don't think it was a cyber issue whatsoever. I'm not saying that, but I'm just saying little things like that can impact and actually cause direct human life loss and damage to physical equipment and all sorts of bad things. It's a different impact and a different reason why we do things differently in OT, right?

Sulaiman Alhasawi (37:33.618): Yeah.

Sulaiman Alhasawi (38:1.418): Yeah, exactly. Totally agree. I patching, think is not the top priority sometimes, you know, for OT people because, or for OT, because like you said, you know, the operation and the business must keep going, you know, and even I know an organization here in Kuwait, when they want to apply patch, you know, they do it in a, like they have a lab, like a demo, you know.

Sulaiman Alhasawi (38:30.835): They tested there sometimes and and maybe when the right time comes, you Maybe they applied if it succeeds in the there and they love so it just depends Yeah Yes

Aaron Crow (38:40.558): That's a great method, right? That's a great way you should do it. Anyways, right? I've built labs for these environments, critical infrastructure, and that's exactly the reason. I'm gonna test it in my lab before I test it in production. And even when I do it for test at production, I'm gonna test on one system, and then I'm gonna wait until that one's done, and then I'll test it on the second system, and then the third, like, I'm not, in IT, I would just push it to everybody, and in OT, I'm gonna be like, I'm gonna do it on one, and I'm gonna wait a day. And then I'll do it on the next one, maybe tomorrow. And it may take me a week to roll it all out, but.

Aaron Crow (39:10.731): I know that I could continue running the plant in that time. Worst case scenario, I lost one system. I've got two or three backups, so I'm good.

Sulaiman Alhasawi (39:14.190): Exactly.

Sulaiman Alhasawi (39:18.714): Yeah, even IT sometimes, know, the patching could lead to problems. you remember, you remember the crowd strike, you know, that happened three months ago, four months ago. was like domino, like domino effect, know, like airports and air flight stopped and banks stopped. Yeah, just from one single update, you know, like, yeah.

Aaron Crow (39:24.451): Cheers.

Aaron Crow (39:27.591): yeah. Mm-hmm. Yep. Yeah.

Aaron Crow (39:38.434): Yep. All around the world.

Aaron Crow (39:44.204): Yep. 100%. So what do you see? So obviously I'm in the States. I do, you know, some international with UK and some places, but from, from what do you see across, you know, other countries and other, you know, how are they approaching OT and are they, are you seeing.

Aaron Crow (40:1.930): as big of a trend, know, obviously U S is really big where we constantly are getting nation state attackers coming after us, et cetera, UK, you're seeing a big effort, Germany, et cetera. What are you seeing internationally with the, the O T response and asset owners really, are they, are they seeing the value or they, are they taking heed? Are they making changes? Like what, are you seeing in international space?

Sulaiman Alhasawi (40:23.834): Yeah, I mean, I can talk about my country and the Gulf region where I belong. I mean, the region, it was hit by my attacks. As you remember, the Triton, the Triton, the Traces, the Triton attack, it was in Saudi Arabia. So since the Shannon, I think the Shannon and Aramco. So, yeah, I mean.

Aaron Crow (40:28.142): Sure. Yep.

Aaron Crow (40:39.694): Mm-hmm.

Sulaiman Alhasawi (40:52.326): The OT security now is getting better in the region because they witnessed those attacks. They know that it could reach them, not just the US and the West. Now there are many conferences. The government of Saudi, for example, they are restricting all industries to follow practices, like best practices, and they developed their own standards. And they fine them if they don't do it. And it's like a rule.

Sulaiman Alhasawi (41:20.700): So yeah, I'm seeing the region is getting better now. I know there are some small entities that still not catching up. Most of those who are securing their network, or the OT, are the oil people, most of them, because they have the money. But I've seen food industries here in Kuwait and simple factories, they still don't know what's going on, even they don't know the term OT security.

Sulaiman Alhasawi (41:49.714): So it's but anyway, it's getting better for the major industry.

Aaron Crow (41:54.510): That's good. Yeah. mean, honestly, it's, really no different here in the States or UK or et cetera, right? Is it's the bigger companies that have the money that are spending the most time and effort. And it's the smaller organizations that don't have the money that they are, they have to prioritize where they're spending their money and their efforts and their people. So, it's, a, it's a common, across, geographies and borders. It seems to be a similar, a similar problem that we're still experiencing that regulation has helped with.

Aaron Crow (42:23.630): You know, grants and funding has helped with, but we're still, it's an uphill battle for a while. Again, I don't want to discourage anyone, but you know, it still means, it doesn't mean you can't do nothing, right? Even with the small budget, limited budget, one person can make a difference, right? You look at tools like ICS rank, like he's talking about, like it's there. Look at that, like take.

Aaron Crow (42:43.946): No, take some action like know where your vulnerabilities are and what can you do about those things? A lot of times it doesn't mean you have to have a staff. It doesn't mean you've got to go buy expensive tools. A lot of things that you can just disable telnet or you know, turn off telnet on your firewall. Make sure you're not on the Internet like little things like that make a big difference.

Sulaiman Alhasawi (43:2.106): Yeah, like you said, know, it's a process. It's small steps, step by step. Read more, follow the community, watch what podcasts. It's not rocket science really. Especially if he's an IT guy, it's simple for him to help in this direction. If they have IT people, of course, I'm sure they have. They could help in this without interfering, of course, with the OT process.

Aaron Crow (43:24.580): Yeah.

Aaron Crow (43:30.912): Sure. So in the next, we've talked about a lot of things. So in the next five to 10 years, what's one thing coming up over the horizon you see maybe that's concerning and one thing that's exciting.

Sulaiman Alhasawi (43:31.803): yeah.

Sulaiman Alhasawi (43:45.751): Well, I think the coming 10 years will witness more AI, of course, we're seeing this, and more integration with the cloud. I don't know whether this is good or not, but we'll see. And I'm seeing the big vendors like Siemens, those big companies, they are going to the cloud, they're pushing it. So I think the asset owners maybe will have to catch up one day with them.

Aaron Crow (44:5.730): Yep. Yeah.

Sulaiman Alhasawi (44:14.630): So this means more integration with the internet, more opening. So this could increase the risk, of course, but it depends. It depends how they implement it. So follow-up technology is not good. It's not black and white. It's not bad. It depends how you use it, how you implement it, how you design it, you segment the network, whatever.

Sulaiman Alhasawi (44:43.576): So yeah, I'm seeing maybe AI, you know, I'm seeing some research using AI to help in dissecting for detection, you know, in the network and also making AI understand more about the processes, is I've seen lately in some research, which could help the human because instead of reading or looking for many alerts, the AI can...

Sulaiman Alhasawi (45:14.510): speed this up for you. So yeah, this is what they call digital transformation, is, yeah, so the bad things, maybe I'm sure the attackers, I'm sure they're coming better now because AI, of course, it helps them to understand the process is better. So if you don't catch up with the bad guys or the attackers, maybe this is bad news for the OT community.

Sulaiman Alhasawi (45:43.556): So it has to be, you have to do your homework and educate yourself.

Aaron Crow (45:51.328): Awesome. Yeah. So, this is the call to action time. So how could people find out about, obviously we'll put all the show in all the show notes, but tell us about your podcast. Obviously you already mentioned about ICS rank. how can people find out more information on that and, and use it in their, in their, in their workplace and, learn more, just kind of give us all the, all the things that people can go to find you and all the things about you guys.

Sulaiman Alhasawi (46:14.864): Yeah, I mean, I'm active in LinkedIn. Just type Al-Hasawi and you will find me. I'm also active in my podcast, ICS Arabia. I interview people, what is called Arabia, because I'm trying to provide Arabic content for the region. But I also interview people from around the world. No problem. ICS Arabia, can find me on YouTube.

Sulaiman Alhasawi (46:44.566): Also my tool ICS rank is free to use, even the next version will be free, but there will be some maybe paid things, it's mostly free. And I will update it, of course, with new vendors, with new products, every time I get my hands on new findings. And that's it.

Aaron Crow (47:8.659): Awesome. Hey, I really appreciate it. was an awesome conversation. Again, I love the fact that you and I are on literally different worlds across the world, right? And we're still fighting the same problems and issues in our spaces, again, from different perspectives and different backgrounds. we've seen a lot of the same issues and have a lot of the same struggles and also doing a lot of the same things to try to fight for the good.

Aaron Crow (47:36.814): right, and to help in these spaces. So thank you very much for your time. I very much hope I get to shake your hand and have a coffee or something with you sometime soon at a conference or at a speaking opportunity or something like that in the future. Thank you very much for your time and joining me today.

Sulaiman Alhasawi (47:42.706): you.

Sulaiman Alhasawi (47:53.458): Thank you for having me and I'm really happy to see you and meet you on the camera. You're doing very good job, great job really in your podcast. Good luck with it.

Aaron Crow (48:5.262): thank you very much i really appreciate it

Sulaiman Alhasawi (48:7.506): Thank you. Thank you.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.